REPORT ALL SUSPICIOUS OR CRIMINAL ACTIVITY TO 911

Showing posts with label Cybercrime prevention. Show all posts
Showing posts with label Cybercrime prevention. Show all posts

Monday, November 17, 2025

CYBERSECURITY- You Need More Than a Strong Password to Protect Your Accounts

Some people may think that all they need is a “strong password” to protect their online accounts. However, while a strong password is important, it is not the only technique that you should use in your toolkit. There are several ways cybercriminals can use to gain access to your online accounts besides cracking your password. There are no single magic techniques to protecting your personal information.

Modern security thinking works in layers. It uses several tools and techniques to protect your house, your business, or you as a person. For example, if you want to protect your home and its contents from a burglar you will lock your front door. But locking just your front door does not guarantee that a burglar cannot break into your house. A burglar could go to the side or back of your house to find a way in. You also need to lock any side doors or back doors. Plus, you need to close and lock any windows. Even by locking all of your doors and windows there is a chance that a burglar can find a way in, so you might put valuables like jewelry and sensitive papers in a safe or locked file cabinet. You also might put away small electronics like your laptop and cell phone. Finally, you might sign up for a security system with cameras to alert police of an intrusion. That way police can possibly catch the burglar in the act or more likely, you can hand over video of the burglar on your property that police can use in their investigation. All of these steps are examples of layered security.

To protect your personal information and your online accounts you also need to think in layers. There are several ways cybercriminals can acquire your passwords and therefore gain access to your online accounts. Relying only on strong passwords is not a magic bullet.

Don’t get me wrong. Long, strong passwords are important to protecting your online accounts. An eight-character password made up of numbers, upper- and lower-case letters and symbols takes about 5 minutes to crack with current computer technology. A 16-character password made up of numbers, upper- and lower-case letters and symbols, the current recommended standard, takes about 5 billion years to crack. Pretty impressive protection. But there are other ways for a cybercriminal to acquire your password. Two ways include buying a list of id’s and passwords that have been acquired in a data breach. A cybercriminal could also send you a phishing email. or text message with a link that either sends you to a fake website that looks like the login page of your account or inserts malware to collect your password.

So, if cybercriminals can steal your password what can you do? You can add a layer by using multifactor authentication (MFA) in addition to a password for all of your accounts. With MFA you verify who you are through email, text, or an authenticator app on your smartphone. You may use a temporary code (something you have) or your fingerprint/face (something you are). If a cybercriminal tries to log into your account, they will not receive the MFA message since it is sent to your email or to your smartphone via text message or the authenticator app. When you receive the message, if you are not logging into your account, then all you have to do is to deny access.

Another technique is to use a unique password for each of your accounts. Using the same password, even if it is strong, across several accounts has turned into a dangerous practice. If a bad guy acquires your password for one account, they will try other accounts that belong to you on the chance that you use the same password to access those accounts.

You should also use antivirus software to protect yourself from malware that could steal your personal information, including your passwords. Be sure that you set it to update regularly and be sure your operation system and your software update regularly.

Finally, use a password manager to store your passwords. We all accumulate many accounts, sometimes in the hundreds. It’s impossible to remember all of those complex passwords. Password managers are encrypted so your passwords are protected from unauthorized eyes. That is even more protection than keeping your passwords in a notebook in a drawer of your desk.
They can also generate new, strong passwords for you when you are opening new accounts or changing passwords due to a data breach, or you suspect someone has stolen your password.

When you are protecting your online accounts, think in layers, long, strong passwords, multifactor authentication, unique passwords for each of your accounts, and keep your software and your antivirus software up to date.

 

 

 

 

Ask Leo:

https://askleo.com/?awt_a=7qbL&awt_l=Ffceh&awt_m=I_EvPxBXwJdfbL&p=34891?utm_source=newsletter&utm_campaign=20251104&utm_medium=email

https://askleo.com/?awt_a=7qbL&awt_l=Ffceh&awt_m=I_EvPxBXwJdfbL&p=34891?utm_source=newsletter&utm_campaign=20251104&utm_medium=email

https://askleo.com/will-ai-crack-your-passwords/?awt_a=7qbL&awt_l=Ffceh&awt_m=JeELTvJp9ZdfbL&utm_source=newsletter&utm_campaign=20230509&utm_medium=email

https://askleo.com/another-reason-not-to-reuse-passwords/

 

Compass IT Compliance:

https://www.compassitc.com/blog/what-will-quantum-computing-mean-for-passwords-and-encryption

 

Norton:

https://us.norton.com/blog/emerging-threats/password-attack

 

Saturday, November 15, 2025

CYBERSECURITY- It Does Matter if Your Account Gets Hacked

More and more people are recognizing that staying secure is important while they are online. However, according to the National Cybersecurity Association there are people who feel that it doesn’t matter if their device or account gets hacked. They may think that their information is not important or that their online data is not critical. However, scammers and cybercriminals can use the most innocent of information to steal from you or others.

Your Facebook account might appear to be innocent, but it can be used against you. While you might only keep up with your family and friends on Facebook, if you overshare the details of your life (such as mentioning when you are taking vacation) someone lurking in the background can use that information to break into your home while you are gone. Your social media passwords are very important because if someone gains access to your account through your password, they can impersonate you a try to scam your friends. Scammers have also been known to take over social media accounts, changing the passwords so that the owners no longer have control of the accounts, using them for their scams or other criminal purposes. So, long secure passwords, 16 or more characters, using a mix of upper- and lower-case letters, numbers and special characters, secured in a password manager is an important step to take.

Other online accounts that are important to protect include financial accounts such as your bank accounts, your credit card accounts, and retirement accounts. Protecting your account credentials such as your password and account numbers can save you a ton of grief. If a scammer only has your account number they can use it on applications, forms, and fake documents to make a fraudulent claim look more legitimate. But if the scammer has your account number and the routing number (found on checks issued by the bank) or the name of the bank or online password they can do much more,

·         Set up payments for goods or services appearing to come from your account.

·         Attempt transfers out of your account through ACH debits or other bank transfer methods.

·         Create counterfeit checks that appear to draw from your account.

·         Use the account for laundering activity, depositing funds and moving them out again to obscure the trail.

·         Make online purchases where limited verification is required.

·         Apply for additional accounts or services using your account as proof of legitimacy, for example, opening a secondary account to stash stolen funds before moving them into cryptocurrency or offshore.

·         Pretend to be from your bank and contact you to collect more personal information. That follow-up scam can be used to harvest even more personally identifiable information (PII) or access details for other bank accounts.

Protecting the usernames, passwords, and account numbers of all of your online accounts is important to protecting your security and privacy no matter how trivial the account may seem. Also, protect any documents that have bank account, credit card account numbers or numbers such as your Social Security number, Medicare number by keeping them in a secure location and destroying bank/credit card statements, or other documents with those account numbers when you are finished with them.

 

Remember,

·         Use long, complex passwords stored in a secure password manager.

·         Use unique passwords for each of your accounts. DO NOT use the same password for multiple accounts!

·         Use multifactor authentication (MFA) for all of your online accounts.

 

 

 

 

 

National Cybercrime Alliance:

https://www.staysafeonline.org/articles/6-cybersecurity-myths-debunked

 

Identity Theft Resource Center:

https://www.idtheftcenter.org/post/what-can-a-scammer-do-with-your-banking-information/

 

Social Security Administration:

https://www.ssa.gov/pubs/EN-05-10064.pdf

 

 

Friday, October 31, 2025

CYBERSECURITY- Keeping It Simple

More and more people are aware of the need to use good cybersecurity practices. However, the National Cybersecurity Alliance (NCA) has found that,

·         46% of people say trying to stay secure online is frustrating.

·         44% say security is intimidating.

·         40% say information on how to be secure is confusing.

While cybercrime and cybersecurity can be highly technical and complex, a few basic practices can keep us secure. The NCA has developed four basic practices, they call the “Core Four,” that include using long, strong passwords and a password manager, turning on Multifactor Authentication (MFA also known as 2FA), keeping your software updated, and recognizing and reporting scams and phishing techniques.

Strong Passwords. While there is talk among cybersecurity professionals of migrating security away from passwords, we still need passwords when we open most online accounts. As computing power has improved over the years cybercriminals have improved their ability to crack passwords quickly to take over other people’s accounts. The current guidance for passwords is that they should be

·         Long, at least 16 characters or more.

·         Complex, including upper and lower case, numbers, and special characters.

·         Unique, use a different password for each of your accounts.

You might have many accounts with passwords and keeping track of them is hard since memorizing each one is impossible. The best way to keep track is to use a password manager (or vault) to securely store all of your strong passwords. Password managers are encrypted to protect your passwords from view of strangers. They also can generate strong passwords for you and often have the capability to fill in your passwords for you when you go into your accounts.

One final thing on passwords. Change the password to any account that has been breached or that you suspect may have been breached.

Multifactor Authentication. When you use a password to enter your account, you are using something that you know to enter your account. By using a second factor, the holders of your account can be assured that you are you, not someone who has stolen your password. Second factors can be something you have, like your cell phone, or they can be something you are, like your fingerprint or your face.

Using MFA improves the security of your accounts. While strong passwords can help to protect your accounts from strangers entering them, they do have some weaknesses. Scammers can acquire your passwords through phishing emails or text messages and cybercriminals can acquire your passwords through data breaches or they can purchase them from other cybercriminals. Using MFA provides a second security layer making it more difficult for a cybercriminal to enter your accounts.

MFA can be used through a text message, a phone call, or email. The most secure method to use MFA is with an authenticator app such as Microsoft Authenticator or Google Authenticator. Authenticator apps communicate with the service holding your account via a secure means precludes a cybercriminal from intercepting the codes that you exchange with the holder of your accounts.

Wherever you can, sign up for MFA to protect your online accounts.

Watch Out for Phishing. Scammers will use a phishing technique to harvest personal information that they can use to impersonate you, including your passwords. Phishing attempts can come through email, text messages (smishing), phone calls, (vishing), or QR code (quishing).  Typically, you will receive an email or text with an urgent message that claims it needs your immediate attention. It will lead you to a link to go to a website where the scammer will harvest your personal information or download malware that can harvest the information on your device.

When you receive an email or text, inspect the email of the sender to make sure it is authentic and that any URL’s are authentic before you click on them. Another thing to do is not to click on the link and use an URL for the organization that you have looked up outside of the email or text. Be suspicious of any emails or texts that are designed to get you emotional and urge you to act quickly. Also, be wary or emails or texts that appear to be from someone you know. Instead of replying to the email/text, call or email them separately.

Update your Software. Updating your software on your devices (PC, smartphone, tablet computer, modem, router, etc.) is important to help fix bugs in your software and to patch security weaknesses in your software. Software designers often update the software that you use to fix bugs that they find after the software has been released to users. They also release “improvements” to their software to make it run more efficiently or easier to use by its users (this can be a contentious issue whether an improvement really improves the operation). Finally, and very importantly, software developers send out security patches to close security weaknesses that they have found in the software code. They may find the weakness on their own, or it may be pointed out to them by other software engineers, or they may find out that cybercriminals have been using a backdoor that they have found and are exploiting for their own purposes.

Updating your devices can be very easy. Go into settings and select the choice to receive updates automatically. While you can check manually for updates, or you can be notified when an update is available, automatically updating is the easiest and best action to take for most of us.

A word of warning. Scammers take advantage of our understanding that we should update our devices. They can use update notifications to fool you into clicking a link. A full screen window telling you to update is a scam.

 

 

National Cybersecurity Alliance:

https://www.staysafeonline.org/events/core-4-webinars

 

Monday, April 8, 2024

MULTI-FACTOR AUTHENTICATION- Beware of MFA Fatigue Attacks

While Multi-Factor Authentication (MFA) has become a premier tool to protect your accounts from being hacked by a cybercriminal, hackers are trying to find ways to overcome its benefits and use it to enter your accounts.

One typical attack is for a cybercriminal to obtain the ID and password for one of your accounts then try to sign in. If the account is set up with MFA then it will send a code or ask for confirmation to open up the account. If you do not approve the login, the cybercriminal will continue to try to login repeatedly hoping that you will become annoyed or “fatigued” enough to give up and allow the login to continue.

Krebs on Security reports that it has received reports of criminals using this technique with a twist against Apple customers. The cybercriminals will try the classic MFA fatigue attack. But if their victim doesn’t approve a login, they will call the victim up claiming to be from Apple support. They tell the victim that they are under attack and that Apple support needs to “verify” a one-time code. Of course, the code is the standard MFA notification with a code to enter or a selection to approve or disapprove logging in.

The attack on Apple systems may take advantage of bugs unique to Apple. Krebs on Security observes that changing your account phone number to a VOIP phone number might help. Also, using an email alias could also help. See the Krebs on Security article below for details.

If you receive a notice to approve a login and you are not logging into your account, then obviously you should deny the request. Someone is trying to get into your account that you do not want in there. If the notifications are persistent and numerous, after the attack subsides (assuming that it does stop) change the password to your account to another strong password. Changing your password should prevent someone with your old password from trying to login in the near future.

 

Krebs on Security:

https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/

 

National Cybersecurity Alliance:

https://staysafeonline.org/resources/multi-factor-authentication/

 

Wikipedia:

https://en.wikipedia.org/wiki/Multi-factor_authentication_fatigue_attack

 

 

Monday, November 6, 2023

CYBERSECURITY- Update Your Software

Long passwords, using Multifactor Authentication, and detecting attempts at phishing are all important techniques to keep your online information secure. One more simple action will also help you keep your online identity and information safe. That is to update your computer, laptop/tablet, and smartphone when updates are available.

Cybercriminals work tirelessly to find vulnerabilities in software to gather information about you or your company. When software developers find out about those vulnerabilities, they plug the holes then send an update (also known as a patch) to the software’s registered users.

It’s important to install security updates as soon as possible. The sooner you update your device, the sooner you will be secure from the specific threat(s) that the update is designed to plug.

The easiest way to update your software is to turn on automatic updates in your settings for your operating system and any of the applications that you have on your device.

Some updates may require your permission to install. Give your permission as soon as possible. That way your device will be safe.

By updating your software from the source of its creation, you ensure that updates come from legitimate sources.

Updating may seem too simple, but it is as essential as long passwords, Multifactor Authentication, and blocking phishing attempts.

 

Cybersecurity & Infrastructure Security Agency:

https://www.cisa.gov/secure-our-world/update-software

https://www.cisa.gov/news-events/news/understanding-patches-and-software-updates

 

National Cybersecurity Alliance:

https://staysafeonline.org/resources/software-updates/

  

Ask Leo:

https://askleo.com/five-resolutions-holidays-new-year/

 

 

 

Thursday, November 2, 2023

CYBERSECURITY- Multifactor Authentication

Using passwords to enter online accounts has been around for a long time. Using long complex passwords works against brute force attacks. But there have proven to be many attack methods for cybercriminals to use to obtain passwords. For example, phishing attacks use social engineering to trick victims into giving over their passwords. Also, your passwords can be acquired through a data breach.

So, passwords have proven to be more fragile as far as security is concerned. If a cybercriminal can trick you into giving him your password or obtain it by stealing it from a database that you have no control over, then there needs to be a different or added way to ensure that you are who you say you are.

As a result, cybersecurity professionals have come up with a new method to authenticate you as you, Multifactor Authentication (MFA). Also known as Two Factor Authentication, MFA adds a second factor to authenticate you. When you use an ID and password, you are using something that you know to give the holder of your online account. With MFA, you use either something that you have (cell phone) or something that you are (fingerprints or face) to authenticate your identity.

When you sign into your account, you enter your ID and password as usual. But then the service might send you a text message or email with a code that you enter into the sign in form. That way, the service knows that it has the right person.

But text messages and email can be intercepted. So, cybersecurity professionals have developed secure authenticator apps such as Google Authenticator and Microsoft Authenticator. With an authenticator app a code will show on the app, which you can enter the code in the dialog on your PC or laptop. The codes are short-term, lasting only 30 seconds or so. This helps ensure security, making it harder for identity thieves to break into your account.

And you don’t have to use MFA every time you log into an account. Most services will let you in without using MFA as long as you are still on the same computer or device. Some services will give you a choice between never using MFA on your current computer, using MFA periodically, or always using MFA. Based on your settings, you will only need to use MFA if you use a different computer or device, or you change your password. Some services know where you are so they may require MFA if you try to log in if you are away from home.

MFA can be circumvented. Scammers have been known to get into online accounts by fooling the victim. They may convince a victim to give over their ID and password then ask for the code if MFA is instituted. Another method is for the scammer to obtain an ID and password via a data breach or purchase on the dark web. When they try to sign into an account with MFA, the real owner of the online account receives an MFA text or MFA push notice to authenticate the sign in. The scammer might sign in multiple times to send the MFA notice, bombarding the account owner in what is called “MFA fatigue” until the owner approves the sign in request.

If you receive an MFA notification and you are not trying to log into an account, disapprove or do not fill in any information. And do not give anyone your ID and password, or MFA authentication code even if you are talking to them.

Even with the workarounds that cybercriminals may have found, MFA works to protect your online accounts. Both Microsoft and Google have announced that MFA can block up to 99% of most attacks on online accounts.

For any online account that offers it, set up MFA to protect your valuable information.

