Posts

Showing posts with the label phishing

Stay Safe: Microsoft Now the #1 Most Spoofed Company

Image
50% of Phishing Attempts Impersonate Microsoft The old advice is still true: don’t trust anything you see on the internet. Within reason, of course: we work hard to make sure this blog is fact-based and trustworthy. But the big-picture advice is still good advice: how can you know for sure our team wrote this and that the whole post isn’t just the figment of a genAI’s imagination? There are signs, like the way this introduction is going. (Not your standard opening, that’s for sure!) So what’s our point? While you can learn a lot online, and you rely on it for a massive slice of your business, you still can’t take everything you see at face value. A recent report looked at a huge number of phishing attempts — those fraudulent emails that pretend to be from someone else and try to get you to give up sensitive information — and found that one company was the undisputed “leader”: more than ⅓ of phishing emails impersonating a brand chose Microsoft. If your business does business with Micr...

Phishing Tactic Alert: Corrupted Word Docs

Image
Corrupt Word Attachments May Be a Scam Sigh… here we go again. The scammers keep innovating, and so we keep having to say it: there’s another new phishing tactic on the rise, and this one’s a stinker. This new phishing tactic has been getting past spam filters and tricking professionals worldwide, taking advantage of both human nature and advancing “good” tech to fool you and attack your business. Here’s what you need to know about how scammers are using corrupted file attachments to attack businesses like yours. How It Starts: A Corrupted Word File (or Similar) This new attack starts with a corrupted file, often a Microsoft Word document file (.docx). It looks like a real file, and it may even seem like it was sent by someone or some entity you trust. Now, if you’ve been at this a while, you already know the old advice not to trust email attachments. But that advice was largely about executables, those .exe files that would not-so-subtly install new malicious software onto your system...

Cyber Attacks (and Cyber Attackers) Are Getting Smarter

New reports suggest that the cyber attacks threatening businesses like yours are getting smarter, stronger, and faster. Advances in cheap computing power, AI, and even hacking techniques themselves mean today’s cyber criminals are accomplishing more with less and doing so using some tactics that are downright frightening. Much of the research stems from the CrowdStrike 2024 Global Threat Report , a wide-ranging report with tons of observations and takeaways. Here’s what you need to know about the latest research — and how to keep your business as safe as possible. Breakout Times Are Getting Faster The first big takeaway was how much shorter breakout times became year over year. Breakout time is how long it takes a cyber attacker to move from the initial point of entry to some other system or area. In other words, it’s how long it takes between when the thief picks the lock (“I got in!”) and when the thief moves into the next room and starts stealing stuff (“I found something worth stea...

Ransomware: To Pay or Not to Pay?

Image
Which ransomware payment option is best? (Hint: none) We don’t like to think about it, but ransomware attacks are on the rise, and that means the chances that your business goes through one are on the rise, too. At Blue Ridge Tech, we genuinely hope you never suffer a ransomware attack — and we can help you reduce your risk in all kinds of ways. But if you do go through a ransomware attack, it pays to be prepared. That means understanding how these attacks work, what kinds of new tactics and innovations the scammers are using, and so on. Most importantly, you need to have a ready answer to this fundamental question: should you pay up, or should you refuse to do so (and risk whatever consequences you’ve been threatened with)? The Best Answer Is Avoiding the Question Entirely Of course, the best answer is “none of the above.” If you can avoid getting into this situation, you should. That’s why robust cybersecurity tactics and cybersecurity awareness training are so important. Why Busines...

Google’s Update to Gmail Security Could Hurt You As Much As It Helps

Image
If you’re handling email marketing in-house, then we highly recommend digging into your email analytics over the next few weeks. If you see any significant changes or drops (like a higher bounce rate or markedly lower open, conversion, or click-through rates), then it’s possible something about your marketing approach is getting snagged in or flagged by RETVec. Google recently updated the way Gmail responds to spam and malicious emails. On net this is a good thing: less spam and scam email in your employees’ inboxes means less chances for the bad guys to dupe someone into giving away information or credentials. But there’s a possible downside to this update — and there’s a very real chance it could negatively impact your marketing efforts. Here’s what you need to know. Introducing RETVec Yeah, we know: RETVec doesn’t exactly roll off the tongue. But that’s the name of Google’s newest weapon in the war against spam. It’s an acronym for Resilient and Efficient Text Vectorizer . (Speaking...

87% of Web-Based Businesses Faced This Threat

Image
Scary stat: 87% of businesses hit by this in the last year Do you interact with customers via the web? Do you sell products online? If so, you’re technically a web-based business (even if you have lots and lots of “offline” business too). And you need to know about this scary statistic from the previous year. CDNetworks performed a massive analysis of more than 45 billion cyberattack attempts during 2022. Its findings were both sobering and encouraging. But let’s start with this 87%. Based on the title alone, would you think we’re about to say 87% of businesses faced an attempted cyberattack in 2022? Good guess, and we wish that was all. But no: CDNetworks found that 87% of web-based businesses faced two or more cyber threats at the same time ! What’s worse, 65% encountered “three or more simultaneous threats.” If you think your business is immune to cyberattack attempts, think again. Now let’s get into the data and figure out what all this means for you. Good News: Billions of Attack...

Thinking About MFA? Microsoft Just Made Implementing Easier

Image
Microsoft 365 makes Multi-Factor Authentication easier We wrote just last week about how crucial it is to implement multifactor authentication (MFA) wherever possible in your business. If you missed that post, check it out now (Have You Implemented MFA Yet? ) — we won’t rehash all of that news here. Still, we figure there’s a sizable group of businesses that fall into one of these categories: Still on the fence about MFA Convinced MFA is important but unsure how to get started In the middle of implementing MFA, and it’s not going well Already implemented MFA, but people are complaining or bypassing it If any of those sound familiar, we have great news: if you’re using Microsoft 365, things are about to get a lot easier. Here’s what you need to know. MFA Already Available Throughout Microsoft 365 First, it’s worth mentioning that MFA isn’t brand-new for M365 users. Microsoft already supported a few different kinds of next-gen authentication, including MFA. Maybe you never got around to ...

Microsoft Windows Remains the Biggest Cyberattack Target

Image
Windows is the prime target for cyber criminals If your business is like most, you rely on Microsoft Windows to get work done. Unless you’re a 100% Mac workplace (or Linux, we suppose), someone, somewhere in your organization is using a PC running Windows. That’s not exactly surprising news, and neither is this: because Windows is ubiquitous throughout the business world, it’s a prime target for cyber criminals and cyberattacks. The important question is what this means for your business, and what you should do about it. Should you throw out all your PCs and switch your entire company to Mac? Probably not. But you need to be aware of the threats and take the necessary steps to stay protected. Good News: Most Attacks Fail We’ll start with some good news: while something like 95 percent of all cyberattacks target Windows itself or applications running in Windows, most of them fail. That’s because, at least in part, Microsoft didn’t achieve this kind of success by failing to protect its u...

Business Software Impostors: Legit Zoom or Malware Lookalike?

Image
Are you really downloading Zoom… or is it malware? We talk a lot on this blog about keeping your company’s digital assets secure — stuff like your network storage, client files, business data, and account access to the systems that keep business moving forward. And there’s a good reason for it: digital threats to your business are all around you, and they’re more significant and more dangerous than most business leaders realize. Today we’re looking at another threat that’s a little different from phishing attacks and business email compromise. Let’s examine what we’re calling business software impostors. The good news on this one is that there are two really great ways to avoid the threat — but you and every member of your team have to know how. What’s a Business Software Impostor? A business software impostor is a fake version of a popular business software product or digital tool, designed with the intent of perpetrating some kind of attack once installed. In other words, it’s malwar...

Many Cyber Criminals are just Fine with Waiting...and Waiting...

Image
What does Persistence mean in regards to a Cyber Attack? Persistence is a tactic that allows attackers to quietly maintain access to a system over time. This “dwell time” is often used to conduct additional research, explore the victim’s environment and determine what the best (i.e. the most profitable) next step should be. Hackers can spend 11-24 days in a network before being discovered! Right Click and save our Infographic The longer an attacker persists on a device, the more intel they’re able to gather—and the more damage they can ultimately do when deploying ransomware, stealing passwords or executing other malicious activity. Not to mention the amount of your Client’s information that they can absorb! Our security agents are always on guard against attack plans like this, shining a light on hidden trespassers and removing them. Give us a call to help get your business properly secured and constantly monitored, today!

Browser Extensions Have Hidden Risks. Are You Protected?

Image
Are you using a malicious browser extension without realizing? If you’re a regular internet user, chances are you’ve come across browser extensions by now. They’re so popular and so widespread that, even if you’ve never heard of them, you’re probably even using some right now as you read this post. Browser extensions can be a fantastic thing: they can enhance your productivity, make you (look like) a better writer, and help your browser be a more enjoyable thing to use. But browser extensions can also have a dark side. It’s important to understand the risks before diving down the extension rabbit hole — especially on business devices. What Are Browser Extensions? Browser extensions are little bits of software that change the way an internet browser behaves. They can deliver tons of helpful functionality, like adding in a grammar checker like Grammarly or a translator or making it easier to take and edit screenshots within your browser. A decade or so ago, extensions that blocked obtrus...

Work From Home Is Here: Are There Hidden Costs?

Image
Is working from home really good for your business? If you’re like most of our clients, work from home showed up in a big way thanks to COVID — and it’s not going away. The truth is, there’s just a lot to like about having the option to work from home at least some of the time. Well, from the employee’s perspective, at least. If you’re an office-oriented, creative, or knowledge-economy sort of business, work from home can work, and it can work well. (And at this point, the cost of not offering it? You could lose team members if you don’t.) Still, nearly three years in, many companies are discovering that WFH isn’t all roses and puppy dogs. There are perks and advantages, sure. But there are challenges, too. For many businesses — maybe yours too — the best approach is offering it, but doing it with both eyes open, staying aware of the costs and the potential downsides that can crop up. Let’s talk about the IT-related challenges as well as some hidden costs that can crop up with permanen...

Staff Working Remotely? Make Sure Your Security Protection Is Sufficient

Image
If any of your staff work remotely, you need to be on top of this Is remote or hybrid work here to stay for your business? It is for many (formerly) office-based businesses operating in services or in the knowledge economy. If you weren’t set up for remote work before the pandemic, chances are you had to pivot quickly to get set up for remote work or work from home. And many businesses that went remote for the first time were operating in “emergency mode”: all that mattered was finding a way to keep business going. But as the pandemic eases into endemic status, one thing is clear: remote work isn’t going away, and hybrid is here to stay, too. If you have staff working remotely, it’s time to make sure your security protection is sufficient. One recent industry poll found that only around half of businesses today had the kind of security protection they need to keep employees and their organization safe no matter where people work. Those aren’t good odds. Here’s what you need to know so ...

Rein In Notifications from Chrome and Windows to Regain Your Sanity

Image
Rein In Notifications from Chrome and Windows to Regain Your Sanity If you’ve been using tech for a few years, you can probably appreciate just how powerful, efficient, and even intuitive today’s computers are compared to what you used 10 years ago or longer. Processor speeds have increased exponentially, and other under-the-hood tech improvements have helped, too. But where we’ve really seen improvements in usability and intuitiveness is in the software and operating systems running on our computers. Now that they have more power available to them, software and OS makers have been able to do some pretty awesome things. Like the humble notification. Notifications: A Powerful Tool, But Easy to Abuse Take notifications, for one. Best case, notifications are intuitive and immensely helpful, letting you know about a crucial email, a new Slack message, or even something like a severe weather alert or a missing child. But like absolutely everything new, notifications have a dark side. Even t...

Watch Out: New Social Engineering Attack Through Your Business’s Contact Form

Image
Alert: A clever new type of ransomware attack Another week, another brand-new form of cyberattack. It certainly feels that way, doesn’t it? As a business leader, it’s easy veer in one of two directions. Either you live in constant fear or you grow numb and complacent to the very real threats. The best approach lies somewhere in the middle, where you recognize the threats for what they are and take appropriate steps to combat them. This week, we’re shedding light on a new threat vector, one that affects any business with a website that has a contact form. The New Threat Explained This new threat isn’t all that complicated, and that’s part of what makes it so effective. Here’s how it works. A threat actor visits your website normally, just like any other visitor would. They look for a contact form and fill it out, posing as a real lead or prospect. So far, if they’ve built an effective attack, they haven’t done anything out of the ordinary or suspicious. They just look like any other cus...

You’ve Heard of Phishing, But What About Whaling?

Image
We’ve covered phishing before on the blog, but have you heard about whaling? Put away your lifejackets: we’re talking about a specific type of targeted digital attack; no seafaring vessels in sight. (If you’ve ended up here expecting a blog post about whale-spotting or whale-hunting, you’re going to be disappointed!) This week, we’re covering whaling attacks. This type of digital attack can feel even more personal than some others—and it can be just as dangerous. Here’s what you need to know about this unique attack vector. Whaling Attacks Explained A whaling attack is one where someone (typically outside the company) imitates a high-ranking company official, usually in an attempt to steal money from the company by tricking an employee into paying a fake bill. Whaling attacks can also be engineered to steal data or credentials. We recognize that this definition is a little murky, so here’s an example. Set aside your actual role at your company for a minute. Instead, imagine you’re a br...

Five Strategies for How to Spot a Phishing Email

Image
Five Strategies for How to Spot a Phishing Email In last week’s blog post, we talked about the rise of the phishing email, now one of the most common methods of digital attacks. We showed you how dangerous these emails can be, and what to do if you think you’ve fallen for one. What Are Phishing Emails, Again? As a reminder, phishing emails are fraudulent messages that usually appear to be from some well-known, legitimate company or authority (like the IRS). But they actually come from scammers trying to steal account information and other personal data. If a user clicks a link in a phishing email and tries to log into the (fake) page, the scammers immediately get access to whatever the user typed (usually a username and password). While it’s good to know about phishing emails, the real trick is to be able to recognize phishing emails in the first place. If employees know the email’s a phony, they should know to delete it, not click through. So, with that in mind, here are our top tips ...