Thursday, August 20, 2020

5 Types of Phishing Scams and How To Protect Against Them

Phishing scams come in different forms. They do not just use different online methods like pop up ads and fake emails but could also include phone calls. The individuals behind such scams tend to employ fear tactics to force their victims to take the bait.
Phishing can be considered as an online con game. Phishers, or people who run this scam, are tech savvy identity thieves and con artists. They use malicious websites, spam, instant messages, and email messages to trick individuals into giving out sensitive information. Credit card accounts, banking information, passwords, and usernames are just a few of the details that phishers are looking to exploit.



5 Common Phishing Scams and How To Avoid Them

Phishing scams are made to appear as though they come from dependable sources, it’s smart to know the difference between fraudulent and real messages and how to identify a few clues that the message could be a scam. Here’s a list of the five type of phishing scams and how you can avoid them.
Email Phishing Scams
Email phishing scams are fraudulent emails that look like a company or person that’s known to the victim. It tries to illegally accumulate personal or/and financial details from the recipient.
phishing Florence SC message generally includes at least a single link to a fraudulent website, which is designed to replicate the website of a legitimate business. The message encourages the recipient to give out information that could be used for online financial theft or identity fraud.
Avoiding email phishing scams
  • Don’t download attachments or click on links from an unfamiliar email.
  • Pay attention and always be vigilant.
  • Double check the URL for misspelled web address.
Vishing Scams
Voice or VOIP phishing is just like email phishing but scam involves voice, instead. It’s a phone scam wherein a person is scared or tricked into giving out personal information or valuable financial details to scammers.
Avoiding vishing scams
  • Don’t give personal or any confidential information over the phone.
  • Don’t call the number the caller provides. Instead, check the company website and make sure that they are running a legitimate business.
  • Watch out for misspellings or other red flags.
Tech Support Cold Scams
Scammers call their targets and pretend to be from a well known security company. They will lie and tell you that they detected malware on your computer. They will pretend to give you a solution by asking you to allow them to install a certain kind of remote desktop software. This will let the attacker gain access to your computer to install real malware. Apart from trying to install software on the computer, they will also ask for a fee for the repair service.
Avoiding tech support call scams
  • Look up the number of the company that the tech support agent is claiming to be working for.
  • Don’t allow remote access to your computer.
Popup Warning Scams
Popups come up when someone is browsing the web and notices a small ad or graphic appear on their screen. Generally, these popups are related to the content that you are viewing and link to a different website with a similar merchandise or content that is related to the content.
Malicious popups could be intrusive, which will make it hard for you to close the ad or graphic. They might show a message that states that the computer is infected with malware and provide a phone number for help with getting rid of the malware. Generally, the cybercriminals create popups appear like they originate from a reliable source in hopes that they will look like a legitimate company.
Avoiding popup scams
  • Check the message closely.
  • Don’t click on the pop-up.
Fake Search Results Scams
Fraudulent firms tend to use paid search ads for what they refer to as support services to make it look like they are a legitimate and reputable company. These listings may appear on top of a search results page, which is a prime location. The results look like it’s real and they will promise to provide support and deals that are too good to be true. This is one of the common ways they use to trick people into allowing them to “fix” their computer. But when you click on the ad, you end up downloading a malware to your device, which will compromise your computer security.
Avoiding fake search result scams
  • Check the url closely.
  • Use a secure search service.
What to do if you have been scammed?
If you think that you have been a victim of a phishing scam, here are the things you can do:
  • Change the passwords of your accounts.
  • Scan for viruses on your computer by running a full system scan.
  • Call your bank and report that you may have been a victim of a phishing scam.
  • Use a reliable anti-virus program.

Call SpartanTec, Inc. and let our team assess your email security. We also have a range of IT solutions to help boost your cybersecurity.


SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com

Friday, August 14, 2020

3 Cybersecurity Risks Of Remote Work

The numbers released by the Bureau of Labor Statistics showed that about 29% of Americans worked from home before the coronavirus outbreak. Meanwhile, Buffer said 99% of workers prefer remote work for at least part of their time or if possible, for the rest of their careers.

These days, employees don’t have any other choice but to work from home. They, along with their employers are beginning to see the many different complications involved in remote work Florence SC. There are other bigger challenges than just feeling lonely and less productive. Remote work can put a business at risk. Although some businesses have already invested in good network and cybersecurity solutions, a lot of firms are still unaware of the risks involved in working remotely.

Organizations of all sizes and kinds are dealing with an increase in endpoint security gaps, email based threats, as well as other issues due to the immediate switch to a fully remote workforce. Therefore, it is not crucial to consider both ethical hacker perspectives and security practitioner to remain secure, that is what all of this is about.


4 Signs of Cybersecurity Breach

  • New programs appear even if you didn’t install them.
  • The computer runs unusually slow.
  • Weird popups appear.
  • Loss of control of the keyboard or mouse.
If you notice any of these signs, be sure to inform your company’s IT experts so they could mitigate the risk right away.

3 Hazards and Concerns of Remote Work

Home Wi-Fi Security

Compared to working at the office, where IT managers can easily control and monitor the security of each Wi-Fi network, your home network most likely have weaker protocols.  For example, you probably have WEP instead of WPA-2. This lets hackers access the traffic of your network easily.

Phishing Scams

Phishing scams are one of the primary causes of data breaches. Cybercriminals could easily send deceptive emails that look like the real thing. When one of your employees click on the malicious link, the hacker will get access the device of the employer.

Weak Passwords

Hackers can easily crack simple passwords. If you use insecure passwords across different platforms, hackers will easily get unauthorized access to different accounts in a short span of time.

The situation brought about by COVID-19 has triggered a transformation. Remote work brings a new set of challenges and risks. Hackers are prepared for that.

Since remote work is mostly mandatory, businesses should make sure that every device is secure. Employers must discard hardware that are hardware based legacy VPNs and choose cloud agnostic as well as scalable network security options.

Legacy VPNs may leave gaps in your remote security efforts because they are difficult to configure and deploy. Furthermore, they do not have the ability to secure remote access that are policy based to on-premise resources, business applications, and hybrid cloud environments.

Virtual training is also another key element. Companies must perform virtual training for all their team members so that they would be educated on how to deal with a cyber attack and what risks they need to watch out for like malware, suspicious emails, and etc.

SpertanTec Inc. has partnered with Fortinet – the world’s foremost provider of network security – to bring your business the security you need. FortiGate 4400F is the world’s first hyperscale firewall delivers unparalleled performance, scalability and security to help meet escalating business needs.

Call us today at 843-396-8762 for a no obligation review of you network. We works with companies of any size.




SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com


Serving: Myrtle Beach, North Myrtle Beach, Columbia, Wilmington, Fayetteville, Florence


Thursday, August 6, 2020

Lessons Learned From 3 Massive Hospital Cybersecurity Disasters

If there’s one thing that hospitals don’t want to happen in today’s time where risks are everywhere, it’s having the confidential patient health information to fall prey to hackers. That’s why your health facility have to do everything it can to prevent cybersecurity problems.
Hospitals have recently faced various cybersecurity Florence SC threats. The question now is how can your facility fight back? Is there anything you can do to reduce your risks? Listed below are three cases faced by the industry recently and what lessons they have to offer.



Older Systems

There are a few hospitals that are still using older operating systems on their computers. They have to keep these devices off their networks so they can’t connect to the internet.
Beth Israel Deaconess in Boston did this with one of its equipment. However, the health facility encountered some problems when the computer required a firmware update. The technician hired to fix it inadvertently connected the computer to the internet in order to download the update.
It didn’t take too long before different malicious programs were downloaded and the computer became unusable. Cybercriminals got access to the information stored on the machine using these programs – a computer located in China got accesses to 2,000 patient X-rays, which was sold on the black market.
So, the lesson here is to make perfectly sure that all of the computers in your facility is running support and recent version of operating systems and have all the programs required to protect them against spam programs and malware.

Fake Website

In most cases, hackers trick staff s they can obtain access to confidential data. One scheme that made a lot of problems for Massachusetts General had something to do with bonuses for doctors. The scammers made a fake version of the actual payroll portal of the hospital and it looked like the real one. The only notable difference was a few different letters in the web address.
Doctors got an email asking them to log into the payroll portal in order to authorize a potential bonus payment. As expected, many doctors agreed. They logged in using their credentials thinking that they would get the promised cash. However, hackers managed to get the doctor’s confidential information instead. They used it to log into the legitimate payroll portal of the hospital and rerouted the direct deposits for the paycheck of the doctors to different accounts. Then they purchased Amazon gift cards using the money.
Although this scheme targeted the bank accounts of the providers, a savvy hacker may try similar tricks to get electronic health records system user names as well as the passwords.
The lesson here is to always remind your staff to double check the websites to make sure that they are authentic. You should also add in another layer of protection like a security question, before the provider can log into the payroll system – especially when they try to access these systems outside the facility.

Malware on Mobile Devices

Cybercriminals do not just target computer systems – they also install malware on to the mobile devices hoping that they could steal confidential information for accessing confidential accounts.
A nurse, who was on break, downloaded the Angry Birds game on her mobile phone. But she used a Bulgarian site instead of getting the app from a reputable site like Amazon or Google. As a result her phone got infected with a malicious software.
Later she used her mobile phone to check her work email. The software saved her information and sent them to email spammers. They used her compromised account to send spam messages.
No PHI were taken, on the off chance that she discussed patients in her work emails that she sent to her colleagues, the hospital she was working for would be faced with a huge scandal.
The lesson learned here is to always remind your staff to remain cautious whenever they are using their personal devices to access their work email as well as other hospital network system. Always remind them to avoid downloading any program that comes from suspicious websites because they may contain hidden malicious software that may infect the hospital network and compromise the PHI safety.

Call SpartanTec, Inc. and let our team of IT professionals help protect your network against online threats like phishing, malware, spam, and more.


SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com

Tuesday, July 28, 2020

Corporate Internet Users Watch Out For Conti Ransomware

Although you may not be familiar with the name, a strain of ransomware called "Conti" is surging in popularity on the Dark Web and seeing a rapidly growing number of installations, so it's definitely one to be on guard against.
Advanced intel's Vitali Kremez has been tracking this strain since it first appeared in late 2019.

According to Kremez, the code appears to be an offshoot of an older strain of ransomware called Ryuk. The number of active installs of Ryuk has been declining for a few years now, while the number of Conti installations increases at virtually the same pace.

Kremez, had this to say about the new ransomware threat:



"Based on multiple incident response matters and current assessment, it is believed that Conti ransomware is linked to the same Ryuk ransomware developer group based on the code reuse and unique TrickBot distribution. The same distribution attack vector is used widely by the Ryuk deployment group."

While there are a number of interesting aspects to the design of Conti, one of the most interesting is the fact that it utilizes 32 threads during the file encryption process. While multi-threaded ransomware Florence SC isn't new or unique, Conti is the first to use 32 threads, which makes it stand out and allows it to encrypt a machine with blinding speed.

The advantage to the attacker here is that the attack might be over before a victim even realizes what's going on. On the other hand though, a wary, observant user might notice that the machine's performance takes a sudden nosedive, which is a red flag that something is wrong. That gives IT professionals a small window to deploy countermeasures and potentially stave off the attack.

The other interesting aspect of this code's design is the fact that it utilizes the Windows restart manager API to close open files. Again, while not unique, it is something not used by many malware strains, which sets Conti apart.

In any case, it's a serious and growing threat, and one your staff should be briefed on and prepared for.

Call SpartanTec, Inc. and let our team of IT experts set up effective cybersecurity measures that can keep ransomware and other possible online threats at bay. 


SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com

Thursday, July 23, 2020

Is DIY Cybersecurity Possible? — SIEM Tools vs. Solutions


We’ve all done it before — searched for how-to instructions on something we feel like we should be able to do ourselves. Whether it’s how to tie a bow tie, how to change your oil, or how to repair a TV, people are constantly looking to do things themselves. There are activities that are beyond our actual ability to do, but can you blame any of us for trying? No, we have the information, resources, and always the desire to save money. That being said, one of the things that is likely beyond DIY abilities is combating cyberattacks for your business.

There are what feels like an uncountable amount of cybersecurity Florence SC services that are created to help the wide variety of companies protect the personal and financial information of their customer. These services are best supported by cybersecurity companies but far too often business owners and managers look to buy the tools and attempt to do it themselves. The problem is, can you really learn everything you need to about things like SIEM and then manage to fight off hackers?

