Cyber-criminals around the world are increasingly focusing their attention on job seekers. According to the security firm Flashpoint, there has been a notable uptick in ploys involving phony job listings that attempt to get job seekers to give up personal information.
Perhaps the biggest surprise is the fact that this is only now becoming a growing threat. After all, from the cyber-criminal’s point of view, it’s low hanging fruit. Job seekers expect that they’ll be asked for all types of personal information when applying for positions, after all.
As long as the criminals take the time to make their offers appear legitimate, most applicants wouldn’t think twice about sending in their resume (complete with physical address and phone number), and then, a bit later in the process, their social security number and other personal and confidential information.
According to Flashpoint analyst David Shear, it’s not just personal information the criminals are after, however. Increasingly, criminals are seeking to engage the services of the people who “apply,” by using them as unwitting money mules, or using them as part of an intricate money laundering scheme.
On top of that, it’s all too easy for the criminal to respond to an applicant’s inquiry with an email containing an attachment (usually a poisoned PDF). Again, since the applicant thinks he (or she) has replied to a legitimate offer for employment, odds are excellent that they’ll open the attachment without hesitation.
At that point, whatever payload the poisoned file contained is installed onto their computer, which can have devastating consequences, depending on the nature of the malware the criminals want to install.
Shear also notes that he and his team have seen an increase in the number of inquiries on the Dark Web asking after compromised business accounts, and offers this explanation as to why: “Attackers want access to business accounts in order to leverage their phony job listings and recruit people who would ultimately participate in fraud without their knowledge.”
All that to say, job seekers beware. It seems that no low is too low where these criminals are concerned.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
Another week, another high-profile data breach, but this one can be filed under “Missed Opportunity.” The site in question is “TicketFly,” which is a web-based event ticket sales website owned by a company called Eventbrite. The TicketFly website was down since May 31st, and the normal homepage had been replaced by an image of Guy Fawkes with the message “Your Security Down I’m Not Sorry.”
A new study recently published by HPE Aruba called “The Right Technologies Unlock The Potential Of The Digital Workplace,” reveals some interesting details about technology in the workplace that’s worth paying attention to.
Microsoft just made a big, significant purchase that has raised more than a few eyebrows. They just acquired GitHub for a hefty $7.5 billion.
Do you own a Surface Book 4? If you do, you may have been unfortunate enough to get one that suffers from a peculiar screen flickering issue. It’s not known exactly how many Surface Book 4’s have been affected by the issue, but thousands of angry users have been comparing horror stories about it on various discussion forums around the web.
Apple’s Legions of users love FaceTime, but there’s a problem with the highly popular app. It only allows you to see and talk to one person at a time. Apple fans have been clamoring for Group FaceTime for almost as long as the app has existed, and soon, they’ll get their wish.
It seems like a new attack vector emerges on a weekly basis, and this week is no exception. The latest threat: Emails containing specialized audio files whose acoustic vibrations can damage your computer’s hard drive. This is possibly damaging to the point of causing system failure, data corruption, and making it impossible to successfully reboot your machine.
ZDNet Researcher Ryan Stevenson recently found a big problem on T-Mobile’s website regarding an unprotected API. As a result of the flaw, untold millions of T-Mobile’s customers’ account information was left exposed and completely unprotected. Literally anyone who stumbled across the site and tried to abuse it could access a wide range of customer information with no password required.
Cisco’s Talos Security Team has identified a new threat, and it’s a nasty one impacting more than half a million consumer-grade routers in the US. According to the Talos Team’s report, the new malware is impacting a broad cross-section of routers made by TP-Link, QNAP, Netgear, Mikrotik, and Linksys.
If you use Apple products, you may have noticed an annoying “feature”. If you’re using the messaging app on your phone and texting someone and then you move to your Mac and access the same program there, the conversation you were having on your phone isn’t present. The two devices are messaging islands that can’t reliably communicate with each other. Since they can’t, you can’t start a conversation on one device and then pick it up later on another.