Check Washing

I can’t believe that check washing is still a thing:

“Check washing” is a practice where thieves break into mailboxes (or otherwise steal mail), find envelopes with checks, then use special solvents to remove the information on that check (except for the signature) and then change the payee and the amount to a bank account under their control so that it could be deposited at out-state-banks and oftentimes by a mobile phone.

The article suggests a solution: stop using paper checks.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

How to Reduce Fake News in Online Advertising

How to Reduce Fake News in Online Advertising

Steps can be taken to reduce the threat of fake news infiltrating online advertising.

Speaking during the Westminster Forum Conference about tackling fake news and online misinformation, Konrad Shek, deputy director, policy and regulation at the Advertising Association, said the advent of disinformation has had an “enormous impact on trust in the media and politics.”

He said within commercial advertising there have been cases of false claims and promoted stories, and manipulated content, which can appear on social media and news feeds, while some websites that do “propagate false information are supported by adverts and legitimate ads can find themselves on these dubious websites.”

He also explained that there are online fraudsters that use tactics to better promote adverts, including adding clicks for misattribution, which can divert advertisers’ money to the fraudulent actor. “I’d refrain from saying that restricting adverts is a solution, as you have to think about the consequences of an approach and the impact it would have on the free internet,” he said. This calls for four options, he contitinued:

  1. Try and choke the funds to fake news websites, as brands are already sensitive about the impact of being associated with these websites and this is a good incentive to work towards being placed on such websites. However, he pointed out that the speed of ads in the supply chain mean it may not always be possible to know where the ad has been published
  2. The use of standards and technology to reduce ad fraud and reduce advertising money in the supply chain. “There are already a number of industry standards that have anti-fraud certification processes,” he said, with technology that can aid in the fight against ad fraud with an ever-increasing number of detection and prevention tools. “To that end, it is really important that the ASA is properly funded and it can continue to invest in technology to help it spot non-compliant ads online”
  3. Aiding the general public to build resistance and encourage critical thinking skills. “We need to invest more in digital literacy to help people inoculate themselves against scams and misinformation,” he said. “With society as a whole, we need to look at media more critically – look at ads with a more critical eye and ask what the motivation behind it is, and is it too good to be true?”
  4. Address political advertising, as this is not regulated by the ASA. “Politicians and political parties need to come together to figure out an appropriate solution soon, as in the meantime, unregulated political advertising erodes trust in all advertising”

“There is obviously a lot more to be done,” Shek said. “Economic gain is a significant factor in why disinformation exists as advertising plays a core part in it, but we need to realize there are other factors in play.”

He claimed a solution requires a holistic and proper multi-disciplinary approach, and work needs to be done to ensure like-minded countries are allied on this, as it is hard to discern what is real and what is not.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Experts Call for Online Fake News to Be Addressed as #COVID19 Vaccine Emerges

Experts Call for Online Fake News to Be Addressed as #COVID19 Vaccine Emerges

There needs to be better steps taken by politicians and social media platforms to deal with fake news, especially as the COVID-19 vaccine is created.

Speaking during the Westminster Forum Conference on tackling fake news and online misinformation, event chair Khalid Mahmood MP, shadow defense minister for procurement, said, as we have seen throughout the pandemic, certain misinformation has been passed around and it is effective in getting to people. “That is just in terms of the pandemic that we are seeing at the moment,” he added, pointing out that fake news is published about politicians too.

He said an issue is how responsibility “is totally negated from platforms where someone can put whatever they want and move forward” and trying to trace that back and address that is becoming increasingly difficult as platforms take time to deal with it.

Admitting that this is a very difficult issue to deal with, he said we need to look at some sort of level footing on this, before it is out of control.

Commenting on the role of platform providers, Katie O’Donovan, head of public policy at Google UK, said there is a challenge around freedom of speech where the meaning around the words can vary, depending on how things are said.

She said: “So you cannot regulate words and sentences, you have to understand the context of how they were made, and ask what is the context and hyperbole and is it a threat made to an individual or a group of people?”  

Asked by Infosecurity if social media platforms are doing enough to prevent fake news whilst enabling free speech, O’Donovan said there is a need for more legislation and regulation. She argued that government is doing a good job on addressing a broad range of harms, whilst offering the opportunity to engage and to “have a vibrant online debate.” However, platforms have a responsibility not to wait for that regulation, and over the years, that has grown very steadily.

Michael Wendling, editor of the Trending and Anti-Disinformation Unit at BBC News, said there is going to be a massive wave of vaccine disinformation, which is ramping up now, and as the vaccine becomes available for COVID-19 “that will make what happened over the 5G masts look like a minor skirmish.” He said if measures by platforms are effective, there will be a larger take up of the vaccine, and if not, there will be less of a take up and the pandemic may continue.

Also speaking was Oscar Tapp-Scotting, deputy director for security and international at DCMS, who confirmed it has been working with platforms to address disinformation and has seen platforms take steps to reduce “misleading narratives.”

He said: “Each of the platforms is different; each has a different user base and provides information in different ways, so how they tackle this will vary by platform.” He also said that in a recent meeting with social media platforms, they would agree to work with healthcare organizations to publish correct information, so users have the ability to make the right choice.

Mahmood said there is a need for politicians to look at social media and how it deals with fake news, “and this has to be the way for all of us in how we deal with fake news, as ultimately there has to be some sort of responsibility between both us and the platforms and how we get the motion across and how we get them to work together.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NCSC Helping Man United Recover from Cyber-Attack

NCSC Helping Man United Recover from Cyber-Attack

The National Cyber Security Centre (NCSC) is assisting Manchester United in dealing with the cyber-attack which struck the English football club last week.

Last Friday, the Premier League side confirmed in a statement that an incident had taken place,  following which affected systems were shut down to “contain the damage and protect data.”

One week later and the club’s internal IT system is not fully back up and running, with staff still unable to access emails alongside other operations. The NCSC is now helping Manchester United as it seeks to secure its network before restoring its IT system to full capacity.

A NCSC spokesperson is quoted as saying: “The NCSC is aware of an incident affecting Manchester United football club and we are working with the organization and partners to understand the impact.”

In its original statement, Manchester United said that its website and app were unaffected by the attack and it was not aware of any breach of personal data belonging to fans or customers, and this was reiterated on Thursday night. Quoted in The Guardian, the new statement read: “This attack was by nature disruptive, but we are not currently aware of any fan data being compromised.

“Critical systems required for matches to take place at Old Trafford remained secure and games have gone ahead as normal.”

Manchester United added that it would not be commenting on who was responsible for the attack or the motives that lay behind it.

Security experts have suggested the attack is likely to be ransomware. Commenting earlier this week, Jon Niccolls, EMEA & APAC incident response lead at Check Point, said: “It isn’t clear what type of attack hit the club, but as its statement mentioned that it ‘shut down affected systems to contain the damage and protect data,’ this suggests ransomware, and possibly a double extortion attack where the attackers both steal data with the threat of leaking it, as well as encrypting it to disrupt operations.”

Commenting on the incident, Adam Enterkin, SVP, EMEA, BlackBerry, told Infosecurity: “The exploitation of sporting giants by cyber-criminals is not a surprise. Amid a pandemic characterized by opportunistic cyber-attackers, and a huge deficit of security professionals in the UK, such an attack was all but inevitable. Manchester United isn’t the first to be hacked, and it won’t be the last.

“These attacks are, however, preventable. The truth is that the entire nation needs better cyber-hygiene. Even national institutions like sports teams can fall prey to simple phishing emails, which are responsible for a large proportion of cyber-attacks. Cyber-criminals are waiting for organizations and the public to drop their guard. We must not give them the opportunity.” 

“Ultimately, security teams at football clubs need the same tech as major banks and hospitals, to protect livelihoods and customer data. AI technology can help manage the volume of potential threats, spotting anomalies in data and dealing with menial and repetitive tasks whilst flagging potentially serious situations to the cybersecurity team. Humans and tech must work hand-in-hand, so the professionals are equipped with the right knowledge and skill sets to keep our nation’s much-loved sporting institutions safe.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Two in Five Home Workers Vulnerable to Cyber-Attacks

Two in Five Home Workers Vulnerable to Cyber-Attacks

Two in five remote workers in the UK are vulnerable to cyber-attacks as they have not received information about how to avoid COVID-19 scams or had any video call security training. This is according to a new report by Fasthosts, which looked at the additional cyber-risks businesses are facing as a result of the shift to home working this year.

The study also found that over half (54%) of remote workers are currently operating without a VPN, potentially increasing the risk of personal and company data getting compromised. Additionally, around a quarter allow others in their household look at confidential documents.

The researchers revealed that those employed in the science and pharmaceutical industry were most likely to allow other members of their household access to their work computer/laptop, while law enforcement and security staff were the biggest culprits in allowing access to confidential data and documents.

Despite recent positive news regarding the development of a vaccine for the virus, it is expected that there will be far more remote working going forward compared to pre-COVID. Fasthosts cited data from the Institute of Directors showing that three quarters (74%) of 958 company directors intend to continue with increased home working after the pandemic. It is therefore vital that organizations provide the tools and training to ensure their staff are more secure whilst operating from home.

Michelle Stark, sales and marketing director at Fasthosts, commented: “It’s sad to see the risks of cybercrime so prevalent whilst many Britons are working from home. Keeping you and the business safe online is critical to keep confidential data secure. We urge all consumers to read our top tips, be more mindful and seek the correct training whilst working from home.”

Last month, a study by Mimecast found that remote workers are increasingly putting corporate data and systems at risk by failing to follow best practice security.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk