5 Cyber Security Measures Every Business Needs

5 Cyber Security Measures Every Business Needs

Cyber criminals are evolving at an alarming rate. Cyber-security product developers are on an infinite loop with felons, each trying to out fox the other with regards to data breaches. Security is absolutely necessary for brick and mortar establishments due to a myriad of reasons, but in 2019, the name of the game is cyber-security. Not only are data breaches an efficient way to steal trade secrets and financial information from businesses, but they can also be done remotely. A proficient hacker or scammer can access a company’s vital company information from halfway across the world, and from that same location, can devastate the company. Within minutes, they can access financial information, trade secrets, distribution and delivery schedules, and private customer information. To prevent this from happening to your business, here are 5 cyber security measures every business should have:

Iron-clad Passwords

This is Internet 101. Since the birth of the World Wide Web, we’ve been educating adults and children alike on the importance of having a strong password to access online accounts. Whether it’s a company’s financial information, or a Grubhub app on an executive’s phone, thieves can crack weak passwords to gain access. As such, it’s important passwords never contain personal information about an individual, especially if that information is visible on social media. Parents often include the name of their kids in their passwords, using their dates of birth for any numerical value requirement. Teens and young adults use the name of their favorite animal, sport, or music artist. Another common tactic is using common words that are easy to remember, and then spelling them backwards for a false sense of security. Experts at the National Cyber Security Alliance also do not recommend using sequences of characters that are near each other on the keyboard, such as “QWERTY,” the first six characters of the keyboard. The current recommended length for strong passwords is between 8-12 characters. If you’re unsure whether or not you password is secure, use an online password checker to verify the passwords level of  cyber security.

Fortified Firewalls

Firewalls have been around almost as long as passwords. Firewalls are shields that protect your business from harmful or insidious traffic. When you connect to the internet, the system is constantly communicating with the wireless network, both sending and receiving units of information known as packets. Firewalls monitor these packets and perform a risk assessment, blocking unsafe packets. These firewalls protect your company’s data from unauthorized remote access by criminals.

Antivirus Protection

Roland Cloutier, the Chief Security Officer for ADP, calls antivirus software “the last line of defense” when protecting your company’s data from hackers and other cyber-criminals. Not only can remote criminals access and view a company’s vital information, but they can also install vicious malware that will copy the target’s hard drive, and subsequently render the machine inoperable. Installing anti-virus and anti-malware programs aren’t enough, though. These programs need to be updated regularly as part of the infinite loop mentioned earlier. Every time a criminal finds a way to bypass an anti-malware product, the product requires changes to combat those breaches.

Laptops and Mobile Phones

It’s important to secure laptop computers and mobile smartphones associated with your business. For this, experts recommend encryption software so any remote felon attempting to access or copy the hard drive cannot do so without the proper password. They also stress the importance of never leaving these devices in ones vehicle, where they are easily accessible to thieves. “Lock-out” options are also standard for these devices in 2019. This setting allows you to establish a time period during which the phone lies idle. After that period expires, the phone locks itself, preventing anyone from accessing it without the password. Smartphones and laptops with remote-wipe features must be enabled. This way, if your device falls into the wrong hands, you can remotely wipe the device and prevent the leak of sensitive company information.

Employee Education

Last, but never least, it’s important your workforce is educated on the security measures in place and regularly enforces them on a day-to-day basis. Companies often neglect employee education under the false impression their IT team will be able to resolve all issues whenever they arise. The fact is, even IT professionals cannot anticipate every cyber threat, and may not be up-to-date on the very latest in cyber-criminal tactics. An ounce of this education is worth a pound of cure—Despite the level of technology literacy in the United States in 2019, an employer or business owner cannot assume an employee’s level of security knowledge. The prevention starts with employees, providing them with an intimate knowledge of company operations and how cyber security measures protect them. 

Regardless of your company’s industry or size, all businesses must update and maintain their cyber security. An ounce of prevention is worth a pound of cure when criminals can bypass cyber security, and devastate a company in minutes.

Phishers Want Your Direct-Deposit

Phishers Want Your Direct-Deposit

money lockedThe invention of direct-deposit payments in electronic banking have likely saved companies millions of dollars over the years in labor hours, materials, and fees that previously caused problems for companies. However, in an age where your paycheck is sent automatically to your checking account, phishers are seeking to exploit this automation for personal gain.

The Internal Revenue Service has reported an upswing in various types of fraud that directly target a company’s payroll. While the ruses come in many forms, one of the most popular is phishing emails disguised as legitimate correspondence from an employee or upper management. It’s always an instruction to alter payroll information so that funds would be rerouted to the scammer’s bank account. Once the deed is done, the money is withdrawn and the company is responsible to replace the missing funds. While the FTC and the IRS are constantly reevaluating their strategies for containing these types of fraud, this particular scheme is hard to detect and often goes unreported. The email can outsmart security measures set down by the company or within a company’s email server, and scammers take amounts that can just be written off as unfortunate missteps on behalf of personnel.

Frauds such as these have gone through an evolution as security technology becomes more sophisticated and what we know about internet culture continues to grow. Internet frauds used to be about volume and inattention to detail—thus the birth of phishers, who sent emails rife with spelling and grammar mistakes out to mile-long email lists, casting a wide net throughout the web. Education about fraud has forced scammers to be more cautious. Today, companies who have seen this scam in its newest form remark that these phishing emails look so authentic that there may not be a question in their mind before obliging their request. Security measures that have risen from the nucleus of electronic banking combat wire fraud every day in the United States. Large sums in wire transfers now throw up giant red flags. Phishers and scammers are getting more bang for their buck by taking smaller amounts with more frequency, lurking below the radar. This does not require sophisticated hacking skills. Just the ability to open a Gmail account. Phishers make the account look cosmetically convincing, then throw out the lure. One of the most targeted entities is non-profit organizations, because of the benevolent nature of their business. The idea of someone ripping off a charity or relief organization is horrifying, but the simplicity of scams like this make the opportunity too lucrative to pass up.

It’s frightening how simple the fraud is to pull off, but there is recourse for businesses who are vulnerable to such a scam. One of the non-profits who fell prey to this scam was KVC Health Systems, an agency for child welfare in Kansas City. Their IT director, Erik Nyberg, says it starts with comprehensive education on company procedures, “The CEO is never going to email you out of the blue and ask you for any deposit changes. And if you have any sliver of a doubt, call the person who is making the request.” He goes on to discourage executives and upper management employees from using their personal email accounts to send staff correspondence, and to set email filters that will catch suspicious incoming messages. Social media managers are also cautioned against posting any company information to their pages that could serve to bolster a phisher’s credibility.

If your business has been the target of this wire fraud scam, you are encouraged to report them to the Federal Bureau of Investigation’s IC3 tip line.

Catfish: Romance Scams in 2019

Catfish: Romance Scams in 2019

romance scams
Those who met their current significant other in an age before the internet often have a difficult time understanding courtship rituals in the year 2019. Even Gen-Xers who are navigating the single-scape are having trouble adjusting to the way social media and dating apps have changed the way relationships are formed in the United States. The internet has done wonderful things for the world of dating. It reignites old flames who haven’t seen one another since high school. It connects the dots between persons across the country. It brings together people from different walks of life for a far more interesting relationship. However, the anonymity of the internet and the potential to be whoever you want to be has fostered one of the most devastating types of scams that exist in the modern world: romance scams perpetrated by “catfish”.

If you follow internet culture, you’re likely aware of a television program called Catfish: The TV Show. The series is a continuation of creator Nev Schulman’s 2010 documentary simply called Catfish. The film followed Schulman’s journey through his own romance scam, in which he met a woman online named Megan through the internet. Megan claimed to be many things: a singer, songwriter, recording artist, photographer, rancher, and part of an equally-talented family. Through their online communications, Megan led Schulman to believe that her life was very picturesque, but tragically, she has cancer. After several attempts to finally meet Megan fall apart, Schulman and his production team make the trip to finally meet her and begin to realize along the way she may not be truthful about her identity. At the end of the film, Schulman and his team realize that there was never really a Megan. “Megan” was actually a middle-aged woman, Angela, who used the internet as a way of connecting with others in her insular life. The online identity of “Megan” was not entirely fiction—Angela did have a daughter named Megan, who was a photographer, and she used that piece of personal information to craft a persona that endeared her to men and garnered their attention on the internet.

Schulman’s story is unfortunately a common thread in today’s dating world. In 2011, a year or so after the documentary first premiered, studies showed that males between the ages of 40-49 and females between the ages of 50-59, made up the largest age groups effected by romance scams or “catfishing,” 28% and 35% respectively. In most confidence tricks, frauds, or scams, the goal is simply to rob an individual of their finances for personal gain. Catfish scams are particularly ugly, because it’s not just about money. A catfish’s target is often a trusting person, a benevolent person who might experience low self-esteem, and is often isolated from others for a myriad of reasons. That person makes a real emotional investment in the catfish with the intention and belief that they will spend the rest of their lives with that person when they finally meet.

“Catfish” is an appropriate name for this particular type of scammer, according to Special Agent Christine Beining, a seasoned financial fraud agent in the Federal Bureau of Investigation’s Houston Division. Even as recently as 2017, she says, romance scams were on the rise. According to the FBI’s website, in 2016, almost 15,000 complaints which fell under the umbrella of romance or confidence frauds were reported, which is 2,500 more than 2015. Beining characterizes a catfish in search of their next victim as throwing a fishing line, “The internet makes this type of crime easy because you can pretend to be anybody you want to be. You can be anywhere in the world and victimize people. The perpetrators will reach out to a lot of people on various networking sites to find somebody who may be a good target. Then they use what the victims have on their profile pages and try to work those relationships and see which ones develop.” She offers the example of a Texas woman who ended up sending a cumulative $2 million to a man she met over the internet who “said all the right things.” This catfish targeted the woman’s strong Christian faith, and capitalized on it to pull her into his web of deception. When scammers are using social media maliciously, how are we supposed to protect ourselves in a digital age?

One of the country’s best fraud watchdogs, the Better Business Bureau, conducted a study last year on the current climate of catfishing and other forms of romance scams. While there are some discrepancies among experts as to what defines a romance scam, four consistent stages of a scam emerge:

Contacting the victims

Like Christine Beining said, scammers use the internet as a fishing line, and create dozens of fake profiles online with stolen pictures and manufactured personas in the hopes of netting a handful of victims. They hope to form an instant connection with that person, usually though an alleged common interest based on information mined from the victim’s page or profile. A potential victim loves to ski? Suddenly that catfish also loves to ski, even if they’ve never been. After a short period of time, the catfish will often encourage the victim to move the conversation somewhere else, like texting or another instant-messaging platform. This way, if their profiles are flagged by the social media platform as a scam, they will still be able to contact victims already in the net.

Grooming behavior

Like any predator, catfish depend on grooming behavior to make the victim emotionally dependent on them. They learn about the victim’s life—their hopes, their dreams, their traumas, their family drama. This stage varies in length, but it can often go on for months as catfish attempt to build an impenetrable wall of trust around themselves and the victim. Endearing themselves so allows them to have credibility in the victim’s eyes when those around them might arch an eyebrow. In a further effort to telegraph their integrity, scammers might also send gifts to their victim as one of the hallmarks of a “real relationship.” This is the stage where scammers begin to test the limits of the victim. They ask for small favors, such as small cash amounts to buy groceries or pay the phone bill so their communication may continue. It’s also the stage where catfish begin to further isolate their victims from their friends and family so the fraud can continue unhindered.

The sting

This is where the predator’s bites out of a victim’s income become exponentially larger. In any romance scam, one of the most common plot points in the catfish’s narrative is an “emergency,” likely with themselves or a close member of their family for which they need a cash sum. It can be anything from hospital bills to a plane ticket. If the victim is always willing to send money, there’s no way to predict when the fraud will conclude. This is also where victims can find themselves in real danger. Victims who are not simply bilked out of their savings can easily get mixed up in things such as money laundering or larger scale frauds as an oblivious participant. In the most severe cases, victims get on a plane to meet the catfish and meet a violent fate at the hands of a person they thought was their sweetheart.

The fraud continues

Exposing a catfish does not mean the nightmare is over. There has been an increase in brazen catfish continuing the fraud after being unmasked, this time disguised as a good Samaritan who just wants to help the victim get their money back. They can take the form of a law enforcement officer or a private investigator. The original persona might also reach back out sheepishly—admitting that they had been caught, but what originally began as a con to get their money has now become true love. It’s not uncommon for victims to allow the fraud to continue, having acknowledged the catfish’s honesty.

If you’ve been the victim of a catfish or romance scam, contact a private investigator today to learn how they can help you expose the culprit. A private investigator’s skill set and lack of any bureaucratic ladder will allow the case to move swiftly and efficiently, as time can be of the essence when chasing a scammer, who can quickly pack up their tent and move on to another social media platform before law enforcement pins them down. Private investigators also have no jurisdictional restrictions within their cases, which is particularly crucial to exposing scammers who are operating outside of the United States. They can also empower you with crucial knowledge to prevent the cycle of fraud from continuing. While it may sound callous to some, the best rule of thumb is to never send money to an individual you have never met in real life. After all, the internet is not a substitution for face-to-face interactions. If you’ve connected with someone over the internet, and the chemistry is there, a genuine person will not have the resistance and excuses that catfish often do when the jig is up.

Carie McMichael is the Media and Communication Specialist for Lauth Investigations International. For more information, please visit our website

 

What to Do About Robocalls

What to Do About Robocalls

CR-Money-Hero-robo-calls-1017

In recent months, many Americans have been receiving calls from parts of the country they have never heard from before. They wonder to themselves, “Who could possibly be calling me from Bristol, Rhode Island? I don’t know anyone in Bristol.” They accept the call, and a voice will tell them that an agent with their firm has reviewed their case file, discovering that they hundreds of dollars in credit card debt, and must pay it all immediately, or else face a smattering of other fees for failure to pay. Fraught with the anxiety of their credit score tanking, they address an envelope to the P.O. box where the voice instructs them to send a check for the full amount. Before they place that envelope in the mail, hopefully they’ll realize they’ve just received a robocall.

They’re almost commonplace nowadays, regarded as more of a nuisance rather than a crime. Strange numbers automatically dial out to phone customers across the country, claiming they’ve won a free cruise or asking for donations to a fraudulent cause. However, many Americans are still not certain about what robocalls are, or the fact that most kinds are illegal.

Robocalls are just one of the latest tools in committing consumer fraud over the phone. There is a great deal of legislation la-fi-lazarus-fcc-robocalls-20160729-snapdistinguishing which types of robocalls are legal. Conventionally they permit robocalls that convey important and/or emergency information, about things like school closures or natural disasters. With the rise of robocalls at the beginning of the millennium, the National Do Not Call Registry was established so that consumers could place themselves on a list in order to avoid them. However, legitimate telemarketing firms are still allowed to contact you over the phone for legal business, as long as your number is not listed on the Do Not Call registry, and you have not formally opted out of receiving phone communication from the business. Indiana law specifically requires that all prerecorded messages that bot calls are famous for must be introduced by a live operator, as well as providing an address where the caller can be reached.

These types restrictions have forced the “robo-callers” to evolve and adapt. Conventional methods of blocking robocalls have been successful in nearly extinguishing the presence of calls to landlines. With smartphones only growing in use throughout the country, the technology designed to stop robocalls has not yet been perfected for them. The good news is that consumers (like the one receiving robo-debt-collection-calls) are never without resolve when it comes to harassing calls from a number claiming to be a collection agency.

Regardless of whom the robocall claims to represent, there is no legal obligation to speak to anyone over the phone. In the event that the call is legitimate, it is perfectly legal to communicate through your personal or business legal representation. If the call is legitimate, the lawyer can represent your interests and review your options with you. If you are without representation, you can also retain the services of a private investigator to ensure that the call is legitimate. The internet provides the ability to perform a reverse-lookup of suspicious or unfamiliar phone number, but most websites require that you pay for the search results, and after you pay, it might turn out that the information is inaccurate. The professional services of a private investigator allow them access to specific tools that provide accurate information to verify the legitimacy of the robocall. Bearing in mind that there is no agency sanctioned to harass you via telephone, consumers who sign up for the National Do Not Call Registry might find this is an imperfect solution. It will merely put you on a no-contact list required to be observed by all accredited, registered businesses. Although there might be a decrease in unsolicited calls, it still does not prevent illegitimate businesses to contact you with robocalls.

nmr-iphone-2-v2The best recommendation that the Federal Trade Commission has made to consumers who are the victim of robocalls on their smartphones is downloading a third-party mobile app that uses both the hardware and the software of a smartphone to block robocalls from plaguing your mobile device,” “Call blocking apps let you create blacklists – lists of numbers to block from calling your cell phone. Many of these apps also create their own blacklist databases from numbers that have received significant consumer complaints. They also let you create whitelists – numbers to allow – that are broader than just your personal contacts.” This process has so far proven very effective. As users utilize the application, it builds a stronger wall that keeps unwanted robocalls out.

The days of telemarketers who always call during dinner are long gone. Now robots are doing the dialing work. As technology advances, Americans feel more and more paranoid about ways the criminal element might have access to their money. Robocalls have only made it simpler to manipulate vulnerable consumers into parting with their hard-earned income. The Federal Trade Commission is attempting to evolve even faster than scammers, developing technology similar to apps like RoboKiller and Nomorbo that can keep robocall schemes at arm’s length. Professionals like lawyers and private investigators are invaluable sources when validating the legitimacy of a robocall a consumer fears might be legitimate. The most important resource, however, is an informed consumer. Vigilance and skepticism are the first line of defense when dealing with robocall consumer fraud.