
Gone Phishing? Cybercriminals Are Getting Savvier
ACCORDING TO LIZ - Phishing is that nasty form of digital fraud that uses e-mail to steal personal information such as usernames and passwords. For texts, it’s known as “smishing” but most of the same comments apply.
Technology experts warn that such credential theft is often just the first stage of a longer attack that can end in fraud and up the ladder, ransomware and hijacking of corporate networks.
In today’s world, all our data is valuable to those who would use it for their own profit. Which puts you as the actual owner in danger.
Phishing schemes are all the more effective the more points of data scammers can score about someone, so it is important for people, especially those at risk, to implement a personal “data minimization policy” to keep all their accounts safe.
Even when it’s being collected and used by reputable companies, they can often turn around and give it to their partners and affiliates to enhance their bottom lines, directly or indirectly.
Without reading the fine print – which is designed to be long and confusing to protect the corporate interests and place all the risk on the consumer, it’s difficult to distinguish what is truly a legitimate use and what could potentially open you to being scammed.
And since a significant number of companies rely on profits from reselling your data more than on fees for services – think Facebook and other “free” online providers – they are incentivized to resist your complaints.
Even innocuous third-party providers can open people to a world of pain, mandating you agree to let them freely access your data and store it on foreign data servers where American protections don’t apply.Places like Israel or the United States where the government can access information for “national security.”
When your information originates from a company with which you do business and consider trustworthy, after their partners – or an underpaid employee with too much debt – resell it to purposely similar-sounding entities, it’s often hard to identify nefarious opportunists.
Often phishing attempts appear to come from state and federal e-mails referencing legitimate programs, but responses are redirected to safe-sounding but malicious operators.
After-the-fact, no records of such outgoing e-mails are found to exist on those government servers.
With the power of A.I. and complex algorithms that match up many disparate bits and bytes of data, full-scale credential phishing, smishing, and identity theft is rampantly escalating.
And too often clicking on a “secure portal” icon can cause a script to run in the background to read and abstract personal information and hijack people’s address books for more victims to whom to send further phishing e-mails.
Often financial phishing first reveals itself as an innocuous infiltration, a small addition – sometimes just pennies, and at times then removed as if it were the mistake of the bank – which can lead to other hack-attacks down the road.
The intent, both in personal intrusions and ones aimed at corporate employees is to trick people with seemingly legitimate requests from a known source to send money or share sensitive information.
For bigger paydays, cybercriminals are increasingly targeting schools and other public sector infrastructure, especially in rural areas, because of their large budgets, limited cybersecurity resources and the critical nature of these community services.
And the scale of the personal information their databases contain to further spread the pain.
With deep-pocketed companies, the incursion can be a ransomware attempt, encrypting files or locking the institution out of its own accounts until large sums are extorted to unshackle their business systems.
Cybercriminals keep replenishing their toolboxes with a plethora of malicious software, including the use of the ubiquitous QR codes as well as SMS messaging and voice messages asking for callbacks that instantly initiate a hack. And, with the advent of A.I., more sophisticated weapons are being developed daily.
Multifactor authentication is currently holding the worst incursions at bay but as phishing scams continue to evolve, relying on the quickening pace of today’s world and the need to make decisions before moving on, newer and more effective countermeasures will need to be devised.
What’s more, identity theft betrays that most basic of human needs – trust. Which is sad since such a betrayal then impinges on all other factors in their lives.
Agreed, ya gotta relax if you’re going to enjoy your life. But that also means protecting yourself so you can relax.
Slowing down is the first and probably most effective way to protect yourself. Then turn to trusted sources for to-do lists tailored for your specific situation. Here’s a start; a few suggestions to review, hopefully before you are the phisherman's next victim.
Before you click:
- Didn’t expect a file? Don’t open it.
- Check the “From” line — is the URL from who it’s purported to be? i.e. whether it says its from a government agency you deal with, your bank, or “Road Kit Courtesy of AAA,” the url, and especially the extension, should reflect it’s sent from the appropriate website and not “@plugandplay.co.id” or a string of uninterpretable letters.
- Check the “To” line – was it really sent to you or is your e-mail just one in a multitudinous Copy-To list?
- Where money or private information is needed, call the sender with the phone number you have for them, NOT by replying to the e-mail or calling any different number it so helpfully gives.
- Never enter your password to “view” a document.
- When unsure, don’t click.
Protect your accounts:
- Turn on two-factor authentication.
- Avoid using biometric data like a face scan or voice recognition for multifactor authentication; today, A.I. easily creates deep fakes of images or sounds.
- Use passwords unique to you – and don’t store them in a document named “Passwords” on your computer or phone.
- Keep your devices and programs updated.
- Remove unused accounts – both online and in your financial universe.
- Regularly check all your accounts, even small amounts can mean someone checking to see how closely you monitor them as a prequel to clearing one out.
If you did click:
- Change your e-mail password immediately.
- To the degree appropriate, alert your financial institutions, your provider, and your family and friends if they might get hacked.
- If you haven’t already, set up some form of two-factor authentication on all accounts needing protection.
- Be alert for strange messages “from” you.
Report it:
- Use companies’ “Report phishing” buttons immediately.
- File at the Federal Trade Commission’s ReportFraud.ftc.gov or the FBI’s ic3.gov.
(Liz Amsden is a former Angeleno now living in Vermont and a regular CityWatch contributor. She writes on issues she’s passionate about, including social justice, government accountability, and community empowerment. Liz brings a sharp, activist voice to her commentary and continues to engage with Los Angeles civic affairs from afar. She can be reached at [email protected].)










