What Hackers Don’t Want You to Know
Now it is more important than ever to stay alert for possible hacking attempts. This week, Microsoft announced emerging global threats from hackers impersonating trusted business partners. Among their tricks and hacks – smishing, vishing, spoofing and spear phishing scams.
While this may sound like a funny tongue twister, there is nothing humorous about these different forms of cyber attack. Each is designed to reel you into revealing sensitive information that can be used to take over bank accounts, hold data for ransom, infiltrate company networks, and more.
For this reason, the ABG Global Compliance & Ethics team has shared the following to help you better understand the threats so you can stay alert.
Smishing:
Fraudsters send misleading text messages to your mobile device to trick you into downloading fake company apps, verifying passwords or confirming personal data.
Your Defence:
- Question unusual text messages and never reply, respond or forward them
- Avoid clicking on links, attachments or downloads from unsolicited text messages
- Keep your smartphone current with scheduled updates (they often update privacy protection)
- Never send your bank account, credit card or password details via text message
- Avoid storing confidential data on your mobile device or using chat/text for sensitive topics
- Immediately delete/block suspicious messages, then report them to Phishing@carnivalukgroup.com
Vishing:
Thieves call your phone and/or leave deceptive voicemails to mislead you into believing they are trusted company representatives verifying passwords or bank information.
Your Defence:
- Ask callers for contact details and verify their identities online before sharing data
- Hang up the phone if the call seems suspicious
- Beware – caller ID numbers can be faked
- Immediately delete suspicious voicemails, block the phone numbers and report them to Phishing@Carnivalukgroup.com
Spoofing:
Cybercriminals impersonate a trusted contact or brand to manipulate you, often asking you to urgently click on links, download attachments or disclose confidential information.
Your Defence:
- Always verify a person’s identity before providing any information
- Avoid clicking on links or buttons in unsolicited emails
- Do not open or download attachments without verifying the request
- Search the sender or company online and contact them directly
- Report all suspicious emails to Phishing@Carnivalukgroup.com
Spear Phishing:
Attackers create well-researched, targeted attacks – weaponising personal information about you, and often imitating friends, co-workers or respected brands to lower your defences.
Your Defence:
- Search the sender or company online and contact them proactively vs. responding
- Beware of unsolicited emails or social media messages asking for personal data
- Set social media pages to “private” (attackers scrape social media profiles to tailor more convincing messages)
- Report all suspicious emails to Phishing@Carnivalukgroup.com
You play an important role in protecting confidential information. Understanding that threats can come in all forms – from email scams to fake text messages to sketchy voicemails – will empower you to stay cybersecure. Remember, if you see something, say something. It is a Culture Essential.
For more information, check out this story from our cybersecurity partner Terranova.