CyberheistNews Vol #5 #52 Dec 8, 2015 |
Scam Of The Week: Apple ID Suspension Phish With A Twist |
OK, this scam is widespread enough to alert your users about it. The email claims to be from Apple Support and says your Apple ID and iCloud are both going to be suspended because you did not complete verification on time. With the massive amount of new Apple devices being sold at the moment, this attack may hit many employees.
Supposedly Apple sent you an earlier email about this but they did not receive a response. The email has a "Verify now" link that allows you to complete the verification process and save your account from suspension. (Yeah, sure.) If an employee clicks the link, they land on a bogus Apple login page asking for their credentials. But wait, there's more!
You will be taken to a second fake page that asks for a large amount of your personal and financial information including credit card and banking details. The page is designed to look like a real Apple webpage and even includes seemingly legitimate information explaining in detail why you need to complete the verification process.
This scam even has retaliation against investigators testing the phish. If you enter false data that includes words such as ‘scam’ into fields on the fake form, your browser will automatically redirect you to a preconfigured Google search for pornography.
I suggest you send the following to all employees, and while you are at it, friends and family will also benefit.
"You need to watch out for a phishing scam that seems to come from Apple. The email is supposedly from Apple Support and they threaten that your account is going to be suspended because you did not reply to an earlier verification email. The phishing email has a link that allows you to "verify now" but if you click the link, you land on a bogus webpage that looks like it's Apple but is a fake, and it tries to manipulate you into giving out your password, credit card and other personal information.
Don't fall for this scam. Always go direct to the website of your vendor and do not click on links in emails that look like they are legit. Think Before You Click!" Happy and Safe Holidays."
|
The Top 5 Reasons To Invest In Cyber Security |
Here's a quick condensed overview, which you can use as bullet points in your 2016 budget discussion.
Today, successful data breaches happen on a daily basis. The frequency of the attacks is increasing fast and those who attack are getting more sophisticated. Cyber-attacks have undergone substantial changes and are increasingly difficult to counteract as the attackers’ technology advances.
Everyone’s a target – government and large corporate websites are no longer the only focus. Medium size corporations, small businesses and individuals are all potential victims. That you will be attacked is a given – but what makes the difference is your security posture, how good your defense-in-depth is, and your incident response after the hack.
Here are the Top 5 reasons to invest in cyber security
1) Frequency of attacks
Industry leaders like Symantec, McAfee, FireEye, and Verizon all report increases in attack frequency over the last 8 quarters. You simply get probed for vulnerabilities more often, by more sophisticated means and attack vectors. One example is the recent use of exploit kits combined with malvertising on major news outlets. One click on a poisoned ad is enough, or even simply browsing to an infected page can kick off a drive-by-download.
2) Cost of attacks
The direct cost of an attack, the downtime it causes, the damage to the PR of your organization, loss of business opportunity, the legal fees, and possibly the loss of your CEO who gets fired by the board (Target).
3) Cybercrime focuses on Small to Medium Enterprises (SMEs) as attack targets
Hacked SME's may feel like they’ve had bad luck, or that the bad guys have handpicked them. The reality is that attackers use both automated software that probes websites for vulnerabilities and flaws that are easily breached, and thoroughly tested, massive phishing campaigns to spread botnets, Trojans and ransomware.
It is rare that the bad guys are targeting your company specifically, but it’s your responsibility if your organization is vulnerable enough to be a soft target.
4) The number of bad actors is expanding rapidly
Dozens of nation states are investing billions in their cyberwar attack capabilities. Don't think that's only focused on power and water infrastructure. They go after whole sectors of the economy, and that means degrading individual organizations running stock markets, financials, insurance, manufacturing and more.
Next, cybercrime-as-a-service is taking off – it is easier than ever for beginning cyber criminals to get started with sophisticated tools that are provided by a fast growing cyber-underground economy. Existing mafias are moving into this area with rapid speed and the criminal competition is furious.
5) Bad guys are going after the low-hanging fruit: your employees
Cyber criminals are business people too. Their time is money. Why spend 3 weeks to uncover a vulnerability in a popular piece of software when you can social engineer an employee in 10 seconds? Stepping employees through effective Security Awareness Training is one of the easiest steps to take with fast, measurable, and excellent ROI. Blog post here: https://blog.knowbe4.com/the-top-5-reasons-to-invest-in-cyber-security
|
KnowBe4 Offer Ends December 31: Order Silver, Get Platinum! |
"You get a great deal. We make it into the Inc. 500..." KnowBe4 is working really hard to make it into the Inc. 500. And you can benefit from that in a big way. As a year-end special, you can order the Silver Level, but get Platinum, a huge value with a lot of additional features.
Platinum has some pretty cool features to help you manage the social engineering problem a lot better. Having all the training modules as an all year, all-you-can-eat option is great, it includes the essential "Basics Of Credit Card Security" and the brand new Outlook Add-in Phish Alert button.
Send us your PO or signed quote before the end of business December 31 and you'll get all the Platinum goodies for the price of mere Silver. Here is a chart with the feature comparison. Find out how affordable this is for your organization and be pleasantly surprised: https://info.knowbe4.com/order-silver-get-platinum?
|
Warm Regards, Stu Sjouwerman |
|
|
|