Posts

Showing posts with the label scams

Stay Safe: Microsoft Now the #1 Most Spoofed Company

Image
50% of Phishing Attempts Impersonate Microsoft The old advice is still true: don’t trust anything you see on the internet. Within reason, of course: we work hard to make sure this blog is fact-based and trustworthy. But the big-picture advice is still good advice: how can you know for sure our team wrote this and that the whole post isn’t just the figment of a genAI’s imagination? There are signs, like the way this introduction is going. (Not your standard opening, that’s for sure!) So what’s our point? While you can learn a lot online, and you rely on it for a massive slice of your business, you still can’t take everything you see at face value. A recent report looked at a huge number of phishing attempts — those fraudulent emails that pretend to be from someone else and try to get you to give up sensitive information — and found that one company was the undisputed “leader”: more than ⅓ of phishing emails impersonating a brand chose Microsoft. If your business does business with Micr...

Malware Threats Are on the Rise in 2024

Image
A new report claims that malware attacks are once again on the rise in 2024. This type of attack seems like it used to be all we talked about, but in recent years, it was dwarfed in popularity and frequency by phishing scams. Since the threat level of malware is rising, it's time to talk about it again. Here's what you need to know about malware attacks: what they are, why they matter, and what's different this time around. What Is Malware? Malware is a portmanteau of “malicious” and “software,” which pretty much explains the game: malware is software that runs on your computer just like any other software you would use, only this particular subset of software is malicious, dangerous, and usually installed without your consent or awareness. What Can Malware Do? All sorts of nasty things. Malware has the ability to do a wide range of things to your computer. It can act as a keylogger, which means recording every keystroke you make and sending that data back to the bad guys...

Cyber Attacks (and Cyber Attackers) Are Getting Smarter

New reports suggest that the cyber attacks threatening businesses like yours are getting smarter, stronger, and faster. Advances in cheap computing power, AI, and even hacking techniques themselves mean today’s cyber criminals are accomplishing more with less and doing so using some tactics that are downright frightening. Much of the research stems from the CrowdStrike 2024 Global Threat Report , a wide-ranging report with tons of observations and takeaways. Here’s what you need to know about the latest research — and how to keep your business as safe as possible. Breakout Times Are Getting Faster The first big takeaway was how much shorter breakout times became year over year. Breakout time is how long it takes a cyber attacker to move from the initial point of entry to some other system or area. In other words, it’s how long it takes between when the thief picks the lock (“I got in!”) and when the thief moves into the next room and starts stealing stuff (“I found something worth stea...

Business Software Impostors: Legit Zoom or Malware Lookalike?

Image
Are you really downloading Zoom… or is it malware? We talk a lot on this blog about keeping your company’s digital assets secure — stuff like your network storage, client files, business data, and account access to the systems that keep business moving forward. And there’s a good reason for it: digital threats to your business are all around you, and they’re more significant and more dangerous than most business leaders realize. Today we’re looking at another threat that’s a little different from phishing attacks and business email compromise. Let’s examine what we’re calling business software impostors. The good news on this one is that there are two really great ways to avoid the threat — but you and every member of your team have to know how. What’s a Business Software Impostor? A business software impostor is a fake version of a popular business software product or digital tool, designed with the intent of perpetrating some kind of attack once installed. In other words, it’s malwar...

An Old Threat Resurfaces: Warn Your Team About This Scam

Image
None of your team would fall for this trick… would they What’s old is new again. Remember the early aughts, when USB flash drives seemed like the definition of our technological future? Think about it: cheap, extremely portable devices that work on just about any computer anywhere and can store any file type you can imagine. It was and still is an awesome technology, even if the advent of cloud storage and faster internet speeds have limited our need for them. The Problem with USB Flash Drives Back Then The USB drive suffered from one very frustrating (and sometimes dangerous) problem, though: because of the way USB works, there was no effective way to stop a USB drive from auto-installing stuff whenever it got plugged into a new machine. The PC simply recognized the new drive and tried to read it, and that was it: the damage was already done. Simply reading the contents of the drive was enough to install malware. If hackers, scammers, or corporate thieves had the right tech capabiliti...

Cyber Awareness Training: Beware of Digital Urgency (in Any Form)

Image
If you’re under pressure to take urgent action – stop and think At Blue Ridge Technology, we talk a lot about cybersecurity, and we publish about it on this blog regularly, too. Why? Because digital threats are one of the biggest risks that businesses, including our clients, could face. It’s vitally important to have strong cyber defenses in place (and we’re certainly ready to audit your hardware, network, and software defenses to find any vulnerabilities—just reach out today). But it’s just as important to train yourself and your employees or teammates on how to be aware of cyber threats. In other words, cyber awareness training is just as valuable as the best firewalls and endpoint protection systems. That may sound like a bold claim, but it’s true. The most common digital attacks don’t happen by bad guys brute forcing their way through your firewall. They happen because someone on your team makes a mistake. Your Biggest Cybersecurity Threat Is on Your Payroll As crazy as it sounds...

Are Ransomware Attacks Really a Threat to Your Business?

Image
Most ransomware victims would pay up if attacked again If you read much in the news — or in tech news specifically — it’s easy to grow a little numb to the constant reporting of digital threats and attacks on businesses. This is especially true if your business has yet to face a cyberattack: your policies and practices have gotten you by so far, so they must be good enough … right? The truth is, ransomware attacks are a threat, one that businesses like yours must take seriously now, not once you’ve already been attacked. How Ransomware Attacks Work Ransomware attacks can start like any other digital threat. Bad actors could go on a phishing expedition and steal the credentials of an unwitting employee. (We’ve said it before, and we’ll say it again: two-factor or multifactor authentication eliminates the vast majority of phishing threats.) Or threat actors could identify a vulnerability in your system through more sophisticated computer wizardry. Whatever way the bad guys find a way i...

Your Staff Wouldn’t Click… Right?

Image
Phishing Emails: How Well Do You Trust Your Team? And Is Trust Enough? As we enter a new year, many of the digital threats targeting small businesses aren’t changing drastically. They’re just getting more sophisticated. Phishing was a top threat to your business’s cybersecurity last year, and it’s going to be this year, too. With attacks getting more and more believable and harder to detect, just how much should you trust your team to get this right? We believe business leaders should leave their digital security up to chance. Now is the time to go on the offensive. Phishing: a Refresher In case the term phishing isn’t quite ringing a bell, here’s a quick refresher. Phishing describes email-based attacks where people or groups send an email that looks like it’s coming from somewhere official (like Microsoft, a big bank, or a prominent supplier in your industry). They send you an urgent message and ask you to click a link (and usually log in). The link is malicious, though: clicking co...

You’ve Heard of Phishing, But What About Whaling?

Image
We’ve covered phishing before on the blog, but have you heard about whaling? Put away your lifejackets: we’re talking about a specific type of targeted digital attack; no seafaring vessels in sight. (If you’ve ended up here expecting a blog post about whale-spotting or whale-hunting, you’re going to be disappointed!) This week, we’re covering whaling attacks. This type of digital attack can feel even more personal than some others—and it can be just as dangerous. Here’s what you need to know about this unique attack vector. Whaling Attacks Explained A whaling attack is one where someone (typically outside the company) imitates a high-ranking company official, usually in an attempt to steal money from the company by tricking an employee into paying a fake bill. Whaling attacks can also be engineered to steal data or credentials. We recognize that this definition is a little murky, so here’s an example. Set aside your actual role at your company for a minute. Instead, imagine you’re a br...