This blog is created to explain why you not only need cybersecurity tools, but also cybersecurity companies to provide you with actual solutions.

SIEM Systems Need Constant Management



As you may already know, depending on the SIEM system, there are different kinds of emphasis for the different services. No matter if the SIEM tool is made by Intel, IBM or Fortinet, the overall goal of being notified of attackers is the same, however, one may have a larger range of coverage for devices and log types while another may have a specific log manager that picks up different readings. Whatever it may be, the system will collect information and present an analysis on the servers, but to optimize your security, there should be someone managing the system the entire time.

Look at it this way, let’s say you want to build a shed in your backyard to protect some equipment and toys from the rain, snow or sun, and you have a hammer, plenty of nails, wood, and a few other tools. Unfortunately, nothing will get done if you don’t pick up the hammer. While it is great that you have the necessary tools and supplies, you will never build a shed to protect/shelter your equipment and toys if no one is utilizing the tools. It is the same with these SIEM services, or tools — without a full-time individual, ideally from a professional cybersecurity company, you are at risk of missing critical notifications and real threats.

Why Cybersecurity is not a DIY Product

Now, if you don’t necessarily think this is the case and you feel confident that you’ll be able to check up on the program every now and again, you might want to reconsider. If you didn’t already know, there were 668 million breaches in the U.S. just last year alone (the year before, there were over 1.5 billion breaches); this means that over 668 million times confidential information was exposed without authority. Also, 38 percent of the world’s cyberattacks are targeted at the United States. While it is a law to secure your customers’ information, these numbers alone are enough reason to understand the necessity to invest in a solid cybersecurity company’s services. So, with a constant attack from unseen sources, are you really all that confident that you’ll be able to manage it all yourself?

Let’s again assume you are adamant in doing this all yourself, are you proficient in programming Java or C/C++? Do you understand web application technologies? Linux Operation Systems? Telephony Technologies (Analog and IP)? Okay, well…maybe you don’t but you can learn, right? If that is the case, are you planning on learning on the fly from a couple of YouTube videos? It’s not that we want to discourage you from learning, but it’s just a matter of being realistic. Trying to install a SIEM program and then following a manual to figure out how to make everything work is about as easy as putting a 4th grader, who is now able to read decently well, into a college-level biology and expect them to do well. the information is right in front of them, but can you really expect that? The answer is obvious.

Maybe we aren’t giving you enough credit and you actually do understand all of these things — if that is the case, good for you for sticking with this blog and reading all the way to here — but can you handle reading all the analyzed data for every device for your entire company every day? That’s where the benefit of hiring a cybersecurity company to manage the entire SIEM system for you comes into play. Not only will you have a service that is linked to your server, but you will also have a team of experts constantly reviewing your system for dangerous activity. With just the SIEM tool at your disposition, you may be alerted when a breach is detected but what will you do from there? A team like this, will not only notify you but also provide you with a solution.

The wisest thing you will do when you are looking to increase your company’s cybersecurity is to not only purchase one of the many tools that are on the market, but make sure you also have a cybersecurity company on your side providing you with all the readings solutions you need. Need help? Contact SpartanTec, Inc. today!



SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com

Thursday, June 18, 2020

How to Protect Your Digital Identity?

Protect Your Company Data Webinar
June 25 1:00 EST
Register Here



You have to responsible for the monitoring your digital identity. But how can you protect it? Here are some tips that can help you get started.

Use Password Manager

Using a password manager is the simplest yet effective IT security tip when it comes to protecting your digital identity. Passwords have become a big problem and are now considered as cockroaches of the industry.

Your email could be the gateway to all of the services you use. If a hacker gets access to your inbox, they will have control over it. They can reset your password, impersonate you and send out emails without your knowledge, and even steal money.

Even if you are already using password managers, it is possible that you have reused the passwords for several years and in different websites.

Set up Two Factor Authentication

If you have enabled two-factor authentication, you need to use two factors in order to authenticate yourself before you can log in or confirm a certain transaction. This could be entering a password, Pin code, or passphrase; using your mobile device, a USB key, or physical token; or a hand gesture, face recognition, or fingerprint.

There are different kinds of two-factor authentication across services and countries. However the most common ones are USB stick tokens, disconnected tokens, mobileauthenticator apps, national ID cards, printed single use passwords, email single use passwords, and SMS one-time passwords.

Think Before You Click or Post

Let’s say you’re checking social media. Someone you follow posts a poll asking if remote workers are more productive and it piques your interest. You should take a second before you click the poll. Do you need to participate in the poll? If you do, will it leak details about yourself or the company you work for?

What if you receive an email for a common service that you are using? It’s asking you to read a blog, click on a link, or download a file. Check first. Is it a legitimate website? If not, don’t open it.

Don’t Believe Someone Calling You Is Who They Claim To Be

Before, it was common for banks to call clients by phone in order to verify some crucialinformation or to confirm a transaction. But that’s no longer the case these days. Now, there are a lot of fraudsters who may try to call and ask for your pin code, password, or other important information like your social security number. They may even ask you to reset your password. Don’t believe anyone who claims they are from the bank. If you receive such a call, ask for a number which you can call. Compare that number on the number listed on their website and check a trusted directory. This also applies to emails. Do not reset your password, if you receive an email out of the blue asking you to do so.

Add A Secondary Password on your Mobile Subscription Account

Call your mobile operator and ask if you can have a secondary pin code that will help protect your subscription. In a few countries, the default PIN is commonly the last four digits of their social security number.

Ask Services To Allow You To Sign Documents Digitally

If you have to sign an agreement, there’s no excuse for printing the paper, affixing your signature into it using a pen, and scanning it back in. Today, digital signatures have become a solid level of security and the tools for signing documents online have become easier and much more intuitive. But, only a few firms and government offices have embraced this new technology. Call your service providers and ask if you can sign documents digitally.

Be Careful Where You Share Your Personal Data

Online services collect data about you and the more info they get the more they can make money out of it. So be very careful what details you provide and where. Be careful who you trust and carefully consider the decisions you make especially when it concerns your digital life. Visit web services that require less personal data or use only those that you have been using for a long time and have a good reputation online.

Monitor Your Credit Files

Always check your credit files regularly as part of your routine in monitoring your digital identity. A bank would check your credit file in case they would like to evaluate your solvency and that’s why it is important to remember that anyone who sees your credit file will leave a mark on it. Monitoring it regularly will help you check for any suspicious activity.

Call SpartanTec, Inc. now and let our team of IT experts help you keep your business and client information safe by setting up only the most effective cybersecurity measures that can help keep online threats and hackers at bay.


SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com





Monday, June 15, 2020

Home Chef Company Data Breach Affected 8 Million Customers

Protect Your Company Data Webinar
June 25  1:00 EST



Are you a Home Chef customer? If so, be advised that the company recently announced a data breach.

It was discovered after the hackers who broke in sold more than 8 million user records on the Dark Web.

The group, calling themselves "The Shiny Hunters" has been busy of late.

They've been selling databases containing records stolen from a total of eleven different companies, with prices ranging from $500 to $2500 per database.

Home Chef was made aware that the database containing their customers' information was available for sale nearly two weeks ago. However, the company waited an inordinate amount of time before coming forward and publicly announcing the breach, a delay which has cost them in the eyes of their customers.

Part of the company's notice on their website reads, in part, as follows:

"Protection of customer data is a top priority for Home Chef and we work hard to safeguard our customers' information. We recently learned of a data security incident impacting select customer information."

The FAQ accompanying the notification goes on to outline that the stolen data includes the following information. It included the customer names, email addresses, phone numbers, the last four digits of any credit card numbers on file, encrypted passwords, and a variety of other general profile information.

Home Chef stressed that only the last four digits of a customer's card was accessed, and reiterated that they don't store complete payment information in their databases.
That's all well and good, but the company is finding it hard to convincingly sell the idea that protection of customer data is a top priority. After all, they waited two weeks to inform their customers that their information was for sale on the Dark Web. That is why, despite the fact that this breach is relatively small compared to others we've seen over the past twelve months, the company is taking flak for it.

In any event, if you're a Home Chef customer, be sure to head to their website and see if yours was one of the accounts accessed. Even if it wasn't, the prudent course of action would be to change your password at the very least.

Call SpartanTec, Inc. and let our team help you set up the most effective cybersecurity strategies to make sure that your client and business information are kept safe at all times. 


SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com