Online Safety
Tools to protect your devices and your network
This Photo by Unknown Author is licensed under CC BY-SA-NC
What will we learn today?
How we get Malware
Recognizing scams
What if???
How to be safe
How do we get malware?
Know what it is, and find tips to avoid
First, what is malware?����Software installed which performs unwanted tasks. �
How a computer gets infected with malware
Accepting without reading the fine print
Downloading infected software from a bad source
Opening email attachments
Using an infected disk, disc or thumb drive
Not running the latest updates
Using a file distribution network (like BitTorrent) for pirated movies or software
Malware can also come as a “bad app”
You cannot get a “virus”, but you can get malware which can:
You may get malware from clicking on a link in your text
Or from a call on your cellphone
Look out for unsolicited calls from
It may come through your email
Or, through a bad site via clickbait
Concealing the story until you click on the headline
Driven by the curiosity gap
Spotting examples of things which may result in malware
Phishing,
How to spot phishing
Grammatical errors
Low resolution logo
Odd web address (URL)
The sender doesn’t seem to know you. ( “Dear Customer”)
There is a “deadline
Techniques used by scammers
URGENCY: TIME-SENSITIVE OFFERS OR ACCOUNT SECURITY ALERTS
EXCITEMENT: FREE GIFT CARDS OR WEALTH-BUILDING SCHEMES
FEAR: FEAR OF VIRUS INFECTIONS AND ACCOUNT ALERTS LEAD TO PANIC
How does a scam website work?
Bait: Draw users in (email, social media, texts messaging, other websites)
1
Compromise: Users do something to expose information or devices to attackers
2
Execute: Attackers exploit the users to misuse their private information for information or to infect devices
3
Example: Instagram two-factor authentication
This is a new scam targeting two-factor authentication on Instagram
Scammers use a code at the bottom to imply that they should type that code in (seems reasonable!)
Hovering over the “sign in” will show you that the website is spoofed. If you can see the website, it ends in .CF (Central African Republic)
Activity: Hover over links in email
Example: Bank account suspended
You receive a note from your bank saying that your account has been temporarily suspended due to unusual activity
You are emailed with a link to reactivate your account
You end up on a fake name asking for your ID and password (BAD!)
Signs it is fake: Spelling or grammatical errors , bad link (shortened website takes you to a pet-store in Israel)
Example: Tax refund scam
Notices that you are due a refund or cash prize is usually a scam
Clicking on this link will either take you to a spoof site or expose your device to malware
The IRS will NEVER email you to ask for personal information. If you receive such a note, call them.
Example: Netflix on hold
An email with the company’s logo says that they are having trouble with your billing information. Clicking on the link will update the method.
You will be sent to a spoof site.
Big giveaway: Addressed to “Hi Dear”.
If you get one, contact Netflix directly!
Example: Big inheritance
FTC getting reports of letters from a law firm looking for the heir of a multi-million-dollar inheritance
This is not a lawyer; if you email them, they will ask for your financial information (social security, bank accounts)
What to do:
Example: Imposter scams
From:
Some red flags of imposter scams:
Example: Tech Support
Apple scammers have found a way to include Apple logo when calling
You may get a person, or you may get a recording
They will say that they have noticed some problems with your device
Or, in a new case involving Apple, they will report suspicious activity on your iCloud account
If Robocall, you will be prompted to connect with customer support as they ask for sensitive information
NOTE: If this were to happen, and someone did hack into your iCloud or Apple account, you will receive an email from Apple. They will not call you!
Example: Business imposter scams
A scammer may say that they are from Publisher’s Clearing house, and you need to pay a fee to get your winnings
Or they may claim to be your bank and need your details to transfer your money to a new account
Also be aware of romance scams.
Other examples
Social security scam calls
Parcel tracking text scam
Amazon Prime Renewal phone scams
Gift card scams
Navy Federal Credit Union scams through email
TSA Precheck Renewal
Email asking to validate your COVID-19 status
Scammers promoting local police support
https://www.verified.org/imposters/scams
What if???
Scammed? Accounts breached? Hacked?
What to do if you are contacted by scammer
Research the person, business or government agency to see if they are a scam
Hang up on any calls about computer issues
Don’t trust caller ID
Don’t send money to someone you don’t know
If someone is claiming to be a relative/friend, validate before giving them money
What if you are a victim of an Imposter Scam
Contact your financial institution
Report the scam:
If you fell victim to tech support scam:
What to do if you are hacked
You may notice that your computer is acting differently (can’t turn it off, running slowly, opening pages you didn’t select, popups)
Steps to take (from the FTC site):
What to do if you are a victim of a data breach
A breach typically exposes personal information, not passwords.
If there are concerns, change your password.
If you reuse the same password elsewhere, change those passwords also; make them strong and unique.
If your account has actually been hacked, you’ll need to confirm or repair all recovery information.
Now is a good time to consider two-factor authentication, if it’s available.
Additional things to do if your accounts are breached
Freeze your credit. Make sure to include all three credit bureaus
1
If it was your phone account, change your cell phone account password and PIN numbers.
2
Consider multifactor authentication
3
Follow the advice of data breach letters and take advantage of free monitoring if offered
4
Be on the lookout for phishing. They may want to exploit what they know already.
5
Monitor your financial accounts (credit cards, banking, utilities)
6
Contact the DMV is your license has been exposed
7
Resources when your identity is breached
Website: Have I been pawned? This website will check if your email or phone is in a data breach. https://haveibeenpwned.com/
Consider contacting the Identity Theft Center . You can call (888.400.5530) or live-chat on the company website www.idtheftcenter.org. You can also check their website for information on latest breaches and additional resources.
Norton (as in anti-virus) provides information on 5 different types of breaches and what to do in each one.
Were you affected by the T-Mobile breach? Here are some suggestions from Consumer Reports
Want to cut down on data collection and hackers? Consumer Reports offers a free personalized plan to help you organize your digital life. Here were the suggestions made when I completed the form.
Ideas to be safe
And avoid being sorry…
Email: Check before agreeing
Check address where email is coming from
Hover over links to see where they are going
Create a strong password which is unique to your email
Use two-step verification
Remove unnecessary apps and websites connected to your data like full name, profile picture, personal information publicly available
Avoid opening unknown attachments
Avoid using public computers
Avoid using public networks
Email: Identifying malicious email attachments
Look at the file extension
Microsoft office documents and macros (A Macro enabled file will have M at the end, like .docm, .xlsm, or pptm)
Potentially dangerous files are executable files, program files, registry files, shortcuts and script files. Examples : .exe, .html, .js, .vbs, .zip, .bat
Attackers will try to disguise these with a name that you would be enticed to open (monthlypayroll.exe, past-due-invoices.zip, etc.)
New: malformed prefixes (http:\)
Avoid malware on your cellphone
Only use trusted sources for apps
Review permissions during installation
Regularly update operating system
Install and regularly update anti-virus or anti-malware
Don’t click on links in texts from unknown people
Avoid public networks
Set up account alerts to banks
Avoiding phone scams
Don’t answer calls from unknown numbers
If you answer and they are not who you expected, hang up
If you are asked to hit a button to stop getting calls, hang up
Never assume an unexpected call is legitimate
Be suspicious: If it is threatening or too good to be true, it is probably spam
Don’t give out any personal information or answer security questions
Do not feel pressured for immediate payment
Block calls that you know are spam
Report spoofing scams to law enforcement, FCC and FTC fcc.gov/spoofing
Use a good antivirus program
Do your research: Visit AV-Test to find the best rated programs (https://www.av-test.org/en/)
Passwords
Strong: Over 8 characters and include letters, numbers & symbols. Mix letters and numbers within password
Consider a long passcode with a term you would remember
No personal information , no sharing passwords, avoid storing on your device
Consider a Password Manager with built in browser tools (free)
Use your cellular hotspot
Avoid airport, coffeeshop, mall or other free Wi-Fi options when accessing sensitive information. Instead use your cellular connection. If using a laptop, use your phone as the wi-fi connection.
Online safety is about:
Paying attention
Taking a little more time to check
Using common sense
A little private detective work as well
Spreading the word!
Stay safe online! Avoid the bad guys!�
Refer to our course website for additional resources