IT security threats appear as London 2012 Olympic Games fast approach

Updated happygeek 0 Tallied Votes 304 Views Share

The head of the UK MI5 intelligence agency, Jonathan Evans, has this week warned that the London 2012 Olympic Games "present an attractive target for our enemies and they will be at the centre of the world's attention in a month or so". But most of the concern, and indeed the advice being doled out, is aimed squarely at the physical terrorist threat to the games. DaniWeb has been finding out what threats there are surrounding the 2012 Olympics from an IT security perspective.

dweb-olympics Although the physical threat does, in fact, cross over into the world of IT (at least hypothetically) with the possibility of a state sponsored hacking or malware attack on critical national infrastructure such as electricity supplies, the reality is likely to be less James Bond and more mundane in approach.

David Emm, a Senior Regional Researcher for Kaspersky Lab, has warned that cybersquatting of domains with similar sounding names to Olympic sponsors or official sites is a real danger. Not just from the driving traffic away from legitimate sites side of things, but also for the setting up of fraudulent phishing scam sites. "Cybercriminals entice people to visit a fraudulent web site that, at first glance, appears to be the legitimate site" Emm explained, adding "this could be used to sell bogus tickets, or simply to trick people into entering personal information".

We've already seen plenty of online ticket scams, many taking the SEO-poisoning route and using ads on Google and other high traffic sites to pull in victims before the scams are discovered and the adverts removed. With ticket availability remaining at a premium now the official lotteries for allocation have finished in the UK, these kinds of scams are expected to ramp up in the weeks remaining before the start of the games and reach a crescendo as star events such as the mens 100 metres final approach.

Then there's hacking to worry about "like any well-known organisation, there's the potential danger that some people might try to hack web sites associated with the Olympics" says Emm "not necessarily for financial gain but as part of a hacktivist campaign".

Perhaps of more concern to your average visitor to London for the 2012 Olympics though is the Wi-Fi network threat. Using unsecured wireless networks and free hotspots could be a major danger in the coming months. "Using an unknown, untrusted Wi-Fi network, it's possible for someone to intercept any data you transmit" Emm warns "so if you're using a laptop or tablet, make sure you have a secure connection by always using 'https' and use a unique, complex password for every online account."

Dani AI

Generated

This thread correctly flags three operational risks for a big, ticketed event: ticket fraud and lookalike domains, phishing, and insecure public connectivity. started the conversation about these vectors, and the comments from and underline the importance of practical controls. The notes below focus on concrete, immediately usable steps that were not fully spelled out in the replies.

For ticket purchases and resales: restrict purchases to official or authorised channels and documented resale programs; prefer payment methods with dispute/chargeback protection and retain electronic receipts and transaction IDs. When buying from a secondary market, use platforms that mark listings as verified and handle delivery (for example, verified-resale services). See official consumer warnings on Olympic ticket fraud and guidance for buying only from authorised sellers. (). ()

For connectivity and device safety at venues: prefer a personal mobile hotspot or a paid VPN over open Wi‑Fi; disable automatic network join, set device network profiles to “public,” and turn off local file/printer sharing before connecting. Keep OS and apps up to date and enable multi‑factor authentication on important accounts. Official public‑Wi‑Fi safety guidance covers these mitigations. (CISA public Wi‑Fi tips). (cisa.gov)

Physical charging risks and domain spoofing: avoid public USB charging ports (use an AC outlet, personal charger, or a USB data blocker) — law‑enforcement advisories have repeated this precaution. Also watch for lookalike (homograph/typosquat) domains: inspect certificate details, view the punycode form for suspicious URLs, and use bookmarks for critical services. Technical notes on IDN/homograph phishing explain how attackers register visually similar domains and how browsers display them. (FBI/CBS coverage on public chargers; IDN/homograph guidance). (cbsnews.com)

Summary: combine buyer-side controls for tickets, strict device/network hygiene for visitors, and simple technical checks (payment methods, verified resale platforms, VPN, MFA, password manager, avoid public USB). These steps translate the thread’s high‑level warnings into actions that materially reduce exposure at large events.

john29 0 Light Poster

it is very important that we keep our security tight for the people who will come to visit olympics.

PrimeOutsourcin -2 Junior Poster in Training

This is a right action. An event will flow smoothly if it has a good security.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.