Monday, 5 January 2026

2019 Cyber Security: Social Engineering Is A Growing Threat

 

Man standing behind a clear glass screen with various computer symbols

Trustwave published its Global Security Report for 2019, which reveals the changing face of malware and data breaches. For business owners and IT managers, what is most important is how cybersecurity strategies must change to stay ahead of advances in attack speed and stealth.

Social Engineering Attacks On The Rise

Among the most significant findings of the report is that one of the biggest categories of threats doesn’t begin with malware at all, but instead are “social engineering” attacks that manipulate users into allowing malicious software to be loaded or access to otherwise secure resources. In 2018, social engineering was the top method of initial compromise.

Phishing, in which a user is presented with fraudulent emails or websites that appear legitimate, is designed to trick a trusting user into entering their credentials. Once the hacker (or hacking software) has the legitimate credentials, it logs into the resource to do its damage.

If the resources are technical in nature, such as the email administrator, network administrator, or other computer resources, the hacker can destroy data, install or distribute ransomware, steal personally identifiable information (PII) for identity theft, steal proprietary business information, or cause other damage. If the resources are financial in nature, purchases can be made and bank accounts emptied.

Warning to Executives

A subset of social engineering and phishing attacks is causing enormous damage. “Business Email Compromises” (BEC) are emails that appear to be from one person within the company and are sent to another. According to a Verizon 2019 Data Breach Report, senior executives are 12 times more likely to be the target of BECs and social engineering attacks in general. And their success is based on two factors.

  • The executives have access to vital company information and resources
  • The senior members of a company tend to be older and less computer savvy

In this kind of an attack, a hacker sends an email to Executive A that appears to be from another Executive B, who has authority. The email requests that access be granted to a company resource. Executive A grants the request, and the resources become instantly available to the hacker. Other requests might include making a purchase, transferring money, or sending a payment.

Imagine the damage when the right person in the company receives an email like this:

  • “Bob, Sally has forgotten her company email login information. Please reset her password immediately and send the information to her Gmail account.”
  • “Bob, please give Kevin access to the accounting volume on our server.”
  • “Bob, please reset my database password and send it to me asap.”
  • “Bob, the routing and account number for the bank wire for Supplier A has changed. Please send our next payment ASAP to the routing number 98764531 and account number 123456789.”

The recipient of this request doesn’t need to be an executive, but does need to have access to the requested resources.

How To Defend Your Company Against Social Engineering

Good endpoint protection can help to protect your users from receiving such emails in the first place. For example, emails that claim to be from your bank but don’t come from your bank’s email servers would be routinely captured by our cybersecurity systems.

But many of these emails don’t claim to be from a business. According to Trustwave, “84% of BEC messages used free webmail services for distribution, 12% used spoofed company domains, and 4% elected to employ misspelled or lookalike domain names to deceive recipients.”

And some social engineering threats don’t even arrive via email. A client of ours recently received a phone call from someone claiming to be an IT consultant, who directed the employee to grant the hacker on the line access to vital company resources.

Training Is The Key

Our Business Protection Toolkit offers many protections for your business, including strong Endpoint Protection, Behavior-Based security, real-time SIEM monitoring of your security logs, and more.

But all of them are strengthened by employees who are aware of the threats your company faces and how to detect them. Cyber Security Awareness Training is a critical part of any company’s cyber security plan, and we now offer it to all our cyber security clients.

In our training series, employees are taught to identify and prevent threats like these. They will be able to identify phishing emails, distinguish legitimate from illegitimate requests, and even detect malicious phone calls.

Get Protected

Data breaches, ransomware, stolen resources, unauthorized access to bank accounts, and other cybercrimes can put a company out of business. No matter the size of your company, from a sole proprietorship to hundreds or thousands of employees, your business needs comprehensive protection. Talk to us about our Cyber Security services, including our Business Protection Toolkit, so that your business doesn’t become part of a statistic in next year’s cyber security report. Contact us online or call us at 213-398-8771.

The Death of the Mac Malware Myth

 

Man sitting at a computer

Do you have Mac computers in your office? A lot of companies use them because there’s long been a myth that Macs are more secure than PCs. “There’s no malware for Macs,” the old saying goes. And while that used to be true, it’s far less true these days. In the year just past, more Mac malware was discovered than in any other year, indicating that as Macs become more popular, they become a bigger target for malware designers.

Why People Believe Macs Don’t Get Malware and Viruses

Plain and simple, Macs are less popular than PCs, especially in business environments, and therefore a virus designed for a Mac will have less effect than a virus designed for PCs. That makes it less attractive to malware designers.

Second, Mac’s OSx is built on top of a Unix-like operating system. Unix was developed as a teaching tool back in the 70’s and is extremely secure. It has evolved into many open-source variants and, because so many thousands of people have contributed to it and patched security holes, it is very secure. All Apple operating systems, like MacOS, have benefited from that history.

Why Even Mac Users Are Threatened Now

Some viruses don’t even depend on a specific computer to be malicious. Malicious code can live inside the scripting languages built into MS Word and Excel files that both Macs and PCs can now run. Malicious JavaScript can be embedded inside PDF files. Some malware even lives on web pages, where malicious software and fake web pages can steal your user credentials as part of a Phishing attack, exposing your business and personal data to the criminals of the dark web.

As for the Mac-specific threats, one user on Quora.com (a popular question-and-answer website) answered a question in 2017 about Macs and Malware and concluded with “I don’t use any anti-virus or anti-malware software on my Mac, but I wouldn’t dream of trying to do that on a PC.”

But 2018 turned out to be a banner year for Malware on Macs. An article on ArsTechnica.com discusses malware that they contend Apple knew about for 4 months and never announced its discovery. An article on ITSPmagazine.com wrote up a list of 11 recent malware and virus threats.

That’s not nearly the number developed for Windows PCs, but it still makes the case that if you use Macs for your business (and even your home) and you value your business (and personal information), you need to protect yourself and your business from these digital threats.

How To Protect Yourself From Mac Malware and Viruses

Generally speaking, reputable Mac software is approved and “signed” by Apple. With the rare public exception of the malware referenced in one of the articles above, Apple does a good job of ensuring that software in its App Store is safe. If what you need can’t be found there, go to the publisher’s official website rather than downloading the software from some other source.

Keep your software updated. A lot of malicious software exploits software bugs. Once the publisher discovers those bugs, they are quickly fixed and patched. If you keep your software updated, you’re less likely to have these kinds of vulnerabilities.

Install good antivirus and anti-malware software on your Macs. Better yet, “Advanced Endpoint Detection” (AED) tools can detect malicious behavior on computers even before they ever show up in a virus definition file. AED knows what normal activity looks like and what malicious behavior looks like, and can shut down malicious behavior when it sees it.

Always be aware of what you’re doing online. Most malware is transferred via the web and email. So training yourself to recognize legitimate websites and links is a good first step. Better yet, use software to monitor and filter your email for phishing attacks and malicious links.

How Digital Uppercut Can Help

All four of these steps are part of Digital Uppercut’s new Business Protection Toolkit. This system can help keep your software up to date, ensure only approved software is installed on your computers, guard your computer against malicious behavior with AED, and monitor your web and email traffic for online threats.

Then we back that all up with a Security Operations Center, where we live computer security experts who monitor your network log files for threat patterns and spring into action if threats are detected.

The Business Protection Toolkit can even help you meet compliance standards, ensuring that your network data is encrypted on a file and folder level, which is far more secure than full-disk encryption.

Contact Us Today

Whether your business network is all Mac, all PC, or a mix of both, let Digital Uppercut protect you from PC and Mac Malware and help keep your business running. Talk to us about our Rapid IT services, Data Protection, Disaster Recovery, Cloud services, and of course, our Business Protection Toolkit. Contact us online or call us at 213-398-8771today.

Beware Money of Transfer Scams

 

Person holding a credit card and entering its account number into a laptop

Buying a home is stressful enough, but now home buyers need to be aware of a new threat to their “happily ever after” story. Property buyers can be at risk of losing hundreds of thousands or even millions of dollars if they’re not careful because hackers have now stepped into an unlikely area of finance: money transfers. Money Transfer Scams are now a real thing...and like any danger, knowing about the threat is half the battle.

Money Transfer Scams for Consumers

The scam begins much like other scams: with the bad guys getting access to your email account. A common consumer (non-business) attack starts when they then monitor your email and read the conversations between you and your real estate professionals -- in particular, your title agents. And right around the time a bank wire transfer is due, the scammers send a fake email with different bank wire instructions.

