Scam Of The Week: RNC Attendees Get Hacked Through Fake Wi-Fi Networks

Stu Sjouwerman | Jul 24, 2016
Scam_of_The_Week.jpgThe PR people at Avast decided to have some fun and created a series of fake Wi-Fi networks at various locations around the Republican National Congress in Cleveland.

Avast’s team set up several networks, using names such as "Trump free Wifi" or "Google Starbucks," which were designed to look as though they were set up for convention attendees. Upon connecting, trusting a random and unprotected network they found in a public setting, the users unwittingly gave Avast access to spy on their devices.

Over the course of a day, Avast found over a thousand attendees that were completely negligent in their device’s security. Over 60 percent of the users who connected had their identity completely exposed, and slightly less than half of them checked their email or used messenger apps.

So, here is what I suggest you send to employees, friends and family. Feel free to cut/paste/edit:
A security company decided it would teach people a lesson and set up several fake Wi-Fi access points around the Republican National Convention site in Cleveland last week.

Over the course of a day, more than 1,000 attendees used these open, unprotected Wi-Fi hotspots to check their mail, used smartphone apps, and even played Pokemon while everything they did was looked at by the security researchers. Imagine if they had been bad guys.

You should always watch what Wi-Fi hotspots you connect to, and use a VPN to help keep your sensitive information out of the hands of hackers.
Would be interesting if they did the same thing at the Democrats' convention and compare the results. Read more about Avast's findings in their press release, they have a bunch of stats on who did what. It's not pretty:
https://press.avast.com/en-gb/amidst-charged-cyber-security-dialogue-republican-national-convention-attendees-show-negligent-behavior

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.