croom new

Patriot Tech Services Inc. Blog

Patriot Tech Services Inc. has been serving the Wheelersburg area since 2006, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

New Cyberattack Targeting Remote Workers

New Cyberattack Targeting Remote Workers

Since the onset of the coronavirus, many businesses have managed to sustain themselves through remote work—also commonly known as telework. While this strategy has allowed quite a few businesses to survive, it has also opened them up to security threats. Here, let’s focus on one such threat: vishing, or voice phishing.

Warnings from Federal Agencies

The issue of voice phishing is currently being pressed by the Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Agency alike. Vishing is the same as any other phishing attack, just conducted through a voice call instead of an email or other form of message.

These agencies have announced that cybercriminals have begun a vishing campaign, directed toward those that are working from home. By extracting login credentials for corporate networks, these criminals can turn a profit by selling access to other cybercriminals.

The Vishing Strategy

According to the FBI and CISA, cybercrime groups have registered facsimile domains to mimic legitimate company resources before developing phishing sites to live on these fake domains. These domains commonly had a structure like the following:

  • support-[company]
  • ticket [company]
  • employee-[company]
  • [company]-support

If someone were to visit these pages, they would find a page that looked very much like a company’s login page to their virtual private network—so as a result, if someone were to input their credentials, the cybercriminal would then have the means to access the business’ network. These pages can even capture multi-factor authentication measures.

Once these pages are completed, the criminal groups responsible then begin to research a company’s employees to build a profile on them. Names, addresses, phone numbers, workplace titles, and how even how long an employee has even been employed at a company are all included in these dossiers. Then, using random or spoofed VoIP numbers, hackers call these employees and swiftly gain their trust.

Once this trust is acquired, the attacker directs the targeted employee to the spoofed VPN page. Quicker than you can say “social engineering”, the hacker can then access the legitimate account. From there, the attacker is free to do as they please—collecting data on other employees and contacts to take advantage of or extracting other data for financial gain.

With attackers now directing these vishing scams toward remote workers, it is more important than ever that your team understands how they can identify phishing scams

Identifying Scams

  • Be suspicious of unsolicited messages—including calls and voicemails—from those you don’t know. If possible, verify their identity through another means to ensure that they are legitimate.
  • Keep track of the number that any suspected vishing messages come from, as well as the Internet domain you were directed to.
  • Don’t visit a website on a whim after a caller directs you to it, unless you have reason to believe it is legitimate.

For more assistance with your business’ security, reach out to the IT pros at Patriot Tech Services Inc.. Give us a call at 877-874-4629 to start a conversation.

Tip of the Week: Getting a Better Wi-Fi Signal at ...
Will We Soon Leave Passwords Behind?
 

Comments

No comments made yet. Be the first to submit a comment
Guest
Already Registered? Login Here
Guest
Thursday, April 25 2024

Captcha Image

Mobile? Grab this Article!

Qr Code

Sign Up For Our Newsletter

  • First Name *
  • Last Name *

      Latest Blog Entry

      The topic of net neutrality has had a tumultuous past few years, with steps forward canceled out by steps taken back. However, new efforts are being considered to restore the policies that made net neutrality what it was in the first place.

      Latest News

      Patriot Tech Services Inc. launches new website!

      Patriot Tech Services Inc. is proud to announce the launch of our new website at www.patriot-techs.com. The goal of the new website is to make it easier for our existing clients to submit and manage support requests, and provide more information about our services for prospective clients.

      Read more ...

      Account login