 

Norton:

https://us.norton.com/blog/emerging-threats/password-attack

 

ZDNET:

https://www.zdnet.com/article/microsoft-using-multi-factor-authentication-blocks-99-9-of-account-hacks/

 

Ask Leo:

https://askleo.com/two-factor-authentication/

 

National Cybersecurity Alliance:

https://staysafeonline.org/online-safety-privacy-basics/multi-factor-authentication/?utm_content=269329244&utm_medium=social&utm_source=twitter&hss_channel=tw-71354375&s=09

 

 Cybersecurity & Infrastructure Security Agency:

https://www.cisa.gov/secure-our-world/turn-mfa

 

Microsoft:

https://support.microsoft.com/en-us/topic/what-is-multifactor-authentication-e5e39437-121c-be60-d123-eda06bddf661

 

 

 

 

 

 

 

Wednesday, September 27, 2023

FRAUD/SCAMS- Don't Blame the Victim

AARP would like you to reconsider your attitudes toward fraud victims. It notes that the language we use when referring to victims of frauds or scams often stigmatizes the victim. Phrases like: "I would not fall for that!" "How could you fall for this?"

According to a study conducted by AARP, the FINRA (Financial Industry Regulatory Authority) Investor Education Foundation, and Heart+Mind Strategies 32% of Americans agree with this statement- “Honestly if you fall victim...a lot of that is on you.”

Also, according to the study, 83% of Americans say that a scam can happen to anyone. Yet, 53% say the victim is to blame for "falling for fraud.”

Much of this attitude is not anyone’s fault. In America we have an attitude of the independence of the individual and for personal accountability.

This attitude may also be a result of some misunderstanding about fraud and fraud victims. Some people mistake fraud with consent. Fraud is defined as “…an intentionally deceptive action designed to provide the perpetrator with an unlawful gain or to deny a right to a victim.”

Also, we often think of fraud victims as the elderly with diminished cognitive abilities. But recent statistics show that younger people report losing money to fraud more often than older people. For example, 43% of 20–29-year-olds reported losing money to fraud versus 23% of 70–79-year-olds. The graphic below, from the Federal Trade Commission (FTC), shows that more younger people report losing money to fraud than older people and that when they do lose money, younger people lose less than older people. For example, for 30-39-year-olds 89 per 100k of population report losing an average of $500 to fraud. While for 80–89-year-olds 39 per 100k of population report losing an average of $1,393 to fraud.  





Being victimized by fraud, like other crimes, brings a feeling of loss, violation, and victimization. The Identity Theft Resource Center (ITRC) points out that it has detected an increase in thoughts of suicide by fraud victims who have contacted it. ITRC provides a toll-free phone number (888-400-5530) for fraud victims to call for help and advice. It also conducts an annual survey that measures the effects of identity theft. As the CEO, Eva Velasquez, points out in its latest Consumer Impact Report, ITRC has noted that 2-4% of its survey respondents identity theft victims have considered suicide for almost two decades. In 2020, during the pandemic, that figure jumped up to 8%. In 2021 it grew to 10%. In 2022, the number of people who said that they considered suicide rose to 16%.

The ITRC attributes this increase to the rise of sophisticated social engineering scams, an increase in very large dollar losses, including an increase in six-figure losses, and a dismissive or judgmental discussion around fraud, even though everyone is vulnerable to it.

AARP urges everyone to treat fraud victims with kindness and empathy. If a relative or friend has been victimized by fraud, show empathy to them. Focus the attention on the fact that the criminal stole from them. Use the terms “criminal” and “crime” instead of “duped” or “fell for.” Three things you can do to help a fraud victim include,

 

·         Skip the blame and shame.

·         Listen with compassion.

·         Help out with fraud reporting, be it to a local police, bank, FTC, or FBI

 

Like victims of other crimes such as assault, domestic violence, or theft, fraud victims deserve our empathy and support.

 

 

 

AARP:

https://www.aarp.org/money/scams-fraud/info-2022/victim-blaming.html

https://www.aarp.org/content/dam/aarp/money/scams_fraud/2022/07/aarp-fraud-victim-blaming-report-06-07-22.pdf

https://www.aarp.org/podcasts/the-perfect-scam/info-2023/victim-blaming.html

https://www.aarp.org/money/scams-fraud/info-2022/mental-health-impact.html?intcmp=AE-FRDSC-MOR-R2-POS3

https://www.aarp.org/money/scams-fraud/info-2023/supporting-loved-ones.html?intcmp=AE-FRDSC-MOR-R2-POS3

 

Identity Theft Resource Center:

https://www.idtheftcenter.org/

https://www.idtheftcenter.org/publication/2023-consumer-impact-report/

https://www.idtheftcenter.org/2023-consumer-impact-report-webinar-by-the-identity-theft-resource-center/

 

Federal Trade Commission:

https://www.ftc.gov/news-events/news/press-releases/2023/02/new-ftc-data-show-consumers-reported-losing-nearly-88-billion-scams-2022#:~:text=Newly%20released%20Federal%20Trade%20Commission%20data%20shows%20that,than%20%243.8%20billion%E2%80%94than%20any%20other%20category%20in%202022.

https://www.ftc.gov/news-events/data-visualizations/explore-data

 

 

 

 

Tuesday, September 26, 2023

INTERNET SAFETY- Educating Your Children to be Safe Online

The internet and social media have become important to our lives. They also become important to your children's lives as they mature. In the latest issue of the Sheriff’s Office’s crime prevention newsletter, “Partners in Crime Prevention, the Sheriff’s Office suggests some ways you can guide your children to be safe on the internet.

 

 

 

Snohomish County Sheriff’s Office:

https://www.snohomishcountywa.gov/ArchiveCenter/ViewFile/Item/7071

 

 

 

Saturday, October 29, 2022

CYBER SECURITY – Phishing/Smishing

You use strong passwords, 12 or more characters long, a combination of numbers, letters, and symbols, you make sure to use a different password for each of your accounts, and you store your passwords in a secure password manager.

Plus, you have set your operating system and your software to update automatically for security and other updates from the originator of the software.

You may think that you have all of your bases covered. But there is one other method that cyber criminals can use to get into your online accounts and your computer, tablet, or smartphone. They can go “phishing.”

Phishing is where scammers send you an email or a text message (called smishing) with links embedded in the email/message that takes you to a website where the scammer collects your personal information or downloads malware that can collect data from your computer for the scammer’s use.

According to the National Cybersecurity Alliance, phishing is the most common cause of data breaches. Phishing exploits a basic weakness of cybersecurity, we human beings.

Phishing attempts employ social engineering techniques to convince you to click on the links in the message. Phishing is especially an important threat for the business world because it can be used to collect intelligence about the company or manipulate the data that a company stores on its computer network as in a ransomware attack. Phishing can affect individuals as targets for identity theft.

The social engineering techniques employ one or more of the following elements:

·         They “Pretend” to be an organization or someone you know. They will impersonate organizations such as Microsoft, Amazon, Comcast, PayPal, or a major bank like Chase or Wells Fargo. They will format an email to look like it comes from the organization. For an attack on a business, they might make the email/text look like it came from a coworker or a supervisor.

·         The scammer will tell you that there is a “problem” that you need to solve. They may provide a link in the email/text that is supposed to take you to a web page that would help you solve the problem. The web page will try to collect your personal information, such as your ID and password for a specific account, your Social Security Number, or an account number. Scammers who target a business might have you move funds (if you are in the finance department) or ask for certain information. In the meantime, the link could also download malware onto your computer.

·         The scammer will “pressure” you to act fast. They will tell you that the problem needs to be taken care of right away or there could be dire consequences to you.

 

When you receive an email or text message, ask yourself the following questions:

·         Does it contain an offer that is too good to be true?

·         Is the language urgent, alarming, or threatening?

·         Are there many misspellings and bad grammar?

·         Is the greeting ambiguous or very generic?

·         Does it ask for your personal information?

·         Does it pressure you to click on a link or attachment right away?

·         Does it make a strange or abrupt business request?

If the answer is yes to any of the above questions, delete the email/text. If the answer is no to the following question, delete the email/text.

·         Does the sending e-mail address match the company that it says it is coming from?

 

Also, report a suspect phishing email. If it came to your business, report it to your IT department. If it came to your personal email account you can report it to your email provider, for example,

·         Microsoft Outlook- https://support.microsoft.com/en-us/office/phishing-and-suspicious-behaviour-0d882ea5-eedc-4bed-aebc-079ffa1105a3

·         Gmail- https://support.google.com/mail/answer/8253?hl=en

·         Mac Mail- https://support.apple.com/en-us/HT204759

 

Here are more resources that explain phishing and smishing,

 

 

National Cybersecurity Alliance:

https://staysafeonline.org/wp-content/uploads/2020/05/To-Click-or-Not-to-Click-1.pdf

https://20740408.fs1.hubspotusercontent-na1.net/hubfs/20740408/Phishing.pdf?utm_campaign=Cybersecurity%20Awareness%20Month&utm_medium=email&_hsmi=215220112&_hsenc=p2ANqtz-8S2-wU4O8ztw09QrtrGmpaPoD7T9TbiO5Pyg1tOVGtPrI9JNsr8c7w97zAytMDJO8pkOWwe-u5qgfFZ0aMKu3RaSYfrL3XhmV-WJ9wIKy6EbTuKwY&utm_content=215220112&utm_source=hs_automation

