Showing posts with label phishing attacks. Show all posts
Showing posts with label phishing attacks. Show all posts

Sunday, October 20, 2019

Cyber World Reality Facts


sobering cyber stats

millenials often fall victim to cybercrime
  1. Microsoft Security Intelligence Report and Consumer Reports
  2. AARP, “Caught in the Scammer’s Net: Risk Factors That May Lead to Becoming an Internet Fraud Victim,” 2014
  3. Norton Cyber Security Insights Report Q1, 2017
  4. Ponemon Institute, “2015 Cost of Cyber Crime Study: Global,” 2015
  5. Facebook
  6. Federal Trade Commission, “The Top Frauds of 2017”
  7. staysafeonline.org

For more information on this topic review The Facts Get Clued into the Cyber World Reality.

Be Secure Online! Refer to Manhattan College's Cyber Safety site for additional resources.



Refer to Manhattan College's Email Signature Knowledge Base 
Article for instructions on how to create your own email signature. 
Using a Manhattan College email signature is important because it is the perfect opportunity to brand every message you send. By creating a cohesive email signature for each employee on your team, you create brand recognition in every person to whom your employees sends emails. 

Reach out to IT Services with any questions:


Saturday, May 13, 2017

Ransomware Alert - How to Stay Safe

A major ransomware cyber attack has been moving through european countries overnight.  The attack spreads through a combination of phishing and vulnerable unpatched Windows systems.

A number of protections are already in place for important JasperNet services such as Moodle and Self-Service, however, it's important to be vigilant when receiving suspicious or unsolicited messages.  While the spread of the attack has slowed, there is an expectation that the same or similar attack will eventually resume.

What is Ransomware?
In a nutshell, ransomware is a cyber attack that "locks" files on your computer (using encryption) and extorts a ransom payment from the victim to the attacker to unlock (unencrypt) the files.

To read more about this cyber attack, see the link below to Google News:
https://news.google.com/news/section?cf=all&hl=en&pz=1&ned=us&q=Ransomware&ict=clu_top

Wednesday, May 3, 2017

Update Phishing

ITS is working to re-enable accounts.  If you clicked on the link, please follow the steps in this article.


Phishing Attack - Google Docs

** ATTENTION ** Phishing Attack  
ITS is aware of a series of phishing email messages indicating that a user has shared a file with you in Google Docs.  A sample of the malicious message is below:

When the "Open in Docs" link is clicked, a malicious application will request access to your Contacts and Gmail.  
DO NOT ALLOW ACCESS
A sample of the access request is listed below:


If you have clicked the "Allow" button, please contact ITS ASAP by calling x7973.
Google is aware of this issue and is working to mitigate the problem.  As you can see on social media, this is an issue that is widely affecting numerous Google users nationally.

Phishing Attack Happening Now

There is a sophisticated Phishing Scam that is currently circulating on campus.  The message text looks like:
First name Last name has invited you to view the following document:

Open in Docs

Do NOT click on this link.  It is a Phishing Scam.
ITS is working diligently to take back control of the compromised accounts.

Thursday, March 16, 2017

Phishing Attacks Become More Sophisticated

Everyone Is Falling For This Frighteningly Effective Gmail Scam



Security researchers have identified a "highly effective" phishing scam that's been fooling Google Gmail customers into divulging their login credentials. The scheme, which has been gaining popularity in the past few months and has reportedly been hitting other email services, involves a clever trick that can be difficult to detect.
Researchers at WordFence, a team that makes a popular security tool for the blog site WordPress, warned of the attack in a recent blog post, noting that it has been "having a wide impact, even on experienced technical users." (See these people, whose accounts were targeted.)
Here's how the swindle works. The attacker, usually disguised as a trusted contact, sends a boobytrapped email to a prospective victim. Affixed to that email, there appears to be a regular attachment, say a PDF document. Nothing seemingly out of the ordinary.
Get Data Sheet, Fortune’s technology newsletter.
But the attachment is actually an embedded image that has been crafted to look like a PDF. Rather than reveal a preview of the document when clicked, that embedded image links out to a fake Google login page. And this is where the scam gets really devious.



This is the closest I've ever come to falling for a Gmail phishing attack. If it hadn't been for my high-DPI screen making the image fuzzy…
Everything about this sign-in page looks authentic: the Google logo, the username and password entry fields, the tagline ("One account. All of Google."). By all indications, the page is a facsimile of the real thing. Except for one clue: the browser's address bar.

google login pageScreenshot of Google login page 
Even there, it can be easy to miss the cue. The text still includes the "https://accounts.google.com," a URL that seems legitimate. There's a problem though; that URL is preceded by the prefix "data:text/html."

WordFence gmail phishing scamVia WordFence 
In fact, the text in the address bar is what's known as a "data URI," not a URL. A data URI embeds a file, whereas a URL identifies a page's location on the web. If you were were to zoom out on the address bar, you would find a long string of characters, a script that serves up a file designed to look like a Gmail login page. This is the trap.
As soon as a person enters her username and password into the fields, the attackers capture the information. To make matters worse, once they gain access to a person's inbox, they immediately reconnoiter the compromised account and prepare to launch their next bombardment. They find past emails and attachments, create boobytrapped-image versions, drum up believable subject lines, and then target the person's contacts.
And so the vicious cycle of hijackings continues.
For more on email, watch:

Phishing and Online Scams 101
Phishing like a Nigerian Prince isn’t the only way to hack info
Google Chrome users can protect themselves by checking the address bar and making sure a green lock symbol appears before entering their personal information into a site. Because scammers have been known to create HTTPS-protected phishing sites, which also display a green lock, it's also important to make sure this appears alongside a proper, intended URL—without any funny business preceding it.
In addition, people should add two-step authentication, an added layer of security that can help prevent account takeovers. Experts recommend using a dedicated security token as well.
A Google spokesperson acknowledged the scam in an email and directed Fortune to a statement:
We’re aware of this issue and continue to strengthen our defenses against it. We help protect users from phishing attacks in a variety of ways, including: machine learning based detection of phishing messages, Safe Browsing warnings that notify users of dangerous links in emails and browsers, preventing suspicious account sign-ins, and more. Users can also activate two-step verification for additional account protection.
Be on the lookout.
Partially reposted from Fortune.com 1/18/17:  https://www.blogger.com/blogger.gblogID=1213578672055534981&pli=1#editor/target=post;postID=3708843725206120241

Tuesday, February 14, 2017

Learn What It Takes to Refuse the Phishing Bait!




Authors Andrew Mantuano
PublisColumns:

Social engineering attacks come in all shapes and sizes — and not just through e-mail. 
Cybercriminals know the best strategies for gaining access to your institution’s sensitive data. In most cases, it doesn’t involve them rappelling from a ceiling’s skylight and deftly avoiding a laser detection system to hack into your servers; instead, they simply manipulate a community member.
According to IBM’s 2014 Cyber Security Intelligence Index, human error is a factor in 95 percent of security incidents. Following are a few ways to identify various types of social engineering attacks and their telltale signs.
  • Phishing isn’t relegated to just e-mail! Cybercriminals will also launch phishing attacks through phone calls, text messages, or other online messaging applications. Don’t know the sender or caller? Seem too good to be true? It’s probably a phishing attack.
  • Know the signs. Does the e-mail contain a vague salutation, spelling or grammatical errors, an urgent request, and/or an offer that seems impossibly good? Click that delete button.
  • Verify the sender. Check the sender’s e-mail address to make sure it’s legitimate. If it appears that your institution’s help desk is asking you to click on a link to increase your mailbox quota, but the sender is “UniversityHelpDesk@yahoo.com,” it’s a phishing message.
  • Don’t be duped by aesthetics. Phishing e-mails often contain convincing logos, links to actual company websites, legitimate phone numbers, and e-mail signatures of actual employees. However, if the message is urging you to take action — especially action such as sending sensitive information, clicking on a link, or downloading an attachment — exercise caution and look for other telltale signs of phishing attacks. Don’t hesitate to contact the company directly; they can verify legitimacy and may not even be aware that their name is being used for fraud.
  • Never, ever share your password. Did we say never? Yup, we mean never. Your password is the key to your identity, your data, and your classmates’ and colleagues’ data. It is for your eyes only. Your institution’s help desk or IT department will never ask you for your password.
  • Avoid opening links and attachments from unknown senders. Get into the habit of typing known URLs into your browser. Don’t open attachments unless you’re expecting a file from someone. Give them a call if you’re suspicious.
  • When you’re not sure, call to verify. Let’s say you receive an e-mail claiming to be from someone you know — a friend, colleague, or even the president of your college or university. Cybercriminals often spoof addresses to convince you, then request that you perform an action such as transfer funds or provide sensitive information. If something seems off about the e-mail, call them at a known number listed in your institution’s directory to confirm the request.
  • Don’t talk to strangers! Receive a call from someone you don’t know? Are they asking you to provide information or making odd requests? Hang up the phone and report it to the help desk.
  • Don’t be tempted by abandoned flash drives. Cybercriminals may leave flash drives lying around for victims to pick up and insert, thereby unknowingly installing malware on their computers. You might be tempted to insert a flash drive only to find out the rightful owner, but be wary — it could be a trap.
  • See someone suspicious? Say something. If you notice someone suspicious walking around or “tailgating” someone else, especially in an off-limits area, call campus safety.
Partially reposted from:  http://er.educause.edu/blogs/2016/11/february-2017-learn-what-it-takes-to-refuse-the-phishing-bait

