<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Phishing Archives - L2 Cyber Security Solutions Ltd.</title>
	<atom:link href="https://www.l2cybersecurity.com/tag/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.l2cybersecurity.com/tag/phishing/</link>
	<description>#SecuritySimplified</description>
	<lastBuildDate>Thu, 01 Aug 2024 15:13:41 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.l2cybersecurity.com/wp-content/uploads/2023/03/cropped-Logo-Only-Favicon-Transparent-32x32.png</url>
	<title>Phishing Archives - L2 Cyber Security Solutions Ltd.</title>
	<link>https://www.l2cybersecurity.com/tag/phishing/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>#WeekendWisdom 091 Phishing for Credentials</title>
		<link>https://www.l2cybersecurity.com/weekendwisdom-091-phishing-for-credentials/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 20 Aug 2021 07:15:24 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[#SecuritySimplified]]></category>
		<category><![CDATA[#WeekendWisdom]]></category>
		<category><![CDATA[Clare]]></category>
		<category><![CDATA[Credential Phishing]]></category>
		<category><![CDATA[Credentials]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Google Account Login]]></category>
		<category><![CDATA[Google Drive]]></category>
		<category><![CDATA[Google Drive Link]]></category>
		<category><![CDATA[Limerick]]></category>
		<category><![CDATA[Link]]></category>
		<category><![CDATA[Microsoft Account Login]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Phishing for Credentials]]></category>
		<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[SharePoint Link]]></category>
		<category><![CDATA[Tipperary]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=2588</guid>

					<description><![CDATA[<p>Welcome to #WeekendWisdom number 91. This week we&#8217;re going to talk about phishing for credentials. This sounds familiar I covered something pretty similar back in #WeekendWisdom number 42 where I covered Consent Phishing. But credential phishing is where the criminals are going to try and get you to give up your login ID, usually your&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-091-phishing-for-credentials/">#WeekendWisdom 091 Phishing for Credentials</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Welcome to #WeekendWisdom number 91. This week we&#8217;re going to talk about phishing for credentials.<span id="more-2588"></span></p>
<div style="width: 1920px;" class="wp-video"><video class="wp-video-shortcode" id="video-2588-1" width="1920" height="1080" preload="metadata" controls="controls"><source type="video/mp4" src="https://www.l2cybersecurity.com/wp-content/uploads/2021/08/WeekendWisdom-091-lo.mp4?_=1" /><a href="https://www.l2cybersecurity.com/wp-content/uploads/2021/08/WeekendWisdom-091-lo.mp4">https://www.l2cybersecurity.com/wp-content/uploads/2021/08/WeekendWisdom-091-lo.mp4</a></video></div>
<h3>This sounds familiar</h3>
<p>I covered something pretty similar back in <a href="https://www.l2cybersecurity.com/weekendwisdom-042-consent-phishing/" target="_blank" rel="noopener">#WeekendWisdom number 42</a> where I covered Consent Phishing.</p>
<p>But credential phishing is where the criminals are going to try and get you to give up your login ID, usually your email address and your password. They can later on compromise your email account or perhaps log into your office systems to be able to execute a ransomware attack.</p>
<h3>How do they carry out phishing for credentials?</h3>
<p>The methods they use are varied, but a very sneaky one that they typically use is, they will send an email with an actual SharePoint link in there, or this could be a Google Drive link as well. People are very familiar with SharePoint links and Google drive links. They are usually fairly safe to click because these are things that people deal with on a day-to-day basis. They&#8217;re not some crazy dodgy site that you are being linked to. It&#8217;s something you&#8217;re familiar with.</p>
<p>Then when you click on the link, then it will say &#8220;Oh. You need to sign into your Microsoft account&#8221; or &#8220;&#8230; your Google account to be able to get into this document.&#8221; That&#8217;s where they catch you. They pop-up a login page and you give up your user ID and password in there. Now they have it.</p>
<h3>How can you protect yourself from this?</h3>
<p>So it&#8217;s really important that you implement something like multi-factor authentication to get an additional set of protections from these sorts of attacks.</p>
<p>So that’s it for this week. Lets be careful out there and we’ll talk to you again next week.</p>
<div class="fl-post-content clearfix">
<hr />
<h2>How can L2 Cyber Security help you?</h2>
<p>We offer a full range of <a href="https://www.l2cybersecurity.com/training" target="_blank" rel="noopener noreferrer">training programmes</a>, which can be delivered online or in-person<strong>*</strong>.</p>
<p>Contact us for more information at <a href="mailto:info@L2CyberSecurity.com" target="_blank" rel="noopener noreferrer">info@L2CyberSecurity.com</a>.</p>
<p><strong>*</strong>With appropriate social distancing and other health and safety measures adhered to.</p>
<hr />
<h2>Follow us on Social media:</h2>
<p>Liam is available on <a href="https://www.linkedin.com/in/l2actual/" target="_blank" rel="noopener noreferrer">LinkedIn</a> and <a href="https://infosec.exchange/@L2actual" target="_blank" rel="noopener">Mastodon</a>.</p>
<p>Follow L2 Cyber on <a href="https://www.linkedin.com/company/l2cyber/" target="_blank" rel="noopener noreferrer">LinkedIn</a>.</p>
<p><a href="https://www.l2cybersecurity.com/" target="_blank" rel="noopener noreferrer">© L2 Cyber Security Solutions</a></p>
</div>
<p>&nbsp;</p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-091-phishing-for-credentials/">#WeekendWisdom 091 Phishing for Credentials</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://www.l2cybersecurity.com/wp-content/uploads/2021/08/WeekendWisdom-091-lo.mp4" length="31363196" type="video/mp4" />

			</item>
		<item>
		<title>#WeekendWisdom 062 Email Thread Hijacking</title>
		<link>https://www.l2cybersecurity.com/weekendwisdom-062-email-thread-hijacking/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 22 Jan 2021 02:15:13 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[#SecuritySimplified]]></category>
		<category><![CDATA[#WeekendWisdom]]></category>
		<category><![CDATA[Clare]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Email Thread]]></category>
		<category><![CDATA[Email Thread Hijacking]]></category>
		<category><![CDATA[Hijacking Email]]></category>
		<category><![CDATA[Hijacking Email Threads]]></category>
		<category><![CDATA[Limerick]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Phishing Emails]]></category>
		<category><![CDATA[Tipperary]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=2429</guid>

					<description><![CDATA[<p>Welcome to #WeekendWisdom number 62. This week we&#8217;re going to talk about Email Thread Hijacking. Lets start with the basics. Phishing emails. Most people are familiar with phishing emails that come in from strange email addresses, that come into their mailbox with attachments or links and they have received decent cyber security awareness training which&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-062-email-thread-hijacking/">#WeekendWisdom 062 Email Thread Hijacking</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Welcome to #WeekendWisdom number 62. This week we&#8217;re going to talk about Email Thread Hijacking.<span id="more-2429"></span></p>
<div style="width: 1920px;" class="wp-video"><video class="wp-video-shortcode" id="video-2429-2" width="1920" height="1080" preload="metadata" controls="controls"><source type="video/mp4" src="https://www.l2cybersecurity.com/wp-content/uploads/2021/01/WeekendWisdom-062-lo.mp4?_=2" /><a href="https://www.l2cybersecurity.com/wp-content/uploads/2021/01/WeekendWisdom-062-lo.mp4">https://www.l2cybersecurity.com/wp-content/uploads/2021/01/WeekendWisdom-062-lo.mp4</a></video></div>
<h3>Lets start with the basics. Phishing emails.</h3>
<p>Most people are familiar with phishing emails that come in from strange email addresses, that come into their mailbox with attachments or links and they have received decent cyber security awareness training which means that they look at this and they say &#8220;There is an unsolicited email with a link or with an attachment. I should delete this because it&#8217;s malicious.&#8221; and get on with their day.</p>
<h3>How is Email Thread Hijacking different?</h3>
<p>But what happens if one of those emails comes into your mailbox and it&#8217;s actually a reply from somebody you know and is actually a reply from an email thread that you&#8217;re involved in. It might just say something like &#8220;Here&#8217;s the information you&#8217;re looking for.&#8221;</p>
<p>That&#8217;s going to be pretty believable and you&#8217;re probably going to click it to open that document or click on the link, that might open a document and you might get something that looks like this, this is saying this is an encrypted document or it could be just saying that it&#8217;s a protected document or it&#8217;s using a different version of word or an online version or an offline version.</p>
<p>But they always have the same instructions. Click &#8220;Enable editing&#8221; and click &#8220;Enable content&#8221;.</p>
<h3>What happens if you fall victim?</h3>
<p>So if you ever open a document and see this type of instruction, close the document immediately, never ever, ever click on &#8220;Enable content&#8221; because as soon as you do, the malware will run and it will go through your inbox and reply to emails in your inbox and try and spread this malware to other people by using the same technique.</p>
<p>So that&#8217;s Email Thread Hijacking. Never ever, ever click &#8220;Enable content&#8221;.</p>
<p>So that’s it for this week. Lets be careful out there and we’ll talk to you again next week.</p>
<hr />
<h2>How can L2 Cyber Security help you?</h2>
<p>We offer a full range of <a href="https://www.l2cybersecurity.com/training" target="_blank" rel="noopener noreferrer">training programmes</a>, which can be delivered online or in-person<strong>*</strong>.</p>
<p>L2 Cyber Security are also a partner of <a href="https://www.cyberriskaware.com/" target="_blank" rel="noopener noreferrer">CyberRiskAware</a> for online self-directed Cyber Security Awareness training and Phishing testing.</p>
<p>Contact us for more information at <a href="mailto:info@L2CyberSecurity.com" target="_blank" rel="noopener noreferrer">info@L2CyberSecurity.com</a>.</p>
<p><strong>*</strong>With appropriate social distancing and other health and safety measures adhered to.</p>
<hr />
<h2>Follow us on Social media:</h2>
<p>Liam is available on <a href="https://twitter.com/L2_Evangelist" target="_blank" rel="noopener noreferrer">Twitter</a>, <a href="https://www.linkedin.com/in/lynchliam/" target="_blank" rel="noopener noreferrer">LinkedIn</a> and <a href="https://www.instagram.com/l2_evangelist/" target="_blank" rel="noopener noreferrer">Instagram</a>.</p>
<p>Follow L2 Cyber on <a href="https://twitter.com/L2Cyber" target="_blank" rel="noopener noreferrer">Twitter</a>, <a href="https://www.linkedin.com/company/l2cyber/" target="_blank" rel="noopener noreferrer">LinkedIn</a>, <a href="https://www.instagram.com/l2cyber/" target="_blank" rel="noopener noreferrer">Instagram</a> and <a href="https://www.facebook.com/L2Cyber/" target="_blank" rel="noopener noreferrer">Facebook</a>.</p>
<p><a href="https://www.l2cybersecurity.com/" target="_blank" rel="noopener noreferrer">© L2 Cyber Security Solutions</a></p>
<p>&nbsp;</p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-062-email-thread-hijacking/">#WeekendWisdom 062 Email Thread Hijacking</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://www.l2cybersecurity.com/wp-content/uploads/2021/01/WeekendWisdom-062-lo.mp4" length="31334939" type="video/mp4" />

			</item>
		<item>
		<title>Not GDPR Compliant &#8211; Really?</title>
		<link>https://www.l2cybersecurity.com/not-gdpr-compliant-really/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 18 Jan 2019 15:36:10 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Scam]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=1573</guid>

					<description><![CDATA[<p>A colleague at another company forwarded me an email he&#8217;d received knowing that I&#8217;d get a kick out of it. It claimed to be from the UK GDPR Compliance Directory and that his company was not GDPR compliant. Of course no such directory exists and this was nothing but a ruse. In fairness it does&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/not-gdpr-compliant-really/">Not GDPR Compliant &#8211; Really?</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="alignleft size-thumbnail wp-image-1574" src="https://www.l2cybersecurity.com/wp-content/uploads/2019/01/Not-GDPR-Compliant-150x150.jpg" alt="Not GDPR compliant" width="150" height="150" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2019/01/Not-GDPR-Compliant-150x150.jpg 150w, https://www.l2cybersecurity.com/wp-content/uploads/2019/01/Not-GDPR-Compliant.jpg 300w" sizes="(max-width: 150px) 100vw, 150px" />A colleague at another company forwarded me an email he&#8217;d received knowing that I&#8217;d get a kick out of it. It claimed to be from the UK GDPR Compliance Directory and that his company was not GDPR compliant. Of course no such directory exists and this was nothing but a ruse. <span id="more-1573"></span>In fairness it does look like a professional email. There&#8217;s no spelling mistakes or poor grammar. There&#8217;s no sense of urgency included (e.g.- &#8220;You must fix this by tomorrow or else puppies will be harmed.&#8221;). The only link would create an email with the subject line of &#8220;please send me the GDPR non compliance report&#8221; to a &#8220;@europe.com&#8221; email address. So there is a whiff of legitimacy to this e-mail.</p>
<p>So here it is. I&#8217;ve removed the identifying bits from my colleague&#8217;s company, but it was his domain name where shown.</p>
<p><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-1575" src="https://www.l2cybersecurity.com/wp-content/uploads/2019/01/GDPR-compliance.jpg" alt="Not GDPR compliant email" width="826" height="668" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2019/01/GDPR-compliance.jpg 826w, https://www.l2cybersecurity.com/wp-content/uploads/2019/01/GDPR-compliance-300x243.jpg 300w, https://www.l2cybersecurity.com/wp-content/uploads/2019/01/GDPR-compliance-768x621.jpg 768w" sizes="(max-width: 826px) 100vw, 826px" /></p>
<p>The only <span style="color: #ff0000;">red flag</span> in this email was the From address. That was a peculiar looking domain name.</p>
<p>While there was no sense of urgency in the email, obviously the thought of your business having a negative listing isn&#8217;t good. Also this service is apparently &#8220;a <strong>FREE</strong> public service&#8221;, so surely it won&#8217;t cost anything to be able to make the listing positive. Right?</p>
<p>I&#8217;m sure if you clicked that link and sent an email looking for the report, an offer would be made to help you get a positive listing &#8230; for a small fee of a few hundred or thousand pounds (this is a UK site after all).</p>
<p>Even without the red flag on the from address, this whole email stank to me. It was simply trying to use a ruse to shame the domain owner into getting in contact to supposedly make their company GDPR compliant. As always treat any <a href="http://www.l2cybersecurity.com/v-cast-aside-e-mails-from-strangers/" target="_blank" rel="noopener">unsolicited email with the contempt</a> it deserves.</p>
<p>If you received anything like this, you can always get in touch with us at <a href="mailto:info@L2CyberSecurity.com" target="_blank" rel="noopener">info@L2CyberSecurity.com</a> and we will be happy to clarify for free. If you&#8217;d prefer an official response, you could contact the Data Protection Commission at <a href="https://www.dataprotection.ie/en/contact/how-contact-us" target="_blank" rel="noopener">https://www.dataprotection.ie/en/contact/how-contact-us</a></p>
<p>Lets be careful out there.</p>
<p>#SecuritySimplified</p>
<p>#GDPR #SimpleGDPR</p>
<p>The post <a href="https://www.l2cybersecurity.com/not-gdpr-compliant-really/">Not GDPR Compliant &#8211; Really?</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How to deal with Ransomware.</title>
		<link>https://www.l2cybersecurity.com/deal-with-ransomware/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 28 Sep 2018 14:01:57 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Commandments]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Defence in Depth]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Training]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=1407</guid>

					<description><![CDATA[<p>I want to come back to this topic on how to deal with Ransomware. This is because I keep meeting business people in the training that I deliver who, either know of somebody or have themselves, suffered a Ransomware incident. I have previously talked about how Ransomware can infect your machine. It can be by&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/deal-with-ransomware/">How to deal with Ransomware.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="alignleft size-thumbnail wp-image-1408" src="https://www.l2cybersecurity.com/wp-content/uploads/2018/09/Dont-pay-the-ransomware-150x150.jpg" alt="Deal with Ransomware" width="150" height="150" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2018/09/Dont-pay-the-ransomware-150x150.jpg 150w, https://www.l2cybersecurity.com/wp-content/uploads/2018/09/Dont-pay-the-ransomware-300x300.jpg 300w, https://www.l2cybersecurity.com/wp-content/uploads/2018/09/Dont-pay-the-ransomware.jpg 500w" sizes="(max-width: 150px) 100vw, 150px" />I want to come back to this topic on how to deal with Ransomware. This is because I keep meeting business people in the training that I deliver who, either know of somebody or have themselves, suffered a Ransomware incident. <span id="more-1407"></span>I have previously talked about how Ransomware can infect your machine. It can be by <a href="https://www.l2cybersecurity.com/evil-e-mail-knows-you/" target="_blank" rel="noopener">dodgy looking e-mails</a> or <a href="https://www.l2cybersecurity.com/dodgy-e-mail-looks-legit/" target="_blank" rel="noopener">legitimate looking e-mails</a>. The variety is endless, but it is generally all down to somebody clicking a link or opening an attachment. I&#8217;ve got an <a href="http://www.l2cybersecurity.com/v-cast-aside-e-mails-from-strangers/" target="_blank" rel="noopener">entire commandment</a> dealing with e-mails and how you should handle them.</p>
<p>What I&#8217;ve talked about above, is all prevention. However that doesn&#8217;t help you if you are staring at a monitor with a ransom demand on it. Let me give you a couple of examples of recently reported Ransomware incidents and how they were handled.</p>
<h3>Bristol Airport recovers from Ransomware Incident</h3>
<p>On the weekend of the 15th and 16th September, <a href="https://www.theregister.co.uk/2018/09/17/bristol_airport_cyber_attack/" target="_blank" rel="noopener">Bristol Airport suffered a Ransomware incident</a>. This incident took their flight information screens off-line for much of the weekend. Luckily no other safety or flight systems were affected.</p>
<p>How did the authorities at Bristol Airport deal with Ransomware? They re-built the systems and restored backups. They did not pay the Ransom.</p>
<h3>Scottish Brewery suffered a Ransomware incident from a job application.</h3>
<p>In the last couple of weeks, the <a href="https://www.bankinfosecurity.com/scottish-brewery-slammed-by-dharma-ransomware-variant-a-11537" target="_blank" rel="noopener">Arran Brewery in Scotland had all of it&#8217;s systems affected by Ransomware</a>. They had been running a recruitment campaign, advertising for a role via their own website. The evil doers took that ad and posted it to some international recruitment websites. The brewery then started receiving several e-mails a day from interested candidates from all over the world. In among those e-mails the bad guys slipped in one with Ransomware. The CV got opened and their files got scrambled. Not only were their live files affected, but their recent backups were too. These were stored online, attached to their network. Their most recent offline backups were 90 days old.</p>
<p>How did the brewery deal with Ransomware? They also re-built their systems and restored what backups they had. In this case though, they did consider paying the (GBP) £9,600 ransom. They came to the determination that the value of the data they lost (90 days of sales data) was less than the cost of the Ransom demand. They also took into consideration that paying the Ransom does not guarantee they would get back their data.</p>
<p>The brewery then did something really sensible. They have kept a copy of the scrambled data.</p>
<h3>Help may be available from the good guys.</h3>
<p>There is a not-for-profit, freely available service called <strong>No More Ransom</strong> (<a href="https://www.nomoreransom.org" target="_blank" rel="noopener">https://www.nomoreransom.org</a>). This is run by various Law Enforcement and Cyber Security firms around the world. They are constantly working on cracking the codes for the different Ransomware variants and enabling people to recover their data for free.</p>
<p>So the Arran Brewery is holding onto the scrambled data in the hope that someday they will be able to unscramble it.</p>
<h3>So how should you deal with Ransomware?</h3>
<p>Prevention is always better than a cure.</p>
<p>The first thing is to make sure you get your staff some security awareness training. This is something that I deliver. Details of the complete training is <a href="https://www.l2cybersecurity.com/wp-content/uploads/2018/04/Security-Awareness-and-Safety-Training.pdf" target="_blank" rel="noopener">available here</a>. We can do customised training to suit your organisation too. Call me on <span style="color: #ff0000;">087-436-2675</span> or e-mail on <span style="color: #ff0000;"><a style="color: #ff0000;" href="mailto:info@L2CyberSecurity.com" target="_blank" rel="noopener">info@L2CyberSecurity.com</a><span style="color: #000000;"> to discuss your requirements.</span></span></p>
<p>Then ensure that you have your systems <a href="http://www.l2cybersecurity.com/use-automatic-updates/" target="_blank" rel="noopener">updated/patched regularly</a>, have security appliances like <a href="http://www.l2cybersecurity.com/have-a-firewall-in-place/" target="_blank" rel="noopener">Firewalls in place</a>, <a href="http://www.l2cybersecurity.com/use-anti-virus/" target="_blank" rel="noopener">Anti-Virus is generally helpful</a> against malicious software and also you <a href="http://www.l2cybersecurity.com/ix-never-insert-a-strange-usb-memory-stick/" target="_blank" rel="noopener">shouldn&#8217;t insert strange USB devices</a> into your computers.</p>
<p>Finally, you should have a good data backup system in place. This can be a very simple set-up or more complicated depending on your business needs. Again, I offer advice and support on backup strategies and business continuity planning. I also have <a href="http://www.l2cybersecurity.com/iv-thou-shalt-always-backup-thy-data/" target="_blank" rel="noopener">a commandment about backups</a>.</p>
<p>That&#8217;s it! With all of the above in place, <span style="text-decoration: underline;"><strong>in the</strong> <strong>very unlikely event</strong></span> that you do subsequently suffer a Ransomware incident, you will be able to recover from it.</p>
<h3>What if it would cost me less to pay the ransom?</h3>
<p>This is a genuine struggle for a business owner, particularly small businesses. Recovering systems from a ransomware incident takes time, which costs money, and the business may be unable to operate while recovery is ongoing, so is not generating revenue. A good business continuity plan, should reduce such risks.</p>
<p>If you are tempted to pay, I just have two things I want you to consider:</p>
<ol>
<li>There is no guarantee that you will get your data back. Figures vary wildly from <a href="https://datarecovery.com/rd/half-ransomware-payments-resulted-decrypted-files/" target="_blank" rel="noopener">50%</a> to <a href="https://gbhackers.com/ransomware-attack/" target="_blank" rel="noopener">100%</a> failure to recover data. If you pay and don&#8217;t get your data back, you will then have to pay the full cost of recovery anyway.</li>
<li>You are funding organised crime. You are paying criminals who not only do cyber crime, but human trafficking, drugs, weapons, etc. People think I am being jokey or have my tongue in cheek when I refer to <em><strong>Evil Doers</strong></em>. I&#8217;m not. This is an accurate description of these people. They! Are! <span style="text-decoration: underline;"><strong>Evil!</strong></span></li>
</ol>
<p>If you pay once, then the bad guys reckon you might pay again, so you will be a bigger target. My advice to deal with Ransomware is to implement preventative measures (call me on <span style="color: #ff0000;">087-436-2675</span> or e-mail <a href="mailto:info@L2CyberSecurity.com"><span style="color: #ff0000;">info@L2CyberSecurity.com</span></a> to have a no obligation chat) and never pay these evil doers.</p>
<h3>What else do you need to consider?</h3>
<p>Don&#8217;t forget that if the data that gets scrambled contains personal data, then you have a data breach on your hands, which may be notifiable under the new Data Protection Act 2018 which incorporates the General Data Protection Regulation (GDPR). I&#8217;ve a short video here:</p>
<p><iframe loading="lazy" title="What is a data breach - Ransomware" width="500" height="281" src="https://www.youtube.com/embed/PVnq6Bu-GEA?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p>
<p>Finally, if you do suffer a Ransomware incident, a crime has been committed, so please report it to local Law Enforcement. They may not be able to do much about it, but it needs to be reported for statistical purposes if nothing else. If it can be shown that Cyber crime is as big a problem, as I know it to be, then the more reports to Law Enforcement will mean they will get more resources to be able to tackle it&#8217;s root cause.</p>
<p>#LetsBeCarefulOutThere and #StaySafe</p>
<p>#SecuritySimplified #GDPR</p>
<p>The post <a href="https://www.l2cybersecurity.com/deal-with-ransomware/">How to deal with Ransomware.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Sneaky Tax Refund e-mails</title>
		<link>https://www.l2cybersecurity.com/sneaky-tax-refund-e-mails/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Thu, 01 Feb 2018 09:55:55 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Commandments]]></category>
		<category><![CDATA[Fake]]></category>
		<category><![CDATA[Fraud]]></category>
		<category><![CDATA[GMail]]></category>
		<category><![CDATA[Password]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Scam]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=1139</guid>

					<description><![CDATA[<p>Tax refund scam e-mails are nothing new. They&#8217;ve been doing the rounds for many many years at this stage. Like the &#8220;Nigerian Prince&#8221; scams, that are enjoying a resurgence presently, the tax refund scams might catch out those who are new to the internet and may not have heard of such scams before. It is&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/sneaky-tax-refund-e-mails/">Sneaky Tax Refund e-mails</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignleft size-thumbnail wp-image-1141" src="https://www.l2cybersecurity.com/wp-content/uploads/2018/02/tax-refund-phishing-150x150.jpg" alt="Tax refund scam" width="150" height="150" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2018/02/tax-refund-phishing-150x150.jpg 150w, https://www.l2cybersecurity.com/wp-content/uploads/2018/02/tax-refund-phishing.jpg 300w" sizes="auto, (max-width: 150px) 100vw, 150px" />Tax refund scam e-mails are nothing new. They&#8217;ve been doing the rounds for many many years at this stage. Like the &#8220;Nigerian Prince&#8221; scams, that are enjoying a resurgence presently, the tax refund scams might catch out those who are new to the internet and may not have heard of such scams before.<span id="more-1139"></span></p>
<p>It is tax season in the US at the moment and there are a lot of scams going on, which the <a href="https://www.irs.gov/newsroom/tax-scams-consumer-alerts">IRS do warn people about</a>. This one caught my attention because it was a simple attempt to steal e-mail account credentials. Apparently there have been some changes made to the US tax code, which people are aware of but may not fully understand them, which may be enough to cause somebody to fall for this scam.</p>
<p>What happens is the victim receives an e-mail with the subject of &#8220;Federal Tax Refund Information&#8221;.</p>
<p>This e-mail then says &#8220;Good afternoon, I have a very important information for you concerning the Federal Tax Refund which I know that it will help you. Kindly check the attached file to view the details.&#8221; For those of you unfamiliar with <a href="http://www.l2cybersecurity.com/v-cast-aside-e-mails-from-strangers/">Commandment 5</a>, you might be tempted to open the attachment.</p>
<p>The PDF that is attached, when opened, simply contains what looks like a link to a Google Drive document.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-1142 size-full" src="https://www.l2cybersecurity.com/wp-content/uploads/2018/02/Screenshot_2018-01-25_17-08-40.png" alt="Tax refund scam google drive link" width="639" height="564" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2018/02/Screenshot_2018-01-25_17-08-40.png 639w, https://www.l2cybersecurity.com/wp-content/uploads/2018/02/Screenshot_2018-01-25_17-08-40-300x265.png 300w" sizes="auto, (max-width: 639px) 100vw, 639px" /></p>
<p>Which of course you want to look at because, money! There is also a sense of urgency introduced by saying the tax refund document is only stored for 14 days. While this is a fairly lengthy period by phishing standards, it still sows a sense of haste.</p>
<p>Clicking on the link, brings you to a website that looks an awful lot like a Google Docs sign-in page which, if you are not paying attention, might cause you to give away your Gmail account name and password. I refer, of course, to not paying attention in regards to the address of the sign-in page, which is circled in <span style="color: #ff0000;">red</span>:</p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-1143 size-full" src="https://www.l2cybersecurity.com/wp-content/uploads/2018/02/Screenshot_2018-01-25_17-05-54.png" alt="Tax refund scam google drive sign-in" width="616" height="536" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2018/02/Screenshot_2018-01-25_17-05-54.png 616w, https://www.l2cybersecurity.com/wp-content/uploads/2018/02/Screenshot_2018-01-25_17-05-54-300x261.png 300w" sizes="auto, (max-width: 616px) 100vw, 616px" /></p>
<p>That is not &#8220;https://accounts.google.com&#8221; which would be what you are would normally expect. Of course if a genuine account and password is provided, then the evil doers will now take full control over the e-mail account and use it for nefarious purposes, UNLESS of course you had followed <a href="http://www.l2cybersecurity.com/vii-use-two-factor-authentication/">Commandment 7</a> and used two-factor authentication. If you had, you could then laugh at the bad guys attempting to login as you and failing because of this brilliant protection mechanism.</p>
<p>Then you calmly go ahead and change that password in ALL accounts that you used it in, because it&#8217;s now compromised.</p>
<p>While this has been relating to the US tax season, expect similar carry-on during October in Ireland.</p>
<p>&nbsp;</p>
<p>The post <a href="https://www.l2cybersecurity.com/sneaky-tax-refund-e-mails/">Sneaky Tax Refund e-mails</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Dodgy e-mail that looks legit.</title>
		<link>https://www.l2cybersecurity.com/dodgy-e-mail-looks-legit/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 17 Nov 2017 10:45:27 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Commandments]]></category>
		<category><![CDATA[Fake]]></category>
		<category><![CDATA[Fraud]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Scam]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=984</guid>

					<description><![CDATA[<p>I received a dodgy e-mail on my personal account yesterday. I&#8217;m surprised the GMail spam filters didn&#8217;t catch it and flag it for me. Like last weeks story, this message looked kinda plausible.It was a typical UPS delivery notification scam, which the evil doers spew out tens of thousands of and expect at least one&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/dodgy-e-mail-looks-legit/">Dodgy e-mail that looks legit.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignleft size-thumbnail wp-image-985" src="https://www.l2cybersecurity.com/wp-content/uploads/2017/11/crash1_20110628102439_640_480-150x150.jpg" alt="Dodgy e-mail" width="150" height="150" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2017/11/crash1_20110628102439_640_480-150x150.jpg 150w, https://www.l2cybersecurity.com/wp-content/uploads/2017/11/crash1_20110628102439_640_480.jpg 300w" sizes="auto, (max-width: 150px) 100vw, 150px" />I received a dodgy e-mail on my personal account yesterday. I&#8217;m surprised the GMail spam filters didn&#8217;t catch it and flag it for me. Like <a href="https://www.l2cybersecurity.com/double-check-security/">last weeks story</a>, this message looked kinda plausible.<span id="more-984"></span>It was a typical UPS delivery notification scam, which the evil doers spew out tens of thousands of and expect at least one person to be waiting on a delivery to fall for it.</p>
<p>Here is the offending dodgy e-mail:</p>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-986" src="https://www.l2cybersecurity.com/wp-content/uploads/2017/11/UPS-Spam-1.jpg" alt="" width="516" height="352" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2017/11/UPS-Spam-1.jpg 516w, https://www.l2cybersecurity.com/wp-content/uploads/2017/11/UPS-Spam-1-300x205.jpg 300w" sizes="auto, (max-width: 516px) 100vw, 516px" /></p>
<p>To me, there are a number of obvious indicators that this is a dodgy e-mail:</p>
<ol>
<li>The sending address (the bit after &#8220;UPS View&#8221;) was not a UPS address.</li>
<li>The two links in the e-mail did not go to a UPS website.</li>
<li>Most obviously &#8230; I wasn&#8217;t expecting a delivery!</li>
</ol>
<p>So lets take them one at a time:</p>
<ul>
<li>Some e-mail clients don&#8217;t actually show you the whole e-mail address of the sender. They just show the <em><strong>Display Name</strong></em>, which in this case is &#8220;UPS View&#8221;. So if you were using such a client, then it would appear to be a legitimate UPS e-mail address. However in my case, there was this @aol.com e-mail address, which is not associated with UPS.</li>
<li>When you see a link in an e-mail or website, you can hover the mouse over it. Somewhere towards the bottom of your browser window, you should be able to see where the link is going to take you. In this e-mail&#8217;s case it was going here, which is not a UPS site:</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-991" src="https://www.l2cybersecurity.com/wp-content/uploads/2017/11/UPS-Spam-2.jpg" alt="" width="252" height="19" /></p>
<ul>
<li>In my case I wasn&#8217;t expecting any delivery. But what if I was? What if I was an under pressure procurement clerk in a large organisation? I&#8217;d be getting deliveries on a regular basis. I&#8217;d be very inclined to click on those links.</li>
</ul>
<p><span style="text-decoration: underline; color: #ff0000;"><strong>Please note</strong></span> I carried out the following action on a sacrificial machine, so please do not be tempted to ever click on links to see what happens next. It could end very badly for you.</p>
<p>So what would have happened if I did click on the link? A word document, with a name that started &#8220;Tracking-3154631&#8230;&#8221; was downloaded. This document, if opened, would persuade me to click on &#8220;Enable Editing&#8221; and then click on &#8220;Enable Content&#8221;. Once I had taken those actions, macros (a set of instructions for a computer) in the word document would have downloaded a really nasty piece of software. Then all of my files would have been scrambled and I would be presented with a ransom demand to get my data back.</p>
<p>If I was that under pressure procurement clerk, it would not have stopped at just the files on my computer, but any files that I could access on the company&#8217;s network. That could be very, very disruptive to the organisation.</p>
<p>Out of curiosity, I checked the website (the bit before the &#8220;/UPS/16-Nov&#8230;.&#8221;) that hosted that document. It appears to be a legitimate business website. However, they&#8217;ve probably been hacked by the bad guys, who are now using their site to host their malicious downloads.</p>
<p>UPS offer advice on <a href="https://www.ups.com/us/en/about/news/fraud-alert.page">fraudulent e-mails</a>.</p>
<p>As usual, we&#8217;ve even got a <a href="https://www.l2cybersecurity.com/v-cast-aside-e-mails-from-strangers/">commandment</a> that covers dodgy e-mails too. So have a read to see what you can do to protect yourself.</p>
<p>The post <a href="https://www.l2cybersecurity.com/dodgy-e-mail-looks-legit/">Dodgy e-mail that looks legit.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Double check your security.</title>
		<link>https://www.l2cybersecurity.com/double-check-security/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Thu, 09 Nov 2017 11:00:10 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Best Practice]]></category>
		<category><![CDATA[Commandments]]></category>
		<category><![CDATA[Fake]]></category>
		<category><![CDATA[Password]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Scam]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=980</guid>

					<description><![CDATA[<p>There is an easy double check that you can implement which will offer you excellent protection. It is called two factor authentication (or two step verification). I bring this up as a real-life scenario came to my attention this week. I was giving a training session and during a break one of the attendees asked&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/double-check-security/">Double check your security.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignleft size-thumbnail wp-image-981" src="https://www.l2cybersecurity.com/wp-content/uploads/2017/11/double-150x150.gif" alt="Double Check Security" width="150" height="150" />There is an easy double check that you can implement which will offer you excellent protection. It is called two factor authentication (or two step verification).<span id="more-980"></span></p>
<p>I bring this up as a real-life scenario came to my attention this week. I was giving a training session and during a break one of the attendees asked me about a strange WhatsApp message that she received.</p>
<p>She showed me the message, which reportedly came from Apple, about a transaction on her account, that occurred in Mexico, which they blocked. There was a link for her to check her account. She told me that she had clicked on the link, and after signing into her iTunes account nothing else happened. Before I could say anything, she clicked on the link again and there was the sign-in page.</p>
<p>I have to say, that the WhatsApp message and sign-in page looked very plausible and legitimate. There were no spelling mistakes or lousy formatting. I had to break the news to her that she had given her iTunes ID and password to the bad guys and she needed to change her password as quickly as possible. So I took her through the process on her iPhone. When we got as far as here, I breathed a sigh of relief.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-982 size-medium" src="https://www.l2cybersecurity.com/wp-content/uploads/2017/11/ios11-iphone7-settings-apple-id-password-security-change-password-300x177.jpg" alt="" width="300" height="177" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2017/11/ios11-iphone7-settings-apple-id-password-security-change-password-300x177.jpg 300w, https://www.l2cybersecurity.com/wp-content/uploads/2017/11/ios11-iphone7-settings-apple-id-password-security-change-password.jpg 550w" sizes="auto, (max-width: 300px) 100vw, 300px" /></p>
<p>With this <a href="https://support.apple.com/en-ie/HT204915">Two-Factor Authentication</a> turned on, the evil doers would not be able to access her iTunes, without access to her phone. That&#8217;s because Two-Factor Authentication is like a double check. When you sign in to an account with an ID and password, the service does a double check and sends a code to your phone as a text message, which you then type in to complete the sign in.</p>
<p>While we were reassured that her iTunes account was reasonably safe from being immediately hacked, I still got her to change her password to something new. I also advised her to change any other account that used that password as well.</p>
<p>This Two Factor Authentication malarkey is such a good idea, I&#8217;d even created it&#8217;s own <a href="https://www.l2cybersecurity.com/vii-use-two-factor-authentication/">commandment</a>.</p>
<p>The post <a href="https://www.l2cybersecurity.com/double-check-security/">Double check your security.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Malicious e-mail from Yahoo! breach.</title>
		<link>https://www.l2cybersecurity.com/malicious-e-mail-yahoo-breach/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Tue, 10 Oct 2017 14:46:57 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Commandments]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Scam]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Yahoo]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=937</guid>

					<description><![CDATA[<p>I&#8217;ve received the first malicious e-mail as a result of a compromised Yahoo! e-mail account. I&#8217;ve warned the individual and hopefully he still has control of the account and can secure it again.It&#8217;s a typical &#8220;phishing&#8221; e-mail, which attempts to get you to carry out some action (e.g.- open an attachment or click on a&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/malicious-e-mail-yahoo-breach/">Malicious e-mail from Yahoo! breach.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignleft size-thumbnail wp-image-938" src="https://www.l2cybersecurity.com/wp-content/uploads/2017/10/Yahoo-compromised-150x150.jpg" alt="malicious e-mail" width="150" height="150" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2017/10/Yahoo-compromised-150x150.jpg 150w, https://www.l2cybersecurity.com/wp-content/uploads/2017/10/Yahoo-compromised.jpg 300w" sizes="auto, (max-width: 150px) 100vw, 150px" />I&#8217;ve received the first malicious e-mail as a result of a compromised Yahoo! e-mail account. I&#8217;ve warned the individual and hopefully he still has control of the account and can secure it again.<span id="more-937"></span>It&#8217;s a typical &#8220;phishing&#8221; e-mail, which attempts to get you to carry out some action (e.g.- open an attachment or click on a link) and this will then lead to some attempt to compromise your computer. Google&#8217;s spam filters picked it up, so I was nice and safe. It is quite likely that this e-mail account was compromised as a result of the <a href="https://www.l2cybersecurity.com/yahoo-breach-round-3/">Yahoo! data breach</a> back in 2013. <a href="https://www.oath.com/press/yahoo-provides-notice-to-additional-users-affected-by-previously/">Yahoo! have admitted</a> that details of every single e-mail account they had, was leaked to evil doers.</p>
<p>These details included weakly protected passwords, so it is likely that the bad guys have accessed this individual&#8217;s account and downloaded his contacts. Here is the malicious e-mail in question, I&#8217;ve redacted the name portion of the e-mail address to protect the individual:</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-940 size-full" src="https://www.l2cybersecurity.com/wp-content/uploads/2017/10/Yahoo-spam1-1.jpg" alt="malicious e-mail" width="733" height="312" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2017/10/Yahoo-spam1-1.jpg 733w, https://www.l2cybersecurity.com/wp-content/uploads/2017/10/Yahoo-spam1-1-300x128.jpg 300w" sizes="auto, (max-width: 733px) 100vw, 733px" /></p>
<ul>
<li>So the Subject of the e-mail is &#8220;Statement from &lt;<em><strong>compromised e-mail address</strong></em>&gt;&#8221;.</li>
<li>The individual&#8217;s e-mail address is buried in the &#8220;From&#8221; address in the e-mail.</li>
<li>Also the last line of the e-mail is the name part of the e-mail address.</li>
<li>However this malicious e-mail did not actually come from that person&#8217;s Yahoo! account, but rather that &#8220;rimports.hostpilot.com&#8221; domain that Google picked up on. This e-mail originated in the Philippines.</li>
</ul>
<p>The use of the address is all an attempt to make it look like this e-mail is from somebody you know and perhaps trust and you may therefore be inclined to click on the link, as in this case. I&#8217;ve also redacted a part of the link in case any of my curious readers attempt to go to that address. I don&#8217;t want you to compromise yourselves. <span id="c128" class="notranslate">?</span></p>
<p>Even without Google&#8217;s spam filters, I would have been suspicious of this e-mail, as I had only ever exchanged 2 e-mails with him 3 years ago. So I would have abided by <a href="http://www.l2cybersecurity.com/v-cast-aside-e-mails-from-strangers/">Commandment 5</a>, I was not expecting that e-mail from that individual, so I certainly wouldn&#8217;t have clicked on the link.</p>
<p>So please watch out for any unusual e-mails that come to you from people with Yahoo e-mail addresses.</p>
<p>Let&#8217;s be careful out there.</p>
<p>The post <a href="https://www.l2cybersecurity.com/malicious-e-mail-yahoo-breach/">Malicious e-mail from Yahoo! breach.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Yahoo breach &#8211; Round 3 &#8230; Billion! ?</title>
		<link>https://www.l2cybersecurity.com/yahoo-breach-round-3/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Wed, 04 Oct 2017 09:31:58 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Commandments]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Password]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spear-Phishing]]></category>
		<category><![CDATA[Training]]></category>
		<category><![CDATA[Yahoo]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=931</guid>

					<description><![CDATA[<p>If you had a Yahoo!, BT or Sky e-mail account (also AT&#38;T, Frontier.com and Rogers) back in 2013, well you are definitely part of the latest and greatest Yahoo breach.It&#8217;s a record that will be hard to beat, but they have now confirmed that all 3 BILLION Yahoo! based customers had their account information stolen.&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/yahoo-breach-round-3/">Yahoo breach &#8211; Round 3 &#8230; Billion! ?</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignleft size-thumbnail wp-image-932" src="https://www.l2cybersecurity.com/wp-content/uploads/2017/10/Yahoo-We-did-it-150x150.jpg" alt="yahoo! breach" width="150" height="150" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2017/10/Yahoo-We-did-it-150x150.jpg 150w, https://www.l2cybersecurity.com/wp-content/uploads/2017/10/Yahoo-We-did-it.jpg 300w" sizes="auto, (max-width: 150px) 100vw, 150px" />If you had a Yahoo!, BT or Sky e-mail account (also AT&amp;T, Frontier.com and Rogers) back in 2013, well you are definitely part of the latest and greatest Yahoo breach.<span id="more-931"></span>It&#8217;s a record that will be hard to beat, but <a href="https://www.oath.com/press/yahoo-provides-notice-to-additional-users-affected-by-previously/">they have now confirmed</a> that all <span style="text-decoration: underline;"><strong>3 BILLION</strong></span> Yahoo! based customers had their account information stolen. They are all being contacted now with information on the compromise.</p>
<p>&nbsp;</p>
<blockquote><p>Subsequent to Yahoo&#8217;s acquisition by Verizon, and during integration, the company recently obtained new intelligence and now believes, following an investigation with the assistance of outside forensic experts, that all Yahoo user accounts were affected by the August 2013 theft.</p></blockquote>
<p>That&#8217;s an absolute world record number of accounts to have been compromised. Only Google or Microsoft would have more e-mail accounts than Yahoo!</p>
<p>As <a href="https://www.l2cybersecurity.com/worrying-aspect-yahoo-breach/">I&#8217;d indicated at the time</a> of the first Yahoo breach notice, they also provide e-mail services to a number of other internet service providers such as BT and Sky in Ireland and the UK. These accounts will have been compromised too. I provided a <a href="https://www.l2cybersecurity.com/yahoo-already-had-world-record/">number of helpful tips</a> in my second Yahoo! post when they went and set the previous world record for accounts breached, I&#8217;ll include them again here for you.</p>
<h3 data-blogger-escaped-style="text-align: justify;"><span data-blogger-escaped-style="font-family: &quot;helvetica neue&quot; , &quot;arial&quot; , &quot;helvetica&quot; , sans-serif;">Two-factor authentication:</span></h3>
<div data-blogger-escaped-style="text-align: justify;">
<p><span data-blogger-escaped-style="font-family: &quot;helvetica neue&quot; , &quot;arial&quot; , &quot;helvetica&quot; , sans-serif;">This will absolutely improve your on-line account protection by a huge amount. Particularly if you use an authenticator app like <a href="https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&amp;hl=en">Google Authenticator</a>. There is even an entire <a href="https://www.l2cybersecurity.com/vii-use-two-factor-authentication/">commandment</a> dedicated to it, because it is that good!</span></p>
</div>
<h3 data-blogger-escaped-style="text-align: justify;"><span data-blogger-escaped-style="font-family: &quot;helvetica neue&quot; , &quot;arial&quot; , &quot;helvetica&quot; , sans-serif;">Use unique passwords on every site:</span></h3>
<div data-blogger-escaped-style="text-align: justify;">
<p><span data-blogger-escaped-style="font-family: &quot;helvetica neue&quot; , &quot;arial&quot; , &quot;helvetica&quot; , sans-serif;">Yes, we know it’s difficult to do this, but this is where the bad guys win. If you haven’t received the <a href="https://www.l2cybersecurity.com/security-awareness-training/">excellent training</a> available from <i><a href="https://www.l2cybersecurity.com/">L2 Cyber Security Solutions</a></i>, then use a Password manager.</span></p>
</div>
<h3 data-blogger-escaped-style="text-align: justify;"><span data-blogger-escaped-style="font-family: &quot;helvetica neue&quot; , &quot;arial&quot; , &quot;helvetica&quot; , sans-serif;">Check auto-forwarding settings:</span></h3>
<div data-blogger-escaped-style="text-align: justify;">
<p><span data-blogger-escaped-style="font-family: &quot;helvetica neue&quot; , &quot;arial&quot; , &quot;helvetica&quot; , sans-serif;">If the evil doers have compromised your e-mail account, they may have done this in a very sneaky fashion by logging on once, and setting your account to automatically forward all received e-mail to them. This is a particularly stealthy way for them to spy on you. Go to your account settings now and check if there is any forwarding of mail going on.</span></p>
</div>
<h3 data-blogger-escaped-style="text-align: justify;"><span data-blogger-escaped-style="font-family: &quot;helvetica neue&quot; , &quot;arial&quot; , &quot;helvetica&quot; , sans-serif;">Don’t save welcome e-mails or password resets:</span></h3>
<div data-blogger-escaped-style="text-align: justify;">
<p><span data-blogger-escaped-style="font-family: &quot;helvetica neue&quot; , &quot;arial&quot; , &quot;helvetica&quot; , sans-serif;">When you sign-up to services or accounts, you provide your e-mail address and that service or account sends you a “are you the person who just signed up to us” type e-mail, followed by a “welcome to our service” type e-mail. You might also have forgotten your password for such accounts and requested a password reset which they helpfully send to you in an e-mail. </span></p>
</div>
<div data-blogger-escaped-style="text-align: justify;">
<p><span data-blogger-escaped-style="font-family: &quot;helvetica neue&quot; , &quot;arial&quot; , &quot;helvetica&quot; , sans-serif;">Well you really should delete all such e-mails after you have read them, because these will lead the evil doers to these accounts, where they will do another password reset and then compromise that account too. If they don’t know what services you subscribe to, they can’t do anything to them.</span></p>
</div>
<p>Lets be careful out there.</p>
<p>The post <a href="https://www.l2cybersecurity.com/yahoo-breach-round-3/">Yahoo breach &#8211; Round 3 &#8230; Billion! ?</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Phishing subject lines &#8211; Top 10.</title>
		<link>https://www.l2cybersecurity.com/phishing-subject-lines-top-10/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Thu, 20 Jul 2017 15:22:46 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Commandments]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Training]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=814</guid>

					<description><![CDATA[<p>What would you expect if you got an e-mail with the subject line of &#8220;Security Alert&#8221;? How about &#8220;Unusual sign-in activity&#8221;? You probably expect it to be an e-mail that is trying to raise your awareness about some potential security issue. I&#8217;m afraid it is likely not. These are just two examples from the Top&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/phishing-subject-lines-top-10/">Phishing subject lines &#8211; Top 10.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignleft size-thumbnail wp-image-544" src="https://www.l2cybersecurity.com/wp-content/uploads/2016/05/Phish-150x150.png" alt="Phishing Subject Lines" width="150" height="150" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2016/05/Phish-150x150.png 150w, https://www.l2cybersecurity.com/wp-content/uploads/2016/05/Phish.png 300w" sizes="auto, (max-width: 150px) 100vw, 150px" />What would you expect if you got an e-mail with the subject line of &#8220;Security Alert&#8221;? How about &#8220;Unusual sign-in activity&#8221;? You probably expect it to be an e-mail that is trying to raise your awareness about some potential security issue. I&#8217;m afraid it is likely not. These are just two examples from the Top 10 Phishing Subject Lines <a href="http://www.prweb.com/releases/2017/07/prweb14499138.htm">report</a> for Quarter 2 2017 that was release by KnowBe4 recently.<span id="more-814"></span></p>
<p>The report shows that people are clicking on e-mails with the above subjects (which could potentially be business related). However some of the other subject lines are not very &#8220;business-like&#8221; at all and people are still going into them and potentially bringing things like Ransomware into their employers networks.</p>
<ol>
<li><span style="color: #0000ff;">21%</span> Security Alert</li>
<li><span style="color: #0000ff;">14%</span> Revised Vacation &amp; Sick Time Policy</li>
<li><span style="color: #0000ff;">10%</span> UPS Label Delivery 1ZBE312TNY00015011</li>
<li><span style="color: #0000ff;">10%</span> BREAKING: United Airlines Passenger Dies from Brain Hemorrhage – VIDEO</li>
<li><span style="color: #0000ff;">10%</span> A Delivery Attempt was made</li>
<li><span style="color: #0000ff;">9%</span>  All Employees: Update your Healthcare Info</li>
<li><span style="color: #0000ff;">8%</span>  Change of Password Required Immediately</li>
<li><span style="color: #0000ff;">7%</span>  Password Check Required Immediately</li>
<li><span style="color: #0000ff;">6% </span> Unusual sign-in activity</li>
<li><span style="color: #0000ff;">6% </span> Urgent Action Required</li>
</ol>
<p>Clearly #4 above is not in anyway a business related e-mail (unless you are a United Airlines employee, obviously <span id="c128" class="notranslate">?</span>). However #3 and #5 could also be unrelated to your company&#8217;s day-to-day business.</p>
<p>The e-mails in the research actually made it passed any spam or malware filters that the surveyed organisations had in place, showing that technology cannot be completely relied upon to give 100% protection against the many evils on the internet. Your staff will be your last line of defence.</p>
<p>Of course you could avail of our <a href="https://www.l2cybersecurity.com/security-awareness-training/">Internet Security Awareness and Safety Training</a>. This will show your staff what to watch out for and how to handle such dodgy e-mails. It will also give them a very comprehensive insight into what threats are out there and how they can prevent downtime in your business</p>
<p>If you don&#8217;t want to go down that road, then at least have a read of <a href="https://www.l2cybersecurity.com/v-cast-aside-e-mails-from-strangers/">Commandment 5</a> of our very own Top 10 &#8211; <a href="https://www.l2cybersecurity.com/the-ten-commandments/">The Ten Commandments of Cyber Security</a>, which will give you plenty to think about in respect to handling e-mail with any type of phishing subject lines.</p>
<p>The post <a href="https://www.l2cybersecurity.com/phishing-subject-lines-top-10/">Phishing subject lines &#8211; Top 10.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
