Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Tuesday, June 14, 2016

Cyber Security - Spear Phishing





Have you ever received a strange email or phone call where the other person knew several key pieces of information about you but you could not place where you knew them from? Criminals will use information from social media sites, blogs, websites, and/or previous hacks to gain this information which makes them seem legitimate. The FBI published this short announcment that talks about what to look for:

The FBI has seen an increase in criminals who use spear-phishing attacks to target multiple industry sectors. These attacks allow criminals to access private computer networks. They exploit that access to create fake identities, steal intellectual property, and compromise financial credentials to steal money from victims’ accounts.

In spear-phishing attacks, cyber criminals target victims because of their involvement in an industry or organization they wish to compromise. Often, the e-mails contain accurate information about victims obtained via a previous intrusion, or from data posted on social networking sites, blogs, or other websites. This information adds a veneer of legitimacy to the message, increasing the chances the victims will open the e-mail and respond as directed.

Recent attacks have convinced victims that software or credentials they use to access specific websites needs to be updated. The e-mail contains a link for completing the update. If victims click the link, they are taken to a fraudulent website through which malicious software (malware) harvests details such as the victim’s usernames and passwords, bank account details, credit card numbers, and other personal information. The criminals can also gain access to private networks and cause disruptions, or steal intellectual property and trade secrets.

To avoid becoming a victim, keep in mind that online businesses, including banks and merchants, typically will not ask for personal information, such as usernames and passwords, via e-mail. When in doubt either call the company directly or open your computer’s Internet browser and type the known website’s address. Don’t use the telephone number contained in the e-mail, which is likely to be fraudulent as well.

In general, avoid following links sent in e-mails, especially when the sender is someone you do not know, or appears to be from a business advising that your account information needs updated.

Keep your computer’s anti-virus software and firewalls updated. Many of the latest browsers have a built-in phishing filter that should be enabled for additional protection.

Tuesday, May 10, 2016

Phishing Scam






Scammers will try to obtain your information by sending emails that look official in hopes you click on a link they provide.

Examples of Phishing Messages

You open an email or text, and see a message like this:
"We suspect an unauthorized transaction on your account. To ensure that your account is not compromised, please click the link below and confirm your identity."
"During our regular verification of accounts, we couldn't verify your information. Please click here to update and verify your information."
“Our records indicate that your account was overcharged. You must call us within 7 days to receive your refund.”
The senders are phishing for your information so they can use it to commit fraud.

How to Deal with Phishing Scams

Delete email and text messages that ask you to confirm or provide personal information (credit card and bank account numbers, Social Security numbers, passwords, etc.). Legitimate companies don't ask for this information via email or text.
The messages may appear to be from organizations you do business with – banks, for example. They might threaten to close your account or take other action if you don’t respond.
Don’t reply, and don’t click on links or call phone numbers provided in the message, either. These messages direct you to spoof sites – sites that look real but whose purpose is to steal your information so a scammer can run up bills or commit crimes in your name.
Area codes can mislead, too. Some scammers ask you to call a phone number to update your account or access a "refund." But a local area code doesn’t guarantee that the caller is local.
If you’re concerned about your account or need to reach an organization you do business with, call the number on your financial statements or on the back of your credit card.
 
Thank you to onguardonline.gov for the information!

Monday, November 16, 2015

Phishing Alert




If you receive an email like the one pictured above please do not click on the link and type in any personal information! These institutions already have your information and do not need you to verify it via an email.
You can tell this is a phishing scam by:
1) The "To:" field is blank
2) Bad spelling and grammar 
3) The email asks for personal information
To file a complaint about an e-scam, visit the FIB's Internet Crime Complaint Center and file a report:http://www.ic3.gov/complaint/default.aspx

Featured Post

Golf Cart Laws

To help keep everyone safe, the Mount Pleasant Police Department would like to remind everyone of the South Carolina laws governing golf...