Sunday, November 20, 2016

Black Friday, Cyber Monday Phishing Scams

Cyber-criminals are stepping up their cyber-scams and phishing campaigns against shoppers looking for the best deals this holiday shopping season, Zscaler researchers said. Check out some of the common spam and phishing attacks targeting Black Friday, Cyber Monday, and Thanksgiving.
Researchers have already observed a "sharp increase" in phishing and spam activities against online shoppers, and the number is expected to increase over the next few weeks, Rubin Azad, a security researcher at Zscaler, wrote on the Threat Labz blog. "The motive behind these attempts is to steal sensitive user information which includes personal credentials and financial data," Azad said. The data comes directly from Zscaler Security Cloud, with Web traffic activity for over 12 million users at 5,000 global customers.
Walmart 
Examples of phishing attacks include this fake page pretending to be from Walmart:
Tasty Spam: Walmart


Amazon
This phishing page has been designed to look like a legitimate Amazon.com page and attempts to trick users into entering their credit card information:

There are also a number of fake websites offering special Black Friday and Cyber Monday deals. The URLs aren't from legitimate retailers but from unrelated domains such as "busycatholicmoms" and "postyourads." You can see a detailed list on the blog post.
Spam Lines
Zscaler also listed some of the common spam subject lines it has seen targeting online shoppers:
  • Make the Most of Black Friday, with A New smart-phone
  • Brand name laptops on sale for BlackFriday
  • [Black Friday Starts EARLY]Saveup to 90% +FREE BonusItems!
  • Walmart One Day Specials BlackFriday
  • Thanksgiving Specials and BlackFriday Discounts!
  • New Early BlackFriday Door busters are Added EveryDay
  • Shop Black Friday to find discounts on electronics
  • Search major Savings on laptops...On black-friday
  • Limited Time Black Friday Deal
  • 10% off Site-Wide. Get Your Black Friday Shopping Started Today!
All online shoppers should be on the lookout for these and related scams, Azad said. Users should scrutinize the source of emails touting shopping deals to make sure they are coming from legitimate senders. They should also check links before clicking on it to make sure the site is valid. E-mailed invoices are convenient, but cyber-criminals also like using them in social engineering attempts. Users should never be entering sensitive information such as payment information or login credentials on pages which aren't protected with HTTPS connections. And it goes without saying you shouldn't be shopping while on an insecure wireless network.
"We caution consumers to be extra vigilant this holiday season when shopping online," Azad wrote.

http://securitywatch.pcmag.com/spam/329927-tasty-spam-black-friday-cyber-monday-phishing-scams