Showing posts with label Phishing. Show all posts
Showing posts with label Phishing. Show all posts

Wednesday, November 11, 2020

November 27 is Black Friday and November 30 is Cyber ​​Monday

One of the strongest sales campaigns in shops and online sales recently established in Spain is Black Friday and Cyber ​​Monday. A tradition imported from the US where all physical stores and online businesses make numerous discounts on all their products for the Christmas season.

Black Friday Cyber Monday

It is a good time to catch a bargain ... If you are thinking of doing it in an online store, you should take into account a series of tips to avoid possible upsets and make your purchases 100% safely:

1. Activate a Card for Online Payments and Deactivate It When You Have Finished Your Purchases 💳

For the maximum security of your bank accounts, many entities enable free virtual cards to be able to make purchases online safely. We will activate and deactivate these cards only when we are going to make a purchase online.

2. Buy on Websites With Trusted Seals 📝

Cybercriminals can spoof websites to mislead consumers into believing that they are buying from a legitimate site. The website may appear almost identical to the real site; however, subtle changes may indicate that it is not. Take a good look at the URLs.

If you are visiting an e-commerce website for the first time, look to see if it has a trust seal such as Confianza Online or Trusted Shops. These seals guarantee that member companies are periodically subjected to complete quality, safety, and service evaluation.

3. Only Use Secure Sites With Certificates 🔒

The way to know if a web page has HTTPS is by looking at the browser. When accessing any website, you can see an indicator in the upper left part of the browser that indicates whether or not the page uses the HTTPS protocol. Depending on the browser, it will be seen in a different way but in all of them, it will be very clear if the web is secure or not. Certified web pages display a  lock next to the domain. When you click on the padlock, a message appears indicating that the connection is made safely.

4. Be Wary of Suspicious Bargains 🏷

On “Black Friday” and “Cyber ​​Monday” many cybercriminals take advantage of it by replicating and introducing many fake offers.

It can be difficult to tell the difference between a real offer and a fake, so it is best to make sure that a website is real. Shop at reputable and trustworthy stores that you know or have recommended to you. Avoid eCommerce that are unknown or that offer dubious discounts that are hard to believe.

5. Find Out About the  Ecommerce Where You Are Going to Buy 🔍

Check that the seller's contact information appears on the website and that the conditions of use are clearly explained: shipping costs, return policy, customer service ... If you have questions, try to contact them before making a buy or consult their social networks to read opinions of other users.

6. Be Careful With the Wifi Networks We Connect to 📶

Many public spaces such as cafeterias or train stations have free access to  WIFI networks. What we must ask ourselves is: Are they safe? Many cybercriminals simulate free Wi-Fi networks in order to access our devices. When in doubt, use your mobile's own internet.

9. Use Strong Passwords 🔐

It's always best to use a unique username and password for your various accounts, so in the unfortunate event of being the victim of an attack, cybercriminals won't have access to all of your accounts.

10. Beware of Fraudulent Emails or Phishing  📧

Phishing is a technique frequently used by hackers, with which forged emails are sent, with an aesthetic appearance very similar to the original, whose mission is to manipulate the user who receives it to steal confidential information.

You Can Identify a Phishing Email in Our Post.

Checking typographical errors, installing antivirus software on our computer, not sharing bank details by email or messaging, are other aspects to take into account when making your purchases online. Enjoy this Black Friday and Cyber ​​Monday in a 100% safe way! 🛍🛒

Monday, November 9, 2020

Cybersecurity: Types of Attacks and What They Consist of

Cyberattacks hit businesses every day. John Chambers, CEO of the multinational Cisco said: "There are two types of companies: those that have been hacked and those that have been hacked but do not know it. To combat a world where computer security has become one of the pillars of organizations, in this article we explain the different types of cybersecurity attacks and what they consist of. Keep reading!

Types of Cybersecurity Attacks


Types of Cybersecurity Attacks: What is a Cyber Attack?

For starters, what is a cyber attack? A cyber attack is a set of offensive actions against information systems. These can be databases, computer networks, etc. The objective is to damage, alter, or destroy organizations or people. In addition, they can take down the services they provide, steal data, or use it to spy.

We live in a digital age. Today most people use a computer with the Internet. Therefore, due to the dependence on digital tools, illegal computer activity grows without stopping and seeks new and more effective forms of crime.

We can classify the types of cybersecurity attacks into three categories:

  • Phishing attacks
  • Malware attacks
  • Web attacks

PHISHING

Phishing is a type of social engineering that is used, generally, to steal user data. They can be credit card numbers or passwords, for example. It occurs when a criminal poses as a trusted person. Then it tricks the victim into opening a text, email, or SMS message using a malicious link. This link can cause a ransomware system to freeze, reveal confidential information, or install malware.

It is simple and very easy to use the technique, which is why it is one of the most dangerous. It can have disastrous results. For an individual, it can lead to identity theft, funds theft, or unauthorized purchases.

SPEAR PHISHING

On the other hand, spear phishing is computer attacks that target a specific person or employee of a specific company. To carry out these types of attacks, criminals meticulously collect information about the victim to gain their trust. Falling for these attacks is usually very common, since a well-prepared email, either with a malicious link or attachment, is very difficult to distinguish from a legitimate one.

This technique is widely used to attack companies, banks, or influencers.

WHALING

In third place on the list of types of cybersecurity attacks, we find whaling attacks. These attacks target a senior manager profile, such as CEOs or CFOs. The objective, like the previous ones, is to steal vital information, since those who occupy high positions in a company usually have unlimited access to confidential information. In most of these so-called "whaling" scams, the offender manipulates the victim to allow high-value wire transfers.

The phrase "whaling" refers to the size of the attack, as the whales are attacked depending on their position within the organization. These types of attacks are easier to detect compared to standard phishing. A company's IT security officers can reduce the effectiveness of this hack.

Malware or Malicious Software

Second, among the types of cybersecurity attacks are malware. Malware is code created to stealthily corrupt a computer system. It is a broad term that describes any malicious program or code that is harmful to systems. Intrusive malware invades, damages, or disables computers, computer systems, mobiles, etc. assuming control of operations.

The goal of malware is usually to get money from the user illegally. Although it generally cannot damage the hardware of the systems, it can steal, encrypt, erase data, or hijack the basic functions of a computer, as well as spy on its activity without anyone noticing.

Malware includes many types of malicious software, such as spyware, ransomware, Trojans, etc.

RANSOMWARE OR DATA HIJACKING

Ransomware is malicious software that, by penetrating our computer, gives the hacker the ability to block a device from a remote location. Also to encrypt the files, removing the user control of all the information and data stored.

In terms of its method of spread, ransomware is usually transmitted as a Trojan. That is, infecting the operating system. For example, downloading a file or exploiting a software vulnerability. The cybercriminal, who has encrypted the operating system files rendering the device unusable, usually asks for a ransom in exchange for removing the restriction on the documents.

AUTOMATIC DOWNLOADS

Automatic downloads to spread malware are one of the most common methods among types of cybersecurity attacks. Cybercriminals search for insecure web pages and plant a malicious script in the HTTP or PHP code on one of them. This script can install malware directly on the device of the user visiting the site. It can also take the form of an iframe that redirects the victim to a site controlled by the attackers. These attacks are called "automatic downloads" because they require no action on the part of the victim. You just have to visit that website.

TROJAN

A Trojan is a malicious software program that tries to disguise itself as a useful tool. They apparently spread software and persuade a victim to install it. Trojans are considered among the most dangerous types of cybersecurity attacks, often designed to steal financial information.

Users are tricked by some form of social engineering into loading and running Trojans on their systems. U activated nice, they allow cybercriminals to spy or steal your confidential information. Unlike viruses and worms, Trojans cannot replicate themselves.

For malware to be a Trojan, it only has to access and control the host machine without warning, under an innocuous appearance.

Attacks on a website

SQL INJECTION

Among the most popular types of cybersecurity attacks is SQL Injection. It is a method of infiltration of an intruder code that takes advantage of a computer vulnerability present in an application. That is, they take advantage of common design errors on web pages. The threat of SQL injections is a serious security problem related to databases. They are used to manipulate, steal, or destroy data.

Cybercriminals are capable of injecting malicious SQL queries into a website's input field, tricking the application into using the commands they want, and accessing the database they want.

An SQL injection attack can slow down the operation of a website, theft, loss or corruption of data, denial of access by any company, or even take full control of the server.

XSS OR CROSS SITE SCRIPTING

XSS attacks use third-party web resources to run scripts in the victim's web browser or programmable application.

They are a kind of injection in which the attacker sends malicious scripts to the content of web pages to discredit them. This occurs when a dubious source can attach its own code in web applications. This is sent in the form of Javascript code snippets executed by the victim's browser.

Exploits can include malicious executable scripts in many languages, including Flash, HTML, Java, and Ajax. XSS attacks can be very devastating. However, alleviating the vulnerabilities that these attacks allow is relatively simple.

What did you think of this article about the types of cybersecurity attacks? Leave us your comments and share! Also, do not forget to install total security software to protect your data from cybersecurity attacks.

Monday, November 2, 2020

6 Tips to Protect Against Phishing Attacks | Total Security

With the growing popularity of social media websites like Facebook and Twitter, it should come as no surprise that cybercriminals are trying to take advantage of flaws in security applications and inadequate protection protocols more often. Twitter, in particular, seems to be a favorite target of malware authors and hackers, judging by some of the latest news in the internet circle.

Protect Against Phishing Attacks

History of Attacks on Twitter

In May, a French hacker calling himself "Hacker Croll" easily managed to access the email account of the administrative assistant, and there, take the information that allowed him to access the application program to the Google employee account. Apparently, people who work at Twitter used the corporate version of this application to share documents and other information within the company. From this, the Hacker Croll was able to steal over 300 private company documents and leak them to the public.

In August, a pro-Georgian blogger nicknamed "Cyxymu" was the target of a denial of service (DDoS) attack, which affected not only his Twitter account - causing a multi-hour outage of the entire site, as well as many other problems. - but also to Facebook and LiveJournal, sites where he also had accounts. Whether Cyxymu's accusations that Russia is responsible for the attack are true or not remains to be seen, but the ease with which this assault was orchestrated has made much wiser.

In September, a Twitter worm was able to spread via direct messages. Hackers who developed the software to generate Twitter accounts can circumvent CAPTCHA technology. The fake Twitter accounts posted messages related to popular topics to trick computer users into clicking the link in the fake message. When the message produced by the machine is clicked, the user is directed to a site that distributes rogue antivirus applications.

Attacks and infiltration of cybercriminals into social network accounts leading to the theft of personal and financial information are not the only problem that many users face. Malware authors have also been very busy.

The biggest danger to social sites today is the Koobface worm. This deadly little parasite attacks users of websites like Facebook, MySpace, hi5, Bebo, Friendster, and Twitter. The Koobface spreads through particularly harmless-looking messages delivered to friends, accompanied by a link. Accessing this link will cause the Koobface worm to be downloaded onto the user's computer. If the infection is successful, the Koobface tries to collect important information from the victims, such as credit card numbers.

These attacks have shown many people that on the web, we are no longer as safe as we were in the past. In July, Los Angeles officials raised concerns about a multi-million dollar proposal to pass emails and other government documents to a Google-sponsored service, the Google Apps service, attacked by hackers Croll the previous month, and this is just the beginning.

Right now, it's difficult to be totally impervious to penetration attacks, but there are ways we can help protect our computers, Internet accounts, and personal and financial information.

6 Crucial Tips to Keep Your PC Safe From Malware Attacks

Here are 6 essential tips to avoid and/or minimize the risk of malware, worms, or infections through websites like Twitter:

1: Keep Your User Profile Short and Do Not Visit User Profiles During Twitter Attacks

Keep your user profile short and never give out your personal information. This includes, but is not limited to, full name, email address, physical address, and telephone numbers. Do not disclose this information to anyone via Twitter, if you can avoid it. If someone accesses your account, this information will be easily discovered. Note that others can and will read your profile and your tweets and that they have the option of forwarding your messages, which means strangers can see your tweets. Remember, once something is posted online, it never goes away, regardless of whether or not the posting is deleted.

During the period of a Twitter attack, it is best to avoid visiting suspicious user profiles that may be infected with a worm or other type of online threat. The Web is a good source for the latest news on Twitter attacks and the accounts involved. A red flag for suspicious activity is displayed when a Twitter user repeats the same message over and over about a product or web page. Please do not click on the links provided by those messages and do not forward them.

2: Practice a Strong Password

Never (and I mean never) give your Twitter password to anyone, this includes friends and family. Make sure the password you are using is not easy to guess. Try using a combination of numbers, letters, and symbols to create a strong password. It is always a good practice to change it periodically or after an alleged attack against Twitter or other social networks. If you are a member of more than one social network, it is suggested that you use a different password for each account. Because if a hacker obtained the password for one of your accounts, he could use it to access your other social accounts.

3: Be Careful What You Download or Link to From Twitter or Other Social Sites

On Twitter, in fact, on many social websites, there are literally hundreds of new apps to use on your profile. Do your research, as many of them may ask for your username and password. Make sure what you send and who you send it to. It is best to ask others about specific applications or test them before using them. Clicking on a short URL such as Bit.ly or Tinyurl are risky practices. The services of a short URL puts you at risk of being redirected to a malicious site that can infect your system with malware. Some shorter URL services such as TinyURL and Bit.ly allow you to preview the link before clicking on it. This is a great feature to take advantage of and avoid visiting an unwanted website. As with spam in email messages,

4: if You See Something, Say It

If you suspect something is wrong, if you are being harassed, or suspect that another user's system is infected by a parasite, it is best to report it to Twitter. Because Twitter has been hit with a number of attacks lately, we all need to be involved in reporting malicious activity. If you receive a message from a user who is clearly trying to spread malware, it is best to send a direct message to Twitter's “spam account” page.

5: Follow General Safety Practices for Social Sites

It is important to always follow the general safety rules when visiting social websites like Twitter or Facebook. The main safety rules to follow are:

Trust no one. Be suspicious of all users, even if they claim to be your friends.

Always be on the lookout for fake social media sites and profiles.

Don't sacrifice your security for popularity by adding unknown users.

It is recommended only to follow people you know in real life. Don't reply to users you don't know. Keep your Twitter information private and only allow people you know to see it. Once you put a Twitter message on someone else's Twitter page, it can be seen by all Twitter users who follow your friend. Never assume that your Twitter message is private. The vast majority of users of social sites are teenagers and do not realize the consequences of posting private information. Users should always inform the appropriate authorities about threats or negative tweets or messages they receive.

6: Keep Your Antivirus, Antispyware, and Other Security Tools Up to Date

Probably the most important and basic line of defense is to make sure your computer has the latest antivirus software. Make sure to update your antivirus program and the operating system often. There are many attractive links browsing Twitter, but there is no way to know which one contains malware waiting to infect your system.

Remember that Twitter is still new, and even with its growing popularity, it can be difficult for developers to include sufficient processes and security settings. There is nothing wrong with trying Twitter and following your friends or favorite bands online, you just have to be smart about using it.

How to Save Your Twitter Account and PC After a Worm or Malware Infection

To prevent the spread of malware through Twitter messages, you need to avoid forwarding them. If you detect any suspicious activity in a profile, for example, tweets that contain the word "Mikeyy", you must take steps to eliminate the threat. To eliminate a common threat, such as "Mikeyy" you must follow the following process:

  • Clear your browser's cache and disable JavaScript with the options.
  • Then go to Twitter to delete all messages on your profile that have the word "Mikeyy" or any other obviously corrupt.
  • Upon completion, you can enable JavaScript again and change your bio, URL, and color scheme for your profile. You can also take this time to change your password for added protection.
  • Download and install a security application like Total Security that scans your system for malicious files that may have infected your system through the message sent from the corrupt Twitter profile.
  • Additionally, you can use a Firefox add-on such as "NoScript" that blocks XSS (cross-site scripting) defects, a common method of worm infections to infiltrate computers via Twitter. No computer user is safe from messages that take advantage of social networks like Facebook and Twitter.

Do you have horror stories to share (experiences on Twitter), or on other social sites like Facebook and MySpace? Do you have tips not mentioned here that you can give people to help them stay safe? Please leave a message and give us an answer.

Friday, October 30, 2020

An Overview of the Most Dangerous Ransomware Viruses in 2020 | Cloud Antivirus

For decades, cybercriminals have successfully exploited flaws and vulnerabilities on the World Wide Web. However, in recent years, there has been a clear increase in the number of attacks, as well as an increase in their rate - attackers are becoming more dangerous and malware is spreading at a rate never seen before.

Most Dangerous Ransomware

Introduction

We are talking about the ransomware that made an incredible leap in 2020, causing damage to thousands of organizations around the world. For example, in Australia, ransomware attacks such as WannaCry and NotPetya have even raised government concerns. To summarize the ransomware “successes” this year, we will look at the 10 most dangerous and most damaging organizations. Hopefully next year we will learn lessons and prevent this kind of problem from entering our networks.

1. NotPetya

The ransomware attack began with the Ukrainian accounting software MEDoc, which replaced 1C, which was banned in Ukraine. In just a few days, NotPetya infected hundreds of thousands of computers in over 100 countries. This malware is a variant of the older Petya ransomware, except that the NotPetya attacks used the same exploit as the WannaCry attacks. As it spread, NotPetya affected several organizations in Australia, such as the Cadbury chocolate factory in Tasmania, which had to temporarily shut down their entire IT system. The ransomware also managed to infiltrate the world's largest container ship, owned by Maersk, which reportedly lost up to $ 300 million in revenue.

2. WannaCry

This ransomware, terrible in scale, has practically taken over the entire world. Its attacks used the infamous EternalBlue exploit, which exploits a vulnerability in the Microsoft Server Message Block (SMB) protocol. WannaCry infected victims in 150 countries and over 200,000 machines on the first day alone. We have published a personal file of this sensational malware.

3. Locky

Locky was the most popular ransomware in 2016, but it has not stopped operating in 2020. New variants of Locky, dubbed Diablo and Lukitus, emerged this year, using the same attack vector (phishing) to target exploits. Locky was behind the Australian Post email fraud scandal.

4. CrySis

This instance excelled in its masterful use of the Remote Desktop Protocol (RDP). RDP is one of the most popular ways to distribute ransomware, as cybercriminals can thus compromise machines that control entire organizations.

5. Nemucod

Nemucod is spread using a phishing email that looks like an invoice for shipping services. This ransomware downloads malicious files stored on compromised websites. In terms of phishing emails, Nemucod is second only to Locky.

6. Jaff

Jaff is similar to Locky and uses similar techniques. This ransomware is not remarkable for its original methods of distributing or encrypting files; on the contrary, it combines the most successful practices.

7. Spora

To distribute this type of ransomware, cybercriminals hack legitimate sites by adding JavaScript code to them. Users visiting such a site will receive a pop-up warning prompting them to update their Chrome browser to continue browsing the site. After downloading the so-called Chrome Font Pack, users became infected with Spora.

8. Cerber

One of the many attack vectors that Cerber uses is called RaaS (Ransomware-as-a-Service). According to this scheme, cybercriminals offer to pay for the distribution of the Trojan, promising a percentage of the money received for this. This “service” allows cybercriminals to send out ransomware and then provide other attackers with tools to distribute.

9. Cryptomix

It is one of the few ransomware that does not have a specific type of payment portal available within the dark web. Affected users must wait for cybercriminals to email them instructions. Cryptomix victims were users from 29 countries, they were forced to pay up to $ 3,000.

10. Jigsaw

Another malware from the list that started its activity in 2016. Jigsaw inserts an image of a clown from the Saw movie series into spam emails. As soon as the user clicks on the image, the ransomware not only encrypts but also deletes the files in case the user delays in paying the ransom, the size of which is $ 150.

Conclusions

As we can see, modern threats are using increasingly sophisticated exploits against well-protected networks. While increased employee awareness is helping to cope with the impact of infections, businesses need to go beyond basic cybersecurity standards to protect themselves. Defending against today's threats requires proactive approaches that leverage real-time analysis capabilities based on a learning engine that includes understanding the behavior and context of threats. You have to more depend on cloud antivirus rather than traditional antivirus so that your security protection will be totally cared for by the cloud server organization.

Tuesday, October 27, 2020

What is Phishing? And How to Avoid Scams Like That?

Phishing messages (or phishing scam ) are among the biggest dangers on the internet. These fraud attempts arrive via email, social networks, WhatsApp, and the like, and can result in serious consequences for victims, especially financial loss.

Phishing Scams

It is to help you protect yourself against this danger so often that this text was written: in it, you will understand what phishing is, you will know how this type of message tries to deceive you and you will see tips on how to prevent yourself.

What is Phishing?

The term phishing refers to the English word fishing, which means "Pescara", in free translation. The association with this activity is not a mere chance: phishing scam is an attempted fraud on the Internet that uses "baits", that is, devices to attract a person's attention and make him perform some action.

If the individual "takes the bait", he may end up informing strangers of bank details or other confidential information, only realizing late on that he was the victim of online fraud. In the same way, you can infect your computer or smartphone with a virus or other malware.

Phishing often arrives via email, but it can also exploit other means, such as SMS, social networks, and instant messaging services, such as WhatsApp, Telegram, and Facebook Messenger.

Typically, messages of this type are created to appear to be issued by well-known institutions, such as banks, telephone operators, government agencies (such as the IRS or some DMV), and credit card administrators, although they can also impersonate individuals.

This is one of the main features of phishing scams. Another is the arguments used to convince the user to click on a questionable link or file that accompanies the message.

Main Dangers of Phishing

Arroba - illustrative image a person receives a phishing scam message and does not realize that they are facing fraudulent content, they can take an action that will result in financial loss or other inconvenience.

An e-mail of the type that passes for bank notice, for example, can guide the user to click on a link to update a record. In doing so, the person will fall on a fake website, but very similar to that of the banking institution. If you do not notice that that page is not legitimate, it will provide sensitive data, such as the current account number and account access password.

This type of fraud is so common that, today, many banks use complementary protection measures, such as requiring an extra code sent by SMS or application or allowing the user to access the account only from registered cell phones or computers.

In a more sophisticated scheme, the message may contain an attachment or link that points to malware. If the user executes it, the plague will install on his computer or mobile device and will be able to perform a series of actions, such as recording typed data, capturing user files, or monitoring his activities on the web.

Another possible consequence of phishing is to confirm that the user's email or mobile number is active. After that, the person will start receiving other messages of the type of SPAM (unsolicited e-mails) and can still be classified as a "potential target": when executing the action of the first message, he told the scammers not to know how to identify misleading content.

Variations can affect the user in other ways. A person can, for example, accept an invitation to a supposed game on a social network. In doing so, the malicious application can automatically issue invitations to other users. These, upon realizing that the invitation came from an acquaintance, will be able to accept it, continuing the scheme.

It doesn't end there. Other examples of problems: the user's computer, if infected by malware, can emit SPAMs; accounts on online services can be hacked thanks to the capture of passwords and usernames; the person may make purchases on a fraudulent website and, for this reason, not receive the product; and so on.

What if the Phishing Has My Full Name or Social Security Number?

It may happen that phishing has your full name, social security number, or other personal information. The objective here is obvious: with this data, it is easier to convince you of something.

Fortunately, this type of message is unusual. What happens is that, in some way, the fraudster had access to a database with people records. This is possible, for example, when an online store is hacked or when an employee of a company improperly resells information.

Therefore, even when the message contains personal data, do not disregard the possibility of an attempted coup there.

Tips to Protect Yourself From Phishing

It is practically impossible to prevent scams from reaching you, but a few simple precautions help you get rid of the danger:

  • The first is to observe the characteristics of the message (visual, spelling errors, suspicious links, persuasive arguments, among others), as explained above;
  • Remember that debt notices, court summons, or registration requests, for example, are not usually made by email or social media, but by correspondence sent to your home or workplace. Do not be carried away by the threatening or alarmist tone of the message;
  • Be suspicious of very generous offers. Nobody will give you prizes for contests that you are not participating in or will offer a product with a price much lower than what is practiced by the market. If you are required to pay a fee or make a cash contribution, you can be sure that it is fraud;
  • Be careful with your curiosity and be wary of sensational news, conspiracy theories or news that cannot be confirmed in renowned vehicles;
  • If you have doubts about the legitimacy of a message, contact the mentioned company or institution by phone or official website to ask for clarification;
  • Use total security software and update your software, especially browsers. They can block inadvertent clicks on malicious files or links;
  • If you are sure that a message is phishing, delete it immediately. You can also mark it as spam when possible. This is because, depending on the service used, if a significant number of users mark a message as such, it can be automatically blocked in other people's accounts;
  • Pass these guidelines on to family, friends, co-workers and other close people to prevent them from falling victim to the problem.

I Fell Into Phishing. What to Do?

  • If you took any action due to the influence of phishing, you must act soon. If you have entered a fake bank website and entered your personal data, for example, you must immediately contact the bank to block your account and obtain a new password. If you have already passed your credit card details, it is important to contact the operator to cancel it and check for unrecognized entries.
  • If you've clicked on malware, it's a good idea to check your computer or mobile device with an up-to-date, reliable antivirus. In addition, it may also be a good idea to change passwords entered after contamination.
  • In the event of injury or any other considerable inconvenience, do not hesitate to seek guidance from law enforcement or judicial authorities.

Tuesday, October 13, 2020

6 Ways to Avoid Phishing and Texting | Antivirus Software

Scams carried out through phishing or smishing are common attacks these days. Who is not inundated with emails and SMS containing fake web addresses, telephone numbers to contact, various offers, each more attractive than the last? After explaining what phishing is, it's time to help you avoid getting caught in the cracks! 

  • Check the subject and sender of the email or SMS
  • Most malicious messages will have a subject similar to this:
  • You won the lottery
  • Verify your account 
  • Your request has been registered
  • Please confirm your identity ( although you have not registered on this site )  
  • Exceptional offers 
  • Refund offers 

The subject combined with the sender should already tease you and create an ounce of suspicion in you. If you receive an email from a distributor/store when you never receive one, you should already be asking yourself questions. If you are asked to validate your registration when you have no memory of this site, do not go further and delete this message.

Identify Phishing and Smishing Messages

Phishing emails can take many forms. Often times they will use the exact logo of the company/company, the signature of one or more important people from that organization, they can use the layout and colors of their official email, website, etc.

Hackers even use phishing to trick users who have already been scammed. They pose as an organization that could help them recover previously lost money and take the opportunity to direct you to a fictitious site in order to recover your personal identifiers or money.

The SMS will usually ask you (often urgently) to click on a link to a website or call a phone number in order to verify, update, or reactivate your account. The link to the website will take you to a fictitious site that will claim to be a legitimate business. The goal is to get you to disclose any information that could help fraudsters steal your money.

Do Not Click on Links

Phishing and smishing messages usually link to fictitious web pages that are an (almost) exact replica of the original site. These scam websites are used by crooks to collect your personal data or to install spyware/malware on your system. So be careful about which links you click. 

Take the right reflexes and connect to the company's website directly by typing the web address into your browser. Do not "cut and paste" the link in the email or SMS and then paste it in your browser. Scammers can create links that are identical to the official website address, but which will direct you to an exact copy of the official website. Also, avoid responding to a fraudulent message. This could activate a system that would indicate that your email is active and that the fraudster can reuse it in future spam.

Secure Website

Make sure you always use a secure website when filling out personal and/or sensitive information. To make sure you are on a secure web server, check the internet address in your browser's bar. starts with   "https: //" rather than "HTTP: //" . You should also see a small padlock near the web address If when connecting to the website your browser displays a security alert indicating that the site is not trusted, you should not continue because it is probably from a pirate site.

  • Increase the security of your system
  • Keep your computer secure with efficient software and regular updates. For example :
  • Install (or improve) firewall protection
  • Keep your browser secure by installing updates as they become available
  • Make sure your operating system is also up to date
  • Use recognized antivirus software and update it regularly
  • Use anti-spyware software
  • Use a spam filter
  • Delete cookies as often as possible
  • Browse the Internet from a user, non-administrator session

If in Doubt

If you believe you have been the victim of a phishing or smishing scam, contact the targeted company directly to determine if this is the sender of the message. If you contact the official sender of the message by phone, be sure to get the number from a directory or the company's official website.

The company will take the necessary measures and will contact the police to report the incident. It is important to report the issue for your benefit if you have been trapped, but also to prevent it from affecting more than one person.

November 27 is Black Friday and November 30 is Cyber ​​Monday

One of the strongest sales campaigns in shops and online sales recently established in Spain is Black Friday and Cyber ​​Monday. A tradition...