https://20740408.fs1.hubspotusercontent-na1.net/hubfs/20740408/CAM_2022_Infographics_Phishing_NOLOGO.pdf?utm_campaign=Cybersecurity%20Awareness%20Month&utm_medium=email&_hsmi=215220112&_hsenc=p2ANqtz-_dKAnZVl1XxHhkRx0PqzuZ58gpvaZW6OZuiZsc1cE3vlDHMU1-hYlSPVbVy3VCbmbQ9hqoHIxzNcPXT6Z3GotYtN6p59N0B_rJhXynYWnHYm8kB1s&utm_content=215220112&utm_source=hs_automation

https://staysafeonline.org/resources/software-updates/?utm_campaign=Cybersecurity%20Awareness%20Month&utm_medium=email&_hsmi=228150127&_hsenc=p2ANqtz-98raGuotQG1srXgV-R3FmsHvnRelgYQpPjwvC9E1e-ryz3GhSTSEJtzCeSW4AOW1_mSmTMjReGvOmxx1DQln5rwweLx9EmLm7-I6-tnh7PJxHN6GY&utm_content=228150127&utm_source=hs_email

 

Ask Leo:

https://askleo.com/phishing_how_to_know_it_when_you_see_it/

https://askleo.com/what-is-smishing/

https://askleo.com/7-signs-of-phishing-to-watch-for/

 

Federal Trade Commission:

https://consumer.ftc.gov/articles/how-recognize-and-avoid-phishing-scams

 

Monday, October 24, 2022

CYBER SECURITY – Password Managers

Multifactor authentication (MFA) adds an additional security layer to your online accounts to ensure that unauthorized people do not access your account. MFA tries to make up for weaknesses in the ID/password model of access that have developed over the years. Those weaknesses include simple, easy passwords to guess or break (like using the word “password,” or “password1234”) or using the same password to access several online accounts.

But, even with the spread of the use of MFA, we still rely on ID and password as an entry into our accounts. There are organizations that seek to eliminate passwords (https://fidoalliance.org/), but, until industry adopts another authentication standard, we will be relying on ID and passwords in whole or in part.

An ID and password represent something we know. But if someone else also knows that ID and password, by stealing it in a hack of a major database or purchasing it in the dark web, they can access your accounts and copy your personal information to use in frauds, or, if it is a bank account, move money from your account to their own account.

Cyber criminals can also guess your password, especially if it is easy to guess like password1234, or it is short. In a brute force attack, cyber criminals use a computer program that guesses passwords. For passwords under 10 characters a successful guess can be instant or just a few seconds or minutes, even if you use numbers, upper- and lower-case letters and symbols. For passwords 12 characters or over a successful guess can take several years to several lifetimes for a successful guess. This is why cybersecurity professionals now recommend passwords be 12 characters or longer and contain a random assortment of numbers, upper- and lower-case letters and symbols.

But this approach causes a problem. Our human brains cannot remember such complicated passwords. We might be able to memorize one password that meets this standard, but not several different passwords. And it is easy for an individual to need passwords for tens if not hundreds of accounts.

A way around this might be to have a “universal” password. A password 12 or more characters long, with numbers, letters, and symbols that you memorize and use for all of your accounts. The problem with that is that if a hacker discovers your password in one account, they can access any account that you own. And cyber criminals will try your password on other accounts that you own. This is why cybersecurity professionals recommend using a different password for each account.

So, you need s separate password for each of your accounts that you own that you cannot remember. What to do?

Use a password manager. Password managers are apps that store your passwords for each of your accounts. They can reside on your smartphone, laptop, and desktop so that you can have access to your passwords just about anywhere. The information in a password manager is encrypted so that no one other than you can access it.

Password managers often offer other features that make it easier to use passwords. They can generate new passwords when you need a password for a new account or when you change passwords. They can fill in your password when you sign into your account. They also can synchronize passwords among several of your devices.

There are several password managers on the market. Some you pay for and others that are free. Check the “PC Magazine” links below for resources that evaluate the password managers that are on the market.

With a good password manager and MFA on your accounts, you improve the security of your personal information. You make it difficult for a cyber criminal to gain access to your accounts. And if someone does learn your password, they cannot access your account with MFA.

 

 

South Snohomish County Crime Watch:

 https://ssnoccrimewatch.blogspot.com/2022/10/cyber-security-multifactor.html.

