8 Tips for Staying Safe from Ransomware Attacks

What is Ransomware?

Over the past year, you may have seen the term ransomware popping up frequently. For enterprising hackers, this once uncommon tactic has become standard operating procedure, and with good reason – it pays. Ransomware is malware that employs encryption to hold a victim’s information at ransom. The hacker uses it to encrypt a user or organization’s critical data so that they cannot access files, databases, or applications. A ransom is then demanded to provide access. It is a growing threat, generating billions of dollars in payments to cybercriminals and inflicting significant damage and expenses for businesses and governmental organizations.  

Why should I care?

McAfee Labs counted a 60% increase in attacks from Q4 2019 to Q1 2020 in the United States alone. Unfortunately, the attacks targeting organizations also impact the consumers who buy from them, as the company’s data consists of its customers’ personal and financial information. That means your data if you’ve done business with the affected company. Fortunately, there are many ways you can protect yourself from ransomware attacks.  

How do I know if my information is vulnerable?

When a company is hit with a ransomware attack, they typically are quick to report the incident, even though a full analysis of what was affected and how extensive the breach may have been may take much longer. Once they have the necessary details they may reach out to their customers via email, through updates on their site, social media, or even the press to report what customer data may be at risk.  Paying attention to official communications through these various channels is the best way to know if you’ve been affected by a ransomware attack. 

Put ransomware fears in your rearview mirror with these tips:

1. Back up your data 

If you get ransomware, you’ll want to immediately disconnect any infected devices from your networks to prevent the spread of it. This means you’ll be locked out of your files by the ransomware and be unable to move the infected files. Therefore, it’s crucial that you always have backup copies of them, preferably in the cloud and on an external hard drive. This way, if you do get a ransomware infection, you can wipe your computer or device free and reinstall your files from backup.  Backups protect your data, and you won’t be tempted to reward the malware authors by paying a ransom. Backups won’t prevent ransomware, but they can mitigate the risks.  

2. Change your credentials

If you discover that a data leak or a ransomware attack has compromised a company you’ve interacted with, act immediately and change your passwords for all your accounts. And while you’re at it, go the extra mile and create passwords that are seriously hard to crack with this next tip. 

3. Take password protection seriously

When updating your credentials, you should always ensure that your password is strong and unique. Many users utilize the same password or variations of it across all their accounts. Therefore, be sure to diversify your passcodes to ensure hackers cannot obtain access to all your accounts at once, should one password be compromised. You can also employ a password manager to keep track of your credentials and generate secure login keys.  

4. Enable two-factor or multi-factor authentication

Two or multi-factor authentication provides an extra layer of security, as it requires multiple forms of verification. For instance, you’ll be asked to verify your identity through another device, such as a phone. This reduces the risk of successful impersonation by hackers.  

 5. Browse safely online

Be careful where you click. Don’t respond to emails and text messages from people you don’t know, and only download applications from trusted sources. This is important since malware authors often use social engineering to get you to install dangerous files. Using a security extension on your web browser is one way to browse more safely.  

6. Only use secure networks

Avoid using public Wi-Fi networks, since many of them are not secure, and cybercriminals can snoop on your internet usage. Instead, consider installing a VPN, which provides you with a secure connection to the internet no matter where you go.   

7. Never pay the ransom

While it is often large organizations that fall prey to ransomware attacks, you can also be targeted by a ransomware campaign. If this happens, don’t pay the ransom. Although you may feel in the moment that this is the only way to get your encrypted files back, there is no guarantee that the ransomware developers will send a decryption tool once they receive the payment. Paying the ransom also contributes to the development of more ransomware families, so it’s best to hold off on making any payments. Thankfully there are free resources devoted to helping you like McAfee’s No More Ransomware initiative McAfee, along with other organizations, created www.nomoreransom.org/ to educate the public about ransomware and, more importantly, to provide decryption tools to help people recover files that have been locked by ransomware. On the site you’ll find decryption tools for many types of ransomware, including the Shade ransomware.  

8. Use a comprehensive security solution

Adding an extra layer of security with a solution such as McAfee® Total Protection, which includes Ransom Guard, can help protect your devices from these cyberthreats. In addition, make sure you update your devices’ software (including security software!) early and often, as patches for flaws are typically included in each update. Comprehensive security solutions also include many of the tools we mentioned above and are simply the easiest way to ensure digital wellness online. 

Stay Updated

To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home on Twitter, subscribe to our newsletter, listen to our podcast Hackable?, and ‘Like’ us on Facebook. 

The post 8 Tips for Staying Safe from Ransomware Attacks appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Sextortion Lands Inmate in Federal Prison

Sextortion Lands Inmate in Federal Prison

An inmate of the South Carolina Department of Corrections (SCDC) has been sentenced to five years in federal prison for his role in a deadly sextortion scheme.

Wendell Wilkins, of Ridgeville, South Carolina, was serving a 12-year sentence for attempted armed robbery when he pleaded guilty to involvement in a cyber-scam to blackmail military members. 

Prosecutors alleged 32-year-old Wilkins posed as young women and joined dating sites using smartphones smuggled into the correctional facility. He then allegedly contacted members of the US military, sending them sexually explicit images of young women that he had obtained from the internet.  

