Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Thursday, March 17, 2022

Cybersecurity: A Small Business Guide



There is a war going on in Europe and as sad as it is, there is very little we can do about it. However, part of that war does affect small business in the form of cyberwarfare and there is something we can do about that. We will detail cybersecurity best practices targeted at protecting small businesses against data breaches.

You already know that small businesses are particularly vulnerable to cyberattacks, but what can you do about it? How familiar are you with the common security pitfalls for small businesses, and do you know how to avoid them?

Cyberattacks and Your Small Business

Cyberattacks can disrupt your business. 

  • 61% of data breaches directly affect small businesses.
  • Strong passwords, up-to-date antivirus software and implementing best practices are just a few tactics you should employ as part of an overall cybersecurity in Florence SC solution.
  • There are countless types of attacks, but distributed denial of service (DDoS) and man-in-the-middle (MitM) attacks are among the most common.

Each second, more than 77 terabytes of internet traffic takes place online. As such, the internet has become a digital Silk Road that facilitates nearly every facet of modern life. And just as ancient merchants were sometimes beset by bandits on the actual Silk Road, today’s entrepreneurs can easily find themselves under attack from cyber malcontents working to derail companies through theft and disruption.

In recent years, headlines have spotlighted crippling cyberattacks against major corporations. While each corporate cyberattack resulted in millions of dollars in damages, most stories fail to mention the many data breaches that affect much softer targets: small businesses. According to Verizon’s Data Breach Investigations Report, 43% of breaches impacted SMBs.

You may not know when the next attack could occur, but taking proper precautions can hamper or completely stymie a hacker’s attempt at gaining access to your network. To help you avoid the mistakes of Target and, most recently, more than 20 government agencies, we’ve compiled info on why your SMB could be at risk and how to avoid a similar fate.

Why cyberhackers go after small businesses

When it comes to starting a small business, new owners have many decisions to make and often leave cybersecurity measures by the wayside. Unless they focus on shoring up their defenses, they may inadvertently end up leaving points of entry wide open for hackers. That can be a major problem. A report by the U.S. National Cyber Security Alliance estimated that 60% of all SMBs fail within six months of a cyberattack.

According to Towergate Insurance, SMBs often underestimate their risk level, with 82% of SMB owners saying they’re not targets for attacks. They believe that, researchers said, because they feel they “don’t have anything worth stealing.”

Couple that with the costs associated with implementing proper defenses, and you have a situation that’s primed for intrusions. Since data breaches can be devastating to a SMB, owners are more likely to pay a ransom to get their data back. SMBs can merely be a steppingstone for attackers to gain access to larger businesses.

cybersecurity-Florence-300x169.jpgCybersecurity attacks to look out for

Regardless of their target, hackers generally aim to gain access to a company’s sensitive data, such as consumers’ credit card information. With enough identifying information, attackers can then exploit an individual’s identity any number of damaging ways.

One of the best ways to prepare for an attack is to understand the different methods hackers generally use to gain access to that information. While this is by no means an exhaustive list of potential threats, since cybercrime is a constantly evolving phenomenon, business owners should at least be aware of the following types of cyberattacks.

  • APTAdvanced persistent threats, or APTs, are long-term targeted attacks in which hackers break into a network in multiple phases to avoid detection. Once an attacker gains access to the target network, they work to remain undetected while establishing their foothold on the system. If a breach is detected and repaired, the attackers have already secured other routes into the system so they can continue to plunder data.
  • DDoS: An acronym for distributed denial of service, DDoS attacks occur when a server is intentionally overloaded with requests until it shuts down the target’s website or network system.
  • Inside attack: This is when someone with administrative privileges, usually from within the organization, purposely misuses his or her credentials to gain access to confidential company information. Former employees, in particular, present a threat if they left the company on bad terms. Your business should have a protocol in place to revoke all access to company data immediately when an employee is terminated.
  • Malware: This umbrella term is short for “malicious software” and covers any program introduced into the target’s computer with the intent to cause damage or gain unauthorized access. Types of malware include viruses, worms, Trojans, ransomware and spyware. Knowing this is important, because it helps you determine what type of cybersecurity software you need.
  • Man in the middle (MitM) attack: In any normal transaction, two parties exchange goods – or in the case of e-commerce, digital information – with each other. Knowing this, hackers who use the man in the middle method of intrusion do so by installing malware that interrupts the flow of information to steal important data. This is generally done when one or more parties conduct the transaction through an unsecured public Wi-Fi network, where attackers have installed malware that helps sift through data.
  • Password attack: There are three main types of password attacks: a brute-force attack, which involves guessing at passwords until the hacker gets in; a dictionary attack, which uses a program to try different combinations of dictionary words; and keylogging, which tracks a user’s keystrokes, including login IDs and passwords.
  • Phishing: Perhaps the most commonly deployed form of cybertheft, phishing attacks involve collecting sensitive information like login credentials and credit card information through a legitimate-looking (but ultimately fraudulent) website, often sent to unsuspecting individuals in an email. Spear phishing, an advanced form of this type of attack, requires in-depth knowledge of specific individuals and social engineering to gain their trust and infiltrate the network.
  • Ransomware: A ransomware attack infects your machine with malware and, as the name suggests, demands a ransom. Typically, ransomware either locks you out of your computer and demands money in exchange for access, or it threatens to publish private information if you don’t pay a specified amount. Ransomware is one of the fastest-growing types of security breaches.
  • SQL injection attack: For more than four decades, web developers have been using structured query language (SQL) as one of the main coding languages on the internet. While a standardized language has greatly benefited the internet’s development, it can also be an easy way for malicious code to make its way onto your business’s website. Through a successful SQL injection attack on your servers, sensitive information can let bad actors access and modify important databases, download files, and even manipulate devices on the network.
  • Zero-day attackZero-day attacks can be a developer’s worst nightmare. They are unknown flaws and exploits in software and systems discovered by attackers before the developers and security staff become aware of any threats. These exploits can go undiscovered for months, or even years, until they’re discovered and repaired.

How to secure your networks

For small businesses looking to ensure that their networks have at least a fighting chance against many attacks, that generally means installing any number of basic types of security software available on the market, each with varying levels of efficacy.

Antivirus software is the most common and will defend against most types of malware. SpartanTec in Florence SC can help you install the best antivirus software for your business.

A hardware- or software-based firewall can provide an added layer of protection by preventing an unauthorized user from accessing a computer or network. Most modern operating systems, including Windows 10, come with a firewall program installed for free.

Along with those more surface-level tools, We suggest that businesses invest in three additional security measures.

  • The first is a data backup solution so that any information compromised or lost during a breach can easily be recovered from an alternate location.
  • The second is encryption software to protect sensitive data, such as employee records, client/customer information and financial statements.
  • The third solution is two-step authentication or password-security software for a business’s internal programs to reduce the likelihood of password cracking.

As you begin considering your options, it’s generally a good idea to run a risk assessment, either by yourself or with the help of SpartanTec, Inc..

managed-IT-Services-Florence-SC-300x225.jpgCybersecurity best practices

In addition to implementing some sort of software-based solution, small businesses should adopt certain technological best practices and policies to shore up vulnerabilities.

  1. Keep your software up to date. Hackers are constantly scanning for security vulnerabilities, Cobb said, and if you let these weaknesses go for too long, you’re greatly increasing your chances of being targeted.
  2. Educate your employees. Teach your employees about the different ways cybercriminals can infiltrate your systems. Advise them on how to recognize signs of a breach and educate them on how to stay safe while using the company’s network.
  3. Implement formal security policies. Putting in place and enforcing security policies is essential to locking down your system. Protecting the network should be on everyone’s mind since everyone who uses it can be a potential endpoint for attackers. Regularly hold meetings and seminars on the best cybersecurity practices, such as using strong passwords, identifying and reporting suspicious emails, activating two-factor authentication, and clicking links or downloading attachments.
  4. Practice your incident response plan. Despite your best efforts, there may come a time when your company falls prey to a cyberattack. If that day comes, it’s important that your staff can handle the fallout that comes from it. By drawing up a response plan, attacks can be quickly identified and quelled before doing too much damage.

All of this may seem impossible to implement for small business owners. SpartanTec is here to help. We can perform an assessment of your business and put together a plan of attack.

SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence, Charleston

Tuesday, January 25, 2022

Can Your Business Afford A Cybersecurity Breach



Each day, more of our activities are digitalized and bring with them large amounts of personal data that can be easily exploited for profit or influence by those who have the desire and the inclination to go against ethical norms. Cybersecurity refers to the protection of personal data stored digitally.

Your business might not need to worry about data security. What are the chances that your site will be targeted? Your website is unlikely to be among the most important companies in the world so anonymity is not an option.

Even though the likelihood of your company being the target of a data breach is low, there is still the possibility. And the potential consequences can be very dire.

Can you afford to take the chance?

Cyber security should be at the top of your priority list.

Customer Data is Very Sensitive

A website that tracks and collects data on regular customers will give the business an unprecedented view of the person’s daily life. This includes their eating habits, allergies, viewing habits, engagement, divorce, vulnerability, etc.

This data is often used to increase sales in the ecommerce industry. Promoting diapers for new parents and expensive gifts for couples celebrating their anniversaries is a good idea. Although it may seem intrusive and creepy, it is easy to ignore. Persuasion is not the worst thing in this world.

However, customer data that is exposed via a security flaw can be made even more dangerous. Blackmailers could threaten to release the data to the public if the business doesn’t pay them extortion money or use it directly to extract payments from the customers affected.

The fact that the data was leaked will do great damage to the company’s reputation. It is unlikely that anyone will continue to buy goods and services from businesses that have requested their data only for them to not keep it safe. The affected company will lose the trust of their clients.

Regulators are getting more strict

The General Data Protection Regulation (GDPR), which was implemented in the European Union (EU) on May 25, 2018, sets a high standard for EU businesses. Although there isn’t any such broad legislation in the USA, there are still a few reasons to be cautious.

First, the Federal Trade Commission (FTC), which is empowered under Section 5(a), Federal Trade Commission Act, has the power to ban “unfair or deceptive acts and practices in or affecting Commerce”. Their resources allow them to be the de facto protector for customer data.

Second, computer security issues will not be going away, no matter what is in the pipeline. The law will catch up eventually, even though it may seem slow at first. It’s impossible to predict when it will happen, and what retroactively might apply because that possibility cannot be eliminated. Therefore, it is important to act immediately.

cybersecurity-Florence-SC-1-300x200.jpgCybersecurity Attacks Encouraged by Exposed Vulnerability

There are two basic types of security vulnerability. The first is the architectural type. This involves the software and protocols used. It includes compliance with the PCI standard for credit card transactions and use of SSL certificates (Secure Sockets Layer). These certificates verify website authenticity. Two-factor authentication protects user accounts.

You can work with a cybersecurity company to increase security. This option can be used to reduce the risk of architectural or outdated software.

There’s also the procedural type, which involves the steps taken by the business to ensure security on a daily and ongoing basis. This includes the use secure passwords, vetting employees, physical protection of data storage solutions and protection against bots, malware and other network intrusions.

A security-compliant web hosting solution is a good choice for businesses. Top platforms are known to invest in security. To combat open-source vulnerabilities, WordPress users should invest in a strong security system. Plugins are particularly susceptible to attacks. However, a strong platform will not make it less likely that weak passwords can be cracked.

Sharks can smell blood in the water and will move in for the easy catches. Although the business world is not as violent, the same principle applies. If people see that your security was breached they will quite sensibly ask if it can again be done.

Operation are becoming more cloud-based

The internet opened up new opportunities for businesses and created hybrid operational modes. Physical premises were linked to digital ones. A typical business would have offices or multiple offices and a website to encourage people to visit.

This helped to minimize the impact of cyberattacks. An online attack cannot compromise the security of physical stores with on-site locks or guards. This has all changed in recent years, both at the legal and operational levels, largely due to the enormous growth of e-commerce. It’s possible to operate a business without a physical presence.

Everything can be compromised by the internet, even entire businesses that exist (for all practical purposes) in the cloud. An entire company’s infrastructure could be destroyed by a malicious attack in seconds and then disappear forever. Although your business may be still office-based, it is important to know how things are moving.

It’s not rational to make your business vulnerable online for the reasons we have discussed. No matter how small or unknown your business may be, the risks are greater than the cost of creating safeguards.

Call SpartanTec, Inc. now if you’re looking for an IT company that can help protect your business against online threats.

SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence, Charleston

Friday, December 10, 2021

Cybersecurity Professionals In Today’s Modern Day Society



The cybersecurity industry has been around for more than three decades. There has been a lot of changes during these years in terms of the industry dynamics as well as the technological innovations.

These days, there’s an exponential growth happening in the cybersecurity industry. The latter continues to define itself with the development and evolution of new and diverse online threats. Even though there’s a tendency to put the charge on technology, online threats have become extremely diversified. In order to deal with such online threats, companies need cybersecurity professionals who also possess diversified skill sets.

Cybersecurity Experts In Transition

According to the incident’s nature, cybersecurity professionals, which almost always include network security experts and computer engineers, also include investigators with varying expertise, lawyers, communicators, and writers. In case the attack comes with a political agenda, human rights activists, business activists, as well as journalists may also be involved. In case a critical and confidential business email is believed to have been compromised, an internal employee communication specialist may be involved.

These days, a bug in a specific application software may include up to 100 IT experts working to deal with that bug. Each one of them contributes to lower the risk and to guarantee immunity from future threat. This goes to show the extent of the diversity of the cybersecurity industry.

Hiring Reliable Cybersecurity Experts

There are to primary aspects in finding the best candidate. The first one is the skill set, which includes legal analysis and coding. The second aspect includes strategic and instinctive sensibilities that come naturally to people. Additionally, expanding the needed pool of expertise while hiring is going to cover a bigger area in identifying and fighting cyber threats. Whatever your hiring strategy is, it’s crucial to make sure that you have a diversified team of cybersecurity experts or may also consider IT outsourcing.

The Skills Gap

There’s a shortage of IT support expert today. They’re difficult to find and demand a higher salary. On the other hand, there’s a growing number of cybercriminals and their attacks are becoming more complicated by the minute. Most companies these days have a cybersecurity department that is understaffed, which makes the job easier for cybercriminals. Most enterprises, particularly SMEs, can only do little or even nothing to detect, prevent, and respond to cyberattacks. If the gap continues to widen, there will come a time when companies will suffer massive information compromise and data breach that will be costly and time consuming to recover from.

Call SpartanTec, Inc. now and let our team of IT experts take care of all your company’s cybersecurity needs.

SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence, Charleston

Thursday, March 18, 2021

Understanding ransomware and the impact of repeated attacks

 


We know ransomware is one of the greatest threats in cybersecurity currently, and we know that once your organization has been hit, you’re likely to be targeted again. But how much do we understand its impact?

To gain greater insight into the risks of repeated ransomware attacks, we took a look at The State of Endpoint Security Today. This report details the findings of a survey polling more than 2,700 IT decision-makers from mid-sized businesses across ten countries.

Despite the splash ransomware made in 2017, the survey found that organizations are still not fully prepared to face today’s rapidly-evolving threats.


What was the impact of ransomware in 2017? For starters, more than half of organizations surveyed were hit with a ransomware attack last year, most more than once. Traditional antivirus alone appears to be insufficient compared to an in-depth IT Services Florence SC, as 75% of the organizations surveyed were running up-to-date endpoint protection when the ransomware attack occurred.

Perhaps unsurprisingly, the survey also found that ransomware attacks are expensive. The median total cost of an attack was $133,000 – not just the cost of the ransom, but lost hours, downtime, device and network costs, and lost opportunities. And when a business was hit hard, it got costly fast: 5% of respondents reported ransomware attacks that cost $1.3 to $6.6 million.

Arguably more telling than the ransomware statistics revealed by this report are the findings uncovered about exploits and anti-exploit technology. Nearly 70% of IT support Florence SC professionals weren’t able to correctly define anti-exploit technology, even while understanding that it is critical to prevent modern, evolving attacks.

DEEP LEARNING FOR DEEPER CYBERSECURITY

Watch Video

 

More than half of organizations don’t yet have anti-exploit technology, leaving them open to falling prey to these effective tactics by hackers.

There is a lack of understanding around predictive, next-generation technologies like machine or deep learning, with more than half (56%) admitting they don’t fully understand the differences between machine and deep learning. Though the understanding of the need for predictive, next generation technology is trending in the right direction – 60% of respondents are planning to implement such technology within a year – currently only 25% have such technology in place.

The state of endpoint protection and how current attacks are impacting users and administrators may be worrying, but we’ve got good news…

The latest version of Intercept X stops ransomware in its tracks, employs deep learning to identify malicious or potentially unwanted files without having ever seen them before and uses anti-exploit technology to block the techniques attackers use to control vulnerable software.

Find out more about our unmatched next-gen endpoint protection.


Call SpartanTec, Inc. now if you need to know more about our IT and computer security solutions. 


SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com

Serving: Myrtle Beach, North Myrtle Beach, Columbia, Wilmington, Fayetteville, Florence


Tuesday, March 9, 2021

The Challenge of Securing IoT

 


By now, everyone has heard the numbers. Internet of Things is part of a networking revolution that is transforming the world. Cybersecurity experts predict that by 2020 there will be over 33 billion IoT devices deployed, or 4.3 Internet-connected devices for every man, woman, and child on the planet.

Of course, IoT is more than just one thing. There are a variety of IoT devices and categories, each with their own implications.

Consumer IoT includes the connected devices we are most familiar with, such as smart cars, phones, watches, laptops, connected appliances, and entertainment systems.

Commercial IoT includes things like inventory controls, device trackers, and connected medical devices.

Industrial IoT covers such things as connected electric meters, waste water systems, flow gauges, pipeline monitors, manufacturing robots, and other types of connected industrial devices and systems.

The implications for networks, and especially cybersecurity Florence SC, are huge.



Increasingly, IoT devices are being woven into local, national, and global networks, including critical infrastructures, creating hyperconnected environments of transportation, water, energy, communications, and emergency systems. Healthcare agencies, refineries, agriculture, manufacturing, government agencies, and even smart buildings and cities all use IoT devices to automatically track, monitor, coordinate, and respond to events.

While automating decisions and processes at machine speeds can generate revenue, improve our quality of life, make us more productive, and even save lives, it also introduces new risks and widens the threat landscape.

1. Some of the data passing from, to, or between connected devices contains personal information that can be exploited, including locations, names and addresses, ordering and billing information, credit card and bank information, medical records, government-issued ID numbers, etc.

2. When compromised IoT devices are connected to ITnetworks, they can become a conduit for breaches or the injection of malware.

3. Compromised Industrial and Commercial IoT devices can be used to make changes on the manufacturing floor. Operations technology, SCADA, and industrial control systems actually control physical systems, not just the bits and bytes of traditional IT networks, and even the slightest tampering can sometimes have far-reaching - and potentially devastating - effects.

4. Increasingly, IoT is also being integrated into our critical infrastructure. Transportation systems, chemical refineries, wastewater systems, energy grids, culinary water, and communications systems all use IoT devices. The cascading effect of a serious compromise can be potentially catastrophic.

The challenge is that many IoT devices were never designed with security in mind. IoT security challenges include weak authentication and authorization protocols, insecure software, firmware with hard-coded back doors, poorly designed connectivity and communications, and little to no configurability. And most IoT devices are “headless,” with limited power and processing capabilities. This not only means they can’t have security clients installed on them, but most can’t even be patched or updated.

The risk is real. Just last fall, compromised IoT devices were gathered into a massive botnet, causing the largest denial of service outage in history. Unfortunately, the general response by the security industry has been woefully inadequate. Sure, the expo floor at this year’s RSA conference is filled with vendors promoting devices and tools to sooth the IoT worries of organizations.

The problem is that the network teams that need to test, deploy, manage, and monitor these devices are already overwhelmed. Dozens of isolated devices with separate management interfaces have placed a strain on limited IT resources. Large enterprises already need to manage an average of 30 security consoles, connected to hundreds of security devices that usually operate in isolation. This makes gathering threat intelligence a cumbersome and time-consuming task, often requiring the hand correlation of telemetry data in order to identify malware or compromised systems.

And now, specialized security tools being created and promoted for IoT are going to expand the number of deployed hardware-based and virtual security devices even further.

The reality is, IoT cannot be treated and secured as an isolated, independent network. It interacts across your existing extended network, including endpoint devices, cloud, traditional and virtual IT, and OT. Isolated IoT security strategies simply increase overhead and reduce broad visibility. Instead, security teams need to be able to tie together and cross-correlate what is happening across their IT, OT, IoT, and cloud networks. Such an approach enables visibility across this entire ecosystem of networks, allowing the network to automatically collect and correlate threat intelligence and orchestrate real-time responses to detected threats.

This requires a rethinking your security strategy. A distributed and integrated security architecture needs to cover your entire networked ecosystem, expand and ensure resilience, secure compute resources and workloads, and provide routing and WAN optimization.

The Fortinet Security Fabric solves the challenge of security sprawl by integrating your security infrastructure together into a single, holistic framework. This allows you to effectively monitor legitimate traffic, including IoT devices, check authentication and credentialing, and impose access management across your distributed environment through an integrated, synchronized, and automated security architecture managed through a single pane of glass.

In addition to our innovative Security Fabric solution, Fortinet is actively driving the development of IoT-specific security solutions. We already hold dozens of issued and pending IoT security patents that complement our industry-leading patent portfolio and have been woven seamlessly into out Security Fabric framework. Our commitment to innovation helps ensure that Fortinet continually delivers the most advanced security solutions designed to help organizations defend against the continually evolving threat landscape that threatens the success of their digital business and the emerging digital economy.

 

Call SpartanTec, Inc. now for more information about our security solutions and managed IT services. 


SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com

Serving: Myrtle Beach, North Myrtle Beach, Columbia, Wilmington, Fayetteville, Florence


Thursday, December 31, 2020

Cyber Security Assessment Services, Your IT New Year’s Resolution

 

cybersecurityJanuary 1st, 2021 is just around the corner. It’s been a tumultuous 2020 and many people are relieved that it has finally come to an end. The new year offers new opportunities and new beginnings, which are also referred to as New Year’s resolutions. These usually short term promises to be much better next year are generally bleak when it comes to the results. As a matter of fact, only 25% of people will get to the new year and still manage to fulfill their resolutions and just 8% still do their best to improve. How does New Year’s resolutions apply to information technology? If you have a business, you need to prioritize its cybersecurity. This is where cyber security assessment services come in.

How To Bad Cyber Security Habits

The first thing you need to remember is to get rid of the bad habits. For people, objectives such as drinking less alcohol or eating less processed foods may be one of their priorities. But these resolutions are generally difficult to follow through, since people are already used to those familiar things. This could be true for companies too. Before end users and cybersecurity Florence SC leaders can make improvements to their outlook for 2021, they have to get rid of the bad habits, even if they’re difficult to do so.

 

 

Top 3 Worst IT Practices

Free Wi-Fi may be filled with security challenges such as MitM attacks and network spoofing. Despite all these risk factors, 77% of the users continue to connect to the free public Wi-Fi outside offices.

Using Weak Passwords

A lot of people are using weak passwords because they’re easy to remember. Having said that, they also create almost no barrier between your company and hackers. Getting rid of this old habit for good is one good way of starting off 2021.

Failing to Address Security Blind Spots

A few CISOs consider fatalistic methods when it comes to cybersecurity, which means they believe that a system compromise cannot be prevented and therefore, it’s not worth the resources and time to employ a cybersecurity strategy. This is a huge mistake that you must not do. What you have to do is make sure that your company takes a proactive as well as reactive approach to fill all the security gaps that are made obvious by cybersecurity assessment services.

Goals over Resolutions

One of the reasons why New Year’s resolutions fail is that they focus on promises instead of planning. Objectives, on the other hand, concentrate on reasonable outcomes that are to be accomplished within a certain time frame, allowing companies to correctly assess their success and then adapt to setbacks easily.

You must exercise your IT defense strategy. You have to work on your defensive muscles constantly so you can make sure that your services and networks are not at risk. You can start by considering IT outsourcing when it comes to your cyber security assessment services to determine any network problems and by providing appropriate security training to employees.

You probably want to spend less as well but make sure that you are not compromising your cybersecurity. Tighten up your password restrictions and conduct mandatory software updates every three months to reduce your company’s overall risks.

Call SpartanTec, Inc. now and let our team of IT experts help reach your cybersecurity goals for 2021.

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence

Thursday, December 24, 2020

Beware of Missed Delivery Parcel Scams This Christmas


 Millions of people go Christmas shopping online. Fraudsters exploit the shopping season by sending scam emails and texts and that's why you should never forget to boost your cybersecurity. These scammers claim that they’re from a trustworthy company and they want to inform you that they were unable to deliver a package.

They also provide a link to a website where you will be asked to key in your bank card details so you can pay additional postage costs. If you don’t your item will be returned to sender. A few days later, you’ll get a call telling you that your bank account is compromised and you have to move the money to a secure account. What you don’t’ know is that the secure account their referring to is still under their control.

A lot of consumers have reported to have fallen victim to missed delivery parcel scams. Some messages even claim that address information provided is incomplete that’s why the parcel wasn’t delivered. They'll say that the need to get more details so they can try to redeliver the parcel. They will then offer collection from their warehouse and say that the arranged delivery isn’t for free.

 

 

Always remember that legitimate firms don’t ask for bank details through texts or emails. You should be careful of these kinds of scams. It’s best if you know how to spot fraudulent texts and email.

Never click on links form emails that come from people or entity you don’t know or not familiar with. It’s better if you type the website address directly into a web browser.

Cybercriminals are looking to cash in on people who are sending and expecting to receive gifts during the holidays. Consumers who are tricked into clicking on the infected links will later on get a call from the fraudster pretending to be from the fraud team of a bank and will try to convince the unsuspecting victim to move their cash to a new account or provide their passcodes.

Never do this whether it’s through text, call, or email. Take the time to think before you part with your money or information. Don’t click on links in a text message or email because it could be a scam. If you receive these kinds of emails or text, be sure to report to the authorities right away. You should also improve your email security.

Scammers are also exploiting the COVID vaccination program by saying that people are given the opportunity to get the shot much sooner. These are done via text or voice message through phone. In both cases, the victim is asked to reply by pressing 1 after they receive the call or by clicking on a link in the text message. They will then be asked to provide their financial details and personal information to book for the vaccination. Don’t be fooled. Always be careful.

 

Call SpartanTec, Inc. now and let us help you improve your company’s cybersecurity Florence SC strategies so you’ll be less at risk of falling victim to cyberattacks.



SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com

Serving: Myrtle Beach, North Myrtle Beach, Columbia, Wilmington, Fayetteville, Florence

Thursday, December 3, 2020

Location-based threats: How cybercriminals target you based on where you live



 Much like legitimate businesses, cybercriminal enterprises have to be dynamic – standing still means falling behind. A significant example of how cybercriminals are evolving is the growing trend of location-based targeting, through what we call “geo-malware” and regionalized email attacks.

Traditionally, we think of online threats in terms of highly targeted attacks on the one hand and opportunistic cash grabs on the other hand. Nation-state sponsored or advanced persistent threat (APT) attackers target specific individuals or organizations, and the more common, financially motivated digital thieves take an “infect them all” approach.

Our SophosLabs research shows that way of thinking is becoming outdated, as APT attackers and common cybercrooks learn and borrow techniques from one another.

Common online crooks have learned how to become more efficient and increase their yield per victim by targeting individuals based on their specific country, using a variety of methods. Here I will go into a few of them: geo IP lookups; traffic direction services; and email targeting. I will also explain how and why cybercrooks avoid certain countries.

 

 

Why geo-targeting is becoming more popular

We can compare an online criminal enterprise to a legitimate business like McDonald’s, a very successful company with restaurants all over the world. Even though you may recognize McDonald’s as the same restaurant wherever you go, there are important differences in every country.

You will have to pay different prices and use different currencies. And you’ll find different offerings on the menu and a different approach to advertising based on the local diet, culture and language.

Cybercrime is now a highly competitive, multi-billion-dollar business. They want to target wealthy countries with particular kinds of malware, like ransomware and banking malware, while utilizing other victims for more mundane tasks like spamming or participating in denial-of-service attacks.

To customize their attacks and make their email scams and phishing attacks more believable, the cybercriminals are imitating local brands and using grammatically correct local languages as lures.

Users have been conditioned to believe they can spot scams by the incorrect grammar and shoddy spelling, which leads to them falling even harder for well-crafted scam messages.

Location, location, location: IP lookups and traffic direction services

A popular tactic favored by today’s criminals is using malware that is geo-targeted based on information gleaned from the computer’s IP address or the language setting in Windows.

Common crooks don’t often infect computers themselves – they typically use services provided by other cybercriminals who have collected thousands of infected (zombified) computers and sell them to the highest bidder.

A criminal may want to drop banking malware on computers in Germany, for example, simply because Germany is a wealthy country, or because the crook has money mules in Germany – people they have recruited to take money out of local ATMs using cards produced from card numbers and PINs stolen by the malware or skimmers.

We have seen examples where criminals go on the black market to use compromised traffic direction services (TDS), which provide real-time bidding and traffic direction, to find the most appropriate victims, much like legitimate ad networks serve you the most relevant ads whenever you visit a website.

Your IP address, which often shows your computer’s location, is detected by the compromised web server that’s sending the malicious stuff, and serves you the malware “designed” for your region.

Traffic direction services

We see this IP lookup technique favored by crooks using banking malware because most banks tend to serve a particular country or region – in our example, users based in Germany have a high likelihood of being customers of Deutsche Bank, so malware targeting that bank will have a high rate of success.

Thus, we see different families of malware used to infiltrate banks and financial institutions converging on specific regions:

  • Various banking Trojans designed to pinpoint Brazil
  • Dridex is predominant in the U.S. and Germany
  • Trustezeb is most prevalent in German speaking counties
  • Yebot is popular in Hong Kong and Japan
  • Zbot is mostly found in the U.S., UK, Canada, Germany, Australia, Italy, Spain and Japan

Geo-malware example: ransomware

One of the more prevalent examples of geo-targeted malware is ransomware.

You’re familiar with ransomware by now – ransomware gets right in your face, with warning messages that pop up on your screen and demand a ransom in your local language. These nasty threats infect your computer and use public-key cryptography to scramble your files, then hold all your data hostage until you pay for the key to decrypt them.

In recent months, we’ve seen most ransomware being distributed via attachments in emails, which are carefully crafted in your local language and spoof local institutions like your region’s postal service or law enforcement agency, luring you to open the attachment and download the ransomware.

Criminals have taken one step further to make ransomware more effective and provide payment pages to instruct you how to pay in your native language or currency.

Ransomware crooks tend to want to infect as many computers as possible and then serve up the correct language based on what keyboard you have installed on your computer or the language setting in Windows.

With crypto-ransomware, the crooks demand payments in bitcoins or other anonymous e-payment systems such as Ukash. The payment pages offer detailed instructions in the local language, with payment amounts listed in the local currency, and links to local Bitcoin exchanges.

TorrentLocker Bitcoin pay page

The most popular ransomware in recent months, Locky, has ransom pages carefully translated into various languages including Portuguese, Danish and Chinese, although for some reason the Locky crooks are not interested in Czech or Arabic-speaking countries. Locky also can check to see if Windows is set to Russian, which causes the malware to exit and delete itself.


Natural geo-targeting: email country codes

Cybercriminals don’t always need sophisticated malware to target your location – they may be able to figure out where you live just based on your email address, using the country code extension.

This is a clean and simple way to filter victims: the crooks can hit all the .uk country code emails with spam targeted for the UK; the .nl email addresses get Dutch spam; the .no ones get Norwegian spam, and so on.

The most common mass-spammed malicious email campaigns have impersonated local postal companies and tax agencies. These emails either contain a malicious Microsoft Word document, JavaScript or lead you to click through to a compromised webpage.

The grammar and spelling of these emails is greatly improved compared to past email spam campaigns, leading to more victims believing the messages are real. The crooks aren’t relying on some sloppy machine translator. They hire human translators who create the messages in their native language – we have heard of freelance translators being contracted to do this type of work for the criminals unwittingly.

Cybercrooks aren’t just customizing email attacks based on language and regional institutions – they shift tactics based on seasons as well. So, during tax season the emails might pretend to be from the IRS in the US or the Office of State Revenue in Australia. Around Christmas time, you can expect to see fake package delivery notices.

Sample malicious email

It’s also important to remember that if you get a phishing email, it doesn’t matter what type of computer or mobile device you’re using. When you get an email trying to phish your banking credentials, you can still give away your bank account password whether you have a Windows or Mac, iPhone or Android computer.

Crooks will use your location to make the trick more convincing. But all bits of information about you are important, and the criminals will always look to take advantage of information they have and use it against you.

No-go zones: country filtering

We also see examples of geo-customization where cybercriminals are programming attacks to avoid certain countries or keyboards with a particular language.

This could be happening for a few reasons. Maybe the crooks don’t want attacks in their home country out of a sense of national pride. Another theory is that the crooks don’t target their own countries because their local law enforcement is willing to look the other way, so long as the victims aren’t locals.

One of the earliest examples we’ve seen of attackers excluding particular countries was the Conficker virus, which at its peak infected more than 11 million PCs globally. Yet there was one country where Conficker would not initially spread – Ukraine.

The first version of Conficker used an online geo IP lookup to determine whether you were in the Ukraine or not, and the virus would avoid Ukrainian computers. (Later versions of Conficker dropped this behavior.)

As mentioned above, Locky ransomware has also been found to delete itself if a computer’s language is set to Russian.

Although circumstantial, other evidence points to Locky being made by an Eastern European criminal. Recently I grabbed some Word docs with malicious macros that were spreading Locky, and noticed that when the document was created the language was set to Cyrillic, an indication that whoever was last editing it had their keyboard set to Cyrillic.

We don’t know for sure that Locky is made by Eastern Europeans, but if not, someone went through a lot of trouble to make it look that way.

What to do

With cybercriminals creating geo-targeted and authentic-looking threats, it is more difficult to recognize malicious spam. Here are some security tips for home and business users to stay protected against email-borne malware attacks.

For home users:

  1. Make sure you protect your computers with an anti-malware and web protection solution. Sophos Home is free, enterprise-grade security software that protects both Macs and PCs.
  1. Keep your files safe from ransomware by backing them up regularly. Keep at least one recent backup offline.
  1. Be very careful about opening email attachments. Malware including ransomware is very often spread in email. You should also be wary of clicking links in emails, as they may take you to a phishing or malware website.
  1. Always keep your computers, devices and applications up to date with the latest security updates.
  1. Use strong, unique passwords for all your accounts. Consider using a password manager to create and store strong passwords for you. Just make sure you use a strong password for the password manager itself.

For business users:

  1. Patch, patch, patch. Malware that doesn’t come in via document macros often relies on bugs in software and applications. When you apply security patches, you give the cybercriminals fewer options for infecting you.
  1. Don’t give yourself more login power than necessary. Avoid browsing, opening documents or other regular work activities while logged in as administrator.
  1. Don’t enable macros. A lot of ransomware is distributed in Office documents that trick users into enabling macros. Microsoft has released a new tool in Office that can prevent you from enabling them on documents downloaded from the internet.
  1. Train and retrain employees in your business. Your users can be your weakest link if you don’t train them how to avoid booby-trapped documents and malicious emails.
  1. Segment the company network. Separate functional areas with a firewall, e.g., the client and server networks, so systems and services can only be accessed if really necessary.
  1. Treat security as a system. Every extra layer of protection, whether encryption or a synchronized endpoint to network solution, will help protect against increasingly sophisticated threats.

 

Call SpartanTec, Inc. now and let our IT experts boost your cybersecurity so you're better equipped at protecting your business from various kinds of online threats.

 

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence