Showing posts with label scams. Show all posts
Showing posts with label scams. Show all posts

Wednesday, October 23, 2013

Safe Shopping Online

Cyber Monday (the Monday after Thanksgiving) and online shopping throughout the entire holiday season have become increasingly popular in recent years, and the trend is expected to continue this season. According to MarketLive, an e-commerce software and solutions provider, online shoppers in the U.S. are projected to spend more than $54 billion this holiday season, nearly a 17 percent increase over the $47 billion spent last year. The increase in online shopping coincides with an increase in mobile device use, and more shoppers will be using special holiday smartphone apps to find the best deals.
Before you click or tap to buy that "must have" item on your holiday list, check out these tips below to make sure you're doing everything you can to avoid becoming a victim of cyber crime:


  1. Secure your mobile device and computer. Be sure to keep the operating system and application software updated/patched on all of your computers and mobile devices. Be sure to check that any anti-virus/antispyware software installed is running and receiving automatic updates. Confirm that your firewall is enabled.
  2. Know and trust your online shopping merchants. Limit your online shopping to merchants you know and trust. If you have questions about a merchant, check with the Better Business Bureau or the Federal Trade Commission. Confirm the online seller's physical address and phone number in case you have questions or problems.

  3. Look for “https” when making an online purchase. The "s" in “https” stands for "secure” and indicates that communication with the webpage is encrypted. If you submit your credit card information through an organization's website, be sure to look for indicators that the site is secure. Look for a padlock or key icon in the browser's status bar and be sure “https” appears in the website’s address bar before making an online purchase. You should also make sure that your browser software is current and up-to-date.
  4. Password protect your mobile device and computer. It’s the simplest and one of the most important steps to take to secure your mobile device and computer. If you need to create an account with the merchant, be sure to use a strong password. Use at least eight characters, with numbers, special characters, and upper and lower case letters. Adhere to the tenant “a unique password for every unique site.”
  5. Do not respond to pop-ups. When a window pops up promising you cash or gift cards for answering a question or taking a survey, close it by pressing Control + F4 for Windows and Command + W for Macs.
  6. Avoid scams and fraud. Don’t ever give your financial information or personal information over e-mail or text. Be aware of unsolicited communications purporting to represent stores or charities. Always think before you click on e-mails you receive asking for donations and contact the organization directly to verify the request. Information on many current scams can be found on the website of the Internet Crime Complaint Center, a partnership between the Federal Bureau of Investigation and the National White Collar Crime Center.
  7. Do not use public computers or public wireless for your online shopping. Public computers may contain malicious software that steals your credit card information when you place your order. Additionally, criminals may be intercepting traffic on public wireless networks to steal credit card numbers and other confidential information.
  8. Pay by credit card, not debit card. The safest way to shop on the Internet is to pay with a credit card rather than debit card, as credit cards are protected by the Fair Credit Billing Act and may reduce your liability if your information was used improperly.
  9. Print your online transactions. Print or save records of your online transactions, including the product description and price, the online receipt, and the e-mails you send and receive from the seller. Carefully review your credit card statements as soon as you receive them to confirm that all charges are legitimate. Contact your credit card company immediately if you have unauthorized charges on your account.
  10. Review privacy policies. Review the privacy policy for the website/merchant you are visiting. Know what information the merchant is collecting about you, how it will be stored, how it will be used, and if it will be shared with others.
What to do if you encounter problems with an online shopping site?

Contact the seller or the site operator directly to resolve any issues. You may also contact the following:
 
 Your State Attorney General's Office - www.naag.org/current-attorneys-general.php
 The Better Business Bureau - www.bbb.org
 The Federal Trade Commission - http://www.ftccomplaintassistant.gov

For additional information about safe online shopping, please visit the following sites:
 Privacy Rights Clearinghouse - https://www.privacyrights.org/Privacy-When-You-Shop
 Internet Crime Complaint Center - http://www.ic3.gov/media/2010/101118.aspx
 Smartphone Security - Android vs. iOS
 
This material has been adapted from an original article by the MS-ISAC.

Monday, October 21, 2013

Test Your Phishing Knowledge

We're a little over halfway through National Computer Security Awareness Month, so how about a game to test your knowledge of phishing and other email scams? 

It only takes a couple of minutes and it's lots of fun.  Who knows - you might learning something as well!

Tuesday, October 15, 2013

Avoiding Social Engineering Attacks

What is a social engineering attack?

In a social engineering attack, an attacker uses human interaction (social skills) to obtain or compromise information about an organization or its computer systems. An attacker may seem unassuming and respectable, possibly claiming to be a new employee, repair person, or researcher and even offering credentials to support that identity. However, by asking questions, he or she may be able to piece together enough information to infiltrate an organization's network. If an attacker is not able to gather enough information from one source, he or she may contact another source within the same organization and rely on the information from the first source to add to his or her credibility.

What is a phishing attack?

Phishing is a form of social engineering. Phishing attacks use email or malicious websites to solicit personal information by posing as a trustworthy organization. For example, an attacker may send email seemingly from a reputable credit card company or financial institution that requests account information, often suggesting that there is a problem. When users respond with the requested information, attackers can use it to gain access to the accounts.

Phishing attacks may also appear to come from other types of organizations, such as charities. Attackers often take advantage of current events and certain times of the year, such as
  • natural disasters (e.g., Hurricane Katrina, Indonesian tsunami)
  • epidemics and health scares (e.g., H1N1)
  • economic concerns (e.g., IRS scams)
  • major political elections
  • holidays
How do you avoid being a victim?
  • Protect your password.  At KUMC, Information Resources will never ask for your password and you should never share your password with anyone, including your supervisor.   At home, remember that your bank and other companies that you do business with do NOT need your password for any reason.
  • Be suspicious of unsolicited phone calls, visits, or email messages from individuals asking about employees or other internal information. If an unknown individual claims to be from a legitimate organization, try to verify his or her identity.
  • Do not provide personal information or information about your organization, including its structure or networks, unless you are certain of a person's authority to have the information.
  • Do not reveal personal or financial information in email, and do not respond to email solicitations for this information. This includes following links sent in email.
  • Don't send sensitive information over the Internet before checking a website's security (see Protecting Your Privacy for more information).
  • Pay attention to the URL of a website. Malicious websites may look identical to a legitimate site, but the URL may use a variation in spelling or a different domain (e.g., .com vs. .net).
  • If you are unsure whether an email request is legitimate, try to verify it by contacting the company directly. Do not use contact information provided on a website connected to the request; instead, check previous statements for contact information. Information about known phishing attacks is also available online from groups such as the Anti-Phishing Working Group.
  • Take advantage of any anti-phishing features offered by your email and web browser software.

What do you do if you think you are a victim?
  • If you believe you might have revealed sensitive information about your organization, report it to the appropriate people within the organization (call (913) 588-7995 at KUMC). They can be alert for any suspicious or unusual activity.
  • If you believe your financial accounts may be compromised, contact your financial institution immediately and close any accounts that may have been compromised. Watch for any unexplainable charges to your account.
  • Immediately change any passwords you might have revealed. If you used the same password for multiple resources, make sure to change it for each account, and do not use that password in the future.
  • Watch for other signs of identity theft (see Preventing and Responding to Identity Theft for more information).
  • Consider reporting the attack to the police, and file a report with the Federal Trade Commission.
This information was adapted from an original production by US-CERT and republished for non-commercial use as outlined in their Privacy & Use policy.

Friday, October 4, 2013

Recognizing Fake Antivirus Software

What is fake antivirus?

Fake antivirus is malicious software (malware) designed to steal information from unsuspecting users by mimicking legitimate security software. The malware makes numerous system modifications making it extremely difficult to terminate unauthorized activities and remove the program. It also causes realistic, interactive security warnings to be displayed to the computer user.

How can my computer become infected with fake antivirus?

Criminals distribute this type of malware using search engines, emails, social networking sites, internet advertisements and other malware. They leverage advanced social engineering methodologies and popular technologies to maximize number of infected computers.

How will I know if I am infected?

The presence of pop-ups displaying unusual security warnings and asking for credit card or personal information is the most obvious method of identifying a fake antivirus infection.

