Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Saturday, March 8, 2014

Beware of Latest Phishing Scam



Tech Talk: Beware of sneaky phishing scams

POSTED: March 7, 2014 11:27 p.m.

There is a new phishing scheme currently circulating on the Internet. Its objective is not just to steal your money but your identity as well.

When you get a fraudulent alert from a bank, a department store or other company you do business with via email, pop-up or text message, it is considered phishing. They fish for your personal information, usually financial, in the hopes you will be intimidated into giving up that sensitive information. This time around though, they just take it without asking.

The latest cyberscam being circulated was discovered last week by a technician at Malwarebytes. It genuinely appears to be from the online movie provider Netflix, but in fact is not. Don’t be so quick to comply should you have a Netflix account and are the recipient of one of those menacing messages.

You are informed that you have violated their terms of service agreement and that your account has been temporarily suspended. They offer to take a look at your computer system with your permission. You are then supposedly switched from customer service to a Netflix tech support operator and sometimes they may even say you are being redirected to a Microsoft technician. But don’t be fooled; you are only talking to a thief.

The dubious error message that is generated on your alert (ERR 19902881811) is the same for everybody that gets it, with the phone number just as bogus.

It turns out the number you dial (800-947-6570), is not a hotline. In fact, it is a call center in India and has nothing to do with either Netflix or Microsoft. These misleading reprobates are not interested in helping you, just themselves — to your money.

Their techs will say in order to release your account, they will have to first repair your system. This, of course, comes with the purchase of a downloaded utility and attempt to sell you other products from a better firewall, to a BOGO multiyear extension to your Netflix account. Don’t believe it.
Even if they say that it is legitimate and they remind you that they didn’t call you, that you could trust them because you called them, don’t fall for it. It is a sham.

While the agents are supposedly scouring your system for errors, they’re actually in quest of your financial data, specifically your banking account info and your passwords. They will run a few fake utilities, put on a dog-and-pony show and mislead you to believe they actually fixed your system.

They may even ask you to verify your identity by holding up your driver’s license and a credit card to the webcam they turned on, just in case you don’t buy anything. Then they’ll have your full name, date of birth, address, license number and credit card info along with a photo of you.

If you do decide to make a purchase, it could be a charge for $400 for their so-called services. Caveat emptor!

Even if you manage to get your bank to cancel the charge, they got away with stealing your identity. While you have your bank on the phone, they’ll be setting up a new credit card account with your info at their bank.

You can be sure that if you get one of these alerts, you have been targeted by these nefarious schemers. To prove it to yourself, always Google a phone number you are given. You’ll find this one has nothing to do with Netflix.

You could also hover — don’t click — on the link for “secure chat” or the link to their email address. By doing this you should see (in a pop-up balloon) that the results are the true address and that it has nothing to do with Netflix.

If they end in the suffix “.in,” they are from India (.it from Italy, .us from the U.S., etc). I’ve even seen some with Yahoo addresses. Anyone that you have an account with will have a domain with their company’s name at the end. It can still be fraudulent even if it says service.Netflix.in.com. Don’t be fooled. Anybody can put anything in a domain name. Watch the suffix to see if it is genuine.

Should you get an alert from a bank you happen to do business with, it’s best to call the number on the back of your credit card as opposed to the one in the alert, just to be safe. Never give out sensitive information to someone that phones you, no matter how legitimate it may appear.

Often, if you request a call-back number from someone who solicits you, they will just hang up on you, proving it was a scam.

Don’t be duped by these parasitical cyber crooks. If you’re subject to this Netflix scam, refuse to give them any information; better yet, don’t click on any links and don’t call them. Remember, it is not Netflix. All you will get in return is a huge charge to your credit card, the potential cleaning of your checking account and the theft of your identity.

Arthur Glazer is a freelance writer and computer technician in Gainesville. His column appears biweekly on the Business page and on gainesvilletimes.com.

Saturday, January 26, 2013

Password Security





Computer Care: The password is ... Best bet is to mix it up




POSTED: October 19, 2012 11:59 p.m.
Passwords are part of computing; there is no way around that. If you use a computer and the Internet, you will eventually need to use them. You may or may not need a password to log onto your computer, but one was needed to get your email this morning. Even if you didn’t have to manually type one in, your computer recalled it for you.

I use a password manager and also allow Google Chrome to remember my passwords for me. There are 15 or so of them that I refer to on a regular basis to access various websites like email, my cloud storage, Amazon and other ecommerce sites that I frequent.

There are also banking PIN numbers, alarm keypad codes and wireless router keys which are forms of passwords. You may use one to gain entry to your smart phone.

Call them what you will, but any series of alpha-numeric codes you use to access something secretly is a password.

There is no easy way for most of us to remember all of those codes, especially when choosing different ones for each site or application.

If you use the same password for all of your websites and accounts, all could be compromised if just one is. So why take a chance?

The poor choices are the obvious ones like your birthday or anniversary dates, your street, pet or your children’s names. Don’t choose the easy options. Stir it up a bit.

Spell out anything that you can remember. Chocolate chip ice cream with chocolate syrup becomes ccicwcs; then add a number or symbol or caps. The end result could be CCiCwCs9*.

Stir things up even more; spell things backward. A. Jones becomes senoja, then add numbers, caps or symbols to spice it up, like senojA5#. Be creative.

Instead of your dog’s name, try using mydogbubba. Add caps or symbols for even more security as in mydogbubbA*7 or shorten it to dogbubbA*7. Backward, bubba becomes abbub.

While on the topic of passwords and email, spam is something we all unfortunately get with email. One of the easiest ways to get spam is by having your email address sold to online merchants. The best way to avoid that is to be careful to whom and where you use your email address.

Many times when you subscribe to a newsletter or sign up for something, it’s stated your address won’t be sold. Often times though, it is. That’s where most spam originates.

One way to avoid this is to create secondary additional Gmail, Yahoo, Hotmail or other accounts that you won’t regularly check or only to verify a subscription that you just signed up for. When the inbox is full on this throw-away account, just sign up for another.

An alternative is to use a Disposable Email Account. I use yopmail, but there are many others to choose from.

They include Dispostable, Dudmail, MailExpire, DeadAddress, Spamex, Incognito Mail, Dodgeit, Yopmail and Mailinator. All work basically the same way. You create a name, they offer an extension and a duration with most adding the ability to check the account for incoming mail.

Sometimes you can get away with simply making up an address with a nonexistent domain and have it work. I’ve used xyz5@abcmail.com, but if a response is required, then that strategy won’t work.

Recently, I signed up for a free sample online that required me to click on a link in an email to verify my address. Using yopmail, I created an address on the fly and checked it from their site (the same page I used to create it) a few minutes later. There was the link.

You don’t need to commit anything to memory; just create a new name next time you need a DEA.
Remember to change your passwords regularly. Use password managers like LastPass, Roboform or Password Safe to help you recall them. Although less secure, you could simply allow your browser to remember them for you.

Visit pwnedlist.com to see if your email address has ever been hacked.

Choose passwords that are unique for every account, not the same one for all of them and give them to no one.

The longer the better. Use at least eight to 10 characters and mix them up with caps, numbers and symbols.

There’s a password generator at random.org if you have trouble on your own.

Don’t fall for phishing scams. Beware of any emails or websites asking you to provide sensitive personal information. Not even your bank will ask you for your password.

Avoid using addresses, birthdays or dog’s names.

To circumvent spam effectively, use disposable email accounts.

The end result will yield higher security for your accounts with less paranoia about being hacked.
As easy as it has become these days to have your privacy compromised, you want to make it as difficult as you possibly can.

Arthur Glazer is a freelance writer and computer technician in Gainesville. His column appears biweekly on the Business page and on gainesvilletimes.com.

Saturday, July 4, 2009

Phishing for data

Computer Care: Don’t take the hook with data phishing games

By Arthur Glazer
arthur@glazerthepctech.com
POSTED July 3, 2009 11:41 p.m.

Phishing is a relatively new term that has roots in its homophone water sport, in that it means one is looking for something that’s not readily available. But as opposed to looking for fish, it is searching online for data: yours.

Those phishing for your information are not phooling around. Unlike its fun counterpart, phishing is not a leisure sport. It’s a full-time business. It employs professional thieves stalking you on the Internet.

The most common phishing trap you could fall for is the e-mail scam. You might get something in your inbox that appears to be from your bank, utility, retailer or credit card company. The ploy is to get you to refresh or confirm your personal information because your account is supposedly being updated or is about to be closed. It preys on your fears and hopes that in your moment of anxiety, you’ll cooperate.

Upon close scrutiny, you can usually tell that these are fraudulent e-mails, but most people are trusting by nature and are tricked into believing they are legitimate. Usually you will not be addressed by your name, but as Client, Patron or Card Holder. The threat may be somewhat vague, yet specific enough to get your attention.

Other e-mails may include a link for you to click on. This will take you to the phisher’s Web site, which may look like those that you do business with, but is not. It will include a blank form with an official-looking header of that company. Any information you type in is then given to the thief, whether it be your account number, password, Social Security number or pin code.

Again, scrutiny will be the tell-all. Look carefully at the web address. It may have your bank’s name in it, but instead of being "www.your-bank.com," it may read something like "www.ag.accounts.your-bank.com."

A good way to tell if a link is legitimate is to hover your mouse over the link. The true destination will appear either in a pop-up or in the browser’s status bar at the bottom of the page.

Alternatively, you may receive an official sounding phone call asking for the same information.

They will be friendly, yet assertive, requesting your personal information. If you didn’t call them, hang up. I guarantee if you ask them for a call-back number, they will hang up on you.

Your bank will tell you that they would never contact you this way. Be aware; be careful; be suspicious. There is a lot at stake: your money or even your identity. If in doubt, call or go to your bank or institution in question.

As always, your best offense is a good defense. Have the proper tools in place and the knowledge of what to do to protect yourself.

Get and use good anti-virus, anti-spam and anti-phishing utilities for your computer and be sure your firewall is in place.

Many companies now have either free downloadable utilities or offer free scans from their Web site. Check out what McAfee has to offer at http://home.mcafee.com/Downloads/FreeScanDownload.aspx?affid=0; McAfee also has a free Site Advisor available that will let you know if the site you are on is legitimate or not.

See what Symantec has at http://security.symantec.com/sscv6/WelcomePage.asp or look at AVG’s LinkScanner at http://linkscanner.avg.com.

Comodo has recently released a new, free utility, Comodo Internet Security, to assist in keeping your system free of malware. It includes a firewall with anti-virus and even comes with a 30 day free trial of LivePCSupport. Download it from their website at http://personalfirewall.comodo.com/download_firewall.html.

Any of these companies also offer full version utilities with more bells and whistles, for a price.

Visit www.staysafeonline.org for some good information including a list of more web sites that will give your system a security scan for free. Here’s a list to help you get started:

Know who you’re dealing with online.

Never click on links in unknown e-mails.

Keep your Web browser and operating system up to date.

Back up important files.

Protect your children online.

Use security software.

Use strong passwords and change them regularly.

Use strong authentication technology.

Don’t use public computers to do your online banking or bill paying.

Learn what to do if something goes wrong.

Other good online resources are www.onguardonline.gov and www.fraud.org.

If you believe you’ve been scammed, file your complaint at www.ftc.gov, and then visit the FTC’s Identity Theft website at www.consumer.gov/idtheft.

Computers are great tools and the Internet is an incredible resource. To think about what the two of them together can accomplish is astounding. But if you’re not careful, you may get caught in someone’s phishing expedition.

Keep your eyes open and be aware of your surroundings as if you were in a bad part of town. These guys don’t phish or cut bait as those in a boat do. They are relentless. Just because the Internet is a virtual place, doesn’t mean you can’t really get ripped off. You can.

It’s virtually the same.

Arthur Glazer is a freelance writer and computer technician in Gainesville. His column appears biweekly. Arthur welcomes your computer questions and ideas for future columns.