The victim sees the email, assumes it is legitimately sent from their title agent, and then sends the money to the scammer’s bank account. Once the money lands in the scammer’s account, it is often transferred immediately to other bank accounts to make recovery harder.

And just like that, with one little mistake, you’ve become a victim of a money transfer scam and handed over hundreds of thousands of dollars of your hard-earned money to some stranger, and your dream of owning a home withers away.

Money Transfer Scams for Businesses

The same kind of scam also affects business owners and financial executives who regularly transfer money via bank wire. According to Forbes.com, just as with the consumer scam, the bad guys will often hack into a vendor’s email to learn who their clients are. Then they send fake invoices or collection notices to real customers, with payment instructions to wire money to the scammer’s bank account.

Similarly, scammers will hack into a business email account (usually one belonging to an employee responsible for paying bills by bank wire), identify the kinds of bills he or she usually pays, and then send emails that look legitimate but aren’t.

How To Avoid Becoming a Transfer Scam Victim

The FBI is well aware of these money transfer scams and is trying to publicize some basic measures to help you avoid becoming a victim. Their first piece of advice is to call the receiving party before making any bank wire transfer. A quick call to your title officer or vendor can confirm whether the bank account information is legitimate.

The FBI also advises you to change your email, bank, and other passwords frequently. Use mismatched and uncommon characters to make your passwords harder to guess.

While that is good advice, it is seldom good enough to prevent your email account from being hacked. Thousands of people click on phishing emails every day and voluntarily give up even the most complex passwords. Once that happens, unusual login activity to email and other accounts happens quickly.

The best way to protect yourself from money transfer scams and hacks, or breaches, starts with complete cybersecurity training for you and your business. Knowing what hacks, scams and phishing threats look like can help tremendously. You should also have comprehensive cybersecurity measures installed on your business network, including malware detection, two-factor authentication, application whitelisting, behavior-based protection, and more.

For an analysis of your network’s current vulnerability, as well as an assessment of how to make your network truly secure, contact Digital Uppercut. We’re the experts in cybersecurity for small businesses like yours, whether internal or external. Every day, thousands of computers are attacked, networks are infiltrated, resources are stolen, and data is encrypted and held for ransom. Don’t let you and your company become a victim. Contact Digital Uppercut today by calling 213-398-8771 or contact us here.

A New Kind of Hack Threatens Office 365 Email Accounts

 

Screenshot of a webpage showing Microsoft Office 365 application links

With the rise of Office 365 email accounts, a new kind of hack is becoming more common. Microsoft expects to have 120 million users by the end of 2018, so a hack targeting these users is likely to spread quickly. Knowing what to look out for is your best defense against having your Office 365 email hacked. Here’s what you need to know to guard against having your own email hacked, and your company hobbled by an Office 365 Cyber Attack.

How An Office 365 Account Gets Hacked

A typical attack begins innocently enough, often with a request to reactivate a suspended email account. The email looks a lot like a legitimate communication from Microsoft, except that Microsoft doesn’t disable email accounts in this way.

Image of a fake email message from a hacker

The link, which looks legitimate, is actually malicious. We are all used to seeing links in blue, and generally expect that a link with a URL (web address) in the text actually goes to that URL. Well, that is not necessarily the case; in this case, the link to Portal.office.com instead leads to a fake login page.

Once you arrive there and enter your real Office 365 username and password, the malicious software immediately begins its work.

Typically, that includes…

  1. Setting up forwarding rules so that every email you receive gets silently forwarded to people who monitor your email. These bad guys are looking for other account usernames and passwords, communication patterns, contact email addresses, and more. The more information someone has about you, the easier it is for them to launch increasingly more dangerous attacks.
  2. With this additional contact information, more emails are generated, ensuring the attack spreads within your organization and among your contacts.
  3. If someone with Office 365 administrative privileges falls for this ruse, the entire Office 365 account is now at risk, and even more dangerous and malicious attacks could happen.

How to Prevent An Office 365 Attack

Microsoft has developed tools to help organizations prevent Office 365 Attacks. They have set up a Security and Compliance Center where they can score the security of your Office 365 setup and provide suggestions to make it more secure.

Some of the features of this security center are only available for larger installations, but some are extremely effective and should be implemented on all Office 365 implementations, including…

  • Enabling “Multi Factor Authentication” for all users. That means all users must take additional steps to log in. Steps might include entering a one-time PIN sent via text message to a cell phone, using a fingerprint scanner, or answering challenge questions. While this is often inconvenient for users, it makes it nearly impossible for hackers to log in to an Office 365 account.
  • Enforce very strong passwords. No more “Password” or “123456” as your password. Long passwords that include punctuation, capital and lowercase letters, and numbers are now required to prevent brute-force hacking attacks.
  • Block forwarding within your Office 365 account.

Microsoft encourages you to visit the Security and Compliance Center at http://protection.office.com. However, you might find it difficult to implement all of Microsoft’s recommendations on your own. That’s where we can help. We’re experts at configuring Office 365 security measures, as well as other network security features, to help protect your business from hacks and threats of all kinds.

Of course, your entire business infrastructure becomes more secure with proper training. We at Digital Uppercut can also provide cybersecurity training to all of your employees. It is a very inexpensive service compared to the cost of a hack that disrupts your business or the cost of cleaning up a hacked system.

Secure Your Business Today

Call Digital Uppercut today and let’s talk about securing your business. We offer plans of all sizes for all kinds of companies. And while they’re all designed to help secure our clients and prevent hacks, they are also designed to help you run your business “as usual” and without overzealous security measures that could actually prevent your people from getting work done. Call us today at 818-713-1335 or contact us here for a free preliminary Security Analysis and consultation.

Beware of Fake WiFi Hotspots

 

Woman working on a laptop in an airport

Do you travel? Almost everyone does at some point or another, whether for business or pleasure. And you are probably very conscious of the threats of having your pocket picked or your luggage stolen while you travel. Well, you should also be aware that there are cybercriminals who are looking to steal from you, and the consequences could be far, far worse than a missing wallet. Whether you’re at an airport, any local restaurant or coffee shop, you need to beware of fake WiFi hotspots trying to steal your data.

How You Can Get Hacked On A Fake WiFi Hotspot

So how does a typical hack on a free or public WiFi network actually happen? There’s more than one way.

The most obvious way is for some malicious person or company to put up its own competing WiFi network. These “Evil Twin” networks are named in a way that looks legitimate, but is far from it. Once connected to one of these malicious networks, users are open to a variety of threats.

  1. Data Eavesdropping: For example, all of your data can be monitored and recorded by criminals. They can see the images you send, the text you type, and even the usernames and passwords you use.
  2. Malware Injection: These fake WiFi hotspots can be configured to load malicious software onto your phone or computer. These viruses or trojans then install themselves on your device and remain there, even when you leave the fake hotspot where you were originally infected. PC and Mobile Malware can steal your passwords, encrypt your data, hold it hostage, and spread to other devices.

And here’s how easily this can happen: The legitimate free WiFi at Los Angeles International Airport is called “_LAX Free WiFi”. A bad guy might name his Evil Twin network something as similar as “LAX Free Public WiFi,” and most of the travelers in the terminal would never know the difference. They’ll happily connect and have no idea they're being hacked by a fake WiFi network.

But the threats don’t come entirely from fake WiFi networks. They can also come from legitimate, but free and open wifi networks. There are dozens of programs that allow hackers to monitor unencrypted network traffic on wifi networks, and most of them are free to download.

Hackread, a website I monitor to learn about trends in hacking and cybersecurity, wrote about a recent report that tells how much at risk you are at certain airports around the country. The report, by Coronet (a cybersecurity software company), surveyed the top 45 busiest airports and rated each one with a “Threat Score”. Here are the top 5 most dangerous airports for connecting to free WiFi:

  1. San Diego International Airport (San Diego) Threat Index Score: 10
  2. John Wayne Orange County Airport (Santa Ana, Calif) – Threat Index Score: 8.7
  3. William P Hobby Airport (Houston) – Threat Index Score: 7.5
  4. Southwest Florida International Airport (Fort Myers, Fla.) – Threat Index Score: 7.1
  5. Newark Liberty International Airport (Newark, N.J.) – Threat Index Score: 7.1

How To Keep Your Devices Secure While Travelling

So what can you do to protect yourself? We wrote about Tech Travel Dangers and how to avoid them before, but here are some tips for you.

  • Don’t connect to free or open WiFi networks EVER. This is by far your best advice.
  • Bring your own WiFi, whether it’s your phone's hotspot or a separate device.
  • If you must connect to a public, encrypted network (wired or wireless), make sure that you have a software firewall enabled on your computer or mobile device.
  • When connecting to any public WiFi, even if it’s secure, instantly turn on a VPN (Virtual Private Network).

Whether you’re in an airport or in the middle of town, fake WiFi hotspots, as well as free or open WiFi networks, are dangerous. By the time your travels are over, you might find your entire office network hacked, your sensitive data breached, or worse.

Why Talk With Digital Uppercut?

That’s why you should talk with Digital Uppercut, whether you’re travelling or not. If your office networks and mobile devices are not secured, whether you think your staff might be connecting to fake WiFi hotspots or not, your business is vulnerable. And if your business is regulated (by medical, financial, or legal authorities), those vulnerabilities could not only cost you your data and your business, but huge fines and worse. Digital Uppercut is a company that not only specializes in digital security but is also an expert in regulatory compliance, including HIPAA, FINRA, and PCI. We can conduct a free preliminary audit to help you determine whether you are vulnerable. Contact us or call us today at 213-398-8771, and let’s set up a time to talk.

Spying on Your Employees?

 


So, your business is running well, you like and trust your staff, they are getting their work done, and the computers and network are mostly running fine. Then you come across an article or talk to an IT expert who says you should start spying on your employees. You’d never even imagined doing something like that...but is there some validity to the advice? Should you monitor your employees' computer activities? The answer is yes, and here’s why.

Risks of Not Spying on Your Employees

The fact that things are running well right now is no guarantee they will continue to do so, and the risks constantly threatening your business can be avoided with proper monitoring. Here are a few common risks your business faces and how monitoring can help you protect yourself.

  • Time Theft: You pay your employees to sit at their computers and accomplish specific tasks. You can’t (and shouldn’t) be physically standing behind each employee watching what websites they visit. There are countless stories of employees spending hours of every workday on Facebook and other social media sites, updating personal websites, selling items on eBay, or even working another job remotely. Any minute spent on personal or other non-business tasks is theft of your payroll dollars, not to mention your company’s productivity.
  • Bandwidth/Resource Theft: Video streaming is becoming more popular every day. Sites like Netflix, YouTube... and even videos sent and received via email... can consume huge amounts of employee time and network bandwidth. We recently had a client complain to us that their internet was slow. They wanted our advice about which internet service they should upgrade to. Before advising them on how to spend more money, we did an analysis of their bandwidth, only to find that employees were streaming Netflix all day long while they worked. We saved them hundreds of dollars every month by avoiding the upgrade.
  • Adult Content: In addition to streaming mainstream content, employees have been found to be watching pornography at work. Not only does it steal time and bandwidth, but allowing such activity opens you up to numerous lawsuits and huge legal costs. It’s best to avoid such things.
  • Dangerous Websites: There are tens of thousands of websites—and even entire countries—that are known to pose risks to any computer if visited. All a user needs to do is load a page from a malicious or compromised website to install a virus on their computer. From there, it’s only a matter of time until that virus can infect your whole network and take down your business. Even certain advertisements from sites as legitimate as Yahoo can include malicious spyware that can suck bandwidth and compromise your company’s privacy.

What to Monitor On Your Business Network

So, how can you avoid these problems for your business? We recommend that our clients monitor not only their employees, but every device on their network in the following ways:

  • Monitor Bandwidth By User and Device: You need a history of a user’s typical bandwidth usage to help you notice a sudden increase in bandwidth. Such an increase might indicate video streaming, sharing of company documents, excessive online gameplay, or worse. And it’s important to not only measure bandwidth by user, but also by device, since a compromised device (such as a network server, mail server, network access point, or other vital pieces of your network) might indicate usage by a hacker or virus.
  • Monitor Activity with Your Firewall and an SIEM: For many larger companies, we install firewalls that collect network traffic and then connect them to a Security Information and Event Management system (SIEM) that not only analyzes that traffic, but also alerts us when something looks suspicious. This technology can even apply Artificial Intelligence to detect abnormalities.
  • Block activity to certain countries and sites: We can configure many firewalls to block all traffic to and from certain websites that are known to be bad. It’s also possible to block traffic to and from entire countries.

