How to Talk to Your Grandparents About Staying Safe Online

Reports filed with the U.S. Federal Trade Commission (FTC) put the risks in perspective — scammers squarely target older adults. In 2023, adults aged 60 and up filed over one-third of all fraud reports. Their reported losses? Close to $2 billion.

While scammers target all age groups, older adults offer them a particular advantage. Technology and everyday internet use came along later in their lives. They didn’t grow up with it like the rest of us did, making them less familiar with technology and more susceptible to attack. Moreover, their lifetime savings, home ownership, and retirement accounts make them attractive targets.

That’s much the case with our grandparents today. It’s little wonder hackers, scammers, and thieves go after them.

Figures courtesy of the FTC

However, your grandparents have a big advantage working in their favor. You.

A chat with your grandparents can keep them safer online

Your knowledge, your expertise, and your overall comfort level with technology and the internet can help them steer clear of fraud. Have a chat about staying safe online. Or have a few chats over time. The advice you pass up can make all the difference.

Here are a few ways you can start:

  1. Talk about the latest online scams.  

As the year rolls on, so do the scams. Every scam has its season, from tax scams early in the year to shopping scams during the holidays. Current events play in too. In the wake of natural disasters, phony relief scams make the rounds on the internet. Encourage your grandparents to keep an eye on the news for the latest online scams so they have a better chance of recognizing fraudulent activity. Or better yet, give them a call when you get word of a new data breach or scam.

  1. Show them how to think like a cybercriminal. 

The secret to beating cybercriminals at their own game is to think like one. Encourage your grandparents to consider what can make them targets. Perhaps they have large retirement funds. Maybe their online bank account is secured with a password that they use for multiple online accounts. Have them think about how they’ve made it easier for a crook to take advantage of them. From there, they can tighten up their security as needed. A tool like our Protection Score can do this for them. It stops weak points and offers solutions for shoring them up.

  1. Strengthen their passwords. 

Each account should get its own strong, unique password. Which is a lot of work, given all the accounts we keep. A password manager can help. It creates and securely stores strong, unique passwords for every account. (No more sticky notes with passwords on the monitor.)

Also, help them set up two-factor authentication on their accounts that offer it. It provides an extra layer of security, as it requires multiple forms of verification, such as a fingerprint scan or facial recognition. This, with strong, unique passwords, makes accounts terrifically tough to crack.

  1. Show them how to spot phishing scams.

Hackers, scammers, and thieves all use phishing attacks to rope in victims. And today, they look increasingly convincing thanks to AI tools. And as we’ve covered here on our blocks, scammers can easily clone voices  —  even faces—on calls and video chats. Plenty more phishing attacks come by text, email, and phone calls. This is where your grandparents need to get savvy.

If they receive an email that appears to be from a business or even a family member, but they are asking them for their Social Security Number, passwords, or money, stop and think. Don’t click on anything or take any direct action from the message. Instead, go straight to the organization’s website and verify that the message is legitimate with customer service. If the message claims to be from a family member asking for financial help, contact them directly to ensure it’s not a scammer in disguise. In all, make sure they show great caution any time a seemingly “urgent” email, message, or call comes their way. Urgency is often a sign of a scam.

  1. Set them up with comprehensive online protection.

Today’s online protection goes far beyond antivirus. It protects people. Their devices, their identity, and their privacy.

Comprehensive online protection like our McAfee+ plans keep them safe from hackers, scammers, and thieves in several ways. Consider this short list of what comprehensive online protection like ours can do for your grandparents:

Scam Protection

Is that email, text, or message packing a scam link? Our scam protection lets your grandparents know before they click that link. It uses AI to sniff out bad links. And if they click or tap on one, no worries. It blocks links to malicious sites.

Web protection

Like scam protection, our web protection sniffs out sketchy links while they browse. So say they stumble across a great-looking offer in a bed of search results. If it’s a link to a scam site, they’ll spot it. Also like scam protection, it blocks the site if they accidentally hit the link.

Transaction Monitoring

This helps them nip fraud in the bud. Based on the settings they provide, transaction monitoring keeps an eye out for unusual activity on credit and debit cards. That same monitoring can extend to retirement, investment, and loan accounts as well. It can further notify them if someone tries to change the contact info on their bank accounts or take out a short-term loan in their name.

Credit Monitoring

This is an important thing to do in today’s password- and digital-driven world. Credit monitoring uncovers any inconsistencies or outright instances of fraud in credit reports. Then it helps put your grandparents on the path to setting them straight. It further keeps an eye on their credit reports overall by providing you with notifications if anything changes in their history or score.

Personal Data Cleanup

This provides your grandparents with another powerful tool for protecting their privacy. Personal Data Cleanup removes their personal info from some of the sketchiest data broker sites out there. And they’ll sell those lines and lines of info about them to anyone. Hackers and spammers included. Personal Data Cleanup scans data broker sites and shows which ones are selling their personal info. From there, it provides guidance for removing your data from those sites. Further, when part of our McAfee+ Advanced and Ultimate, it sends requests to remove their data automatically.

Identity Theft Coverage & Restoration

Say the unfortunate happens to your grandparents and they fall victim to identity theft. Our coverage and restoration plan provides up to $2 million in lawyer fees and reimbursement for lawyer fees and stolen funds. Further, a licensed expert can help them repair their identity and credit. In all, this saves them money and their time if theft happens.

The post How to Talk to Your Grandparents About Staying Safe Online appeared first on McAfee Blog.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

New 0-Day Attacks Linked to China’s ‘Volt Typhoon’

Malicious hackers are exploiting a zero-day vulnerability in Versa Director, a software product used by many Internet and IT service providers. Researchers believe the activity is linked to Volt Typhoon, a Chinese cyber espionage group focused on infiltrating critical U.S. networks and laying the groundwork for the ability to disrupt communications between the United States and Asia during any future armed conflict with China.

Image: Shutterstock.com

Versa Director systems are primarily used by Internet service providers (ISPs), as well as managed service providers (MSPs) that cater to the IT needs of many small to mid-sized businesses simultaneously. In a security advisory published Aug. 26, Versa urged customers to deploy a patch for the vulnerability (CVE-2024-39717), which the company said is fixed in Versa Director 22.1.4 or later.

Versa said the weakness allows attackers to upload a file of their choosing to vulnerable systems. The advisory placed much of the blame on Versa customers who “failed to implement system hardening and firewall guidelines…leaving a management port exposed on the internet that provided the threat actors with initial access.”

Versa’s advisory doesn’t say how it learned of the zero-day flaw, but its vulnerability listing at mitre.org acknowledges “there are reports of others based on backbone telemetry observations of a 3rd party provider, however these are unconfirmed to date.”

Those third-party reports came in late June 2024 from Michael Horka, senior lead information security engineer at Black Lotus Labs, the security research arm of Lumen Technologies, which operates one of the global Internet’s largest backbones.

In an interview with KrebsOnSecurity, Horka said Black Lotus Labs identified a web-based backdoor on Versa Director systems belonging to four U.S. victims and one non-U.S. victim in the ISP and MSP sectors, with the earliest known exploit activity occurring at a U.S. ISP on June 12, 2024.

“This makes Versa Director a lucrative target for advanced persistent threat (APT) actors who would want to view or control network infrastructure at scale, or pivot into additional (or downstream) networks of interest,” Horka wrote in a blog post published today.

Black Lotus Labs said it assessed with “medium” confidence that Volt Typhoon was responsible for the compromises, noting the intrusions bear the hallmarks of the Chinese state-sponsored espionage group — including zero-day attacks targeting IT infrastructure providers, and Java-based backdoors that run in memory only.

In May 2023, the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and the Cybersecurity Infrastructure Security Agency (CISA) issued a joint warning (PDF) about Volt Typhoon, also known as “Bronze Silhouette” and “Insidious Taurus,” which described how the group uses small office/home office (SOHO) network devices to hide their activity.

In early December 2023, Black Lotus Labs published its findings on “KV-botnet,” thousands of compromised SOHO routers that were chained together to form a covert data transfer network supporting various Chinese state-sponsored hacking groups, including Volt Typhoon.

In January 2024, the U.S. Department of Justice disclosed the FBI had executed a court-authorized takedown of the KV-botnet shortly before Black Lotus Labs released its December report.

In February 2024, CISA again joined the FBI and NSA in warning Volt Typhoon had compromised the IT environments of multiple critical infrastructure organizations — primarily in communications, energy, transportation systems, and water and wastewater sectors — in the continental and non-continental United States and its territories, including Guam.

“Volt Typhoon’s choice of targets and pattern of behavior is not consistent with traditional cyber espionage or intelligence gathering operations, and the U.S. authoring agencies assess with high confidence that Volt Typhoon actors are pre-positioning themselves on IT networks to enable lateral movement to OT [operational technology] assets to disrupt functions,” that alert warned.

In a speech at Vanderbilt University in April, FBI Director Christopher Wray said China is developing the “ability to physically wreak havoc on our critical infrastructure at a time of its choosing,” and that China’s plan is to “land blows against civilian infrastructure to try to induce panic.”

Ryan English, an information security engineer at Lumen, said it’s disappointing his employer didn’t at least garner an honorable mention in Versa’s security advisory. But he said he’s glad there are now a lot fewer Versa systems exposed to this attack.

“Lumen has for the last nine weeks been very intimate with their leadership with the goal in mind of helping them mitigate this,” English said. “We’ve given them everything we could along the way, so it kind of sucks being referenced just as a third party.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains