Using AI to Scale Spear Phishing

The problem with spear phishing it that it takes time and creativity to create individualized enticing phishing emails. Researchers are using GPT-3 to attempt to solve that problem:

The researchers used OpenAI’s GPT-3 platform in conjunction with other AI-as-a-service products focused on personality analysis to generate phishing emails tailored to their colleagues’ backgrounds and traits. Machine learning focused on personality analysis aims to be predict a person’s proclivities and mentality based on behavioral inputs. By running the outputs through multiple services, the researchers were able to develop a pipeline that groomed and refined the emails before sending them out. They say that the results sounded “weirdly human” and that the platforms automatically supplied surprising specifics, like mentioning a Singaporean law when instructed to generate content for people living in Singapore.

While they were impressed by the quality of the synthetic messages and how many clicks they garnered from colleagues versus the human-composed ones, the researchers note that the experiment was just a first step. The sample size was relatively small and the target pool was fairly homogenous in terms of employment and geographic region. Plus, both the human-generated messages and those generated by the AI-as-a-service pipeline were created by office insiders rather than outside attackers trying to strike the right tone from afar.

It’s just a matter of time before this is really effective. Combine it with voice and video synthesis, and you have some pretty scary scenarios. The real risk isn’t that AI-generated phishing emails are as good as human-generated ones, it’s that they can be generated at much greater scale.

Defcon presentation and slides. Another news article

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

6 Tips for a Safer and Easier Telemedicine Visit

We’ve all been there. It’s the middle of the night and you wake up to a sad and sniffly kiddo shuffling into your room. Yup, looks like someone has a temperature. You phone the on-call doctor to make sure it’s nothing serious and then set an alarm so you can make an appointment when the office opens. Yet this time that doctor’s visit could go a little differently. It may not take place in the office at all. You may be offered a chance to see the doctor with a telemedicine visit. 

What is telemedicine? 

Telemedicine has been in use for some time. For several years now, it’s connected patients to health care services using live video and sometimes special diagnostic tools that pass along information via the internet. Overall, it’s a way of going to the doctor without actually going to the doctor’s office. Historically, it’s done a great job of caring for people who live in remote locations and for people with ongoing conditions that need long-term monitoring.  

That all changed last year. Telemedicine visits saw a big spike during the early days of the pandemic, partly to help keep the spread of the virus in check and to protect vulnerable patients. Even though that spike has since tapered off, one study found that about 40 percent of consumers in the U.S. say they’ll use telemedicine moving forward—and our own research from earlier this year put that worldwide figure at nearly 30 percent. Telemedicine seems to be taking root.  

While telemedicine leaves many families with more healthcare options, it may leave them with a few more questions about their security as well. After all, our health data is a precious thing. In the U.S., HIPPA privacy standards protect our information and consultations with healthcare professionals. However, online visits add an entirely new dimension to that. 

Make your telemedicine visit safer with these tips 

If your health care provider recommends a telemedicine visit for you or your child, it can be both a convenient and safe experience with a little prep on your part. With a few straightforward security measures lined up (some of which you may already have in place), you can make sure that everyone’s private health information will be safe and secure during your virtual visit. 

1. Protect your devices 

A great first step for a safer telemedicine visit is to protect your devices with comprehensive security software. Like security software protecting you while you manage your finances, file your taxes online, and so forth, it will help protect you while sharing your private health information. Plus, it will give you plenty of other features that can help you manage your passwords, protect your identity, safeguard your privacy in general, and more.   

Be sure to protect your tablets and smartphones while you’re at it, even if you’re not using them for telemedicine. With all the shopping and banking we do on those devices, it’s a smart move to protect them in addition to laptops and computers.  

2. Use strong, unique passwords 

Your telemedicine visit may require setting up a new account and password, one that will add to your growing list considering all the banking, social media, and payment apps you probably use. Plus, there are the umpteen other passwords you have for your online shopping accounts, your children’s school records, your taxes, and so on. Don’t give into the temptation of re-using an old password or making a simple one. Hackers count on that, where stealing one password means stealing several—and gaining access to multiple accounts in one blow.  

When you set up your account, use a strong, unique password. This may also be a good time to get a handle on all your passwords with a password manager. Also found in comprehensive security software, a password manager can create and securely store strong and unique passwords for you, which can keep you safe and make your day a little easier too. 

3. Use a VPN 

A VPN, or virtual private network, offers a strong layer of additional protection when you’re transmitting health data or simply having a private conversation about your health with a professional. A VPN creates an encrypted tunnel to keep you and your activity anonymous. In effect, your data is scrambled and hidden to anyone outside your VPN tunnel, thus making your private information difficult to collect. 

Like many of the security steps, we’re talking about here, using a VPN offers benefits beyond telemedicine. A VPN is a must when using public Wi-Fi, like at airports and cafes, because it makes a public connection private (and safe from prying eyes). Additionally, it’s also great for use at home when taking care of sensitive business like your banking or finances. 

4. Look out for phishing attacks and scams 

If you’re searching for a telemedicine provider online, keep an eye out for sketchy links and scams. The sad thing with the increased use of telemedicine is that hackers have clued in and are looking for targets. One way you can stay safer is to use a web advisor with your browser that can identify potentially hazardous links and sites. Anti-phishing technologies in your security software can help as well by preventing email-based scams from reaching your inbox in the first place.  

5. Check in with your provider 

Even better than searching online, consider contacting your pediatrician or doctor’s office for a recommendation, as they can point out the best healthcare options for you and your concerns—and let you know if a telemedicine visit is the best course of action for you in the first place. This way, you can get comfortable with what your visit will look like, find out what special apps (if any) are used, and how your care provider will protect your privacy. Also, you can decide which device you will use and where you’ll use it so that you feel at ease during your virtual visit. 

A reputable care provider will likely put all this pre-appointment information together for you on their website or “frequently asked questions” (FAQ) page, which will include helpful links and numbers to call if you need help or have questions. For an example of what that could look like, check out the telemedicine page that Virginia Mason/Franciscan Health designed for its patients. 

6. Pick a private place 

We’ve talked plenty about digital security, yet there’s the old-fashioned issue of physical eavesdropping to think about too. When it’s time for your actual appointment, pick a place in your home where you can assure yourself some privacy. (Of course, don’t go online for your virtual appointment in a public place.) Look for a space where you can’t be overheard by neighbors and passers-by—preferably someplace like your bedroom where you can be comfortable as well. If your child has an appointment, let them know that this is like any other doctor’s visit and help them keep their voice down so they can keep their info private. 

What else should parents know about telemedicine? 

With telemedicine becoming more and more of an option for families, it’s just one of the many tools your doctor or pediatrician can use to keep you and your family well. So as always, if you have a health concern, call your doctor or pediatrician’s office for guidance. They’ll know the best path forward. 

In the meantime, there are some great resources out there that can help you make the best decision about telehealth if the time comes. One really helpful article from the American Academy of Pediatrics helps parents get up to speed on telemedicine and outlines a few cases where a telemedicine visit might be right for your child 

With the sniffles, fevers, and plenty of, “Mom, I don’t feel so good …” comments that come along with parenthood, it’s nice to know that telemedicine gives us another tool we can use to keep our families well—one that’s ultimately up to you and your doctor to choose if it’s right for your child. 

Stay Updated 

To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home on Twitter, subscribe to our newsletter, listen to our podcast Hackable?, and ‘Like’ us on Facebook.  

The post 6 Tips for a Safer and Easier Telemedicine Visit appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

New Anti Anti-Money Laundering Services for Crooks

A new dark web service is marketing to cybercriminals who are curious to see how their various cryptocurrency holdings and transactions may be linked to known criminal activity. Dubbed “Antinalysis,” the service purports to offer a glimpse into how one’s payment activity might be flagged by law enforcement agencies and private companies that try to link suspicious cryptocurrency transactions to real people.

Sample provided by Antinalysis.

“Worried about dirty funds in your BTC address? Come check out Antinalysis, the new address risk analyzer,” reads the service’s announcement, pointing to a link only accessible via ToR. “This service is dedicated to individuals that have the need to possess complete privacy on the blockchain, offering a perspective from the opponent’s point of view in order for the user to comprehend the possibility of his/her funds getting flagged down under autocratic illegal charges.”

The ad continues:

Some people might ask, why go into all that? Just cash out in XMR and be done with it. The problem is, cashing out in Monero raises eyebrows on exchanges and mail by cash method is sometimes risky as well. If you use BTC->XMR->BTC method, you’ll still get flagged down by our services labelled as high risk exchange (not to mention LE and exchanges). Our service provides you with a view from LE/exchange’s perspective of things (with similar accuracy, but quite different approach) that provides you with basic knowledge of how “clean” your address is.”

Tom Robinson, co-founder of blockchain intelligence firm Elliptic, said Antinalysis is designed to help crypto money launderers test whether their funds will be identified as proceeds of crime by regulated financial exchanges.

“Cryptoassets have become an important tool for cybercriminals,” Robinson wrote. “The likes of ransomware and darknet markets rely on payments being made in Bitcoin and other cryptocurrencies. However, laundering and cashing-out these proceeds is a major challenge.”

Cryptocurrency exchanges make use of blockchain analytics tools, he said, to check customer deposits for links to illicit activity. By tracing a transaction back through the blockchain, these tools can identify whether the funds originated from a wallet associated with ransomware or any other criminal activity.

“The launderer therefore risks being identified as a criminal and being reported to law enforcement whenever they send funds to a business using such a tool,” Robinson said. “Antinalysis seeks to help crypto launderers to avoid this, by giving them a preview of what a blockchain analytics tool will make of their bitcoin wallet and the funds it contains.”

Each lookup at Antinalysis costs roughly USD $3, with a minimum $30 purchase. Other plans go as high as $6,000 for 5,000 requests.

Robinson says the creator of Antinalysis is also one of the developers of Incognito Market, a darknet marketplace specializing in the sale of narcotics.

“Incognito was launched in late 2020, and accepts payments in both Bitcoin and Monero, a cryptoasset offering heightened anonymity,” he wrote. “The launch of Antinalysis likely reflects the difficulties faced by the market and its vendors in cashing out their Bitcoin proceeds.”

Elliptic wasn’t impressed with the quality of the intelligence provided by Antinalysis, saying it performs poorly on detecting links to major darknet markets and other criminal entities. But with countless criminals now making millions from ransomware, there is certainly a vast, untapped market for services that help those folks improve their operational security.

“It is also significant because it makes blockchain analytics available to the public for the first time,” Robinson wrote. “To date, this type of analysis has been used primarily by regulated financial service providers.”

That may not be entirely true. Nick Bax is an independent expert in tracing cryptocurrency transactions, and he said it appears Antinalysis may be little more than a clone of AMLBot, an anti- anti-money laundering intelligence service that first came online in 2019.

AMLBot’s user interface.

“It looks almost identical to the cheap version of AMLBot,” Bax told KrebsOnSecurity. “My guess is they’re just white-labeling that.”

Bax said a lookup at AMLBot on the virtual currency address used in the sample provided by Antinalysis shows a near identical result. Here’s AMLBot’s result for the same crypto analysis performed by Antinalysis in the screenshot at the top of this story:

AMLBot’s response for the same cryptocurrency address provided as an example by Antinalysis.

“If you look at the breakdown the percentages are all almost identical,” Bax said. “I use AMLBot occasionally for good and righteous purposes. And it could also be useful for people who are just selling stuff online to make sure they aren’t receiving tainted funds.”

Update, 1:42 p.m. ET: Corrected the story to note that AMLBot has been around since 2019.

Update, 1:52 p.m. ET: Elliptic updated its blog post to confirm the connection between Antinanlysis and AMLBot, noting that AMLBot itself is a reseller of yet another service: “As first suggested in an article by Brian Krebs, we can now confirm that the results provided by Antinalysis are identical to those provided by AMLBot. It is therefore likely that Antinalysis makes use of the AMLBot API. AMLBot is itself a reseller for Crystal Blockchain, an analytics provider.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

GoVanguard Acquires Gotham Security

GoVanguard Acquires Gotham Security

A boutique cybersecurity firm that provides the financial, health care and retail sectors with custom security services has been acquired by technology security firm GoVanguard.

Gotham Security, acquired by the firm for an undisclosed sum, was described by GoVanguard CEO Mahdi Hedhli as a close partner of some years’ standing. 

The headquarters of Gotham Security are situated a two-minute walk away from world-famous landmark the Empire State Building. The company, which specializes in professional security services and managed security SOC services, has a second office in Washington, DC. 

Gotham Security CEO Trevor Goering and COO Blake Shalem co-founded the company in 2013. Following the acquisition, Shalem will be joining GoVanguard as its chief customer officer.

She said: “This move allows us to elevate what we do best, which translates to a superior class of protection for our clients.”

GoVanguard said the acquisition would allow it to provide elite-level cybersecurity to its clients, which include Odyssey Group, nTopology, Insurance Technologies, and Abacus Group. 

“As threat actors become more sophisticated, it’s become obvious that the best defense is to go on the offensive. Adversary simulation has become increasingly valuable for organizations looking to quickly gauge and improve their security position. After all, if you can’t measure it, you can’t improve it,” said Hedhli.

“Gotham Security has been a close partner for years, and this was a natural next step to allow our red-teaming experts to take our clients’ defenses to the next level and continue our dedication to finding the security gaps before cyber-criminals do.”

Gotham offers security assessments that include penetration testing, phishing vulnerability analysis, and an evaluation of an organization’s system for weak points.

GoVanguard said that the acquisition was part of a move to provide clients with adversarial red-team tactic cybersecurity assistance that could identify and resolve vulnerabilities before cyber-criminals had a chance to strike. 

“We’re doubling down on our commitment to improve the cybersecurity landscape by honing our focus on red teaming,” Hedhli said. “We feel this is the area where GoVanguard makes the biggest impact for our clients and the industry as a whole.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

23 Charged Over BEC Scam

23 Charged Over BEC Scam

Police in Europe have arrested nearly two dozen individuals on suspicion of being part of an international group of online fraudsters.

The alleged cyber-criminals are accused of cheating companies in at least 20 countries out of approximately $1.17m.

Charges were brought against 23 individuals on August 10. The suspects were taken into custody in a series of raids simultaneously carried out at 34 addresses in Ireland, Romania, and the Netherlands. 

Europol, which coordinated the action, said the cyber-criminal gang had been running scams for years, updating its tactics to exploit current events.

“The fraud was run by an organized crime group which prior to the COVID-19 pandemic already illegally offered other fictitious products for sale online, such as wooden pellets,” said Europol in a press release

“Last year the criminals changed their modus operandi and started offering protective materials after the outbreak of the COVID-19 pandemic.”

The group accused of running the scams is allegedly made up of individuals hailing from various countries in Africa, who relocated to Europe. There, they created fake web pages and email addresses that allowed them to impersonate legitimate wholesale companies.

Members of the group, posing as employees of these wholesalers, would then defraud other companies by soliciting orders from them and requesting payments in advance of goods’ being shipped. 

Victims companies – most of which were located in Europe and Asia – sent the money in good faith; however, the goods they had ordered never arrived. 

Europol said that the gang’s criminal proceeds “were laundered through Romanian bank accounts controlled by the criminals before being withdrawn at ATMs.”

An ongoing investigation into the cyber-criminal gang has been supported by Europol since 2017. Assistance offered by the organization included the deployment of two of its cyber-crime experts to the raids that took place in the Netherlands to help secure relevant evidence and support Dutch authorities with cross-checking data against real-time information gathered during the operation.

This latest coordinated action against cybercrime follows an Interpol operation that led to the arrest of an alleged 45-year-old sexual predator and human trafficker on August 6 in Guatemala. The unnamed man is suspected of producing and distributing child sexual abuse material.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Attackers Increasingly Turning to DDoS as a Ransom Vector

Attackers Increasingly Turning to DDoS as a Ransom Vector

Nearly half (44%) of organizations have been targeted or fallen victim to a ransom-related distributed denial of service (RDDoS) attack in the past 12 months, according to a survey of 313 cybersecurity professionals by the Neustar International Security Council (NISC).

Interestingly, during the same period, a lower proportion (41%) of organizations were targeted by a ransomware attack, suggesting cyber-criminals are increasingly using DDoS attacks as a means of extorting money from victims.

Rodney Joffe, chairman of NISC, SVP and fellow, Neustar, explained: “Rather than spending a lot of time and careful planning on infecting an organization’s network with malware or ransomware, cyber-criminals are taking an easier approach and using DDoS as a ransom vector. For bad actors, launching a DDoS attack is relatively simple and also has the added benefit of being harder to trace back to its origin.”

The research indicates that this is an effective ransom tactic; 70% of organizations hit by RDDoS were targeted multiple times, and 36% admitted they paid the ransom. This compares to 57% of those infected by ransomware being targeted on multiple occasions, with the same proportion (36%) choosing to pay the ransom.

Neustar added that while RDDoS threats have traditionally targeted online industries, attackers are increasingly turning their attention to other sectors, including financial services, government and telecoms.

Worryingly, less than a quarter (24%) of cybersecurity professionals said they were ‘very confident’ in their organization’s knowledge of how to respond to an RDDoS attack. The respondents listed ransomware (70%), DDoS (68%) and targeted hacking (66%) as the most increasing cyber-threats to their organization.

Joffe commented, “It’s common for organizations to feel pressure to pay to get their website back up and running and avoid disruption. However, with attackers targeting the same company multiple times, paying the ransom only makes it more likely that you will fall victim again. Instead, businesses must take an ‘always on’ approach to DDoS security, ensuring that their site remains protected even in the event of an attack.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Accenture Tied Up in $50M Ransom Lockbit 2.0 Attack

Accenture Tied Up in $50M Ransom Lockbit 2.0 Attack

Global consulting firm Accenture has been the target of ransomware group Lockbit, with the gang reportedly taking encrypted data from the company.

Lockbit says it will publish the data if Accenture does not pay the ransom, according to screenshots of the ransomware group’s website. Infosecurity has asked Accenture for a comment on the ransomware attack.

In a statement provided to CNN, an Accenture spokesperson told the international outlet., “Through our security controls and protocols, we identified irregular activity in one of our environments. We immediately contained the matter and isolated the affected servers.”

This data breach comes after the Australian Cyber Security Centre (ACSC) alerted organizations in the country that cybercriminals were frequently using Lockbit 2.0 ransomware. “The ACSC has received reporting from several Australian organizations that have been impacted by LockBit 2.0 ransomware,” explains the alert. “This activity has occurred across multiple industry sectors.

“Victims have received demands for ransom payments. In addition to data encryption, victims have received threats that data stolen during the incidents will be published.”

What is Lockbit 2.0?

Lockbit 2.0 was rolled out earlier this month — the latest version of the ransomware — and implements lots of additional features.

“With the recent international efforts on fighting ransomware, those gangs are finding it difficult to advertise their malware in hacking forums,” explains Felipe Duarte, security researcher, Appgate.  “A few posts from this new version of LockBit were spotted on a few forums frequented by cybercrime gangs, but they were quickly removed. This version is currently advertised on a new version of their website.

“Our team got access to LockBit’s deep-web site, where the ad is published along with data from victims that refused to pay the ransom,” continues Duarte. “Among the advertised capabilities is a new dangerous feature to encrypt entire Windows domains through group policies.

“After infecting a domain controller, the malware creates new group policies and pushes them to every device connected on the network. Those policies disable antivirus protections and execute the ransomware. Additionally, LockBit seems to have copied a feature from Egregor ransomware that, after a successful infection, sends to all connected printers a command to repeatedly print the ransom note.”

Appgate explains that the new version of Lockbit adds a new strategy to acquire affiliates — after encrypting a device, it sets the wallpaper to a ransom note and claims responsibility for the attack, and points to a more detailed one note .txt file.

“Now the set wallpaper also contains a recruitment ad, promising millions of dollars to employees that provides them access to the company systems so they can launch a ransomware attack,” the security researcher explains. “According to the ad, the access can be a valid credential or even executing a threat attached in an email.

“This strategy may seem unusual at first, but it’s somewhat common for companies to get breached by employees. For example, in 2020, a Russian citizen living in the U.S. was arrested after offering $1 million to a Tesla employee to deploy ransomware in Tesla’s internal network.”

What is Accenture’s response?

At the time of reporting, Accenture had not confirmed the details of the ransomware attack to Infosecurity. However, multiple news sources appear to show  Accenture giving little weight to the attack, with the company saying that it has had “no impact” on the business.

According to ZDNet, the consultancy firm provided a statement that says, “There was no impact on Accenture’s operations or on our clients’ systems.”

However, the outlet also reports that cybercrime intelligence firm Hudson Rock says that 2,500 computers of employees and partners were compromised in the ransomware attack. Another firm, Cyble, claims to have seen a ransom demand of $50 million for six terabytes (TB) of stolen data.

What is Accenture’s response?

At the time of reporting, Accenture had not confirmed the details of the ransomware attack to Infosecurity. When asked to provide further details, a spokesperson told Infosecurity: “We aren’t providing any more comment other than the statement.

However, from what we do know from multiple news sources, Accenture is downplaying the attack, saying it has had “no impact” on the business.

According to ZDNet, the consultancy firm provided a statement which says: “There was no impact on Accenture’s operations or on our clients’ systems.”

However, the outlet also reports that cybercrime intelligence firm Hudson Rock says that 2,500 computers of employees and partners were compromised in the ransomware attack. Another firm, Cyble, claims to have seen a ransom demand of $50 million for 6 terabytes (TB) of stolen data.

  

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

NCSC Launches Microsoft Office 365 Button to Report Business Email Spam

NCSC Launches Microsoft Office 365 Button to Report Business Email Spam

UK employees can now use one single click to flag scam emails to the National Cyber Security Centre (NCSC), with the organization already receiving 6.5 million reports from the public since its original launch.

Launched today, the NCSC says it has made it easier than ever for employees in the UK to join the fightback against email scams targeting their organizations. Guidance has been published on how IT administrators can add a new reporting tool to their organizations’ Microsoft Office 365 accounts.

According to its announcement today, the NCSC, part of GCHQ, says that by clicking the new button, employees can report “potential scams directly to the NCSC’s Suspicious Email Reporting Service (SERS). It will also report the scam to the organization’s IT team.

Since its launch in April 2020, the NCSC says that its SERS has received over 6,500,000 reports from the public. The reports have resulted in the removal of over 87,000 scam URLs. In July, it took four hours on average to remove malicious URLs in phishing emails reporting to the SERS, according to the NCSC.

“Opportunistic scams during the pandemic have demonstrated how cyber-criminals constantly find new ways to target us,” says Dr. Ian Levy, technical director, NCSC. “The good news is that you can help protect your workplace by forwarding suspected scam emails to the [SERS] from your work email account at the click of a button.

“This simple technical innovation could enable millions more people to join our mission to stop scam emails from ever reaching UK inboxes.”

According to the NCSC, typical phishing URLs identified by its experts that target business organizations include: malware, clone login pages and enterprise software spoofs. Businesses in the financial services industry are expecting email-borne attacks to increase, as reported by Infosecurity, says a report by Mimecast.

This action by the NCSC is part of its Active Cyber Defence programme. It is also working in partnership with the City of London Police and has committed to protecting organizations from cybercrime, which it says cost them over £5 million in the last 13 months.

Mike Cherry, national chair of the Federation of Small Business, welcomes this innovation: “[These] are crucial to calling time on business crime. Small achievable steps will go a long way to protect thousands of small firms from cyber attacks.

“Every year, there are almost 4 million cases of cyberattacks against small businesses in the UK, and more than 50% of these come from phishing,” he continues. “We’d encourage as many small firms as possible to look further into this NCSC tool and see how they can implement it to protect employees as well as businesses from harm. And anyone can take part, any small business, employee or self-employed person can forward attempted scam emails to report@phishing.gov.uk.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Smartsearch Finds 10% Of Regulated Businesses Do No Checks on Business Customers

Smartsearch Finds 10% Of Regulated Businesses Do No Checks on Business Customers

A regulatory technology (RegTech) company has launched a new campaign to encourage UK organizations to ditch manual “outdated” identification and verification methods for regulated businesses.

SmartSearch, based in West Yorkshire, UK, launched its Electronic Verification Uncovered campaign to raise awareness of the dangers of manual ID checks. As part of the campaign, it has published its SmartSearch Index report, conducted by 3Gem Market Research, to highlight the ongoing threat of money laundering in the UK.

The research, which surveyed 500 regulated businesses in the UK in June 2021, found more than a third (34%) of regulated businesses across the financial services, legal and property sectors still make manual checks when onboarding new customers. In the legal sector, manual verification methods are still preferred, says the report, with 42% of the firms saying it’s their preference. Whereas a third (33%) of financial services, banks and estate agents confirmed they relied on manual checks.    

SmartSearch also found that almost one in ten (8.5%) firms in the property agency sector said they do not verify customer ID at all, with 10% of all firms in the report saying they carry out no checks on business customers.

John Dobson, chief executive officer, says, “It’s really important for regulated businesses to realize that when it comes to secure methods of customer ID verification, documents are high risk and should be at least supplemented with reliable low-risk electronic verification. This is not only because of the increase in money laundering and financial crime we’ve seen since the start of the pandemic but also the increasing cost of manually complying with regulations.

“Businesses need to make due diligence and Know Your Customer (KYC) obligations more efficient in terms of speed and cost, as well as remaining secure and accurate,” he continues. “That is not possible by relying on checking passports, driving licenses and council tax bills.”

When SmartSearch asked the business why they still used manual verification methods, one-third said they felt hard copy documents reassured them that the customer was genuine. “It’s that kind of belief that we are looking to overturn with our campaign, because increasingly when you’re inviting a customer to send copies of hard documents for verification, you’re actually inviting fraud in through the front door,” explains Dobson.

According to the research, businesses cite “Issues of compliance” to be behind their decisions to still use manual methods of verification. A quarter overall (24%) say it meets Anti Money Laundering (AML) obligations and a further 30% claim it’s the only way to guarantee a person’s identity.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains