Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Friday, June 3, 2022

Identifying and avoiding spam email and phishing scams

Updated MON JUL 31 2023


Approximately 10,746 days 
ago (1992) while working at Ticketmaster (an American ticket sales and distribution company / Live Nation Entertainment) as a call center supervisor and trainer I was first introduced to "email" – back then the email was nothing like it is today.  

In 1992 we used a basic monitor that looked more like small portable TV with a black screen and green text that was always left-justified to send an email.  Email messages would be sent using a line or two of code with your message, press enter, then wait for the cursor to start blinking whenever a message was received.  That was the basis of high-tech.  No cute little notification bell or fancy "you've got mail" in the '90s and absolutely nothing to fear. 

Fast forward to 2022 – one email can take over your computer, access your private documents, download malware, and lock you out of your computer among other unbeknown threats.  That's one bad step for man, one giant malware for mankind if you ask me.

"Email spam senders, or spammers, regularly alter their methods and messages to trick potential victims into downloading malware, sharing data, or sending money."  – Rahul Awati, Taina Teravainen, techtarget.com

Over the years email has helped advance the speed of business communications and helped others keep in touch with family without the need for a mailman or the "Forever Stamp" (always represents the current price of a one (1) ounce First-Class Mail postage) first promoted by the USPS (United States Postal Service) on April 12, 2007.

As not only an entrepreneur but one that helps other entrepreneurs market their businesses, I've seen hundreds of thousands of emails in my day.  Everything from promotional emails, email marketing, auto-reply, and drip campaigns, to Constant Contact, MailChimp, Keap, GMAIL, Hotmail, Yahoo Mail, EarthLink, and beyond.  In nearly 30 years I've managed to avoid most email phishing scams and spam messages to a fault. 

Identifying and avoiding email phishing scams

I've found that always looking at the "reply email address" of the email you received is your most efficient line of defense.  No, I don't trust spam blockers because hackers can be pretty tricky when it comes to navigating around well-known fences.  

In fig. 1 screenshot is phishing of an actual email said to be from Godaddy, yet the reply email address says has a typo and reading "Godady.com" which can easily be overlooked.


Other times you can identify email marauder by looking at the letters after the “dot” – as in “dot com” – to represent the Top Level Domain (TLD) such as Germany '.de', Australia '.au', Russia '.ru' which as you can see are all foreign.  Best practice would be "don't click on links" within emails that are not people or organizations, people, and companies you trust. But, I'll be honest, this can even be tricky.  

In fig. 2 screenshot is a screenshot of an email that is supposed to be from Apple, but the reply email address is "@t-online.de" – phishing for my Apple ID.


Don't open suspicious emails

Marking spam as spam when an unsolicited email makes an appearance in your inbox, never just delete it. Spam refers specifically to unsolicited bulk email (UBE). Unsolicited is the key word there. For example, You provide your email address to a company in order to download a business plan template. The company then begins emailing you updates about new products or related content. While the emails about new products or related content may be unwanted, they're not spam. Why? Technically speaking, You solicited them by giving the company your email address, which very well might sell your email address to another company. If this second company starts sending you emails, that's spam. Why? The emails from the second company are both unsolicited and unwanted because you never gave your email address to that second company.

Spam emails are almost always commercial and driven by a financial motive. These hackers try to promote and sell questionable goods, make false claims and deceive You into believing something that's not true.  Don't be bamboozled by the use of the logo.  

In Fig. 3 screenshot is a phishing email using an outdated version of the Godaddy logo.



Popular spam subjects often include: 
pharmaceuticals, adult content, financial services, online degrees, work-from-home jobs, online gambling, cryptocurrencies

The difference between spam and phishing

The primary difference between spam and phishing is that, although they both may be big nuisances:

• Phishing is actively aiming to steal login credentials and other sensitive data. 

• Spam is a tactic for hawking goods and services by sending unsolicited emails to bulk lists.

Don't forward emails to your friends or website designer

Forwarding your suspected emails to your friends or website designer will only spread the mayhem.  I've found that one of the best courses of action is to notify the "proposed" company of the spam by forwarding them the emails:

  • Godaddy abuse@godaddy.com
  • PayPal spoof@paypal.com 
  • Square spoof@squareup.com 
  • American Express spoof@americanexpress.com
  • Apple reportphishing@apple.com
  • USPS (United States Postal Services) spam@uspis.gov
  • FTC (Federal Trade Commission) reportphishing@apwg.org
  • Constant Contact abuse@constantcontact.com
  • SquareSpace reportphishing@squarespace.com
  • Wix security-report@wix.com
  • Weebly abuse@Weebly.com
  • Shopify safety@shopify.com
  • Webflow form-spam-reports@support.webflow.com
  • Jimdo privacy@jimdo.com
  • BlueHost tos@Bluehost.com

Most phone carriers in the U.S. allow you to report phishing text messages by forwarding the message to 7726 or SPAM. The Global System for Mobile Communications (GSMA) has designated 7726 (spells SPAM) for reporting spam texts, and most U.S. carriers are part of the program.

An example of a spambot could be using the bot to distribute links to an email phishing scam.

Try using (at) or _at_ and (dot) or _dot_ on website pages to avoid having email addresses found by spambots that search for a regex that matches email address formatting. By using _AT_ and _DOT_, the symbols that the spambot is looking for will not show up on the page, and therefore your email address will not be found. (Credit: Stack Overflow)

Over half of all global email traffic is spam

According to Cisco Systems, some 320 billion spam emails are sent every day, and 94% of malware is delivered via this medium.  Search by IP, domain, or network owner for real-time threat data.  Spam is always annoying, sometimes amusing, and often dangerous. According to Google, its Gmail service blocks more than 100 million phishing emails every single day.

You might also think for veterans like me who have had the same email company and email address for more than 20 years, and maybe it's a bit late to start using aliases, but think again. It's never too late to start dealing more effectively with the problem of email spam and phishing.


Related Content: Using Free Email Accounts for Business (Podcast: Morning Joe with Gibrón) 

 

Make a brand difference.™

Wednesday, April 27, 2022

Did your website just get hacked?

A relaxing day at the beach may be one person's definition of having fun. Unfortunately, this person may also be a hacker who's breached your website security while lounging at the beach – injecting scripts that redirect traffic to destinations where they usually get scammed or infected with malware. And more importantly, you don't even know it's going on until someone tells you.


No website security?


Not having website security is worse than being caught with your pants down. That's because you know when your pants are down, and the very moment you hear someone entering the room, you cover your goodies and smile as if nothing ever happened. But when your website has its pants down, you'll be clueless until someone sends you an email, text, or actually picks up the phone to call you and tells you about it. For a business owner, this can be a rather embarrassing experience.


"The most recent Microsoft breach occurred on March 20, 2022, when the hacker group Lapsus$ announced on Telegram that they had breached the company. Several Microsoft projects, including Bing and Cortana, were compromised in the incident."  

 – Fire Wall Times, Microsoft Data Breaches: Full Timeline Through 2022, March 23, 2022


In a nutshell, Hackers illegally access devices or websites to steal peoples' personal information, which they use to commit the crimes like identity theft. Many people shop, bank, and pay bills online. People also store financial information, like credit cards or bank account numbers, on their devices. This isn't probably one of your business' offerings, but it's happening more and more each day.  


Common types of cybersecurity attacks


If you used WIX, Squarespace, Weebly, or Webflow to build your website you are probably a fish out of water trying to identify the common types of cybersecurity attacks (SQL injections, DNS hijacking, Malware, Cross-site scripting).


Cybersecurity involves safeguarding your business' website against cyberattacks. One of the easiest ways to thwart attackers is using website security that offers continuous website monitoring to detect malware and any indicators of compromise.


Cyberattacks can be costly to fix


The cost of putting your website back in order after a cyberattack can run you hundreds, if not thousands of dollars. By acting quickly, you can often prevent further damage to your website and hopefully thwart additional attempts.  A hacked website costs your business a pretty penny because you will have to pay the website developer for the time they spend identifying the type of attack, whether the remaining files that make up your website can still be used, and removing files the hackers leave behind to do their dirty work.


If you are lucky and your pages are still in cache, or available in the Wayback Machine (digital archive of the World Wide Web founded by the Internet Archive), you will be able to recover your full content or at least take the text from the page.


Protect your visitors by keeping hackers at bay


Malware scans regularly check your website daily to look for any malicious code. Intuitive options allow you to set notification preferences for yourself. When malware, blocklisting, or security issues are detected on your website, you will be alerted immediately. Set up notifications, and you can avoid getting caught with your pants down.


Help ensure continuity and protect your business against adverse cyber events by using our comprehensive suite of security and resilience solutions. Exceptional threat management through a modern, cloud-native stack.


Oevae.com offers website security options that include:

  • Denial-of-service (DDoS) protection
  • Content Delivery Network (CDN) speed boost
  • Denial-of-service attack
  • A Firewall to prevent hackers
  • SSL certificate (Secure Sockets Layer) aka URL starting with "https://"
  • Malware scanning.
  • Unlimited site cleanups


The best brands create positive experiences

Your brand experience happens both live and online – for their audiences. But today's audiences have higher expectations. You also put a tremendous amount of time, effort, and money into building your brand and creating a website experience that visitors will appreciate. Don't throw it all away at the fingertips of a hacker.  If you need more information, contact us at
Oevae.com 
– we help you find website security solutions.