Cybersecurity Month
At Owens, we’re dedicated to empowering you with the tools and knowledge needed to confidently navigate the digital world and protect yourself! This October, we’re excited to reinforce our commitment to online security while equipping our community with essential insights.
Since its launch in 2004, Cybersecurity Awareness Month has emphasized the importance of understanding cyber safety and overcoming the everyday challenges we encounter online.
Get Ready for an Exciting Learning Experience!
Our Information Technology Services team has put together a fantastic array of activities, packed with valuable tips, strategies and engaging brief trainings designed to strengthen your cybersecurity skills.
Take Charge of Your Security!
Gain the knowledge to protect yourself online while also becoming a trusted resource for your colleagues, friends and family.
Prizes Await You!
Don’t miss out on weekly opportunities to win exciting prizes by demonstrating your cybersecurity awareness through our ONews articles and emails.
What to Know About Cybersecurity
Email Encryption/Secure File Attachments
Each day, companies worldwide utilize email to communicate, both internally and externally, often sending email messages and/or attachments that contain valuable and sensitive data, so there are many advantages to having email security. When properly implemented, the best email encryption protects email content, ensuring that it is only accessible to its intended recipient(s).
If left unencrypted, emails intercepted by malicious actors like hackers and cybercriminals can be read and leveraged through phishing attacks and the likes, making any information present within such emails completely vulnerable. On the other hand, through a technology most commonly referred to as end-to-end encryption, encrypted emails are only legible to those in possession of the correct decryption key. With end-to-end encryption, a public key is mobilized by the sender to encrypt the email, and then a private key is used by the recipient to decrypt the message.
Cybersecurity is a top priority for all businesses in today’s digital world, where email systems are among the most common attack vectors that criminals take advantage of. This is why most businesses opt for integrating advanced email security systems into their existing email architecture, including Microsoft’s Office 365 and Google’s G Suite.
The theft of delicate data via email can result in irreparable damage for a school or business, at times even dramatically compromising a business’s ability to securely communicate with customers, peers, investors, employees, etc. But with robust encryption, this data can remain protected with email security.
It’s important to use reputable encryption methods and solutions to prevent email threats and fully secure your email accounts. Implementing advanced email safety systems is the best way to protect you from email attacks, prevent loss of data due to network or email server problems, isolate your endpoint software from malware, and give you full control over email flows in your organization.
Email Security for Compliance
Schools or Businesses dealing with financial data, student records, medical records, credit card information, etc., must abide by certain compliance guidelines. Many of these guidelines, specifically HIPAA, CJIS and CFPB, require encryption, while others, like GDPR, strongly encourage it. Although there are various compliance metrics that either mandate or recommend email encryption, they all require that organizations protect employee and customer data, such as electronic Personal Health Information (ePHI), Personal Identifiable Information (PII), or Nonpublic Personal Information (NPI).
Email encryption serves to help individuals and businesses accomplish this, “preventing accidents, and preventing data breaches in the case of a hacker breaking into your system.” The Sending/sharing of file attachments is essential to how people get work done. From contracts and financial reports to project drafts and HR data, collaboration often means sending files back and forth. When sending emails with confidential data, it’s very important to make sure you are sending those messages encrypted, especially when the data is sent externally.
Why You Should Encrypt Email Attachments
- Data Protection: Encryption converts sensitive data into an unreadable format, protecting it from unauthorized access if the email is intercepted during transit or inadvertently sent to an incorrect email address.
- Regulatory Compliance: For many industries, using email encryption is a requirement for complying with regulations like HIPAA, CJIS and GDPR.
- Preventing accidental data leaks: Encryption can prevent sensitive information from being seen by the wrong people, especially when combined with features that prevent forwarding.
What Confidential Data Should I Encrypt?
- Social Security numbers
- Protected health information (PHI)
- Health Insurance Portability and Accountability Act data (HIPAA)
- Clinical trial data
- Credit card numbers
- Grades for assignments and courses
- Disciplinary records
- Salary and tax records
Zoombombing
Zoombombing or Zoom raiding is the unwanted, disruptive intrusion, generally by internet trolls, into a video call. In a typical Zoombombing incident, a teleconferencing session is hijacked by the insertion of material that is disruptive or offensive in nature, typically resulting in the shutdown of the session and/or the removal of the interloper.
These intruders often disrupt meetings by sharing inappropriate content, making loud noises, or flooding the chat with unwanted messages. The term is especially associated with and is derived from the name of the Zoom videoconferencing software program; however, it has also been used to refer to the phenomenon on other video conferencing platforms.
Zoombombing has caused significant issues, particularly for schools, companies, and organizations worldwide. Such incidents have resulted in increased scrutiny on Zoom as well as restrictions on the usage of the platform by educational, corporate, and governmental institutions globally. In response, Zoom, citing the sudden influx of new users during the COVID-19 pandemic, took measures to increase the security of its teleconferencing application. Incidents of Zoombombing have prompted law enforcement officers in various countries to investigate such cases and file criminal charges against those responsible.
How to Protect your Meetings
- Use unique meeting IDs and strong passwords for each session.
- Enable waiting rooms to screen participants before admitting them.
- Restrict screen sharing capabilities to hosts only.
- Lock meetings once all expected people have joined, so no new participants can join.
- Avoid sharing meeting links on public platforms or social media.
- Use the latest version of your video conferencing software.
- Disable attendees’ video. Hosts can turn anyone’s video off. This allows them to block unwanted, distracting, or inappropriate gestures on video.
- Turn off file transfer. In-meeting file transfer allows participants to share files through the chat interface. Toggle this off to keep the chat from getting bombarded with unsolicited images, GIFs or other files.
- Turn off annotation. You and your attendees can annotate a screen share to mark up content. You can disable the annotation feature in your Zoom settings to prevent disruptive misuses of this feature.
- Remove disruptive participants. From the same “Participants” menu, hover your mouse over a participant’s name. Several options will appear, including “Remove.” Click that to kick someone out of the meeting.
- Disable private chat. Zoom has an in-meeting chat feature, but participants can also message each other directly. Restrict participants’ ability to chat privately while your event is going on to limit distractions.
- Educate your team or students about online meeting etiquette and security, and familiarize yourself with the actions you can take as a host to stop inappropriate behavior in the moment.
YouTube Video
Internet of Things (IoT) Risks
Internet of Things (IoT) cyber-attacks have been around for some time now. However, what has accelerated is the scale and evolution of these attacks. At its core, IoT is all about connecting and networking devices. This means that all ‘smart’ devices, ranging from connected home appliances to connected vehicles, through to connected IoT medical devices, create a new entry point to the network and pose increasing levels of security and privacy risk.
In addition, we also need to think on a larger scale about how connected IoT devices have evolved—where they are prevalent in every area of our day-to-day lives, and that any single component can be compromised. The impact of each attack can vary dramatically, depending on the ecosystem, the device and environment, and the existing levels of protection.
Botnets
A botnet is a network of systems combined together with the purpose of remotely taking control and distributing malware. Controlled by botnet operators via Command-and-Control-Servers (C&C Server), they are used by criminals on a grand scale for many things: stealing private information, exploiting online-banking data, DDoS attacks, or for spam and phishing emails. With the rise of the IoT, many objects and devices are in danger of or are already being part of so-called thingbots—a botnet that incorporates independent connected objects.
Botnets, as well as thingbots, consist of many different devices, all connected to each other—from computers, laptops, smartphones and tablets and now to “smart” devices. These bots have two main characteristics in common: they are internet-enabled and they are able to transfer data automatically via a network.
Anti-spam technology can spot pretty reliably if one machine sends thousands of similar emails, but it’s a lot harder to spot if those emails are being sent from various devices that are part of a botnet. They all have one goal: sending thousands of email requests to a target in hopes that the platform crashes while struggling to cope with the enormous number of requests.
Denial of Service
A denial of service (DoS) attack happens when a service that would usually work is unavailable. There can be many reasons for unavailability, but it usually refers to infrastructure that cannot cope due to capacity overload. In a Distributed Denial of Service (DDoS) attack, a large number of systems maliciously attack one target. This is often done through a botnet, where many devices are programmed (often unbeknownst to the owner) to request a service at the same time.
In comparison to hacking attacks like phishing or brute-force attacks, DoS doesn’t usually try to steal information or lead to security loss, but the loss of reputation for the affected company can still cost a lot of time and money. Often, customers also decide to switch to a competitor, as they fear security issues or simply can’t afford to have an unavailable service. Often, a DoS attack lends itself to activists and blackmailers.
Why IoT Devices Are Vulnerable
- Insecure default settings: Devices often ship with insecure default settings and credentials that make them easy targets for hackers. One of the most significant risks to IoT security is that default passwords are widely known, making it simple for thieves to compromise them.
- Limited hardware resources: Many IoT devices have limited memory and processing power, restricting the implementation of strong security features like robust encryption.
- Lack of security updates: Unlike traditional computers or smartphones, many IoT devices do not receive regular security patches from their manufacturers, leaving known vulnerabilities exposed for extended periods.
- Poor security design: Many manufacturers prioritize features and speed-to-market over robust security. They often use insecure components, lack robust encryption, and fail to provide mechanisms for easy software updates.
Examples of IoT Attacks
- Baby monitor eavesdropping: Attackers have used unsecured baby monitors to speak to families or spy on them.
- Smart camera hijacking: Hackers have taken control of smart home security cameras to spy on users or use them as part of a botnet.
- Hackable Cardiac Devices: IoT devices have tremendous potential in the field of medicine. This was starkly illustrated by an incident in 2017 when the FDA announced that it had discovered a serious vulnerability in implantable pacemakers made by St. Jude Medical.
- Jeep Hack: This attack was first demonstrated in July of 2015 by a team from IBM. They were able to access the onboard software of a Jeep SUV and exploit a vulnerability in the firmware update mechanism. Researchers took total control of the vehicle and were able to speed it up and slow it down, as well as turn the wheel and cause the car to veer off the road.
“Free” WiFi Security
Public Wi-Fi is not inherently safe due to risks like data interception and fake hotspots, so you should avoid sensitive activities like online banking, shopping, or logging into accounts that require personal information. To stay safer, use a personal VPN when doing any of these activities. To verify your connection is secure, look for an “https:” connection in the browser and the “lock icon” on websites. Also, disable automatic Wi-Fi connections in the Settings/WiFi on your device.
Risks of Public WiFi
- Unencrypted data: Even on password-protected public Wi-Fi, the network is often less secure than a private home network. A shared password means anyone on the network could potentially access your data. Without a VPN, your traffic may be visible to others.
- Malicious Hotspots: Hackers create “evil twin” Wi-Fi networks that mimic legitimate ones, like “Free Airport WiFi.” When you connect to these fake networks, your data is routed through the attacker’s computer, giving them access to your unencrypted online activity and credentials.
- Man-in-the-middle attacks: An attacker can secretly position themselves between your device and the network. While many websites use encryption (HTTPS), a determined hacker can downgrade your connection to an unsecured version (HTTP) to intercept your traffic, passwords, and personal information.
- Packet Sniffing: On unencrypted public networks, attackers can use software to “sniff” or capture data packets sent over the network. This can expose everything from your browsing history to your login credentials.
- Malware and identity theft: Attackers can exploit vulnerabilities in public networks to inject malware into connected devices through infected pop-ups or corrupted web pages. This malware can then be used to steal data or take control of your device.
How to Stay Safe
- Verify the Network: Connect only to networks you are sure are legitimate. Be suspicious of names that look misspelled or have extra words like “free”.
- Turn off auto-connect: Prevent your device from automatically joining potentially insecure networks by disabling this setting.
- Look for “https”: Ensure the websites you visit use encryption by looking for “https” in the address bar, which should show a lock icon.
- Use strong, unique passwords: Use strong, unique passwords for all your accounts and enable two-factor/(MFA) authentication whenever possible.
- Disable file sharing: Turn off file sharing so that your files are not potentially accessible to hackers/others.
- Use a personal VPN: A virtual private network (VPN) creates an encrypted tunnel for your data, making it unreadable to others on the public network.
- Use your cellular data: For more secure browsing, consider using your phone’s cell connection or mobile hotspot instead of public Wi-Fi.
- Limit your activities: Avoid accessing sensitive information, such as online banking, logging into email, or entering credit card details. Save these tasks for a trusted network, or use your phone’s cellular data.
Video
Malicious Email Attachments
Malicious email attachments are designed to launch an attack on a user’s computer. Disguised as documents, voicemails, e-faxes or PDFs, malicious email attachments are designed to launch an attack on the victim’s computer when the attachment is opened. Malicious email attachments may be designed to install viruses on a computer, set up ransomware attacks, launch advanced persistent threats or set up attacks on another organization.
Some of these infections could also allow the attacker to take control of the victim’s computer, giving the attacker access to the screen, capture keystrokes, and access other network systems. A good rule of thumb is only to open file attachments you are expecting and if they are relevant to the work you are doing.
Since many email systems automatically block obvious malicious programs, attackers conceal a piece of software called an “exploit” inside other types of commonly emailed files—Microsoft Word documents, a ZIP or RAR file, Adobe PDF documents, or even image and video files. The exploit takes advantage of software vulnerabilities and then downloads the intended malicious software, called a “payload”, to the computer.
Attackers can also embed a malicious macro into documents and use social engineering to trick the user into clicking the “Enable Content” button that will allow the macro to run and infect the victim’s computer. Attackers typically send these email attachments and provide email content that is sufficiently convincing to get the user to believe it is legitimate communication.
What steps can you take to protect yourself?
Be wary of unsolicited attachments, even from people you know. Just because an email message looks like it came from someone you know does not mean that it did. Many spammers can “spoof” the return address, making it look like the message came from someone else (this is also known as a “forged” email). It is strongly suggested that you check with the person who supposedly sent the message to make sure it’s legitimate before opening any attachments. If you’re still concerned about an email message, you can forward it to: spam@owens.edu, where an ITS member can look at it and respond back to you.
Trust your instincts. If an email or email attachment seems suspicious, don’t open it, even if your antivirus software indicates that the message is clean. Attackers are constantly releasing new viruses, and the antivirus software might not have the signature. At the very least, contact the person who supposedly sent the message to make sure it’s legitimate before you open the attachment.
However, especially in the case of forwards, even messages sent by a legitimate sender might contain a virus. If something about the email or the attachment makes you uncomfortable, there may be a good reason. Don’t let your curiosity put your computer at risk.
Social Engineering Threats
Social Engineering Definition
In a cybersecurity context, social engineering is the set of tactics used to manipulate, influence, or deceive a victim into divulging sensitive information or performing ill-advised actions to release personal and financial information or hand over control over a computer system. Social engineering uses psychological manipulation, persuasion and exploitation to deceive users into making security mistakes or relinquishing sensitive information. Social engineering attacks rely on human interaction and often involve conning victims into breaking normal security procedures. For instance, social engineering attacks can be highly effective because they’re based on the human tendency to trust others or explore one’s curiosity about new offers or information, acting as bait.
Examples of Social Engineering Techniques
The overall technique used in social engineering is using emotions to trick users, but attackers use several standard methods to push the user into performing an action (e.g., sending money to a bank account) and making the attack look more legitimate. Usually, the techniques involve email or text messages, because they can be used without voice conversations.
A few common examples of social engineering techniques include:
- Phishing: With social engineering, an attacker usually pretends to be a corporate executive to trick users into sending money to an offshore bank account.
- Baiting: It’s common for attackers to promise prizes or money in exchange for a small payment. The offer is usually too good to be true, and the payment is usually for shipping or some other cost coverage.
- Pretexting: Attackers may create a false pretext to gain sensitive information or access to a system. For example, an attacker might impersonate a bank teller and contact a target individual to claim that there’s been suspicious activity on their account and ask them to share/confirm sensitive information to confirm their account.
- Tailgating or piggybacking: Corporations that use security scanners to block unauthorized access to the premises. An attacker uses tailgating or piggybacking to trick users into using their own access cards to give the attacker physical access to the premises.
- Quid pro quo: Disgruntled employees could be tricked into providing sensitive information to an attacker in exchange for money or other promises.
- Watering hole: This form of social engineering attack involves targeting certain groups by infecting websites that the group is likely to visit. For example, an attacker might infect a popular news site with malware with the intention that employees of a certain company will visit the site and inadvertently download the malware.
- Responding to a question never asked: The targeted victim will receive an email “responding” to a question, but the response will ask for personal details, contain a link to a malicious website, or include a malware attachment.
- Threaten loss of money or accounts, or threaten prosecution: Fear is a useful tool in social engineering, so an effective way to trick users is to tell them that they will suffer money loss or go to jail if they do not comply with the attacker’s request.
Social Engineering Prevention Keys
- Identify valuable information: Personally identifiable information (PII) should never be shared with a third party, but employees should know what data is considered PII.
- Limit personal information online: Avoid sharing any personal details, like schools you’ve attended, pet’s names, or other details reflecting the answers to security questions or access passwords.
- Keep devices secure and close: Lock your computer and mobile devices, especially when in public places like airports or coffee shops. Keep your devices in your possession to prevent theft.
- Keep anti-malware software up to date: Should an employee download malicious software, anti-malware will detect and stop it in most cases.
- Be suspicious of requests for data: Any request for data should be received with caution. Ask questions and verify the sender’s identity before complying with the request.
- Enhance security with multifactor authentication: Adding extra layers to verify your identity can make online accounts much safer and impenetrable.
- Train employees: Employees can’t identify attacks if they do not have the education that helps them, so provide training that shows employees real-world examples of social engineering.
YouTube Video
CEO Fraud—Whaling
CEO Fraud is a variation of a spear phishing email attack in which the attacker impersonates your CEO/President. It is a sophisticated email or phone text scam that cyber criminals use to trick employees into transferring money or providing them with confidential company information.
CEO Fraud is a social engineering technique that relies on winning the trust of the email recipient. The cyber criminals behind it know that most people don’t look at email addresses very carefully or fail to notice minor spelling errors.
Cyber criminals use emails or text messages to impersonate the company CEO or other company executives and ask employees, typically in HR or accounting, to help them by sending a wire transfer, updating account information or providing account details.
Increasingly, gift card scams are associated with CEO fraud because they are impossible to trace once sent to the recipient. These scams might also not be CEO-specific. Scammers could impersonate someone else, like a manager or supervisor, so the employee has even less suspicion.
One example of this attack is when the impersonator sends an email or text to an employee asking them to purchase some gift cards and then provide the numbers to them, stating they are busy or currently in a meeting. The request is always “urgent” in nature. Always verify the other person in this type of scenario; it is almost always a Scam.
CEO Fraud is also sometimes referred to as a “Whaling Phishing Attack” or just “Whaling” (the BIG fish!). Whaling is a cyber-attack that occurs when an attacker utilizes spear phishing methods to go after a large, high-profile target, such as c-suite executives, including the CFO or CEO. Due to their highly targeted nature, whaling attacks are often more difficult to detect and prevent than standard phishing attacks.
Whaling attack emails and fake websites are highly customized and personalized, and they often incorporate the target’s name, job title or other relevant information gleaned from a variety of sources, including the company website. These cyber-attacks can fool victims because attackers are willing to spend more time and effort constructing them due to their potentially high returns. Attackers will often use social media, such as Facebook, Twitter and LinkedIn, to gather personal information about their victim to make the whaling attack more plausible. This level of personalization makes it difficult to detect these attacks.
CEO Fraud Prevention Tip
If you receive an urgent purchase or transfer communication from an executive, reach out to that person on their company phone, check the senders email address or phone number, and if possible, check calendars to see where that person is currently. Follow-up with the executive’s administrative assistant for more information if needed.
AI Deepfakes
With the recent rise of AI, it’s much easier for a scammer to create messages with a very accurate replication of an individual’s voice or image. These videos with the person’s voice can be very convincing. It only takes a short sample of a person talking or making a speech on the web to create a deepfake imitation voice. This means that following up, before making a financial mistake, is even more important.
USB Drop Attacks
Imagine that you find a USB drive somewhere on campus, or perhaps receive one for free in the mail. What do you do? Or more importantly, what shouldn’t you do? While it may be tempting to plug that drive into your computer either to find information that will help you return it to its owner or to use it for yourself, think twice!
A hacker starts the process by dropping the sticks in heavily trafficked locations around their target. In some cases, they drop the devices in parking lots, lunchrooms, bathrooms or business lobbies, hoping for a curious person to pick it up. All the victim needs to do is take the USB drive and plug it in to their device, and click on a file listed on the stick, such as “salaries 2023.doc” or “layoffs 4th quarter,” likely sparking an employee’s interest.
Once opened, the file may prompt the user to “enable macros.” After this, the document will be able to run malicious software that can do anything from activating the webcam to keeping a running log of keystrokes. The USB drive could also contain malware, viruses or other threats to the victim’s device.
There are three main types of USB drop attacks:
- Malicious code: The user clicks on one of the files on the drive, triggering malicious code that automatically activates upon viewing and can download further malware from the Internet.
- Social engineering: The user clicks on one of the files on the drive and is taken to a phishing site which attempts to trick them into entering their login credentials.
- HID (Human Interface Device) spoofing (or BadUSB attack): The USB drive contains software that tricks the computer into thinking a keyboard is attached. The drive then injects keystrokes to command the computer to install malware, such as ransomware, or even give a criminal remote access to the victim’s computer. And once that USB device has been plugged in, it is like inviting a bank robber into an unlocked vault. The hacker can go almost anywhere.
Trying to determine how common this type of attack is difficult. Still, researchers from the University of Michigan, the University of Illinois Urbana-Champaign, and Google spread around 297 USB flash drives on a university campus.
Their study reported that 45 percent of USB drives were picked up and opened. These results suggest that USB drop attacks are a relatively common threat. Further, the study found that 68 percent of users said they took no precautions when plugging in the drive.
It’s also worth noting that antivirus software may not be effective in stopping these types of attacks.
Key Steps to Take to Help Prevent Becoming a Victim
- Do not plug in USB drives that you find in public places. Even if the drive looks legitimate, it could be infected with malware.
- Keep operating systems and software up to date with the latest security patches.
- Back up your data regularly. In case you need to restore any files.
Note: If you do find a USB laying on the ground at Owens, report it to the ITS Help Desk at (567) 661-7120, email the HelpDesk, or take it to the Help Desk on the 2nd floor of College Hall in Room 213.
Data Breaches
Recent Major Data Breaches in Consumer Data Services
- On August 28, 2025, TransUnion, an online credit reporting company, experienced a significant data breach. This breach allegedly exposed up to 4.4 million customer records were exposed.
- In May 2025, LexisNexis, a data broker, disclosed that an unauthorized party accessed the sensitive personal data of over 364,000 customers.
- In 2024, AT&T experienced two data breaches. Personal data, including Social Security numbers, addresses, birthdates, and passcodes, for approximately 73 million customers (both current and former) was exposed.
Risks of the Exposed Data
The compromised data in these breaches can be exploited for different cybercrimes and fraudulent actions. The following list shows possible risks associated with each category of exposed information:
- Full Names: Misuse of your identity for fraudulent activities, such as opening new accounts or making unauthorized purchases.
- Social Security Numbers: High risk of identity theft, which can lead to fraudulently opened credit accounts, loans and other financial activities. It’s important to monitor your credit reports. You might want to consider placing a fraud alert or credit freeze on your Social Security number.
- Addresses: Access to your physical address increases the risk of identity theft and physical threats. These threats can include fraudulent change-of-address requests and potential home burglaries.
- Phone Numbers: There is a high likelihood of increased phishing attacks through text messages and phone calls, potentially resulting in unauthorized access to personal and financial information. This also increases the risk of unsolicited (spam) calls.
- Email addresses: Increased risk of targeted phishing, account takeovers, unauthorized access and a higher chance of spam emails.
- Birthdates: Combined with any of the above categories, could be used to apply for various forms of credit.
Recommended Actions
Based on the type of information exposed, consumers should consider the following steps to reduce risks. Unless you know exactly what was exposed, you should assume all of the personal data types listed were exposed. As such, we recommend taking the following actions.
Social Security Numbers:
- Consider placing a credit freeze with the major credit bureaus. For more details about credit freezes, see: How You Can Help Us Protect Your Social Security Number and Keep Your Information Safe?
- Regularly review your credit report and sign up for free weekly credit reports.
- Place a fraud alert with the major credit bureaus
- If you know that your Social Security number was compromised, contact the Social Security Administration.
- Monitor your financial accounts (banks, credit cards, line of credit, etc.) for suspicious activity.
There have been numerous other data breaches by other companies, and these events are becoming more frequent. As time goes on, hackers that utilize the Dark Web will continue to collect additional data on individuals that may eventually allow them to be able to create much more complete profiles of citizens that can be used in attempts to impersonate these compromised individuals.
Ransomware
Ransomware is a type of malware that prevents or limits users from accessing their system, either by locking the system’s screen or by locking the users’ files until a ransom is paid. In many cases, the ransom demand comes with a deadline. If the victim doesn’t pay in time, the data is gone forever or the ransom increases.
Several government agencies, including the FBI, advise against paying the ransom to keep from encouraging the ransomware cycle, as does the (No More Ransom Project). Furthermore, half of the victims who pay the ransom will likely suffer from repeat ransomware attacks, especially if it’s not cleaned from the system.
Growing Prevalence of Ransomware Has Brought About Increasingly Complex Ransomware Attacks
- Scareware: This common type of ransomware deceives users by displaying a fake warning message claiming malware has been detected on the victim’s computer. These attacks are often disguised as an antivirus solution demanding payment to remove nonexistent malware.
- Screen lockers: These programs are designed to lock the victim out of their computer, preventing them from accessing any files or data. A message is typically displayed that demands payment to unlock it.
- Encrypting ransomware: Also called “crypto-ransomware,” this common ransomware encrypts the victim’s files and demands payment in exchange for a decryption key.
- Sextortion: A scammer will send an email stating that they have hacked into your PC and have a compromising video of you, unless you pay a Bitcoin ransom.
- DDoS extortion: A Distributed Denial of Service extortion threatens to launch a DDoS attack against the victim’s website or network unless a ransom payment is fulfilled.
- Mobile ransomware: As the name suggests, mobile ransomware targets devices like smartphones and tablets and demands payment to unlock the device or decrypt the data.
- Doxware: While less common, this sophisticated type of ransomware threatens to publish sensitive, explicit, or confidential information from the victim’s computer unless a ransom is paid.
- Ransomware-as-a-Service (RaaS): Cybercriminals offer ransomware programs to other hackers or cyber-attackers who use such programs to target victims.
These are just some of the most common types of ransomware. As cyber criminals adapt to cybersecurity strategies, they pivot to new and innovative ways to exploit vulnerabilities and breach computer systems.
Types of Ransomware
By learning about the major ransomware attacks below, organizations will gain a solid foundation of their tactics, exploits, and characteristics. While ransomware codes, targets, and functions continue to vary, attack innovation is typically incremental.
- WannaCry: A powerful Microsoft exploit was leveraged to create a worldwide ransomware worm that infected over 250,000 systems before a kill switch was tripped to stop its spread. Proofpoint was involved in identifying the sample used to find the kill switch and deconstructing the ransomware. Learn more about Proofpoint’s involvement in stopping WannaCry.
- CryptoLocker: This was an early current-generation ransomware requiring cryptocurrency for payment (Bitcoin) and encrypted a user’s hard drive and attached network drives. CryptoLocker spread via an email with an attachment claiming to be FedEx and UPS tracking notifications. A decryption tool was released for this in 2014. But various reports suggest that upwards of $27 million was extorted by CryptoLocker.
- NotPetya: Considered one of the most damaging ransomware attacks, NotPetya leveraged tactics from its namesake, Petya, such as infecting and encrypting the master boot record of a Microsoft Windows-based system. NotPetya targeted the same vulnerability as WannaCry to rapidly spread payment demands in Bitcoin to undo the changes. Some have classified it as a wiper since NotPetya cannot undo its changes to the master boot record and renders the target system unrecoverable.
- Bad Rabbit: Considered a cousin of NotPetya, using similar code and exploits to spread, Bad Rabbit was a visible ransomware that appeared to target Russian and Ukrainian media companies. Unlike NotPetya, Bad Rabbit did allow for decryption if the ransom was paid. Most cases indicated that it was spread via a fake Flash player update that impacted users via a drive-by attack.
- Double extortion Ransomware (Doxware): Is authored by a group of financially-motivated attackers. It exfiltrates data before encryption to blackmail targeted victims into paying if they choose not to send the ransom. Examples of this are REvil & Maze ransomware.
- Ryuk: Ryuk is a manually-distributed ransomware application mainly used in spear-phishing. Targets are carefully chosen using reconnaissance. Email messages are sent to chosen victims, and all files hosted on the infected system are then encrypted.
YouTube Video
Gas Pump/ATM Security Scams
In 2023 alone, more than 315,000 credit cards were compromised through skimming attacks, affecting at least 3,500 financial institutions across the U.S. These types of scams now cost consumers and banks over $1 billion annually.
From old-school card (magnetic stripe) skimmers to newer devices hidden inside EMV (smart chip) readers, gas station fraud tactics have become more advanced—and harder to spot. Gasoline pump or ATM scams involve criminals using devices called skimmers and shimmers to steal credit or debit card information, often with hidden cameras or fake keypads to capture PINs.
To protect yourself, look for signs of tampering on the card reader, use pumps closer to the building, or pay with cash inside to avoid these devices as scammers tend to target the least visible or most isolated (furthest) gas pumps.
How the Scams Work
- Skimmers: Small devices are attached to or installed inside the card reader to capture the magnetic stripe data of your card.
- Shimmers: Paper-thin devices are placed inside the chip reader to steal information from EMV chip cards.
- Hidden cameras/keypads: Scammers may install tiny cameras or overlay keypads to record your PIN when you enter it.
- Wireless data theft: Some devices use Bluetooth to transmit the stolen data wirelessly, allowing criminals to retrieve it from a distance. Scammers can retrieve data from up to 100 yards away.
How to Protect Yourself
- Inspect the card reader: Grab and wiggle the card reader; if it’s loose, looks different, or has a broken security seal, don’t use it.
- Look for tamper-evident stickers: Many pumps have stickers across the panel seams. If the sticker is cut/broken or has a “VOID” message, move to a different pump.
- Choose safer pumps: Use pumps that are well-lit and closest to the building. Isolated pumps are more likely to be targeted.
- Use “Tap-to-pay” instead of using the credit card slot.
Cover when inputting a PIN: Always use one hand to cover the PIN pad when inputting your code, just in case a hidden camera is recording your transaction. - Pay inside: The safest option may be to go inside to pay with cash.
- Monitor your accounts: Regularly check your bank and credit card statements for any unauthorized charges and report suspicious activity immediately.
What to Do if You’re a Victim
- Contact your card issuer or financial institution immediately. They can freeze your card, issue a replacement, and investigate the charges. Also, go to the banks app and change your card PIN.
- Notify the clerk in the Gas station. Ask them to check the card reader and possibly take that pump our of service until it can be verified as safe.
- Notify local law enforcement and provide details of the location and pump you used.
- Place a fraud alert with one of the three credit bureaus (Equifax, Experian, TransUnion).
YouTube Videos
How to tell if there is debit card skimmer on gas pumps, ATMs
Juice Jacking
“Juice jacking” is a security exploit in which an infected USB charging station is used to compromise devices that connect to it. The exploit takes advantage of the fact that a mobile device’s power supply passes over the same USB cable the connected device uses to sync data.
Juice jacking exploits are a security threat at airports, shopping malls, restaurants and other public places that provide free charging connections/stations for mobile devices. While the risk of becoming the victim of a juice jacking exploit is extremely low, the attack vector is real and is often compared to ATM card skimming exploits. Both juice jacking and card skimming rely on the end user feeling confident that the compromised hardware is safe to use.
How Juice Jacking Works
Juice jacking is a hardware-focused “man-in-the-middle” attack. The attacker uses a USB connection to load malware directly onto the charging station or to infect a connection cable and leave it plugged in, hoping an unsuspecting person comes along and uses the “forgotten” cable.
Juice jacking exploits are successful because the same port used to charge a device also transfers data. A USB connector has five pins. But only one is needed to charge a connected device, and only two of the five pins are needed to transfer data. This architecture is what enables an end user to move files between a mobile device and a computer while the mobile device is connected to the charging station.
USB ports and phone charging cables are the most common devices used in juice jacking attacks. Other less common devices may include USB ports in video arcade consoles and portable battery power banks.
Choice Jacking
A new, more sophisticated form of the juice-jacking attack has been discovered recently. The new variation of the theme is called “ChoiceJacking.” Researchers at the Graz University of Technology in Austria recently exploited current methods of detections to defeat the protections.
Those researchers went on to devise ChoiceJacking, the first known attack to defeat juice-jacking mitigations. In response to the findings, Apple updated the confirmation dialogs in last month’s release of iOS/iPadOS 18.4 to require user authentication in the form of a PIN or password. The researchers say the new mitigation works as expected on fully updated Apple and Android devices.
How to Prevent Juice Jacking
Juice jacking enables an intruder to copy sensitive data from a mobile device, such as passwords, files, contacts, texts and voicemails. Users may not know they have been a victim of an attack until they realize their device is infected.
Users can guard against juice jacking attacks by purchasing a protective attachment called a USB Data Blocker (available on Amazon). A USB Data Blocker is a device that connects to a charging cable and sits between the device’s charging cable and the public USB charging station.
A USB Data Blocker works by blocking connections to all the pins in the USB male connection except two—the pins that transfer power. The USB Data Blocker prevents the pins that transfer data from establishing a connection, while still allowing the device to charge.
Another way to prevent juice jacking is to avoid using chargers left plugged into outlets. Also, keep mobile devices and operating systems/apps updated, and never accept free promotional charging devices or devices from unverified sources. If your device is running low on charge, it may not be a good idea to just utilize that convenient charging port.
Carrying your own personal cable (with a USB Data Blocker) or portable battery pack would also be good options to prevent being a victim of this potential threat.
Types of Juice Jacking Attacks
- Data theft: In data theft juice jacking attacks, users are not aware their sensitive information has been stolen. Depending on how long a device is left plugged into a compromised cable or port, large amounts of data may be compromised. Given enough time and storage space, attackers may even be able to make a full backup of the data on a device.
- Malware installation: When malware installation juice jacking attacks occur, malware placed on the device may do a great deal of damage, including manipulation of a phone or computer, spying on a user, locking the user out of the device or stealing information.
- Multidevice attack: On top of harming the device plugged into a compromised charger, a device charged by infected cables may, in turn, infect other cables and ports with the same malware, becoming an unknowing carrier of the virus.
- Disabling attack: Some malware uploaded through a charging device can lock owners out of their devices, giving full access to the attackers.
Juice Jacking History
Juice jacking first emerged at the DEF CON hacking conference in August 2011. Conference attendees were offered free charging stations for their mobile devices. When they plugged them in, a message appeared warning them not to trust convenient but suspicious offers of free charging because the devices could be loaded with malicious code.
In response to juice jacking, Apple and Android updated their devices to warn users whenever they charge and to allow users to choose whether to trust the charging port, power bank or other charging process. If users choose the untrusted device option, their devices only charge and do not allow data transfer.
YouTube Video
Mobile Device Security
Smartphones and tablets are only becoming more sophisticated, especially with the emergence of wearables like Samsung and Apple watches. With this growth comes new challenges for security—and new opportunities for scammers and hackers.
When mobile phones were merely used for making phone calls while on the go, significant threats numbered in the single digits, namely the potential for voice phishing (vishing). Now, the dangers number in the thousands. Phishing emails, smishing texts, unsecured WiFi connections, and Bluetooth vulnerabilities are likely to come immediately to mind as far as threats associated with modern mobile devices. It’s important to recognize that nearly every “smart” feature poses a risk to your business.
Mobile Device Security Best Practices
- Go above and beyond a basic password: The four-digit passcode that is the default on many devices is simply not a high enough bar to set with regard to a locking mechanism for smartphones and tablets. At minimum, users should upgrade to a six-digit code, though alphanumeric passwords and biometric options (think Apple facial scanners or fingerprint scanners) offer even greater protection. When accessing a website or using an app with your mobile device. It would also be best practice to set up MFA (Multi-Factor Authentication) access as well. You can also use an Authenticator App (such as Google Authenticator or Microsoft Authenticator) for access as well. Another method to consider would be a “Passkey” instead of a password.
- Update your OS regularly: If you’re using outdated software, your risk of getting hacked skyrockets. Vendors such as Apple (IOS) and Google Android constantly provide security updates to stay ahead of security vulnerabilities. Don’t ignore those alerts to upgrade your device. To help with this, ensure you have automatic software updates turned on by default on your mobile devices. Regularly updating your operating system ensures you have the latest security configurations available!
- Use a Password Manager: Let’s be honest, passwords are not disappearing any time soon, and most of us find them cumbersome and hard to remember. We’re also asked to change them frequently, which makes the whole process even more painful. Enter the password manager, which you can think of as a “book of passwords” locked by a master key that only you know. Not only do they store passwords, but they also generate strong, unique passwords that save you from using your cat’s name or child’s birthday…over and over.
- Avoid Public WiFi: Although it’s very tempting to use that free Wi-Fi at the coffee shop, airport or hotel lobby – don’t do it. Any time you connect to another organization’s network, you’re increasing your risk of exposure to malware and hackers. There are so many online videos and easily accessible tools that even a novice hacker can intercept traffic flowing over Wi-Fi, accessing valuable information such as credit card number, bank account numbers, passwords, and other private data. The only caveat here is… if you absolutely must use a public Wi-Fi network, make sure you are also using a VPN to encrypt your internet activity and make it unreadable to cyber criminals. But remember, even this tactic may not offer the cybersecurity protection you need to be truly secure when using public internet access. Interesting but disturbing fact: although public Wi-Fi and Bluetooth are a considerable security gap and most of us (91%) know it, 89% of us ignore it.
YouTube Video
QR Code Fraud
QR codes, easily recognized as those square-shaped barcodes, are designed to store information in a way that digital devices can quickly read. These codes, made up of black and white squares, are common in various settings, notably for keeping tabs on products as they move through a supply chain.
Moreover, with most mobile devices having the capability to scan QR codes, these codes have become a staple in marketing efforts. Notably, in recent times, they’ve been instrumental in tracking and slowing the spread of the coronavirus by tracing contacts.
This innovative QR code technology was pioneered in 1994 by Denso Wave, a branch of Toyota. Their goal was simple yet ambitious: to track vehicles and parts more accurately during the manufacturing process. To do this, they created a barcode that could store more than just numbers and letters—it could also include Japanese kanji and kana characters.
What sets QR codes apart from the standard barcode is their ability to store more information. Traditional barcodes are like one-dimensional images, read from top to bottom, and can only hold a limited amount of data. QR codes, however, can be read both vertically and horizontally, giving them a two-dimensional structure. This means they can hold a lot more information, making them a more versatile choice for various applications.
QR codes are versatile, capable of holding various types of data, including website links, phone numbers, or text up to 4,000 characters.
Smartphones make QR code scanning easy. By simply pointing the phone’s camera at the QR code, consumers can access promotions, see restaurant menus, access digital tickets, and more. However, not all QR codes are legitimate.
The FBI has issued warnings about cybercriminals tampering with QR codes to steal users’ login and financial information. After scanning a QR code, victims can be directed to a website disguised as legitimate but that gathers identity information and inserts digital infections.
QR Code Fraud Is Rampant
- Parking meter payment: Fraudulent QR codes have often been placed on parking meters, leading victims to assume that they can pay for parking through the QR code if they do not have exact change. After paying through the QR code, some victims return to find their vehicle has been towed or has received a parking ticket. Plus, their payment information is typically harvested for later use.
- Bank phishing scams: Banks are increasingly using QR codes to promote their financial services. Bank branches will have a sign on their entry doors or on an easel placard with special promotions encouraging the use of additional services or new account signup. A cybercriminal can easily overlay the QR code with one that redirects to their malicious site.
- Bank phishing scams: Banks are increasingly using QR codes to promote their financial services. Bank branches will have a sign on their entry doors or on an easel placard with special promotions encouraging the use of additional services or new account signup. A cybercriminal can easily overlay the QR code with one that redirects the customer to their malicious site.
- Utility and government impostors: Cybercriminals often disguise themselves as representatives from a utility company, the Social Security Administration, or the IRS regarding an outstanding debt. The scammer claims that failure to pay will result in arrest, additional fines, or shutting off access to electricity, gas, or water. The cybercriminal will tell the consumer that the payment portal for these services is currently offline, but they can submit payment through another portal that they can access by following a link or scanning a QR code.
- Romance scams: In some instances, cybercriminals spend months building an online romantic relationship with their victim, which ultimately results in them offering financial advice or asking for financial assistance through a cryptocurrency exchange. The victim follows the provided QR code and transfers the requested money to the scammer’s digital wallet.
Does a QR Code Collect My Personal Information?
Software used to generate QR codes typically does not gather any personally identifiable information (PII). However, it does collect certain types of non-personal data, which can be accessed by the creators of the QR code. This includes:
- Location Data: Identifying the geographical location where the QR code was scanned.
- Scan Metrics: Recording the number of times the QR code was scanned and the specific times of each scan.
- Device Information: Determining the operating system of the device used for scanning, such as whether it’s an iPhone or an Android device.
This information, while not personally identifying, offers valuable insights into the usage patterns and reach of the QR code, assisting creators in understanding and optimizing the effectiveness of their QR codes.
Can Someone Hack a QR Code?
Yes, QR codes can be compromised. Hackers may manipulate QR codes to conduct malicious activities in two primary ways:
- Malicious URL Embedding: By encoding a harmful URL into a QR code, attackers can lead individuals to download malware or unwanted software. Once scanned, these QR codes can initiate the download and installation of malware, putting personal data at risk.
- Phishing Expeditions: Similar to malicious URL embedding, hackers can also direct users to phishing websites through a QR code. These websites, often masquerading as legitimate sites, aim to trick individuals into entering sensitive information, such as login credentials or financial data, thereby compromising their security.
Four ways to help avoid becoming a victim of QR code fraud:
- Never scan a QR code from an untrusted source, whether it be in an email or a physical place.
- When possible, feel the QR code to see if a sticker has been applied over the original and legitimate QR code.
- Only download/use a QR reader application with built-in security features. Understand that some QR reader apps are more secure than others. Important features to look for include showing the content of the link before it’s visited and checking the link against a database of known malicious links.
- If you find a malicious QR code, report it to the owner of the business where you discovered it.
YouTube Video
Importance of Secure/Strong Passwords (Password Manager)
Securing Your Passwords
- Never send a password by email, instant message or any other means of communication that is not reliably secure.
- Don’t write them on sticky notes or cards that you keep near the thing the password protects, even if you think they’re well-hidden.
- It’s ok to write your passwords down, as long as you keep them in a secure location.
- Use a unique password for each website. If crooks steal your account information from one site, they’ll try to use those credentials on hundreds of other well-known websites, such as banking, social media or online shopping, hoping you’ve reused the password elsewhere. That’s called a “Credential stuffing attack,” and it’s extremely common.
- If you don’t want to memorize multiple passwords, consider using a Password Manager app.
- Many web browsers (such as Google Chrome) also have a built-in ability to create random passwords, and even save them if desired. This is much less secure than a Password Manager, though.
Where Not to Store Passwords
Storing passwords in unencrypted files, such as documents, spreadsheets, or note-keeping apps, is almost as bad as writing them down on a sticky note. If the device that contains the file is not encrypted, cybercriminals can access your passwords without much effort.
A strong password is:
- At least 16 characters, but longer is stronger. (Using a password manager will allow you to create very long cryptic passwords that will be virtually unbreakable.)
- A combination of uppercase letters (A-Z), lowercase letters (a-z), numbers (0-9), and symbols (such as !, #, or %).
- Significantly different from your previous passwords. Many systems will not allow you to create a new password that’s too similar to the last one.
- Easy for you to remember, but difficult for others to guess.
Tips for creating a unique password. Use a phrase (Passphrase) and incorporate shortcut codes or acronyms such as:
- 2BorNot2B_ThatIsThe? (To be or not to be, that is the question – from Shakespeare)
- L8r_L8rNot2day (Later, later, not today – from the kid’s rhyme)
- 4Score&7yrsAgo (Four score and seven years ago – from the Gettysburg Address)
Password Managers
With a password manager, you can use one very strong password to protect the passwords of all your other accounts. Let your password manager create long, complex passwords for personal services like Facebook or Amazon. You don’t have to remember them all, just remember your one password.
Some of the more popular Password Manager apps are:
- 1Password
- BitWarden
- NordPass
- Keeper
- Dashlane
- LastPass
A good password manager will:
- Create strong, unique passwords for new accounts or when resetting passwords for existing accounts.
- Provide passwords when you visit the specified website (Auto-fill)
- Compare your passwords to lists of known compromised passwords
- Protect your passwords with strong encryption—so only you have access
- Sync passwords between your devices (PC, mobile devices). This may require a “plug-in” to be added to your web browser.
- Support 2-Factor Authentication for an extra layer of security. If the Password Manager app supports it, enable 2-Factor Authentication!
Videos
Cybercriminals Like to Go Phishing
Cybercriminals Like to Go Phishing, but You Don’t Have to Take the Bait
Phishing is when criminals use fake emails, social media posts or direct messages with the goal of luring you to click on a bad link or download a malicious attachment. If you click on a phishing link or file, you can hand over your personal information to the cybercriminals. A phishing scheme can also install malware onto your PC or mobile device.
There’s no need to fear your inbox, though. Fortunately, it’s easy to avoid a scam email, but only once you know what to look for. With some knowledge, you can outsmart the phishers every day.
See It so You Don’t Click It
The signs can be subtle, but once you recognize a phishing attempt you can avoid falling for it. Before clicking any links or downloading attachments, take a few seconds (like literally five seconds) and ensure the email looks legit. Here are some quick tips on how to clearly spot a phishing email:
- Does it contain an offer that’s too good to be true?
- Does it include language that’s urgent, alarming, or threatening?
- Is it poorly crafted writing riddled with misspellings and bad grammar?
- Is the greeting ambiguous or very generic?
- Does it include requests to send personal information?
- Does the email have a link that takes you to a website asking for your login/password?
- Does it stress an urgency to click on an unfamiliar hyperlinks or attachment?
- Is it a strange or abrupt business request?
- Does the sender’s e-mail address match the company it’s coming from? Look for little misspellings like pavpal.com or anazon.com.
Uh Oh! I See a Phishing Email. What Do I Do?
Don’t worry, you’ve already done the hard part, which is recognizing that an email is fake and part of a criminal’s phishing expedition.
If you’re at the office and the email came to your work email address, report it to your IT Help Desk as quickly as possible.
If the email came to your personal email address, don’t do what it says. Do not click on any links – even the unsubscribe link – or reply back to the email. Just use that delete button. Remember, DON’T CLICK ON LINKS, JUST DELETE.
You can take your protection a step further and block the sending address from your email program.
Report Phishing
Some email platforms let you report phishing attempts. If you suspect an email is phishing for your information, it’s best to report it quickly. If the phishing message came to your work email, let the Owens IT department know about the situation ASAP. Please forward the suspicious email to: helpdesk@owens.edu and/or spam@owens.edu
Email Spoofing
Email spoofing is a technique used in spam and phishing attacks to trick users into thinking a message came from a person or entity they know or trust. In spoofing attacks, the sender forges the email header so that client software displays the fraudulent sender address, which most users take at face value.
Users don’t realize the sender is forged unless they inspect the header more closely. If it’s a name they recognize, they’re more likely to trust it. So, they’ll click malicious links, open malware attachments, send sensitive data and even wire corporate funds.
Security protocols were introduced in 2014 to help fight email spoofing and phishing. Since then, many spoofed email messages are now sent to users’ spam/junk mail folders or are rejected and never sent to the recipients’ inboxes.
How to Identify Spoofing Emails
While spoofing scams continue to become increasingly elaborate, particular signs and cues can help you identify a spoofing email:
- Look for discrepancies between email addresses, display names, etc.: An email address that doesn’t match the sender’s display name is a telling sign of a spoofed email, especially if the domain of the email address looks suspicious.
- Assess the email content: Spoofed emails often contain alarming or aggressive messaging to provoke a sense of urgency and impulsiveness. If the tone of the subject line and email content is tailored to scare you or alarm you, then it likely is a spoofed email.
- Avoid clicking links or downloading attachments: If you receive an email that appears suspicious or is from an unknown sender, do not click links or download attachments.
- Be watchful for emails requesting personal information: Spoofed emails are often used in conjunction with phishing scams, where fraudsters impersonate brands or identities to get your personal information.
- Look for inconsistencies in the email signature: If the information in the email signature, such as the telephone number, does not align with what is known about the sender, it may be a spoofed email.
- Check the email header: The email header contains information like the date, subject line, recipient’s and sender’s names, and email address. Check to see if the email address appears from a legitimate source and that the name and other details match up.
It’s no wonder that email spoofing has become a commonly exploited avenue for cyber-attackers. Consider the following statistics:
- 3.4 billion spoofing emails are sent per day. That amounts to 1.2% of all emails sent daily.
- More than 90% of cyberattacks start with an email message.
- 91% of bait emails are sent via Gmail, with just 9% coming from other sending domains.
- Phishing’s cost in 2024 is part of the broader cybercrime landscape, with reports stating that scams cost consumers over $1 trillion globally in the past year.
- The number of phishing emails has surged due to AI-driven automation, leading to a 1,265% increase in some areas
- The FTC received 2.6 million fraud reports from consumers in 2023, an increase of about 8% from the 2.4 million reported in 2022.
- One in four people reported losing money, with a median loss of $500 per person.