Don’t go phishing this is Cybersecurity Awareness Month!
21 October 2024
Cybersecurity Awareness Month 2024 runs throughout October and at Veritau, we’re raising awareness of cybercrime and cybersecurity issues affecting the public sector. Cybersecurity covers a wide scope, from high-level robust IT infrastructure to simpler measures that we are all responsible for, like password security. A cyberattack is an attempt to steal, expose, alter or destroy information through unauthorised access to computer systems. Cyber criminals are motivated by financial gain through money theft, data theft or business disruption. According to Deloitte 91% of all cyber attacks originate from phishing emails. That’s why this October we’re focussing on understanding phishing and how you can avoid falling victim to it. Don’t go phishing this is Cybersecurity Awareness Month!
What is phishing?
‘Phishing’ is when a fraudster uses scam emails, text messages (SMiShing), or phone calls (Vishing) to try and persuade you to give them your data or other sensitive information. They may also use you as an entry point to gain access to other systems. Often they will try to get you to visit a website which may also download a virus onto your computer.
Scammers will make you feel that they have a sense of authority over you and urge you that you need to act quickly. They may also threaten you with a consequence if you do not comply. These are all tactics to stop you from thinking critically and lure you into making a mistake!
What is spear-phishing?
This is when a scammer specifically targets one person, group, or organisation rather than distributing their messages indiscriminately. They will tailor their message to be of particular interest or relevance to you after having done some research. Remember, them knowing something about you does not mean they are trustworthy!
What is whaling?
This is the most common type of spear-phishing attack and refers to when scammers specifically target the ‘big fish’ – eg CEOs, Directors, Heads of Service, etc. The bigger the fish you are, the more likely you are to be targeted.
What could happen?
- Personal or business data could be taken – this can then be sold on without your knowledge.
- The attack could be costly – you may lose money or it could cost you time and effort to recover after the cyberattack.
- The supply of essential goods and services could be interrupted or your communications networks could be lost for a period of time.
What can you do?
- Be alert to ‘phishing’, ‘spear-phishing’ and ‘whaling’ emails, texts and phone calls.
- Don’t open suspicious emails – and be alert to when an email comes from an external sender.
- Don’t click on suspicious links – always think before you click.
- Don’t be baited by phishing emails that contain valid, targeted information about you or your job role.
- Ensure you keep your devices and software updated.
- Don’t reuse the same password on different online accounts or across your work and personal accounts. Use a strong password as prescribed by your organisation.
- Turn on multifactor authentication where available.
- Review your social media privacy settings to reduce what other internet users can find out about you.
- Always lock your computer when away from your workstation.
- Don’t give out your personal information unless you are sure it is a legitimate source.
- Destroy receipts with your card details on and post with your name and address on.
Useful Information
The Cyber Helpline is a charity that offers free expert help for victims of cybercrime, digital fraud, and online harm.
For more advice on how to create a strong password and the threats to look out for, checkout the Be Cybersmart Kit or visit the National Cyber Security Centre website.
Check if your data has been breached by inputting your email address on https://haveibeenpwned.com/ which will show if any of your accounts have been compromised. Change the passwords of any accounts shown or consider deleting them if they are no longer in use.