Posts

Showing posts with the label Phishing

5 hot topics to include in your cybersecurity awareness program

Image
You've heard me say this before, and I'm saying it again… your cybersecurity awareness program needs to be built with purpose. When you build your program with purpose, your program will be different from mine, Bill's, and Sally's. BUT… There are some topics that every cybersecurity awareness program needs to address, and I've got 5 HOT TOPICS YOU NEED TO INCLUDE IN YOUR PROGRAM Building a culture of cybersecurity – it's YOUR responsibility Cybersecurity isn't just my responsibility. It' isn't everyone else's responsibility. It's YOUR responsibility. Each person in your business makes a difference, and everyone needs to be invested in creating and maintaining a secure environment, and it starts with culture. Humans are the key to defending your business Tell your humans that they matter to you and why they matter. Social engineering Tell your humans what social engineering is, why it's being used, and how it's being used against them ...

Why can't you resist clicking?

Image
If you’ve been following me for a while you’ve heard about phishing, but have you ever wondered how the email was crafted? Perhaps you’ve been duped before and didn’t realize it until it was too late, because it felt like a Jedi mind trick.   I think we do a really good job of telling everyone to watch out for phishing emails, and not to click on them. But I think as an industry we fall short when it comes to sharing how those emails are crafted, why they’re so dang irresistible, and what they can do to reduce their risk of receiving those super slick emails.   To close this knowledge gap I now offer an on-demand video training class called “ Social Engineering: The Art of the Click”   During this video training, you’ll learn • What social engineering is • How cybercriminals create an irresistible offer  • Why you want to click • How cybercriminals come after you AND • What you can do today to stop cybercriminals from preying on you   ...

will the real slim shady please stand up?

Image
Let’s talk about phishing emails and impersonation. Hackers often use impersonation to get you to open their phishy emails. If the email is from someone you know you’re more likely to open it. For many years, Microsoft was the most impersonated company in phishing emails. It makes sense, I mean, what big business doesn’t use Microsoft? But there’s a new winner, and it’s DHL. In Q4 of 2021, DHL was the most impersonated company in phishing emails, thus dethroning Microsoft? Why the spike? Bad guys follow the money. Q4 means shopping, and with spikes in online shopping again last year, it only made sense that even more cherished Christmas presented would be shipped. How does it work? The attacker used a from name of ‘DHL Customer Support’ The Subject contains ‘DHL Shipment Confirmation…’ It works, because who doesn’t want to know where their package is?! Beware, DHL wasn’t the only shipping server that’s impersonated. FedEx entered the top 10 list as well. How can your cybersecurity awar...

My online phishing quiz is back

Image
December was a busy month for me. How about you? With all the busyness of the season, you might have missed my Phish or Friend Online Quiz Event. What’s this Phish or Friend Online Quiz Event you ask? It’s an online event that anyone can sign up for, and I’m sharing real life emails, and YOU have to decide if it’s a phish email from a bad guy, or legit. The faster you answer with the correct answer, the more points you get. It’s a great opportunity for you to get expert cybersecurity training that’s fun at an unbeatable price. What you get... 🎣 Practice catching phishing emails in a safe and controlled environment 📝 Test your knowledge ✔️ See how your phish detection skills up against others 😈 Learn how fraudsters lure you in 👉 Receive a bonus tip sheet to help you spot that phish Attend the Phish or Friend Quiz live on January 27 at 11 AM CT for only $12.99 per person. Register Today https://siliconprairiecyber.com/Quiz Some more notes for you: Phish or friend won’t be back until ...

What's your 2022 cyber resolution?

Image
Here are 5 Cybersecurity Resolutions that you can put to use in 2022 at work AND at home.   1.       Fight Phish Keep your eyes peeled for phishing emails. That means checking the sender’s email address (not just the from name), hovering over links, and not falling for tricks that demand urgency.   1.       Enable Multi Factor Authentication (MFA) This adds a second layer of security to your accounts. Even if the fraudster has your password, he can’t access your account because he doesn’t have your code. Get MFA codes via an app, text, or email. Turn it on everywhere!    3.       Use a unique password on every site (hint: use a password keeper) Unique passwords are awesome. If a bad guy gets your password for one account, he can only access that one account. Now, if you were still using one password everywhere, he could get into all your accounts AND you have to change the passwo...

Beware of the holiday phishing email

Image
  The bad guys are licking their candy canes in sweet, sweet anticipation.   Anticipation of what?   They can't wait to steal your holiday joy (and cash, passwords, and personal information) through the many online scams, cons, fake websites, phishing emails, and tricks they've prepared just for you. You’ll these scams everywhere this month. Especially in your inbox.   Let’s talk holiday phishing emails.   The holiday phishing email often includes an unbelievable coupon, special shopping offer, or impossible to get item. Other lures include bogus gift card offers, giveaways, contests, and too-good-to-be-true deals. The scams will also try to create a sense of "act now" urgency, like putting time limits on the deals.   How good are you phish catching skills? Find out in my Phish or Friend Online Quiz event on December 14 at Noon CT and only $12.99. Learn more and register at https://siliconprairiecyber.com/Quiz   I also talked ab...

How do your phishing skills stack up?

Image
Are you an entrepreneur, solopreneur, or a small business owner? Have you ever wanted to get in on some expert cybersecurity training, but never had room for it in your budget? Maybe you'd like to try you hand at one of those phishing email tests. Have you ever wanted to send a phishing email test to your employees' knowledge? You did some research but you found all the tech and expense put it out of your reach as a small business owner? I've been thinking about you, and how to get you the cybersecurity awareness training that you need, and you're why I've created a new service just for entrepreneurs, solopreneurs, and small businesses. And so a new Online Quiz Event called  Phish or Friend  was born. During Phish or Friend you will... 📝 Test your knowledge 🎣 Practice catching phishing emails in a safe and controlled environment ✔️ See how your phish detection skills up against others 😈 Learn how fraudsters lure you in 👉 Receive a bonus tip sheet to help you spo...

Black Friday and Cyber Monday Secure Shopping Tips

Image
Have you seen the Black Friday and Cyber Monday ads that started Nov 1 st ? The black Friday shopping that started Nov 4 th ? Clearly, businesses want you to spend your money shopping with them. And that means cyber criminals are just a few steps behind, and ready to snag your cash instead. In order to help you keep your money safe and receive the gifts you want this holiday season, I’m sharing… 10 TIPS FOR A SAFE AND SECURE HOLIDAY SHOPPING SEASON 1.  Turn on MULTI-FACTOR AUTHENTICATION Add that extra layer of security to all of your accounts by adding an extra step to your login-procedure. This is a code you enter after you submit your username and password. The code can arrive via an app (such as Google Authenticator), text, or email. It may also called to as dual-factor or two-factor and is abbreviated as MFA or 2FA. Enable it everywhere possible -especially on password keepers, email, and financial accounts. 2.  Avoid FREE WIFI That FREE WiFi you're using might ...

Are you a bad phisher or a good phisher?

Image
Phishing emails, they’re a big deal. That’s probably because ~91% of data breaches start with a phishing email. In response to the sheer volume of phishing emails out there, many companies include sending simulated phishing emails to their employees as part of their cybersecurity awareness program. The frequency, content, and punishment for failure can run the gambit. A few bad phishers have made headlines, and now the question ‘to phish or not to phish’ your employees is a hot topic. What did they do? They sent simulated phishing emails to their employees promising big bonuses (up to $10,000) as a thank you for all their hard work during COVID. They said their company had been receiving similar phishing emails IRL, and it made sense to simulate these types of emails. The worst phisher of all didn’t even tell employees for TWO DAYS that they failed the test. Many of those employees spent their ‘bonus money’ during those two days. What happened next? The employees got pissed. The employ...

Fight the Phish

Image
The theme for Week 2 of Cybersecurity Awareness Month is Fight the Phish From the Colonial Pipeline to T-Mobile, cybersecurity attacks have been rampant over the last 12-24 months. However, for all the emerging threats and news that are cropping up, phishing continues to quietly wreak havoc, and remains a major threat to individuals and businesses. Don’t overlook phishing as a cyber risk. It’s been a major threat for decades. In fact, 43 percent of cyberattacks in 2020 featured phishing or pre-texting, while 74 percent of US organizations experienced a successful phishing attack last year alone. Phishing is one of the most dangerous and effective attacks methods used against your organization. As a result, you need to know how to fight the phish. 3 TIPS TO HELP YOU FIGHT THAT PHISH AND WIN Know the Red Flags Phishes are masters of making their content and interactions appealing. From content design to language, it's difficult to determine whether the content is genuine or a po...

Don't get tricked by the word new

Image
Let’s talk about phishing emails and the techniques used by cyber criminals to get you to click. Today, I’m going to focus on the subject line.   The subject line is super important, and that’s why the bad guys are using it against you. Why is the subject line so important? The subject line is the first and only hint at what the email is about. If you can’t reel ‘em in with the subject line they might never open your email. In fact, the subject line is so important that marketers test different subject lines against each other to see which one will get the most opens.   Cyber criminals try to invoke a sense of urgency and emotions to get you to click. That’s why words like ‘URGENT’ and ‘IMPORTANT’ have appeared in their subject lines for years. But now, there’s a new word in the subject line, and that new word is ‘NEW.’   THE NEW WORD IS NEW.   WHY IS ‘NEW’ SUCH A POWERFUL WORD IN PHISHING EMAILS? Legit emails and alerts contain the word ‘new’ The...

Cybersecurity Awareness Month is coming

Image
Suddenly summer is over and pumpkin spice everything is out in full force, and that can only mean one thing…   Cybersecurity Awareness Month is coming.   That’s right, October 1 marks the start of Cybersecurity Awareness Month 2021!! Who else is excited?! This year’s theme is Do Your Part. #BeCyberSmart.  This year’s theme brings four new weekly themes, and provides you with some great opportunities to build relationships in your business.   As you’re churning out lots of awesome content and tips for Cybersecurity Awareness Month, I want to share some tips to keep in mind when your creative juices are flowing.   5 TIPS FOR WRITING CYBERSECURITY AWARENESS INFO Speak the language of business Keep it short and sweet Make your content mobile friendly Avoid technical jargon Don’t get lost in the weeds   Finally, if you need a guest speaker for Cybersecurity Awareness Month or need help planning I still have a few openings availab...

Rising Cryptocurrency Scams

Image
Did you know Bitcoin increased in value by almost 400% between October 2020 and April 2021? Fraudsters follow the money, and with the recent spikes in value and popularity of cryptocurrency it is no surprise that crypto currency email scams are flooding inboxes. HERE’S WHAT YOU NEED TO KNOW… WHAT IS CRYPTOCURRENCY? It’s a digital currency, and it doesn’t exist in a physical form. There's no central control – there isn't a central bank of digital currency. Bitcoin was the first. Ransomware tends to demand payment in Bitcoins. TOP 3 CRYPTOCURRENCY SCAMS TO WATCH OUT FOR Emails from businesses and government agencies asking for payment in cryptocurrency A person, website, or social media ad that only accepts payment via cryptocurrency Cryptocurrency investment opportunities TOP 3 TERMS USED IN CRYPTOCURRENCY SCAMS Urgently today Nearest bitcoin machine Day Runs Have you received any cryptocurrency scam emails? What happened? What did you do? Drop a comment below and share your sto...

Why phishing emails are bad for business

Image
Have you heard about the UC San Diego Health data breach?   It started with a phishing attack back in December, and now the personal info of patients, students, and employees could be in the hands of cybercriminals. The victims could face identity theft at any time.   A CLASSIC EXAMPLE OF AN EMPLOYEE DOING THE EVIL BIDDING OF THE BAD GUY. Employee(s) took action as directed in the phishing email. Those actions gave the hackers access to employee email accounts. The hackers could access everything in the employee email accounts.   WHY IT’S BAD FOR BUSINESS The hackers can access any password reset links that arrive via email. The hackers can access any multi factor authentication codes that arrive via email. The hackers can send emails directly from your email account and message your contacts requesting information or even changing payment instructions.   WHAT YOU NEED TO KNOW Sometimes maliciou...

Are the bad guys winning?

Image
  What do you think? Are the bad guys winning?   If you’ve been watching the news lately you might think, yes, the bad guys are prevailing over cybersecurity. In under a week over 1,500 businesses got hit with Ransomware thanks to a vulnerability in Kaseya VSA and the cyber gang REvil. Then there’s another cyber gang launching Trojan attacks against the Indian Military.   Sounds bad, right?   Let’s talk about some victories for the good guys . They arrested the suspected hacker Dr HeX for many cyber crimes, including financial fraud that affected thousands. Microsoft finally issues a patch to put an end to the PrintNightMare bug.   Don’t let the news overwhelm you . Businesses of any size can implement a successful cybersecurity strategy that can reduce your risk of cyber attack by 80%. But how...   FIVE TIPS TO PROTECT YOUR BUSINESS Beware of phishing emails Stop and think before you click Protect your accounts Secure your devices ...