 

Norton:

https://us.norton.com/blog/emerging-threats/password-attack#

 

KFMB CBS8, San Diego:

https://www.cbs8.com/article/news/verify/people-with-shorter-passwords-should-change-them-immediately/509-1e4a5b50-3692-4bb8-b17b-ff77a2e63826

 

 

National Cybersecurity Alliance:

https://staysafeonline.org/online-safety-privacy-basics/what-about-password-manager-risks/

 

Ask Leo:

https://askleo.com/are_password_managers_safe/

https://askleo.com/responses-to-your-three-common-password-manager-objections/

 

PC Magazine:

https://www.pcmag.com/picks/the-best-password-managers

https://www.pcmag.com/picks/the-best-free-password-managers

 

Monday, October 10, 2022

CYBER SECURITY – Multifactor Authentication Blocks 99.9% of Account Attacks

Lately, cyber security professionals have been promoting the use of Multifactor Authentication (also known as 2 Factor Authentication) with your online accounts. According to Microsoft, multifactor authentication (MFA) blocks 99.9% of automated attacks on user accounts.

MFA adds a layer of security to our traditional ID and password method of gaining access to online accounts. Your ID and password is a factor that tells the custodian of your account that you have a right to use that account. This is something you know. But if someone else can find out your ID and password they can also gain access to your account because they know your ID and password. And if they are someone you do not want in your account, they can cause a lot of mischief. What if that account is your bank account, credit card account, or your email account?

According to some sources, there are over 15 billion passwords for sale by cybercriminals on the dark web. And 81 % of breaches leverage stolen or weak passwords.

MFA adds a second factor to authenticating you as you. That factor can be something you have, such as your smartphone, or something you are, such as your fingerprint or face.

With MFA, when you enter your ID and password, the custodian of your account might send you a code via email, text message to your phone, or an authenticator app on your phone. You enter the code as a second step when you sign in. This way, you verify who you are with your phone which is in your possession. Someone else cannot pose as you because they do not have your phone. Even if they have your ID and password, they don’t have your phone. If they do have your phone, it is important to lock your phone with a PIN, fingerprint, or facial scan, so that someone else cannot use your phone.

Authenticator apps are considered the best way to use MFA because they are the most secure method of authentication.

Security is often considered to add inconvenience to our online lives. MFA is not necessarily adding inconvenience. You will use MFA the first time that you sign onto an account. But as long as you are from the same computer or device as when you started you won’t have to use MFA. You might have to use MFA if you access the account from a different device, after changing your password, or if you have not accessed the account for a long time.

As Microsoft has noted, MFA blocks 99.9% of automated attacks on accounts. That leaves some room for successful attacks. The National Cybersecurity Alliance has seen instances where hackers have circumvented MFA by seeking MFA approval multiple times and the owner approves the log-in out of confusion or annoyance. There also have been instances of scammers contacting victims and asking for access to a bank account for example and telling the victim to give the scammer the MFA code. A good rule of thumb is to not to approve access to your account if you did not log-in to the account.

Major software developers have tried to provide another easy-to-use layer of security to protect your privacy and your sensitive information. You will use MFA occasionally. But you have the confidence that other people will not have access to your accounts.

 

 

National Cybersecurity Alliance:

https://20740408.fs1.hubspotusercontent-na1.net/hubfs/20740408/CAM_2022_Infographics_MFA_NOLOGO.pdf?utm_campaign=Cybersecurity%20Awareness%20Month&utm_medium=email&_hsmi=215220112&_hsenc=p2ANqtz-8zBj3BniJ-u2dPGM3xzAJZiMu4LKoI2AVhPBsCe1Zpi2vWz5fkINCnswSXf60loEg3jk0iKfwFRov17ZcxmoBMgdUaABUuboDOw0pBZ7LMaIYM3NU&utm_content=215220112&utm_source=hs_automation

https://staysafeonline.org/online-safety-privacy-basics/multi-factor-authentication/?utm_campaign=Cybersecurity%20Awareness%20Month&utm_medium=email&_hsmi=228150127&_hsenc=p2ANqtz--M2F81ZWdsurpV_FEXcZuI_G_rJWaREwUOBR8PmV9fRqN8eHzA6iMiTxVaCapdHiwrEu6AFDVv2v8yjtgW9rZ-PoYvI6LLjdTH3IbP96xvudGZPKg&utm_content=228150127&utm_source=hs_email

 

 

ZDNET:

https://www.zdnet.com/article/microsoft-using-multi-factor-authentication-blocks-99-9-of-account-hacks/

 

Tom’s Guide:

https://www.tomsguide.com/news/google-2fa-50-percent-reduction

 

South Snohomish County Crime Watch:

https://ssnoccrimewatch.blogspot.com/2022/02/multifactor-authentication-new-way-to.html