'Don't Click on Things,' Says Cybercrime Expert

slfisher 1 Tallied Votes 896 Views Share

"It's unbelievable, the kind of data that's out there about you," Cisco's principal security strategist Patrick Gray told a crowd in Boise, Idaho, this morning.

The problem is that criminal hackers can use that kind of information to target a company, Gray said. He described one case where criminals in the Ukraine targeted a particular large company, went onto Facebook to look for employees of that company, and upon finding one, created a Facebook account in the name of one of her high-school friends and asked to "friend" her. When she did so, the "friend" then suggested she click on a link to see a picture of herself from high school -- which downloaded malicious software into the corporation's network, he said.

Before joining Cisco, Gray spent 20 years with the Federal Bureau of Investigation, including forming one of the first cybercrime units.

In particular, Facebook is huge, Gray said, noting that if it were a country, it would be the third-largest worldwide, after China and India. In other Facebook statistics:

  • 50 percent of active Facebook users log on to Facebook on any given day
  • 60 million users update their status daily
  • People spend more than 500 billion minutes per month on Facebook
  • 3 billion photos are uploaded every month
  • 5 billion pieces of content are shared each week
  • Millions of local businesses have pages
  • More than 20 million people become fans of pages
  • There is a total of 5.3 billion fans
  • 100 million people use Facebook through smart phones
  • 43 percent of all Americans -- 40 percent of men and 45 percent of women -- are on Facebook
  • In August alone, 41 million minutes were spent on Facebook

"Social media users believe there is protection in being part of a community of people they know," said Gray. "Criminals are happy to prove them wrong." He cited one study showing that 46 percent of people approached agreed to give full access to their sites on Facebook to users that were, respectively, a duck and a cat. 700 other accounts were compromised in just two hours by telling people that they could click on a link to talk to a 23-year-old woman, he added.

In a similar example, criminal hackers used Facebook to send people a link offering video of "cheerleaders gone wild," telling them that due to the nature of the video, people had to click to confirm that they were over 18 -- which downloaded malware to their computer.

"Men are pigs," Gray said, tongue-in-cheek.

Organizations need to educate their users to not click on things, Gray said.

Dani AI

Generated

The examples summarized by show a straightforward pattern attackers still use: build trust on social sites, then send a lure that gets someone to click. That pattern remains a major breach driver today — social engineering and credential misuse are still central to many confirmed breaches. (verizon.com)

Concrete, high-impact first steps for organizations and individuals:

  • Require phishing-resistant multi-factor authentication (start with admins and remote access). Microsoft telemetry shows MFA stops the vast majority of automated account-takeover attempts. (microsoft.com)
  • Put technical barriers in front of clicks: email/web gateways, URL scanning, safe-browsing controls and endpoint protection.
  • Reduce your attack surface: least-privilege access, remove unnecessary social integrations and keep software patched.

Make training useful, not cosmetic. Short, repeated, measured simulations with targeted follow-up work far better than a single yearly lecture; academic field work shows repeated, data-driven phishing campaigns reduce real-world click rates. For outreach to parents or students (as is doing), focus on clear behaviours: hover to preview, verify with a known channel, never enter credentials from a link, and report suspicious messages. CISA provides practical tip sheets and free resources for small organizations and families. (cris.tau.ac.il)

If someone clicks and you suspect compromise, follow an incident-response playbook: isolate the device, preserve logs/evidence, rotate exposed credentials, run endpoint scans/forensics, and notify your IR team and legal/compliance leads. NIST’s incident-handling guidance describes a repeatable triage and recovery process to follow. Compliance and KYC work (as notes) help, but they must sit alongside technical controls and continuous awareness to be effective. (csrc.nist.gov)

cisamitesh 0 Newbie Poster

In 2010 expansion session will take place which include
1.PaymentsKYC
2.Regulatory Compliance and
Data protection shall help indeed against Cyber crime

joelchrist -9 Posting Whiz

Informative news, Thanks for sharing.

remarkablyso 0 Junior Poster in Training

This is a great article. I've recently started doing 'cyber talks' to both parents and students about the use of Facebook, privacy warnings, how to set your settings correctly, what to watch out for etc.

It amazes me how trusting and innocent people are!

slfisher 0 Posting Whiz

thanks! glad you liked it!

Elihu5991 0 Junior Poster in Training

Wow. Powerful story. I'm sharing this on Facebook and will evangelize this.

jonlucas 1 Newbie Poster

It is not surprising to read the data on facebook...and don't be surprised too, if you find that stats rising, especially those related to facebook.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.