For the last few weeks there have been reports of malware infections that state a computer has been locked until the owner pays a $300 “ransom” to the malware developers. This ransomware pretends to be a lock screen placed on your computer by the Department of Justice, Department of Homeland Security, and the FBI that states child pornography was detected on your computer. It then proceeds to state that you will face a $250,000 fine and imprisonment from four to 30 years unless you pay a fine in the amount of $300. If you do pay the money online then your account information is captured by the criminals that initiated the attack.
The infection will also check your web browser history to see if you accessed certain sites. If you have, it will include the list of matched web sites in the lock screen to further scare you into thinking that your activities have been monitored. This is just the infection accessing your browser history to trick you into believing the scam and you do not have to be concerned about it.
Cyber Security
•Phishing: a method to acquire sensitive information, such as usernames, passwords and credit card details by masquerading as a trustworthy entity. Identity theft is big business. Hundreds of millions of identities are exposed every year. Tens of millions of those are exploited in the commission of a financial crime. Phishing often uses a mix of emails and web sites that mimic well known and trusted brands. Examples include: banks, government agencies and shipping companies. This is a con.
Phishing often takes advantage of current events, making them more difficult to detect for the less tech-savvy.
How to recognize phishing scams:
•Requests for personal information
•Urgent wording
•The need to open either a URL or an attachment
•May use poor English
Often the domain from email does not match that from the link:
Email: jefferey.jones@whitehouse.gov
Link: http://elvis.com.au/card/
Identifying Malicious Links
Links may be designed to trick the eye:
•www.micosoft.com
•www.verify-microsoft.com
•www.mircosoft.com
These are not www.microsoft.com.
Best Practices
•Do not trust unsolicited email.
•Do not click links or attachments in unsolicited emails.
•Do not provide personal information or information about your organization.
•Do not respond to phishing emails.
