Showing posts with label IT consulting. Show all posts
Showing posts with label IT consulting. Show all posts

Friday, January 17, 2020

New Hacking Method Looks Like A Locked Computer

Scammers have breathed new life into an old scam.

For years, the old 'Law Enforcement Lock' trick has been used to cheat unsuspecting victims of their hard-earned money. The new wrinkle works like this:

Scammers will redirect users using the Chrome web browser to sites that host a full-screen image of a Windows 10 desktop with a notice that appears to come from local law enforcement agencies. This pages informs the user that their computer has been locked for some unspecified illegal activity.

The groups running this sort of scam make sure to display a legitimate government URL in order to make it look more convincing. Victims of this scam are informed that they can unlock their computer again by paying the fine via credit card, right then and there.

Of course, the computer actually isn't locked at all. However, this scam has taken in a surprising percentage of users who aren't paying close attention.

A typical lock screen from the scammers will bear a message that closely follows this script:

"Your browser has been locked due to viewing and dissemination of materials forbidden by law of (country name), namely pornography with pedophilia, rape and zoophilia. In order to unlocking you should (amount and currency type) fine with Visa or MasterCard. Your browser will be unlocked automatically after the fine payment.

Attention! In case of non-payment of the fine, or your attempts to unlock the device independently, case materials will be transferred to (name of local law enforcement agency) for the institution of criminal proceedings against you due to commitment of a crime."

As you can see from the grammatical errors in the script, this is by no means an official announcement, but it looks real enough that it sends people into a panic, causing them to enter credit card information without thinking.

Naturally, this information is harvested and resold on the Dark Web, putting money in the scammers' pockets. Make sure your employees are aware of it, and stay vigilant.


Call SpartanTec, Inc. in Greenville if you want to make sure that your computers and your networks are safe from hackers and scammers. 


SpartanTec, Inc.
Greenville, SC 29601
(864) 326-5914
https://spartantec-greenville.business.site/


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer


Tuesday, December 17, 2019

Phishing Emails Are Becoming Even Harder To Identify

According to data collected by Microsoft, phishing emails accounted for 0.62 percent of all inbox receipts in September 2019.

That's up from 0.31 percent just one year prior to that. The increase is alarming of course, but at first glance, these look like fairly harmless numbers.

Unfortunately, last year, phishing emails targeting business owners (BEC, or Business Email Compromise) cost companies around the world more than a billion dollars last year.  That fact makes the year over year increase terrifying.

The reason BEC campaigns are so successful and so expensive for businesses is that the scammers tend to impersonate CEOs and other high-ranking corporate officials.  When you get an email that by all outward appearances comes from your boss, and it's marked urgent, you tend to respond right away.  That's exactly what the scammers are counting on.

Even worse, scammers have gotten increasingly good at crafting their emails.  It has reached the point that even IT professionals have been taken in by them in some cases. They've been unable to spot the subtle differences between a scammer's email impersonating a CEO and an email from the CEO himself.  If an IT professional gets taken in, what hope is there for a busy HR employee or someone from the accounting office who doesn't face those types of threats on a daily basis?

Given the rapid increase in the number of well-crafted phishing emails, this is a serious, legitimate concern. Unfortunately, bolstered by their own success, you can bet the scammers will be even more prolific.

If there's a silver lining here it is this:  Microsoft reports that taking the simple step of enabling two-factor authentication across the board is an effective countermeasure.  Phishing attacks tend to be automated, and 2FA blocks 99.9 percent of automated attacks. If you're not currently using it everywhere, you're putting yourself at unnecessary risk.

Call SpartanTec, Inc. in Greenville for expert assistance in making sure that your network is protected against phishing emails. 


SpartanTec, Inc.
Greenville, SC 29601
(864) 326-5914
https://spartantec-greenville.business.site/


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer




Friday, December 6, 2019

New T-Mobile Data Breach Compromised Customer Info


Recently the US branch of the global telecom company T-Mobile disclosed a security breach that impacted a small percentage of its customer base.

Specifically, the security breach revealed certain information belonging to a small number of the company's prepaid cellphone users.

The exposed data included customer names, billing addresses, account numbers, rate plans, plan features and user phone numbers. The company stressed that no payment card information or passwords were compromised.

T-Mobile has contacted and has begun working with law enforcement agencies to further investigate the matter. If you were among the impacted users, you should have already received an SMS today from the company.  If you haven't received a notification and you're concerned that you may have been impacted, you can get a definitive answer from T-Mobile by contacting them at privacy@t-mobile.com.

This has been a fairly good year for Telecoms in general.  Other than Sprint's data breach earlier in the year, this is only the second data breach in 2019 involving a major Telecom company.

As breaches go, this one is quite minor, and odds are quite small that you have been impacted by it.  Again though, if it's something you're worried about, the company has made it easy to get peace of mind.  Overall, T-Mobile's handling of the incident has been better than average. In the weeks ahead as the investigation draws to a close, if there are new details to be learned, the company will no doubt disclose them when and as they are able.

With 2019 rapidly drawing to a close, it seems unlikely that we'll see a spate of Telecomm data breaches. 2019 is likely to be remembered as a year where the Telecomm companies dodged a bullet. Overall, the total number of data breaches continues to surge higher, a trend which is likely to continue for the foreseeable future.

Protect your company from data breaches by setting up safety and protective measures with the help of professional IT experts. Call SpartanTec, Inc. in Greenville now. 


SpartanTec, Inc.
Greenville, SC 29601
(864) 326-5914
https://spartantec-greenville.business.site/


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer


Friday, November 22, 2019

Cybercriminals Are Taking Aim At Your Business… Is Your Network Protected?

Cybercriminals love to test your defenses. They love to see how far they can get into the networks of businesses all over the globe. Cybercriminals really love going after small businesses because they can all too often sneak onto a network, copy data and move on. Through the use of ransomware, they can hold your data hostage and refuse to cooperate until you pay them some amount of dollars – and if you don’t pay up, they threaten to delete all your data.

But protecting yourself is not as hard as you might think. While cybercriminals and hackers are an everyday threat to businesses, you can take steps to significantly reduce that threat and take that target off your back.

The first thing you need to do is understand why cybercriminals target small businesses and what makes your particular business vulnerable. There are many things small businesses do and don’t do that open them to attack and data theft. These may include not having enough (or any) security in place or not training employees on security protocols.
Realistically speaking, the biggest threat to your business does, in fact, come from your own employees. This doesn’t mean they are intentionally harming your business or leaving your network exposed to outside threats. It means they don’t have the proper training and knowledge to protect your business from a cyberthreat.

For instance, your team needs to be trained to use strong passwords, and those passwords must be changed periodically (every three months is a good rule of thumb). A lot of people push back on strong, complicated passwords or use the same password for everything, but this is just asking for trouble and should not be allowed at your company.
Once strong passwords are in place, enable two-factor authentication (2FA) on everything you possibly can, from network access to every account you and your employees use. This is an additional layer of security on top of standard password protection. This feature is generally tied to a mobile number or secondary e-mail, or it may be in the form of a PIN. For example, when 2FA is enabled, after you’ve put in your password, you will be prompted for your PIN for the associated account.

Another thing you must do to get that target off your back is to get anti-malware software installed. Every workstation or device should have some form of this protection. Not sure what to use? This is when working with a dedicated IT company can come in handy. They can help you get the right software that will meet your specific needs without slowing you down. They will install software that is compatible with your PCs and other networked equipment. Plus, they will make sure anti-malware software is working and is regularly updated.

On top of this, you want to have an active firewall in place. Every business should have its network protected by a firewall; like antimalware software, firewall security comes with a number of different settings, and you can customize it to fit the needs of your network. Firewalls help keep attackers and malicious software off your network. When paired with a good anti-malware software, your layers of security are multiplied. The more layers, the better protected you are.

Finally, with all of this in place, your employees need to know what it all means. Keep your team up-to-date on your business’s security protocols. This includes items like your password policy, malware protection policy and proper e-mail and web-surfing etiquette.

The bad guys are never going to stop attacking, but you have the power to protect your business from those attacks. Call SpartanTec, Inc. now and let our team help you with your cybersecurity needs.



SpartanTec, Inc.
Greenville, SC 29601
(864) 326-5914
https://spartantec-greenville.business.site/


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer


Tuesday, November 5, 2019

Importance Of Backup and Recovery Plans


In the past, backup was made to deal with prolonged outages, equipment failure, occasional virus, and natural disasters. What would it cost your business if you go to work one day and all the computers have been encrypted? Or the server that is responsible for your order processing system is down for five days and the hackers are demanding 50k to get it back up and running once again? 

What do you think your customers will feel if they can’t get in touch with you for a week? As a business owner, when you look at your company, it’s crucial to consider technology not only as your revenue enabler but also as a risk. Breaches, IP theft, and cyberattacks are not just geek issues. They are can easily become your worst nightmares. Small business comprise 58% of malware attack victims and cyber attacks cost a small medium businesses a whopping $22 million on average. Disaster recovery and business continuity is taking on a whole new meaning in the world of ransomware.

Although the cloud offers wonderful opportunities for cloudbased applications, offsite backups, and more, the cloud cannot solve everything. Most companies are not even aware that Microsoft does nto backup their calendars or mailboxes.

These days, MSPs will take the principles behind SOC II and cybersecurity framework into account as he works with you and your business to come up with a straightforward, practical, and real backup as well as disaster recovery plans for not just the conventional physical threats of outages and availability, but the new world of cloud scale and cyber security. The results of a well made and tested business continuity plan takes into account the inevitability of non technical workaround, breach, as well as independent software solutions that will make sure that you are among the 40% that makes it beyond the inevitable.

Training and Compliance


Although there’s some level of mystery linked to the word hacker, hacking a system isn’t rocket science. It can even be done by just an email. The shift from conventional to modern msp involves not only securing systems but also training and teaching end users. Any business’ weakest link is its people. It doesn’t matter how good your email and spam filtering solutions are or your perimeter systems, the threats will continue to evolve and people are going to be the main target to override your security system. Technology service providers and managed IT services could help test, validate, and train your employees so that they understand the risks involved and make sure that the integrity of your safeguards are maintained.

MSPs will provide dark web monitoring as well as automate testing for easily compromised and weak passwords. Credential sharing and phishing will be tested at random and staff trained, scored, and counselled not by the human resource department but by the IT department.

Support From The Cost Center To The Differentiator


Some things will never change, computers fail to boot, printers are going to jam, files will inadvertently disappear, and some power point presentation doesn’t display correctly. You and your business always needs support. A good IT department is results driven and customer focused. Support will not just be about tech geeks fixing issues, it will be about getting the problem fixed as soon as possible on your terms.

Call SpartanTec Inc. in Greenville if you want to know more about business continuity planning, IT consulting, or managed IT services.


Learn more about managed services by clicking on the links below:



SpartanTec, Inc.
Greenville, SC 29601
(864) 326-5914
https://spartantec-greenville.business.site/


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer


Monday, October 28, 2019

Browser Update Warnings May Actually Be Malicious Hackers

Researchers at FireEye have recently unearthed a particularly nasty new campaign that is both multi-faceted and dangerous.

At the heart of the attack are hacked websites which display seemingly innocuous popup message informing the site visitor that their browser is out of date.

It will helpfully provide a one-touch solution to the non-existent problem via a button that promises to download the latest version of the browser in question.

Naturally, it does no such thing.  Instead, it uses a series of JavaScripts to gather information about the target computer and send the details back to the command and control server.

The server then responds to the findings reported by the initial script by uploading the initial payload.  This varies based on the details gleaned, but generally includes some type of banking trojan malware and a backdoor such as Dridex, NetSupport Manager RAT, or similar.  If the initial scan reveals that the target computer is part of a corporate network, then an additional payload is also injected onto the target machine, but we'll get to that in a moment.

The first part of the payload will busily ferret out login credentials and other sensitive information, exfiltrating any files of value back to the command and control server.

Only when this operation has been completed and if the computer is part of a corporate network will the second stage we referenced earlier trigger, which is a strain of ransomware, normally BitPaymer or DoppelPaymer. The ransomware spreads through the network as far as it is able, encrypting files network wide.

These two ransomware strains are known for their hefty ransom demands, which often run into the hundreds of thousands, or even millions of dollars.

This multi-stage approach is dreadfully effective.  It not only allows the hackers to squeeze a wide range of sensitive data from infected systems, but then, locks them down hard and demands a hefty payment.  Be sure your staff is aware.  This one's about as dangerous as they come.

Nowadays, whether you own a startup or established company, you need to be cautious, aware, and proactive when it comes to online security. Let SpartanTec Inc. in Greenville help you secure your computers and networks against various types of online threats. 


SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer

Tuesday, October 15, 2019

Google Adds Several New Password Features To Help Users

Google is taking additional steps to provide a safer and more secure environment for their massive user base.  Chrome is the most widely used browser in the world. In recent months, Google has made moves to provide better password security. Most recently, they released a Chrome Extension called Password Checkup that scans all of your stored login credentials to see if they've been found in data breaches. If they have been breached, it prompts you to change them.

As good and helpful as that is, the company has taken an additional step and has now integrated the Password Checkup tool directly into Google's Password Manager.

Here's how it works:
  • Open your Google Password Manager, which you can access via https://passwords.google.com.
  • When the page displays, you'll see a new link labelled "Check Passwords." Click that.
  • Google will then proceed to check your stored login credentials to see:
    • If any of your passwords have been exposed via a third-party data breach
    • If the password in question is being reused among multiple sites
    • Assess the relative strength of all of your stored passwords.
Once this check is complete, it will display the results in different categories that show you exactly which passwords are at risk, and why they were flagged.  From there, you'll be able to change any problematic passwords and re-run the check to give yourself a clean bill of health.

This is a fantastic move, but the company isn't stopping there.  Ultimately, the company plans to have Chrome automatically alert you when your saved passwords were discovered in a breach and allow you to act immediately to change them and keep your accounts safe.

When the plan is fully realized, Google's password security feature built into Chrome will rival the capabilities of many paid password management offerings, and that's a very good thing indeed.
Kudos to Google for raising the bar.

Online security is an integral part of any company these days. If Google is taking steps to help their users secure their passwords, you should also do you part. Call SpartanTec Inc. now if you want to know how to keep your personal or business information secure.

SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914


Friday, September 27, 2019

Your Google Calendar Settings May Be Sharing Your Info

Twelve years ago, Google introduced a new feature to Google Calendar that allowed users to share their calendars with others.  It's a great feature and invaluable in a corporate environment because it gives teams an easy way to collaborate.  Google itself even touted the "make it pubic" feature of their calendar as being a cool way to use their search engine to discover upcoming events.

Unfortunately, as with most things, there's a potential downside.  Recently, a security researcher named Avinash Jain discovered more than 8,000 publicly accessible Google Calendars, searchable via Google's own search engine.  Many of these calendars contain sensitive information (which is bad enough), but worse, they allow any user to add new events that can cause real harm to the system hosting the calendar. This is done via maliciously crafted events or poisoned links.

As Avinash Jain reports:

"I was able to access public calendars of various organizations leaking out sensitive details like their email IDs, their event name, event details, location, meeting links, zoom meeting links, google hangout links, and much, much more.

This is more of an intended setting by the users and intended behavior of the service. The main issue however, is that anyone can view anyone's public calendar, add anything on it - just by a single search query without being shared the calendar link.

Jain goes onto say that several calendars belonging to many of the top 500 Alexa company's employees were made public, which is certainly cause for concern.

This most recent finding adds to the chorus already warning of the dangers of calendar sharing.  Just a few months ago, researchers from Kaspersky Lab discovered scammers abusing Google Calendar in a variety of ways. For example, there were phishing scams that contained poisoned links masquerading as google calendar event links.

Stay vigilant and be sure you have all employees check their Google Calendar security settings so you're not revealing more than you intended to.

It is also crucial to make sure that your computers or the entire business network is not in any way at risk of any kind of online breach. Call SpartanTec, Inc. in Greenville now and let our team set up and efficient strategy to protect your business.

SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer

Wednesday, August 7, 2019

Equifax Breach Victims Could Be Entitled To Settlement Claims

Equifax is one of the three credit reporting firms in the US that suffered a massive data breach in 2017 that exposed the personal and financial state of literally half the country (more than 150 million people). As a result, Equifax was ordered to pay a hefty $700 million fine to settle a series of Federal and State investigations. While the size of the fine sounds impressive, digging a bit deeper reveals it to be a bit underwhelming.

Only $425 million of that fine will go into a fund designed to actually reimburse impacted customers. However, Equifax will be allowed to earmark an unspecified portion of that to provide free credit monitoring services to anyone who was impacted by the breach.

Here's the problem:  Free Credit Monitoring is actually a money-maker for Equifax because of the way the "free" service is offered.  It's free for a year, and then automatically converts to a paid service.  Given that most people don't pay close attention to that sort of thing, a significant percentage of customers will continue paying Equifax for their credit monitoring service, which essentially sees the company profiting from their own data breach.

In any case, impacted customers will be eligible for a small amount of money from Equifax if their data was compromised. The company is on the hook for paying some $300 million in fines and civil penalties across 50 states and to the Consumer Financial Protection Bureau.

On top of that, the company has been ordered to provide all American consumers, (whether they were impacted by the breach or not), six free credit reports each for the next seven years. This is in addition to the one free annual credit report they already get beginning in January 2020.

It's a decent settlement, but it lets Equifax off the hook too easily. That is especially true given that they can turn one of the largest data breaches in American history into a profit center.  The CFPB could have and should have demanded more.

Call SpartanTec, Inc. if you want to make sure that your network is secured against potential online breach.

SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914

Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer