by Sasha Aronson | Jan 28, 2020 | Cybersecurity, Safety Tips, Technology, Trends
Today is Data Privacy Day! Led by the National Cyber Security Alliance (NCSA) in North America, Data Privacy Day is an annual international effort to promote awareness among businesses and individuals about the importance of privacy and protecting personal information.
Privacy is the ability to control access to our personal information. Historically, the United States has not had strong online consumer protection laws, but this is beginning to change. However, individuals must remain vigilant about protecting their privacy.
Best Practices:
- Update your privacy and security settings. The NCSA has created a helpful tool consisting of direct links to privacy settings on popular devices and online services.
- Talk with your family and friends about ways to stay safer online.
- Personal information is like money. Value it. Protect it.
- Share with care. Think before posting about yourself and others online, such as on Facebook, Instagram, or other social media sites. Consider what a post reveals, who might see it, and how it could be perceived now and in the future. For example, if you post vacation pictures while you’re away, you are essentially advertising to others that you are not home.
Find out more about Data Privacy Day- www.staysafeonline.org/data-privacy-day
by Sasha Aronson | Jan 14, 2020 | Cybersecurity, Risk control, Safety Tips, Technology, Trends
It’s a new year and a new decade, a time for predictions and resolutions. But we don’t need a crystal ball to predict that keeping pace with the increasing number of ever-evolving cyber threats will be challenging for businesses, governments and individuals this year and beyond, and that demand for cyber security skills will continue to be on the rise.
Hackers continue to prey on existing security weaknesses and with their progressively advanced attack methods, people’s health, safety and lives are at risk. Cyber incidents are widely reported in the news and serve as a reminder that constant vigilance is necessary to mitigate risks. Below are some of the potentially impactful issues as a new decade commences.
- Cyber corruption will persist as organized crime syndicates ban together and nation-state threat actors use more progressive tactics along with simple and advanced technology to propagate their agendas. In 2019 there were over 5,000 data breaches leaving over 7.9 billion records exposed. Security issues worsen with every breach leaving people more vulnerable.
- Social engineering will continue to be employed by hackers in all forms of phishing attacks, which will become more sophisticated. The simple technique of targeting human weaknesses to circumvent technical obstacles is low risk/high reward for malefactors. All it takes is one employee to click once for a cyber criminal to gain entry.
- Increased reliance on mobile devices combined with projected worldwide growth to over 16 billion devices by 2023 will increasingly make them lucrative targets for hackers.
- Poorly protected IoT (Internet of Things) devices are a valuable source for hackers attempting to obtain personal information and gain access to other devices residing on the same network. It is estimated that the number of IoT devices worldwide will grow to over 75 billion by 2025. Cameras, garage door openers, light controls, baby monitors, and lawn watering systems are some examples of IoT devices.
- Ransomware impacted over 900 government agencies, educational establishments, and healthcare providers in the United States in 2019 at a potential cost of over $7.5 billion. State and local governments are prime targets because they are often ill-equipped when it comes to cyber protection.
- Third-party vulnerabilities present an enormous amount of risk to corporate organizations and are often the weakest link in the supply chain making them opportune entry points for an attacker.
- Artificial Intelligence (AI) will become more powerful and infiltrate all aspects of life. Transportation, healthcare, manufacturing, and education are some of the areas where AI is benefiting society and increasing our ability to solve problems. Unfortunately, it is inevitable that AI will be exploited for nefarious purposes.
- The quality of deepfakes will improve and eventually rival that of special effects studios.
- Though some states have enacted privacy and security laws, federal legislation is still lacking. The California Consumer Privacy Act (CCPA) took effect on January 1, 2020 and is considered by many to be one of the toughest data privacy laws in the United States.
- Cyber security will be imperative to preventing interference with the 2020 United States elections. Ransomware targeting voter databases, foreign meddling, and deepfakes are among the cyber threats with the potential to disrupt the election process.
by Sasha Aronson | Dec 11, 2019 | Cybersecurity, Risk control, Technology
Gift card fraud is a big business, especially around the holiday season. According to the National Retail Federation, gift cards remain the most popular items on holiday wish lists for the 13th year in a row.
The serial number of a physical card can easily be recorded by someone using a handheld card reader, and the PIN scratch-off sticker can simply be replaced with an inexpensive decal available for purchase online. Thieves monitor gift card accounts via merchants’ online portals or customer service telephone numbers to determine when they are bought and activated. At this point they can easily encode the activated stolen data onto the magnetic strip of any card to make purchases, which they then often sell to make even more money. Cyber criminals also use automated bots, software robots or programs, to scan balances associated with gift cards and loyalty points in their quest to steal balances.
Security Best Practices
- Buy gift cards online directly from vendors instead of a third-party or, if purchasing a physical gift card, buy cards from behind the counter if possible.
- Examine gift cards for evidence of tampering: Is the PIN visible? Does it look like the scratch-off sticker may have been peeled off and replaced?Be attentive when paying to ensure the cashier does not activate a card then give you an inactive card. Verify the serial number on the card matches the receipt.
- Include the activation receipt with the gift card.
- Treat gift cards like cash.
- Don’t scratch the PINs until you’re ready to use or register them.
- Register cards with the merchant or add to an existing account.
- Use gift cards soon after you receive them.
- Check your unused gift card balances with the merchant periodically. If the balance is gone, report it immediately.
- Securely store your gift cards in your password-protected mobile wallet app if the merchant is affiliated with it. The merchant may require you download their app to redeem the card prior to adding it to your wallet.
- Beware of activation, transaction, and inactivity fees as well as expiration dates. Federal law requires that a gift card cannot expire for at least five years from the purchase date. Some states have longer terms.
- Though you won’t receive the entire amount of the gift card, unwanted cards can be sold to third-parties. Check with the Better Business Bureau to determine if the business is trustworthy.
And remember – anyone who demands payment with a gift card is a scammer!