The next time someone suggests spying on your employees, know that the advice is not coming from an overbearing Big-Brother-like desire to suppress employee creativity. It comes from a real concern for the health and welfare of your company and all its employees. Proper employee and computer monitoring can save your company from theft, viruses & malware and even lawsuits.

If you’d like to talk with us about implementing these kinds of monitoring systems in your business, we’re here for you. Contact us via email or call us at 213-398-8771 to set up a consultation.

Monday, 22 December 2025

What’s worse than getting hacked?

Laptop keyboard with a stethoscope

Doctors have a lot of deal with these days, especially with all the new changes in health insurance and advances in modern medicine. Getting hacked has got to be a horrible experience for doctors, too, because not only does someone else have a copy of your data, the "bad guys" may be holding your data hostage (and charging you thousands of dollars to get it back). Or they might simply have deleted it from your network entirely (including your backups).

So what could be worse than that?

The short answer is that the law has no problem with kicking a company when it’s down, and so, as your office might be struggling to figure out how badly you were hacked, to restore the lost data, and to get back to “business as usual,” the Department of Health and Human Services just might come along and fine you a million dollars or more.

Why One Company Was Fined 2.3 Million Dollars

In 2015, the FBI conducted an undercover operation where they bought some stolen medical records on the “Dark Web,” a part of the Internet that most people know nothing about. (Hint: It’s the marketplace for stolen data.) The FBI traced the data back to 21st Century Oncology, a company that performs cancer testing. The FBI found "personally identifiable information" (PII) and "Personal Health Information" (PHI) in patient data, including social security numbers, medical diagnoses, and more.

In December 2017, the Office for Civil Rights, a part of the HHS, reached a $2.3 million settlement with 21st Century (21CO) for violating HIPAA. Specifically, 21CO failed to...

  • Conduct an accurate and thorough assessment of the potential risks and vulnerabilities of their data.
  • Implement security measures sufficient to reduce risks and vulnerabilities sufficiently.
  • Implement procedures to regularly review information system activity records, such as audit logs, access reports, and security incident tracking reports.
  • Have a written “business associate agreement” before disclosing protected health information to third-party vendors.

Why does this matter to a small medical office like yours?

Because the OCR doesn’t care how small or large your practice is. If your company were hacked and your data were breached, they would apply the HIPAA standards and fine you accordingly. And in case you were wondering, you could also end up in jail.

And what’s more, you don’t even have to get hacked to get fined.

Notice that the four things that the Office of Civil Rights listed, none of them have to do with the actual breach of the data. ALL of them have to do with following the procedures to protect your data. In other words, protecting yourself from multi-million dollar fines is easy.

Here’s how you protect yourself

If you are just learning about your potential risk for huge HIPAA fines, there is really only one thing you need to know:

Protecting your practice starts with a HIPAA Risk Assessment. Simply having your Assessment done can save you almost a quarter of a million dollars in fines. And maybe just as importantly, it provides a clear roadmap to becoming HIPAA-compliant, securing your data, and protecting your staff and patients from the problems associated with a data breach -- including having your business shut down.

Generally speaking, small businesses, including medical practices like yours, often don’t have the budget to protect themselves the way a big business can. But 21st Century Oncology shows that just having a big business budget doesn’t mean you’re going to do the right thing.

Even with a small business budget, you can get protection that greatly exceeds whatever 21CO was doing.

It might interest you to know that 21st Century Oncology has since filed for Chapter 11 bankruptcy protection.

If your business stores or uses Personally Identifiable Information or Personal Health Information (like a physician, optometrist, dentist, hospital, attorney, therapist, psychologist, manufacturer, or personal care organization normally does), you need to protect yourself from the effects of getting hacked and having your data breached.

Find out how easy it is to have your HIPAA Risk Assessment completed. Digital Uppercut is one of the most thorough and respected Regulatory Compliance companies in Los Angeles. Our approach, which combines regulatory compliance with security and solid IT, is unique in Southern California. Contact or call us today, and let’s chat about you, your business, and what we can do together to help protect it.

What to do About Microsoft Ending Support for Your Software

  Microsoft has announced that it will no longer be supporting a long list of its software. On that list could be many programs you might ha...