News

10 Ways to Protect Your Identity

We’re online more than ever, in large part because it allows us to take advantage of online conveniences like bill pay and booking appointments. But these many benefits might also leave us exposed to risks, like identity theft.

Identity theft is characterized by one person using another’s personal or financial data for their benefit. Cybercriminals may take information like a person’s name, birthday, Social Security number, driver’s license number, home address, and bank account information and use it for their benefit. A name and matching financial information, for instance, can be used to apply for credit cards or open new accounts.

The good news is that you can safeguard yourself and your family with some best practices — allowing you to enjoy your best life online and worry less about cybercriminals. Share these 10 tips with your family to help keep your entire household safe.

Password-protect your devices with strong passwords

A good habit to get into is to password-protect your computer, tablet, and mobile devices through unique, strong passwords. These devices are home to some of your most sensitive information, including everything from emails to apps that connect to your bank accounts. So, if these devices fall into the wrong hands, a password makes it harder to access your personal data.

Take some time to come up with your passwords, though. It’s important to create strong passwords that hackers can’t guess. A strong password will include a mix of symbols, numbers, and letters. Steer clear of simple passwords like “123456” (it might seem obvious, but this is one of the most common passwords people use). Also, avoid including information that other people can guess, like your birthdate, home address, or name.

Don’t forget to use different passwords for different accounts. If you use the same password across multiple accounts, and a fraudster gains access to one account, they may access the others. Fortunately, McAfee’s identity protection services include a password manager, which can help secure your account credentials across multiple devices. This tool encrypts passwords, storing them safely and making it easy to keep track of them.

Learn how to identify and avoid phishing scams

Identity thieves are skilled at leveraging new technologies. Phishing is one great example of this. Phishing involves criminals masquerading as trustworthy entities, such as government agencies or banks, and using this trusted position to get sensitive information. Phishing scams started with traditional mail. They’re now also done via phone, text, and email.

As a general rule of thumb, never give out any personal information when contacted by a business, bank, or another entity. Also, make sure your email spam filters detect phishing attempts. Never open emails from people you don’t know, and don’t download email attachments without knowing what they are. Some phishing emails include malware, which can infiltrate your device and access personal data. A McAfee Total Protection plan is an all-in-one protection solution that can help you detect and avoid malware.

Fraudulent websites may also use phishing techniques. A website may look similar to the legitimate website of a mortgage lender, bank, or credit card company but might be a fraudulent platform seeking to get information from consumers. Always verify that any website you visit is the legitimate website of the institution, and consider McAfee antivirus software, which offers a safe browsing solution.

Set up alerts through your bank

When financial identity theft occurs, this can also impact financial institutions like banks and lenders. So, they’re eager to prevent fraud, as well. One way they do this is through fraud alerts. You can set up your online banking to issue fraud alerts — for example, via an email, text message, or phone call — if your bank suspects suspicious activity on your account.

In some cases, a bank will also freeze your account until you verify whether the activity is legitimate. This is a common tactic used to protect against credit card fraud. Geo-control is one example: If you live in the U.S., but a German IP address uses your credit card, your credit card provider will likely issue an alert. You can also set up alerts for certain transaction amounts or types.

Review your credit report regularly

Your credit report is one of the most powerful tools you have at your disposal for catching identity thieves and stopping them in their tracks. You’re entitled to a free credit report every 12 months via AnnualCreditReport.com, an initiative of the Federal Trade Commission (FTC). You can get a free copy of your report from each major credit bureau: Experian, Equifax, and TransUnion.

Review your report thoroughly, checking for inaccuracies. When credit monitoring, check your:

  • Personal information: Verify that your name, address, phone number, birthdate, Social Security number, and employment details are correct.
  • Accounts: Confirm that all accounts listed are yours and current. Keep an eye out for unrecognized credit cards, utility accounts, phone accounts, or streaming accounts.
  • Public records: Check for foreclosures, civil suits, liens, or bankruptcies. If these issues are on your credit report and you don’t recognize them, you might be affected by identity fraud.

 

If you find any discrepancies, contact the appropriate credit reporting company. You should also contact the relevant financial institution and visit IdentityTheft.gov. You can report the suspected identity theft and find resources to help you recover.

Be mindful of what you share on social media

Social media is great for connecting with others online, but it does open the door to some vulnerabilities. Be careful about what you post, and steer clear of sharing personal details like your home address, children’s names, pet’s names, or birthdays, which some people use as passwords. If a social media platform offers two-factor authentication, opt in.

Images are another touchy subject. Never post photos that include private data, like a picture of your passport or vaccine card. Consider what’s in the background of any photos — from your home (with a house number) to mail with your address. Finally, you may want to set your visibility to private on all social media accounts, limiting who can view them. And even if your account is private, you should still follow the above tips.

Shred sensitive documents

Some identity thieves get people’s personal information by dumpster diving. One solution? Invest in a paper shredder. You’ll be able to shred documents into tiny bits that are hard to piece together, making it that much harder for someone else to piece together any personal information they contain.

Here are some documents worth shredding:

  • Debit card statements, credit card statements, and bank statements that contain personal financial information
  • Invoices or receipts containing details like financial account numbers
  • Documents containing your Social Security number, like pay stubs and work contracts
  • Junk mail with contact information, like your name and address
  • Old photos and IDs, which people can use to create fake IDs
  • Shipping labels, like those you might get from online retailers to make returns
  • Medical records or receipts, which may contain insurance information
  • Canceled checks

If you’re not sure whether something needs to be shredded, go ahead and destroy it. It only takes seconds, and you’re better off safe than sorry.

Protect all of your devices with antivirus software

Whether you use a computer, tablet, or mobile device for many of your online activities, like paying bills, these devices contain a lot of personal data. So, it’s good to protect them from hackers. ​​Install antivirus software like McAfee’s to protect against viruses and spyware. It would be best if you also had a firewall, which is a network security system that controls the incoming and outgoing network traffic based on set security parameters.

To take your device security a step further, you may also want to invest in a virtual private network (VPN). This helps hide your online activity. It can safeguard against hackers on public networks but is also worth using at home. It hides details like browsing activity, personal data, and IP address from potential snoops. McAfee also offers VPN services.

Keep personal documents in a safe space

While your computer, tablet, or mobile device may hold a great deal of personal data, you likely also have hard copies of sensitive documents worth protecting. Documents like your birth certificate, Social Security card, and passport contain valuable information that identity thieves can use for personal gain, so you want to make sure they’re kept in a safe space.

Don’t simply shove these documents into your desk drawer. It’s best to keep them in a locked, fireproof home safe with a secure code. To keep things organized, put each document in a protective plastic sleeve and put the sleeves in a binder. This can be useful if you have a large family and need to keep track of everyone’s data.

Follow the news to learn about data breaches

Sophisticated hackers don’t just target individuals. They may also try to infiltrate businesses, government agencies, higher education institutions, health care facilities, and any other organization that gathers sensitive consumer information. If an entity is subject to a data breach, they’re legally required to notify any consumers who may have been impacted.

However, it’s still good to inform yourself about potential breaches that may affect you. Larger-scale data security risks are usually reported in the media. We also post about data breaches on the McAfee blog. If an entity you do business with has been affected, change your passwords and the passwords of any related accounts immediately.

Know the warning signs of identity theft

Knowing possible signs of identity theft can help you catch it early so that you can continue to enjoy your time online. Educate yourself and your family about these warning signs, ensuring everybody stays safe. Here are some possible indications identity thieves have targeted you:

  • You receive phone calls from debt collectors about accounts you aren’t familiar with. Don’t provide personal information over the phone immediately. Check your credit report to get the details about the debts in question.
  • Your credit score experiences unexplained changes. Get a copy of your credit report from the major credit reporting agencies to find out why.
  • Your bank accounts or credit cards have unknown charges you (and your family) can’t account for. Contact your financial institution to report the suspected fraud, providing relevant documentation to back up your claims. You can also report fraud to your local government.
  • You receive a fraud alert from your financial institution. Check any activity deemed potentially fraudulent as soon as possible.
  • You get mail addressed to another person’s name. This could include medical bills, W-2 forms related to unfamiliar employers, or credit card bills, for example. Follow up with the relevant institution.
  • You experience problems with your tax return For example, the Internal Revenue Service (IRS) may reject your filing if someone else has already filed in your name (to get your tax refund). Contact the IRS fraud department.

You’re only a step away from better protection

The internet keeps all of us connected, but that’s why identity theft protection is important. With people increasingly connected, doing more, and sharing more online, cybercriminals can pinpoint weaknesses and take advantage. Hackers are ready to leverage your information for personal gain, and identity theft is no exception.

McAfee is here to help. McAfee’s identity protection services provide 24/7 monitoring of your email addresses and bank accounts, providing up to $1 million worth of ID theft coverage. You deserve to enjoy the comfort offered by the internet without stressing about identity theft. Implement the best practices above in your household so that you and your loved ones can stay connected with confidence.

The post 10 Ways to Protect Your Identity appeared first on McAfee Blogs.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Nurse Arrested in Hacking Investigation

Nurse Arrested in Hacking Investigation

Detectives investigating a hacking incident at a Florida college have charged a former nurse with possessing child sexual abuse material (CSAM).

An investigation was launched in June 2021 when two IT accounts belonging to a program coordinator and an instructor at Polk State College were hacked. The employees were locked out of their labs and scheduling accounts, and their password recovery hints had been changed to “Sell Out” or “Ha Ha Ha Loser.”

The administrative rights associated with eight additional Polk State College employee accounts were also impacted in the incident. Polk College said that the data breach did not involve any student information.

Law enforcement linked the cyber-attack to 38-year-old Winter Haven resident Brandon James Diaz. A former paramedic, fireman, and nurse, Diaz had worked as a clinical coordinator for the Polk State College EMS program but was fired in May 2021 for his “inability to complete his job duties.”

Diaz’s employment at the college was terminated after he reportedly failed a drug test and lost his job at Lakeland Regional Health. 

In an interview with Polk County detectives, married father of four Diaz admitted hacking into Polk State College’s database with his personal computer. 

Speaking at a press conference on Friday, Polk County Sheriff Grady Judd said Diaz targeted the instructor and the program coordinator because he held them responsible for his termination by the college. 

While executing a search warrant of Diaz’s personal computer, detectives discovered 75 images of children and infants being sexually abused.

Judd described the images as “very graphic,” examples of child sexual abuse material that Diaz had obtained by “going to the deep web, to the dark web.”

Diaz was charged on Thursday with 10 counts of accessing a computer without authorization, the use of a two-way device to commit a felony, and 75 counts of enhanced possession of CSAM. 

“If he hadn’t messed up by hacking the computers, we at least at this moment in time wouldn’t have known he was accessing child porn,” said Judd. 

He added: “What I have to say to Brandon is, ‘Ho, ho, ho, merry Christmas. You got a jail cell for Christmas from us.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Cyber-Attack Impacts Aussie Companies

Cyber-Attack Impacts Aussie Companies

A cyber-attack on Australian recruitment company Finite Group is impacting both companies and government agencies across the country.

Finite was compromised by threat actors in October in an incident that is still being investigated. During the attack, some of the company’s data was exfiltrated and later published online.

Information stolen in the attack includes the personal details of employment-seeking Australians who registered with the company. News source ABC viewed stolen data that contained individuals’ resumes, salary details, and details of checks that had been carried out to verify their employment references, criminal history, and visa information.

The cyber-criminals behind the attack threatened to release the data unless they received a ransom payment. 

Finite serves the recruitment needs of corporate clients and government agencies as well as those of individuals. Banks, businesses, and government agencies that have reportedly been impacted by the cyber-attack on Finite include Adairs, AMP, Westpac, Coles, ME Bank, Suez Australia, NBN Co., and the departments of defense, health, and home affairs.

Finite said that it will contact any individuals and stakeholders impacted by the incident to notify them that their data may have been compromised. 

The Conti ransomware gang has claimed responsibility for the attack on Finite. In a notice posted on its website, the cyber-criminal organization bragged that it had stolen more than 300 gigabytes of data from Finite. 

The stash allegedly included financial data, contracts, NDA forms, customer databases with phone numbers and addresses, contracts with employees, scans of passports, and mail correspondence. 

Conti was also responsible for a recent attack on the South Australian government’s payroll provider in which the personal information of public-sector workers in South Australia was compromised. 

The attack on Frontier Software exposed the names, dates of birth, tax file numbers, home addresses, bank account details, remuneration, and superannuation contributions of close to 80,000 workers.

Speaking last week, State Treasurer Rob Lucas said: “I am advised all public sector employees, except for Department of Education staff who are on a different payroll system, should assume that their personal information has been accessed during Frontier Software’s cyber-attack.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Tech Companies to Protect Data on Undersea Cable

Tech Companies to Protect Data on Undersea Cable

American companies Google and Meta have agreed to protect data traveling on an undersea fiber-optic cable system that will connect the United States, Taiwan, and the Philippines. 

On Friday, the Department of Justice announced that Google LLC and its subsidiary GU Holdings Inc., and Meta Platforms Inc. (formerly known as Facebook Inc.) and its subsidiary Edge Cable Holdings USA LLC have entered into national security agreements to safeguard data traveling on the Pacific Light Cable Network (PLCN) system.

The agreements were made with the Departments of Justice (DOJ), Defense (DOD), and Homeland Security (DHS) in their roles as members of Team Telecom (the Committee for the Assessment of Foreign Participation in the United States Telecommunications and Services Sector).

Under the agreements, Meta and Google will annually assess what risk exists to sensitive data moving through the PLCN system. Their risk assessments will also delve into what happens to data when it exits the cable.

The companies will also pursue ways to diversify the system’s interconnection points in other parts of Asia, including Thailand, Singapore, Vietnam, and Indonesia. 

Meta and Google have further agreed to restrict access to information and infrastructure by the Hong Kong–based owner of PLCN, Pacific Light Data Communications Co. Ltd (PLCD). 

PLCD applied for an FCC license but withdrew the application after Team Telecom, in June 2020, advised against accepting PLCD’s proposal to connect the PLCN to Hong Kong and to the portions of the PLCN owned by PLDC.

“These agreements enable Google and Meta to take advantage of critical, additional cable capacity while protecting US persons’ privacy and security through terms that reflect the current threat environment,” said Assistant Attorney General Matthew G. Olsen of the Justice Department’s National Security Division.

Olsen, who leads Team Telecom’s work for the Justice Department, added: “This resolution also demonstrates Team Telecom’s ability to resolve complex cases involving critical infrastructure in a timely matter, thanks to recent reforms of our structure and process.”

Under the agreement, Edge USA has the ability to interrupt traffic to and from the United States on the U.S.–Philippines segment within twenty-four hours of notice.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Ransomware Gang Publish Confidential Police Data on the Dark Web

Ransomware Gang Publish Confidential Police Data on the Dark Web

The Clop ransomware gang has published confidential data held by UK police on the dark web, according to reports over the weekend.

The Mail on Sunday reported that the notorious cybercrime group accessed the information following a successful phishing attack on IT services provider Dacoll in October 2021. This provided Clop with access to vast amounts of material, including data held on the police national computer (PNC), which Dacoll manages.

According to the Mail on Sunday, the attackers uploaded hundreds of files on the dark web after Dacoll refused to pay a ransom demand. Among the PNC files uploaded were close-up images of motorists taken from the UK’s National Automatic Number Plate Recognition (ANPR) system.

It is currently unclear whether Clop holds other information held by the UK Police that it could release in the future.

The report quoted a spokesman for the National Cyber Security Centre (NCSC), who stated: “We are aware of this incident and working with law enforcement partners to fully understand and mitigate any potential impact.”

Breaches of data held by law enforcement agencies are especially concerning, given their highly confidential nature, the potential to disrupt criminal investigations and even fears serious risks will be posed to victims and witnesses of crime should the information fall into the wrong hands. Earlier this year, an FoI request revealed there were more than 2300 data breach incidents reported by just 22 UK police forces in 2020.

Commenting on the story, Jake Moore, cybersecurity specialist at ESET, said: “You may be mistaken for thinking that sensitive data held by police is under very strong protection, but the truth is that even this level of security can still very easily be breached. The level of cybersecurity protection on offer remains as strong as the weakest link, which is often swung by the human factor. The release of personal information amplifies the attackers’ demands and highlights their anger at not having their demands listened to.  

“Like many persistent campaigns, Clop is very sophisticated and determined in their ways, making it very difficult to mitigate against. When very targeted attacks persist, it is very onerous to withstand, and therefore relying on current measures with a touch of good fortune is often the only answer. The release of this data could have very dangerous consequences for those affected and they should ideally be made aware to reduce any follow-on impact.”

The Clop group is believed to be responsible for a number of major ransomware attacks in recent years, including on oil giant ShellSwire Pacific Offshore and the University of California. In November, Interpol revealed it is still on the hunt for two suspected members of the Clop ransomware gang after making multiple arrests in the summer following a 30-month operation.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Ukrainian War Games Test Electricity Grid

Ukrainian War Games Test Electricity Grid

Hundreds of Ukrainian cyber experts have taken part in a large-scale incident response exercise against the country’s energy grid as geopolitical tensions with Russian continue to escalate.

President Putin on Friday issued a series of security demands, including that NATO limits deployments of troops and weapons to Ukraine’s eastern border with Russia and that the country commits to never joining the military alliance.

It warned of a military crisis in the region if its demands weren’t met. Russia has already massed 100,000 troops, alongside missiles and artillery, on its side of the border.

Many Ukrainians will be thinking back nervously to December 2015 and 2016 when Russian state-backed hackers disrupted the power grid, leaving hundreds of thousands in the dark and cold of winter for several hours.

That’s likely to have informed a recent exercise in which 250 participants and 49 teams competed to fend off an attack on a fictitious energy provider after it suffered major operational technology (OT) failures, according to reports.

The hours-long exercise, which featured private industry experts and participants from universities and other institutions, focused on three key elements: finding out what had happened, ejecting the intruders and remediating affected systems.

It was apparently run using the Sans Institute’s Grid NetWars suite, designed for OT professionals to pit their wits against fictional attackers in the electricity sector.

“Grid NetWars is a suite of hands-on, interactive learning scenarios that enable OT security professionals to develop, test and master the real-world, in-depth skills they need to defend real-time systems,” Sans says of the platform. “It is designed as a challenge competition and is split into separate levels to allow players to quickly move through earlier levels based on their expertise.”

According to Sans, participants move through four levels, conducting: incident response; environment discovery, mapping, and reconnaissance; identification of adversary actions; and eradicating adversary access and recovering/restoring systems

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Execs Get 16+ Years After SBA Fraud Scheme

Execs Get 16+ Years After SBA Fraud Scheme

Four Indianapolis executives have been sentenced to over 16 years behind bars for their part in a 13-year fraud scheme that targeted the US Small Business Administration (SBA).

The quartet worked for now-defunct lender Banc-Serv Partners, an outsourcing provider that assessed small businesses for their eligibility for loans, amongst other things.

However, the co-conspirators worked to trick the SBA into providing loans for clients they knew weren’t eligible, according to the Department of Justice (DoJ).

In a scheme that ran from 2004 to October 2017, they secured loans on behalf of various lenders, obtaining SBA guarantees by misrepresenting what the loans would be used for, hiding facts about some borrowers and even diverting denied loan applications into “expedited approval channels” at the SBA.

When the loans defaulted, the four execs submitted requests to the SBA to purchase the loans from investors and lenders, effectively shifting financial liability to the government agency.

Investigators and prosecutors argued the four had effectively robbed US small businesses which would otherwise have received loan support from the SBA.

“These sentences hold the defendants accountable for their egregious conduct to cheat a government-guaranteed loan program – by lying on loan documentation, concealing key information and asking the government to pay for defaulted loans,” said inspector general Jay Lerner of the Federal Deposit Insurance Corporation (FDIC).

“We remain committed to working with our law enforcement partners and investigating those who seek to exploit federal programs and undermine the integrity of our nation’s banks.”

The four executives are: former Banc-Serv president, founder and owner Kerri Agee; former COO Kelly Isley; former CMO Chad Griffin; and co-founder Matthew Smith, 53. A fifth co-conspirator, Nicole Smith, 44, of Indianapolis, is scheduled to be sentenced on January 7, 2022.

Agee was sentenced to 68 months, Isley got 57 months, Griffin was handed 28 months and Smith received 46 months.

Alongside their sentences, Agee and Isley were each ordered to pay $2.2m, Griffin was ordered to pay $685,000, and Matthew Smith was ordered to pay $1.7m

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

New Log4j Patch Released to Fix DoS Flaw

New Log4j Patch Released to Fix DoS Flaw

Apache has released a new patch for Log4j to mitigate a high severity vulnerability, as researchers separately found a new attack vector for the Log4Shell bug.

The open-source web server community had previously released a patch to fix the now-infamous CVE-2021-44228 flaw in the popular logging utility.

However, in an update, it admitted that this fix did not address a newly discovered issue in Log4j, which has been given a CVSS score of 7.5.

“Apache Log4j2 versions 2.0-alpha1 through 2.16.0 did not protect from uncontrolled recursion from self-referential lookups,” it explained.

“When the logging configuration uses a non-default Pattern Layout with a Context Lookup (for example, $${ctx:loginId}), attackers with control over Thread Context Map (MDC) input data can craft malicious input data that contains a recursive lookup, resulting in a StackOverflowError that will terminate the process. This is also known as a DoS (Denial of Service) attack.”

The news comes as researchers at Blumira made a discovery that effectively expands the attack surface for Log4Shell, by enabling Javascript WebSocket connections to trigger the remote code execution bug on unpatched Log4j instances.

It means that even services running as localhost that aren’t exposed to a network could be impacted.

“Previously, we understood that the impact of Log4j was limited to vulnerable servers. This newly discovered attack vector means that anyone with a vulnerable Log4j version on their machine or local private network can browse a website and potentially trigger the vulnerability,” said Blumira.

“The client itself generally has no direct control over these WebSocket connections, which can silently initiate when a webpage loads. WebSocket connections within the host can be difficult to gain deep visibility into, which increases the complexity of detection for this attack.”

The threat from Log4Shell is now so great that the US Cybersecurity and Infrastructure Security Agency (CISA) on Friday updated its patching deadline for federal agencies from December 24 to “immediately.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains