Translate

Posts mit dem Label Cyber Safety Tips werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Cyber Safety Tips werden angezeigt. Alle Posts anzeigen

12/27/2013

After TARGET Data Breach: There is a Need to target on Web Security

As multinational banks as other financial institutes struggle to protect clients after a massive data breach at retail giant Target, small service companies also should be concerned about their Online Security. Its just not tough enough to be protected in a secure way, as Online Fraud is increasing every year in a more and more faster way.


Between November 27th and December 15th, cybercriminals hurried off with data from 40 million credit and debit card accounts of people who shopped regulary at Target’s 1.924 stores in the United States and in Canada.

So far, at least three class-action lawsuits have been filed.

The U.S. Small Business Administration says cyber threats are an issue for everyone, and small businesses are becoming more common targets for such threats and crimes because they often have fewer preventive or responsive resources, as being or getting protected in a competent way also increases the costs. But Security start with yourself.

USSBA Seal
The USSBA though offers in its latest online training course some of the Basics in: “What is cybersecurity?”. (See Link at the end of this post beneath)

With the help of technology and best practices, cybersecurity is the effort to pro-tect computers, programs, networks and data from fraudulent Attacks. Or to ask in other words:

Why is cybersecurity important ?

 

Consider all the information you have that needs to be secure, like personal information for employees, Businesspartner information, sensitive information for consumers, and also sensitive and secret business information.

It’s essential to do your part to keep these details safe and out of the hands of those who could use your data to compromise you and everything surrounding your business.

CNN reported, that nearly half of the data breaches that Verizon has recorded in 2012, took place in companies Staff with less than one thousand. Symantec reports show that 31 % of all Cyberattacks in 2012 happened to businesses that had less than 250 employees. In 2011 Attacks were rising up to 81 percent.

The Methods

 

The Range of ways getting compromised is Vast. This Range might vary between Web site tampering, data breach, DoS up to Malware and Trojans.

Website tampering is a form of Web-based attack in which certain parameters in the Uniform Resource Locator (URL) or Web page form field data entered by a user are changed without the Webmasters authorization. This finally directs the browser to a link, page or site other than the one the user intended (although it may look exactly the same to the usual client).

Parameter tampering can be employed by Cybercriminals and identity thieves to stealthily obtain personal or business information about the user. Countermeasures specific to the prevention of parameter tampering involve the validation of all parameters to ensure that they conform to standards concerning minimum and maximum allowable length, allowable numeric range, allowable character sequences and patterns, whether or not the parameter is actually required to conduct the transaction in question, and whether or not null is allowed.

A denial-of-service attack DoS happens on a CPU or Web site and locks the computer and/or crashes the system, resulting in stopped or slowed work flow.

Malware code and/or viruses are sent over the Internet and aim to find and send your files, find and delete critical data, or block your computer or system. They can hide in programs or documents and make copies of themselves  without your knowledge.

What Prevention measures YOU should take

The main first step secureing the critical information of your business, is to create a far-reaching firm security policy. Second Step: keep them up-to-date. Third Step: convincing your employees to keep the proprieties according to the policies.

  • Be ensured that your computer hardware and software are updated regularly. 
  • Change passwords periodically and use firewalls to protect your systems. 
  • You should back up your data on a regular basis so that if something is compromised, you have a secure copy.

If interested, the following Link brings you to the Small Business Learning Center at www.sba.gov and will take 30 Minutes:

Click to Start Your Course now !

11/29/2013

Tips to Avoid Being Scammed the Next Holiday Season

In advance of the holiday season, its always good to beware of cyber criminals and their aggressive and creative ways to steal money and personal information. Scammers use many techniques to fool potential victims, including fraudulent auction sales, reshipping merchandise purchased with a stolen credit card, sale of fraudulent or stolen gift cards through auction sites at discounted prices, and phishing e-mails advertising brand name merchandise for bargain prices or e-mails promoting the sale of merchandise that ends up being a counterfeit product.



  • Fraudulent Classified Ads or Auction Sales

Internet criminals post classified ads or auctions for products they do not have. If you receive an auction product from a merchant or retail store rather than directly from the auction seller, the item may have been purchased with someone else’s stolen credit card number. Contact the merchant to verify the account used to pay for the item actually belongs to you.

Shoppers should be cautious and not provide credit card numbers, bank account numbers, or other financial information directly to the seller. Fraudulent sellers will use this information to purchase items for their scheme from the provided financial account. Always use a legitimate payment service to protect purchases.



Diligently check each seller’s rating and feedback along with their number of sales and the dates on which feedback was posted. Be wary of a seller with 100 percent positive feedback if they have a low total number of feedback postings and all feedback was posted around the same date and time.


  • Gift Card Scam


The safest way to purchase gift cards is directly from the merchant or authorized retail merchant. If the merchant discovers the card you received from another source or auction was initially obtained fraudulently, the merchant will deactivate the gift card number and it will not be honored to make purchases.



  • Phishing and Social Networking

Be leery of e-mails or text messages you receive indicating a problem or question regarding your financial accounts. In this scam, you are directed to follow a link or call the number provided in the message to update your account or correct the problem. The link actually directs the individual to a fraudulent website or message that appears legitimate; however, any personal information you provide, such as account number and personal identification number (PIN), will be stolen.

Another scam involves victims receiving an e-mail message directing the recipient to a spoofed website. A spoofed website is a fake site or copy of a real website that is designed to mislead the recipient into providing personal information. (See Picture)



Consumers are encouraged to beware of bargain e-mails advertising one day only promotions for recognized brands or websites. Fraudsters often use the hot items of the season to lure bargain hunters into providing credit card information. The old adage: 

"If it seems too good to be true, it probably is," 

is a good barometer to use to legitimize e-mails !

Black Friday has traditionally been the "biggest shopping day of the year." The Monday following Thanksgiving has more recently (2005) been labeled Cyber Monday, meaning the e-commerce industry endorses this special day to offer sales and promotions without interfering with the traditional way to shop. Scammers try to prey on Black Friday or Cyber Monday bargain hunters by advertising "one day only" promotions from recognized brands. Consumers should be on the watch for too good to be true e-mails from unrecognized websites.



Along with online shopping comes the growth of consumers using social networking sites and mobile phones to satisfy their shopping needs more easily. Again, consumers are encouraged to beware of e-mails, text messages, or postings that may lead to fraudulent sites offering bargains on brand name products.

Some tips you can use to avoid becoming a victim of Cyber Fraud this year:

  • Do not respond to unsolicited (spam) e-mail.
  • Do not click on links contained within an unsolicited e-mail.
  • Be cautious of e-mails claiming to contain pictures in attached files, as the files may contain viruses. Only open attachments from known senders. Always run a virus scan on attachment before opening.
  • Avoid filling out forms contained in e-mail messages that ask for personal information.
  • Always compare the link in the e-mail to the web address link you are directed to and determine if they match.
  • Log on directly to the official website for the business identified in the e-mail, instead of "linking" to it from an unsolicited e-mail. If the e-mail appears to be from your bank, credit card issuer, or other company you deal with frequently, your statements or official correspondence from the business will provide the proper contact information.
  • Contact the actual business that supposedly sent the e-mail to verify that the e-mail is genuine.
  • If you are requested to act quickly or there is an emergency, it may be a scam. Fraudsters create a sense of urgency to get you to act impulsively.
  • If you receive a request for personal information from a business or financial institution, always look up the main contact information for the requesting company on an independent source (phone book, trusted Internet directory, legitimate billing statement, etc.) and use that contact information to verify the legitimacy of the request.
  • Remember: If it looks too good to be true, it probably is.