Showing posts with label Spear-Phishing. Show all posts
Showing posts with label Spear-Phishing. Show all posts

Wednesday, 18 January 2017

Scary new way to have your GMail password and account stolen.

This is an incredibly easy way for the evil doers to steal your GMail ID and password. This one could even catch out security people like me! 😱

So what happens is you receive an e-mail from somebody you know, who also had a GMail (note the emphasis on had). 

This e-mail will have a subject line of a previous e-mail conversation that you have had with that person and also, what appears to be an, attachment that had been attached in an earlier e-mail in that conversation. So far this e-mail is looking EXTREMELY legitimate.

That attachment, is actually an image in the e-mail with a link embedded in it and if you click on it, it will take you to, what appears to be, the GMail log-in screen, as follows:
Being asked to log-in like this would certainly trigger an alert in my mind that something was up. I would immediately check to see where this password page has come from, so I would look up at the address bar of the browser. This is what you would see:

So that looks OK doesn't it? https:// (nice and secure site) accounts.google.com (legitimate address) and the e-mail came from somebody I know, from an e-mail conversation I have had with them, that had an attachment, which was here again in this new e-mail. All very believable! So let me enter my GMail ID and password and ... you've now given the hackers your credentials.

Within minutes, they will have taken over your GMail account and will be sending this nasty surprise e-mail to your friends, family and colleagues.

So how do I know it's not a legitimate GMail login screen? Let's take another look at that address bar:

That first part of the address (highlighted) looks a bit odd, don't you think? It is very odd. It actually has a verrrrrrrrry long string of text, which stretches off beyond the end of what you can see in the address bar that executes a script, which brings up that log-in page.

Also, if you know your secure websites, you know that where there is proper https:// there is also a green padlock symbol like this:

That gives a high degree of confidence that the site is legitimate and properly secure.

Here's the best possible protection

I've said this numerous times. I tell everyone I know, that they must set this up to protect their accounts. 

It is known by many names - Two factor authentication or Two step verification or Login approvals.

I've a whole commandment dedicated to it, so please have a read and please implement it.

This protection, won't prevent you falling for the scam outlined above. What it will do is prevent the bad guys from accessing your account, even though they have your GMail ID and Password, they won't have your smart phone and as such won't be able to sign in as you.

Please implement Two factor authentication on all your on-line accounts. It really gives you the best possible protection.

h/t to the folks over on WordFence for the details on this.

Thursday, 22 December 2016

Could the attempted theft of €4.3m from Meath County Council happen to your business?

As was widely reported at the weekend, Meath County Council were the victim of an attempted theft of some €4.3 million. A lot of the reportage was pointing to hackers and this being a cyber attack, but based on what is known, in my opinion, it's not really.

This attempted theft was facilitated by the use of technology, but not necessarily the abuse of it. They're no longer commenting about it now while the matter is investigated, so we'll need to await the outcome of that before we know for sure.

However this sort of theft is incredibly common and is known variously as CEO fraud or Business Email Compromise (BEC). Basically what the bad guys do, is send an e-mail or even a text message that appears to come from the CEO, the MD, the Head Honcho, the Big Boss. This e-mail/text is sent to somebody in the finance department and it instructs them to urgently transfer or wire funds to some account that is outside of the EU area. If the transfer was within the EU area, it can be recalled under SEPA regulations, but outside of the area the money can be a taken and never seen again. 

Wednesday, 21 December 2016

Don't ignore that e-mail from Lynda.com

I received two e-mails in recent days from online training provider Lynda.com customer care, this is because I have had two accounts with Lynda.com in the past. Both were set-up when they had a 30 day free trial offer, which I made use of.

I'm one of the 9.5 million customers/former customers of Lynda.com who have been contacted by them about a breach of their data security. They state that my contact information and courses taken were compromised, however they believe my password was not compromised. Here is the text of the e-mail:
We recently became aware that an unauthorized third party breached a database that included some of your Lynda​.com learning data, such as contact information and courses viewed. We are informing you of this issue out of an abundance of caution.
Please know that we have no evidence that this data included your password. And while we have no evidence that your specific account was accessed or that any data has been made publicly available, ​we wanted to notify you as a precautionary measure.
So this doesn't sound so bad. Right?

Thursday, 27 October 2016

There is a lot of variations in evil e-mail the last couple of days.

I yearn for the days when evil e-mail was so easily identified "becuse it wuz ritten in, gud, inglish wit grate spellhng an pun.tation". ðŸ˜ƒ

In the last couple of days, the evil doers have been varying their scam e-mails fairly wildly and it's bound to catch out some people.

I'll run through three sneaky methods that have been attempted on others over the last 48 hours.

Thursday, 29 September 2016

Using the Internet Safely. Training from L2 Cyber Security Solutions.

Human Error
Did you know that evil software gets past commercial anti-virus and e-mail filtering products on a worryingly regular basis.

Firewalls and Anti-virus packages lure people into a false sense of security. While they do provide protection up to a point, if somebody opens an e-mail attachment that contains new Malware, these protections are effectively useless.

Cyber incidents, most notably Ransomware attacks have seen massive increases recently. 93% of phishing e-mails in Quarter 1 2016 have carried a Ransomware payload (source - PhishMe Q1 2016 Malware review). 30% of people that receive phishing e-mails open them and 12% of those that do, then open attachments or click on links (source - Verizon 2016 Data Breach Investigations Report).

These statistics highlight the fact that a significant weak link in any organisation, where it comes to using the internet and e-mail, are THE STAFF, but it's not their fault.

The best protection to cover this gap are staff that are aware of what the threats are and how they manifest themselves. Once they are armed with the knowledge of what to look out for, they will be much less likely to cause a security breach.

The training that L2 Cyber Security Solutions delivers is comprehensive, yet simple for all to follow.

Using the Internet Safely

Course Outline

Lecture / Workshop


Duration:

1 day


Audience:

People who have access to and utilise the internet and e-mail, whether for personal or business purposes, as part of their day. 


Prerequisites:

A basic understanding of internet browsing and e-mail usage is a prerequisite.


Programme Aim:

This training will give the attendees an understanding of the risks and threats associated with using the internet and e-mail.


Learning Outcome:

The participants will know how they can take some simple steps to avoid being adversely affected by the various risks presented to them. They will also learn how to create unique and strong passwords.


Course Content:

  1. Malware (incl. Ransomware)
  2. Spam
  3. Social Engineering
  4. Phishing and Spear-Phishing (incl. CEO Fraud)
  5. Safe Web Browsing
  6. Good Security Practices
  7. Mobile Security
  8. Creating a unique and strong password

Call us on 087-436-2675 or e-mail info@L2CyberSecurity.com to discuss your requirements and get a quotation.

Monday, 11 July 2016

Security Awareness Training by L2 Cyber Security Solutions.

Cyber incidents, most notably Ransomware attacks have seen massive increases recently. 93% of phishing e-mails in Quarter 1 2016 have carried a Ransomware payload (source - PhishMe Q1 2016 Malware review). 30% of people that receive phishing e-mails open them and 12% of those that do, then open attachments or click on links (source - Verizon 2016 Data Breach Investigations Report).

These statistics highlight the fact that a significant weak link in any organisation, where it comes to using the internet and e-mail, are THE STAFF, but it's not their fault.

Firewalls and Anti-virus packages lure people into a false sense of security. While they do provide protection up to a point, if somebody opens an e-mail attachment that contains new Malware, these protections are effectively useless.

The best protection to cover this gap are staff that are aware of what the threats are and how they manifest themselves. Once they are armed with the knowledge of what to look out for, they will be much less likely to cause a security breach.


The training that L2 Cyber Security Solutions delivers is comprehensive, yet simple for all to follow.

Security Awareness Training

Course Outline

Lecture / Workshop


Duration:

1 day


Audience:

People who have access to and utilise the internet and e-mail, whether for personal or business purposes, as part of their day. 


Prerequisites:

A basic understanding of internet browsing and e-mail usage is a prerequisite.


Programme Aim:

This training will give the attendees an understanding of the risks and threats associated with using the internet and e-mail.


Learning Outcome:

The participants will know how they can take some simple steps to avoid being adversely affected by the various risks presented to them. They will also learn how to create unique and strong passwords.


Course Content:

  1. Malware (incl. Ransomware)
  2. Spam
  3. Social Engineering
  4. Phishing and Spear-Phishing (incl. CEO Fraud)
  5. Safe Web Browsing
  6. Good Security Practices
  7. Mobile Security
  8. Creating a unique and strong password


Call us on 087-436-2675 or e-mail info@L2CyberSecurity.com to discuss your requirements and get a quotation.