What can I do to protect myself?

There are lots of things you can do to protect yourself from these antivirus scams:
  • Become familiar with how your antivirus works and make sure it is always up to date.
  • Be cautious when visiting web links or opening attachments from unknown senders.
  • See Using Caution with Email Attachments for more information.
  • Keep software patched and updated.
  • See Understanding Patches for more information on the importance of software patching.
  • To purchase or renew software subscriptions, visit the vendor sites directly.
  • Monitor your credit cards for unauthorized activity.
This information was adapted from an original production by US-CERT and republished for non-commercial use as outlined in their Privacy & Use policy.

Monday, December 3, 2012

12 Scams of Christmas



Are you the 1 person out of 4 that will be shopping from a mobile device this year?  McAfee has just released a list of the 12 most popular scams that online shoppers should watch out for this Christmas season.  It's great list!

  1. Social media scams: Cybercriminals know social media networks are a good place to catch you off guard because we’re all “friends,” right? Scammers use channels, like Facebook and Twitter, just like email and websites to scam consumers during the holidays. Be careful when clicking or liking posts, while taking advantage of raffle contests, and fan page deals that you get from your “friends” that advertise the hottest Holiday gifts, installing apps to receive discounts, and your friends’ accounts being hacked and sending out fake alerts. Twitter ads and special discounts utilize blind, shortened links, many of which could easily be malicious.
  2. Malicious Mobile Apps: As smartphone users we are app crazy, downloading over 25 billion apps for Android devices alone! But as the popularity of applications has grown, so have the chances that you could download a malicious application designed to steal your information or even send out premium-rate text messages without your knowledge.
  3. Travel Scams: Before you book your flight or hotel to head home to see your loved ones for the holidays, keep in mind that the scammers are looking to hook you with too-good-to-be-true deals. Phony travel webpages, sometimes using your preferred company, with beautiful pictures and rock-bottom prices are used to get you to hand over your financial details.
  4. Holiday Spam/Phishing: Soon many of these spam emails will take on holiday themes. Cheap Rolex watches and pharmaceuticals may be advertised as the “perfect gift” for that special someone.
  5. iPhone 5, iPad Mini and other hot holiday gift scams: The kind of excitement and buzz surrounding Apple’s new iPhone 5 or iPad Mini is just what cybercrooks dream of when they plot their scams. They will mention must-have holiday gifts in dangerous links, phony contests (example: “Free iPad”) and phishing emails as a way to grab computer users’ attention to get you to reveal personal information or click on a dangerous link that could download malware onto your machine.
  6. Skype Message Scare: People around the world will use Skype to connect with loved ones this holiday season, but they should be aware of a new Skype message scam that attempts to infect their machine, and even hold their files for ransom.
  7. Bogus gift cards: Cybercriminals can't help but want to get in on the action by offering bogus gift cards online. Be wary of buying gift cards from third parties; just imagine how embarrassing it would be to find out that the gift card you gave your mother-in-law was fraudulent!
  8. Holiday SMiShing: “SMiSishing” is phishing via text message. Just like with email phishing, the scammer tries to lure you into revealing information or performing an action you normally wouldn’t do by pretending to be a legitimate organization.
  9. Phony E-tailers: Phony e-commerce sites, that appear real, try to lure you into typing in your credit card number and other personal details, often by promoting great deals. But, after obtaining your money and information, you never receive the merchandise, and your personal information is put at risk.
  10. Fake charities: This is one of the biggest scams of every holiday season. As we open up our hearts and wallets, the bad guys hope to get in on the giving by sending spam emails advertising fake charities.
  11. Dangerous e-cards: E-Cards are a popular way to send a quick “thank you” or holiday greeting, but some are malicious and may contain spyware or viruses that download onto your computer once you click on the link to view the greeting.
  12. Phony classifieds: Online classified sites may be a great place to look for holiday gifts and part-time jobs, but beware of phony offers that ask for too much personal information or ask you to wire funds via Western Union, since these are most likely scams.
Want more information?  Check out the results of the 2012 Holiday Shopping Study.