1 of 41

Online Safety

Tools to protect your devices and your network

This Photo by Unknown Author is licensed under CC BY-SA-NC

2 of 41

What will we learn today?

How we get Malware

Recognizing scams

What if???

How to be safe

3 of 41

How do we get malware?

Know what it is, and find tips to avoid

4 of 41

First, what is malware?����Software installed which performs unwanted tasks. �

5 of 41

How a computer gets infected with malware

Accepting without reading the fine print

Downloading infected software from a bad source

Opening email attachments

Using an infected disk, disc or thumb drive

Not running the latest updates

Using a file distribution network (like BitTorrent) for pirated movies or software

6 of 41

Malware can also come as a “bad app”

You cannot get a “virus”, but you can get malware which can:

    • Steal money and credit card info
    • View and contact your contacts and photos
    • Track your location
    • Read text messages
    • Save passwords,
    • Send SMS messages
    • And more…

7 of 41

You may get malware from clicking on a link in your text

8 of 41

Or from a call on your cellphone

Look out for unsolicited calls from

    • People claiming to be government, public utility or major tech firm (Microsoft or Apple)
    • Charity workers especially around holidays and disasters
    • Calls pitching products or services to good to be true
    • Offers that include free product trials, cash prizes, cheap travel, medical devices, preapproved loans, debt reduction and investments
    • An automated sales call from a company that you have not authorized to contact you

9 of 41

It may come through your email

  • Phishing is an attempt to get money from you
  • Can be in different forms (attachment, link)
  • Link may take you to a page which looks familiar (bank, credit card provider) and will ask for your personal information
  • But remember: Your bank or credit card provider will never ask you to provide account information online.

10 of 41

Or, through a bad site via clickbait

    • Misleading headlines
    • Story may not fit the headline

Concealing the story until you click on the headline

    • We don’t like ambiguity
    • Will most likely remember unfinished task
    • Fear of missing out

Driven by the curiosity gap

11 of 41

Spotting examples of things which may result in malware

Phishing,

12 of 41

How to spot phishing

Grammatical errors

Low resolution logo

Odd web address (URL)

The sender doesn’t seem to know you. ( “Dear Customer”)

There is a “deadline

13 of 41

Techniques used by scammers

URGENCY: TIME-SENSITIVE OFFERS OR ACCOUNT SECURITY ALERTS

EXCITEMENT: FREE GIFT CARDS OR WEALTH-BUILDING SCHEMES

FEAR: FEAR OF VIRUS INFECTIONS AND ACCOUNT ALERTS LEAD TO PANIC

14 of 41

How does a scam website work?

Bait: Draw users in (email, social media, texts messaging, other websites)

1

Compromise: Users do something to expose information or devices to attackers

2

Execute: Attackers exploit the users to misuse their private information for information or to infect devices

3

15 of 41

Example: Instagram two-factor authentication

This is a new scam targeting two-factor authentication on Instagram

Scammers use a code at the bottom to imply that they should type that code in (seems reasonable!)

Hovering over the “sign in” will show you that the website is spoofed. If you can see the website, it ends in .CF (Central African Republic)

16 of 41

Activity: Hover over links in email

17 of 41

Example: Bank account suspended

You receive a note from your bank saying that your account has been temporarily suspended due to unusual activity

You are emailed with a link to reactivate your account

You end up on a fake name asking for your ID and password (BAD!)

Signs it is fake: Spelling or grammatical errors , bad link (shortened website takes you to a pet-store in Israel)

18 of 41

Example: Tax refund scam

Notices that you are due a refund or cash prize is usually a scam

Clicking on this link will either take you to a spoof site or expose your device to malware

The IRS will NEVER email you to ask for personal information. If you receive such a note, call them.

19 of 41

Example: Netflix on hold

An email with the company’s logo says that they are having trouble with your billing information. Clicking on the link will update the method.

You will be sent to a spoof site.

Big giveaway: Addressed to “Hi Dear”.

If you get one, contact Netflix directly!

20 of 41

Example: Big inheritance

FTC getting reports of letters from a law firm looking for the heir of a multi-million-dollar inheritance

This is not a lawyer; if you email them, they will ask for your financial information (social security, bank accounts)

What to do:

    • Don’t respond
    • Pass this information to a friend
    • Report it to FTC at reportfraud.ftc.gov/

21 of 41

Example: Imposter scams

From:

    • a specific person or representative of business or government
    • May call, send text or email

Some red flags of imposter scams:

    • Money needed immediately
    • Pay a fee to get something “free”
    • Won a prize but they need more information
    • Something is wrong with your computer
    • Friend or relative needs to borrow money
    • Person or business requests money in form of a gift card, wire transfer or prepaid debit
    • Details do not add us.

22 of 41

Example: Tech Support

Apple scammers have found a way to include Apple logo when calling

You may get a person, or you may get a recording

They will say that they have noticed some problems with your device

Or, in a new case involving Apple, they will report suspicious activity on your iCloud account

If Robocall, you will be prompted to connect with customer support as they ask for sensitive information

NOTE: If this were to happen, and someone did hack into your iCloud or Apple account, you will receive an email from Apple. They will not call you!

23 of 41

Example: Business imposter scams

A scammer may say that they are from Publisher’s Clearing house, and you need to pay a fee to get your winnings

Or they may claim to be your bank and need your details to transfer your money to a new account

Also be aware of romance scams.

24 of 41

Other examples

Social security scam calls

Parcel tracking text scam

Amazon Prime Renewal phone scams

Gift card scams

Navy Federal Credit Union scams through email

TSA Precheck Renewal

Email asking to validate your COVID-19 status

Scammers promoting local police support

https://www.verified.org/imposters/scams

25 of 41

What if???

Scammed? Accounts breached? Hacked?

26 of 41

What to do if you are contacted by scammer

Research the person, business or government agency to see if they are a scam

Hang up on any calls about computer issues

Don’t trust caller ID

Don’t send money to someone you don’t know

If someone is claiming to be a relative/friend, validate before giving them money

27 of 41

What if you are a victim of an Imposter Scam

Contact your financial institution

    • (as long as you did not pay them with a gift card, prepaid debit card or wire transfer)

Report the scam:

    • Contact FTC at 1-877-382-4357 (or online at reportfraud.ftc.gov
    • Report it to the FBI Internet Crime Complaint Center
    • Report to your local police department

If you fell victim to tech support scam:

    • Disconnect your computer from the Internet immediately
    • Use another PC to change passwords
    • Check browser for unfamiliar extensions or add-ons and remove them
    • Run your anti-virus and ant-malware programs

28 of 41

What to do if you are hacked

You may notice that your computer is acting differently (can’t turn it off, running slowly, opening pages you didn’t select, popups)

Steps to take (from the FTC site):

    • Stop: Stop shopping, banking and entering passwords until the problem is resolved
    • Update: Update your security software. Install a new version.
    • Find and Delete: Using security software, scan your system. It will flag malware, which you can delete (or archive). Restart your computer. Contact a professional if problems persist.
    • After cleaning: Change critical passwords to long and strong passwords
    • Final notes: Keep your operating system and web browsers up to date

29 of 41

What to do if you are a victim of a data breach

A breach typically exposes personal information, not passwords.

If there are concerns, change your password.

If you reuse the same password elsewhere, change those passwords also; make them strong and unique.

If your account has actually been hacked, you’ll need to confirm or repair all recovery information.

Now is a good time to consider two-factor authentication, if it’s available.

30 of 41

Additional things to do if your accounts are breached

Freeze your credit. Make sure to include all three credit bureaus

1

If it was your phone account, change your cell phone account password and PIN numbers.

2

Consider multifactor authentication

3

Follow the advice of data breach letters and take advantage of free monitoring if offered

4

Be on the lookout for phishing. They may want to exploit what they know already.

5

Monitor your financial accounts (credit cards, banking, utilities)

6

Contact the DMV is your license has been exposed

7

31 of 41

Resources when your identity is breached

Website: Have I been pawned? This website will check if your email or phone is in a data breach. https://haveibeenpwned.com/

Consider contacting the Identity Theft Center . You can call (888.400.5530) or live-chat on the company website www.idtheftcenter.org. You can also check their website for information on latest breaches and additional resources.

Norton (as in anti-virus) provides information on 5 different types of breaches and what to do in each one.

Were you affected by the T-Mobile breach? Here are some suggestions from Consumer Reports

Want to cut down on data collection and hackers? Consumer Reports offers a free personalized plan to help you organize your digital life. Here were the suggestions made when I completed the form.

32 of 41

Ideas to be safe

And avoid being sorry…

33 of 41

Email: Check before agreeing

Check address where email is coming from

Hover over links to see where they are going

Create a strong password which is unique to your email

Use two-step verification

Remove unnecessary apps and websites connected to your data like full name, profile picture, personal information publicly available

Avoid opening unknown attachments

Avoid using public computers

Avoid using public networks

34 of 41

Email: Identifying malicious email attachments

Look at the file extension

Microsoft office documents and macros (A Macro enabled file will have M at the end, like .docm, .xlsm, or pptm)

Potentially dangerous files are executable files, program files, registry files, shortcuts and script files. Examples : .exe, .html, .js, .vbs, .zip, .bat

Attackers will try to disguise these with a name that you would be enticed to open (monthlypayroll.exe, past-due-invoices.zip, etc.)

New: malformed prefixes (http:\)

35 of 41

Avoid malware on your cellphone

Only use trusted sources for apps

Review permissions during installation

Regularly update operating system

Install and regularly update anti-virus or anti-malware

Don’t click on links in texts from unknown people

Avoid public networks

Set up account alerts to banks

36 of 41

Avoiding phone scams

Don’t answer calls from unknown numbers

If you answer and they are not who you expected, hang up

If you are asked to hit a button to stop getting calls, hang up

Never assume an unexpected call is legitimate

Be suspicious: If it is threatening or too good to be true, it is probably spam

Don’t give out any personal information or answer security questions

Do not feel pressured for immediate payment

Block calls that you know are spam

Report spoofing scams to law enforcement, FCC and FTC fcc.gov/spoofing

37 of 41

Use a good antivirus program

Do your research: Visit AV-Test to find the best rated programs (https://www.av-test.org/en/)

38 of 41

Passwords

Strong: Over 8 characters and include letters, numbers & symbols. Mix letters and numbers within password

Consider a long passcode with a term you would remember

No personal information , no sharing passwords, avoid storing on your device

Consider a Password Manager with built in browser tools (free)

39 of 41

Use your cellular hotspot

Avoid airport, coffeeshop, mall or other free Wi-Fi options when accessing sensitive information. Instead use your cellular connection. If using a laptop, use your phone as the wi-fi connection.

40 of 41

Online safety is about:

Paying attention

Taking a little more time to check

Using common sense

A little private detective work as well

Spreading the word!

41 of 41

Stay safe online! Avoid the bad guys!�

Refer to our course website for additional resources