Wilkins is accused of tricking the military members into sharing personal information and nude photographs of themselves with him by making them believe that they were communicating with a woman. 

As part of the scam, Wilkins, and other SCDC inmates under his direction, then allegedly contacted each military member, purporting to be the father of the young woman with whom the member believed that they had been communicating.  

The scammers then told the military members that the women they had been exchanging sexually explicit images with were underage and that, as a result, they were now in possession of Child Sexual Abuse Material (CSAM). 

Posing as the fake women’s fake fathers, the scammers threatened to have the military members arrested or dishonorably discharged unless they paid money, said prosecutors.

“In total, more than 300 military members throughout the United States were victims of the scheme, and the amount of loss exceeded $350,000,” said Acting US Attorney Rhett DeHart. “Several military members committed suicide after falling victim to this extortion scheme.”

Wilkins pleaded guilty to money laundering for his role in the scheme and was sentenced to 66 months in federal prison and 36 months of supervised release to be served after he completes his current 12-year state prison sentence. 

“This is another example of how dangerous it is for inmates to have illegal cell phones,” said South Carolina Department of Corrections director Bryan Stirling.

“States need the ability to jam cell phone signals inside prisons so we can keep inmates from continuing their illegal activities.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Teen Crashes Florida School District’s Network

Teen Crashes Florida School District’s Network

A teenage boy from Florida is facing felony charges after carrying out a cyber-attack that knocked 145 schools offline last spring. 

The unnamed 17-year-old junior at St. Petersburg High School crashed the entire computer network of the Pinellas County School District in Florida by deploying a distributed denial-of-service (DDoS) attack. His actions caused all the schools in the district to lose internet access on March 22 and 23.

According to a search warrant from the St. Petersburg Police Department, the youth said he had become “fixated” on the idea of disrupting the district’s digital peace after watching a video online that highlighted the vulnerability of school networks. 

CI Security founder Michael Hamilton said: “What the student did was he brought down a distributed denial-of-service attack, which is not the same as breaking in and stealing things and changing grades. What it does, is it makes the whole network unavailable.”  

The teen, who has since been expelled from school, said that he immediately regretted his actions.

“By the time it was done, there was no way to undo it,” he said in an interview with the Tampa Bay Times

“If I could go back, I wouldn’t do it again.”

The teen said he hopes to get his GED and have a career in cybersecurity. His mother said her son “was just pushing it to see how smart he could go with it.”

“It wasn’t something that was malicious,” she said, “it was just something like a video game to him in his head.”

According to documents filed by the St. Petersburg police to get a search warrant for the teen’s phone, the school district’s director of network and telecommunications, Brian Doughty, told investigators that the attack was considered “critical” because it coincided with statewide testing.

Charter-Spectrum had provided the Pinellas County School District with distributed denial-of-services protection for years, said district spokesperson Isabel Mascareñas. However, the protection was not maintained when the district migrated to a new system in late 2020.

Mascareñas said that, following the attack, Charter-Spectrum has reactivated the protection and given Pinellas County School District a $23,000 credit. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Scripps Notifying 147K People of Data Breach

Scripps Notifying 147K People of Data Breach

A California healthcare provider is informing more than 147,000 people that their personal data may have been exposed in a recent cyber-attack.

Scripps Health, which operates five acute-care hospitals in San Diego, among other facilities, took most of its network offline after detecting a ransomware infection at the beginning of May. 

The San Diego–based nonprofit system suspended access to several applications, including MyScripps and scripps.org. 

While the majority of Scripps’ network has now been restored, the attack caused four weeks of disruption, with patient appointments’ having to be canceled or rescheduled. Employees were forced to rely on offline documentation methods, and ambulances had to be diverted, causing a surge of patients at other local facilities.

After learning that Personal Identifiable Information (PII) was exposed in the attack, Scripps has begun the process of notifying 147,267 individuals that their information may have been compromised. 

Data exposed includes health information, Social Security numbers, driver’s license numbers, and financial information. 

In a letter mailed to patients Tuesday, Scripps stated that an investigation into the security incident had determined that an unauthorized person had gained access to the healthcare provider’s network and exfiltrated copies of some documents before deploying ransomware.

The company said: “Importantly, this incident did not result in unauthorized access to Scripps’ electronic medical record application, Epic. However, health information and personal financial information was acquired through other documents stored on our network.”

Scripps said that while it had not found evidence that any of the exposed data had been used to commit fraud, it would be offering credit monitoring to some individuals affected by the attack. 

“For the less than 2.5% of individuals whose Social Security number and/or driver’s license number were involved, we will be providing complimentary credit monitoring and identity protection support services,” said the company. 

The investigation into what documents were exposed is ongoing, and Scripps said the number of individuals whose data was breached could rise. 

“We have kicked off an extensive manual review of those documents. This is a time-intensive process that will likely take several months, but we will notify affected individuals and entities as quickly as possible in accordance with applicable regulatory requirements,” the company said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Banking Fraud up 159% as Transactions Hit Pre-Pandemic Volumes

Banking Fraud up 159% as Transactions Hit Pre-Pandemic Volumes

Banking fraud attempts soared by 159% from the final three months of 2020 to Q1 2021 as scammers sought to hide their attack in legitimate online activity, according to Feedzai.

Data used in the firm’s Financial Crime Report Q2 2021 Edition includes 12 billion global transactions between January-March 2021.

The vast majority (93%) of banking fraud during the period, as always, was online. However, while telephone banking made up less than 1% of total transactions, Q1 2021 saw fraud attempts via this channel spike by a dramatic 728% from the previous quarter.

The primary tactics cyber-criminals used to defraud banks and their customers include account takeover (42%), followed by new account fraud (23%), impersonation (21%), purchase scams (15%) and phishing (7%).

Account takeover (ATO) is usually the result of a scammer getting hold of victims’ online banking log-ins, while account openings can be done with real, synthetic or a blend of the two identities. Impersonation typically involves a fraudster pretending to be a figure of authority in order to access the victim’s bank account.

Overall, card-not-present (CNP) — dominated by online and mobile channels — accounted for 83% of all fraud attempts despite making up just 18% of card transactions. Part of that may be due to the roll-out of EMV cards, which has made in-person fraud using cloned cards more difficult.

That may also be responsible for the drop in POS malware designed to harvest card data from card magstripes as they are entered by customers at restaurants and convenience stores. This was particularly prevalent in the US.

Feedzai linked the increase in fraud to a broader surge in transaction volumes globally — and especially in the US, where generous government stimulus funding has put more money in consumers’ pockets.

Transaction volumes for all regions are now greater than pre-pandemic levels, it said.

“As vaccines become more widespread, we expect the behavioral changes taking place in the US today — namely more travel and a consumer base that more closely resembles a pre-pandemic world — to be mirrored in other countries,” the report argued.

“But that also means the high levels of fraud will only continue to grow. Consumers aren’t the only ones betting on recovery. Fraudsters are too.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Critical Zero-Day in WordPress Plugin Under Active Attack

Critical Zero-Day in WordPress Plugin Under Active Attack

Security researchers have warned of a critical new zero-day vulnerability in a WordPress plugin actively exploited in the wild.

The Fancy Product Designer plugin is installed on over 17,000 sites, allowing users to upload images and PDF files to products, according to experts at security vendor Wordfence.

“We initiated contact with the plugin’s developer the same day and received a response within 24 hours. We sent over the full disclosure the same day we received a response, on June 01 2021,” explained threat analyst Ram Gall.

“Due to this vulnerability being actively attacked, we are publicly disclosing with minimal details even though it has not yet been patched in order to alert the community to take precautions to keep their sites protected.”

The file upload vulnerability has a Common Vulnerability Scoring System (CVSS) score of 9.8. Although the Fancy Product Designer plugin has some checks to block malicious file uploads, attackers can easily bypass the checks. In theory, an attacker could upload executable PHP files to any site with the plugin installed, Gall warned.

“This effectively makes it possible for any attacker to achieve Remote Code Execution on an impacted site, allowing full site takeover,” he added.

Wordfence issued a new rule to its paid firewall product on Monday, with subsequent updates to its free version on June 30 to protect customers from the attacks.

However, users were urged to uninstall the plugin for the time being.

“As this is a critical zero-day under active attack and is exploitable in some configurations even if the plugin has been deactivated, we urge anyone using this plugin to completely uninstall Fancy Product Designer, if possible, until a patched version is available,” concluded Gall.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Battle for the Galaxy: 6 Million Gamers Hit by Data Leak

Battle for the Galaxy: 6 Million Gamers Hit by Data Leak

A Chinese game developer has accidentally leaked nearly six million player profiles for the popular title Battle for the Galaxy after misconfiguring a cloud database, Infosecurity has learned.

AMT Games, which has produced a string of mobile and social titles with tens of millions of downloads between them, exposed 1.5TB of data via an Elasticsearch server.

A research team at reviews site WizCase found the trove, which contained 5.9 million player profiles, two million transactions, and 587,000 feedback messages.

Profiles typically feature player IDs, usernames, country, total money spent on the game, and Facebook, Apple or Google account data if the user linked these with their game account.

Feedback messages contain account IDs, feedback ratings and users’ email addresses. At the same time, transaction data includes price, item purchased, time of purchase, payment provider, and sometimes buyer IP addresses, according to WizCase.

The firm warned exposed users that their data might have been picked up by opportunistic cyber-criminals searching for misconfigured databases. Data on how much money individuals have spent on the site could enable fraudsters to target the biggest spenders, it added.

WizCase warned that “it is common for unethical hackers and criminals on the internet to use personal data to create trustworthy phishing emails. The more information they possess, the more believable these emails look.”

It went on add that confidential information such as email addresses and user issues with the service could enable bad actors to “pose as game support and direct users to malicious websites where their credit card details can be stolen.”

The firm urged gamers to input the minimum amount of personal information possible when purchasing or setting up an account and parents not to lend children their credit cards.

WizCase said it reached out to AMT Games with news of the data breach but did not receive a response. The company later disabled access to the database.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk