Category: Article

  • How to Secure Microsoft 365 for a Small Business: 12 Settings to Change

    By J. Mesa

    Most small businesses run on Microsoft 365. Email, calendars, files, and Teams all sit behind one sign-in. Criminals know that, so a Microsoft 365 account is the most common target in business email compromise. Microsoft supplies strong protections with most plans, and many of them stay switched off until someone turns them on. Work through this list with whoever manages your tenant.

    Is Microsoft 365 secure by default?

    Partly. Microsoft secures its data centers and the service. You are responsible for how your accounts are set up: who can sign in, how they prove who they are, and what they can share. Microsoft calls this the shared responsibility model. A tenant left on its original settings from years ago has gaps that attackers use every day.

    What are the most important Microsoft 365 security settings?

    1. Require multi-factor authentication for everyone. This single setting blocks the large majority of account takeovers. No exceptions for the owner. If your tenant has no custom policies, turn on Security Defaults in the Microsoft Entra admin center. It requires all users to register for multi-factor authentication and costs nothing.
    1. Protect administrator accounts. Give each administrator a separate account used only for admin work, with no mailbox and no daily use. Keep the number of Global Administrators between two and four. Require the strongest sign-in method you have on those accounts.
    1. Block legacy authentication. Old protocols such as POP, IMAP, and basic SMTP authentication can’t perform multi-factor authentication, so attackers use them to get around it. Security Defaults blocks them. Confirm that no old copier, scanner, or app still depends on them, and replace what does.
    1. Use the authenticator app with number matching. Text message codes are better than nothing, and they can be intercepted. The Microsoft Authenticator app with number matching resists the “approve this prompt” trick.
    1. Turn on the email protections. In the Microsoft Defender portal, apply the Standard preset security policy. It sets anti-phishing, anti-spam, and anti-malware protection to Microsoft’s recommended levels. With Business Premium or Defender for Office 365, it also enables Safe Links and Safe Attachments, which check links and files when a user opens them.
    1. Turn on impersonation protection. List your owners, executives, and finance staff as protected users, and your own domain as a protected domain. The filter then flags mail that poses as them.
    1. Tag external email. Enable the external sender tag in Outlook, so staff can see when a message “from the boss” came from outside the company.
    1. Block automatic forwarding to outside addresses. After taking over a mailbox, an attacker often creates a rule that forwards a copy of every message to an outside account. Disable external auto-forwarding in the outbound spam policy.
    1. Confirm that auditing is on. The unified audit log records sign-ins, mailbox access, rule changes, and file activity. You need it to investigate an incident. Verify it is enabled in the Microsoft Purview portal, and know how long your plan retains it.
    1. Tighten sharing. In the SharePoint admin center, change the default sharing link from “Anyone with the link” to “Specific people.” Set guest links to expire. Review which sites allow outside sharing at all.
    1. Stop users from approving apps. Attackers trick users into granting a malicious app permission to read their mail, which survives a password change. In Entra, restrict user consent so that an administrator must approve new apps.
    1. Publish SPF, DKIM, and DMARC for your domain. These DNS records stop others from sending mail that claims to come from your address. Google and Yahoo began requiring them from bulk senders in February of this year.

    Which Microsoft 365 plan should a small business buy?

    For most businesses under 300 users, Business Premium gives the best security value. Compared with Business Standard, it adds:

    • Conditional Access, which lets you set sign-in rules by user, location, and device
    • Defender for Office 365, with Safe Links and Safe Attachments
    • Defender for Business, an endpoint detection and response tool for your computers
    • Intune, to manage and wipe laptops and phones
    • Information protection, to label and encrypt sensitive files

    Bought separately, those tools cost far more than the price difference between the plans.

    What is Conditional Access?

    Conditional Access is a rules engine for sign-ins. Each rule says: when this kind of user signs in to this app under these conditions, require this. Useful starting rules:

    • Require multi-factor authentication for all users
    • Require stronger authentication for administrators
    • Block legacy authentication
    • Block sign-ins from countries where you have no staff
    • Require a managed, compliant device to reach company data

    Before you enforce any rule, create one emergency “break glass” administrator account with a long random password stored in a safe, and exclude it from the policies. It keeps you from locking yourself out.

    How do I check my Microsoft 365 security?

    Open Microsoft Secure Score in the Defender portal. It grades your tenant against Microsoft’s recommendations and lists each improvement with instructions. Treat the score as a to-do list. Work from the top, and check it each quarter.

    How do I know whether a mailbox has been hacked?

    Look for these signs:

    • Inbox rules the user did not create, often ones that move mail to the RSS Feeds or Conversation History folder or mark it as read
    • Forwarding to an unknown outside address
    • Sign-ins from unfamiliar cities or countries in the sign-in log
    • Sent messages the user did not write
    • Contacts reporting strange emails from the user
    • Multi-factor prompts the user did not start
    • A new authentication method or device registered on the account

    What should I do if an account is compromised?

    1. Reset the password.
    2. Revoke all active sessions, so stolen tokens stop working.
    3. Review and remove unknown multi-factor methods and devices.
    4. Delete suspicious inbox rules and forwarding.
    5. Review app consents and remove any the user does not recognize.
    6. Search the audit log to learn what the attacker read and sent.
    7. Warn the contacts who received messages, and your bank if invoices or payments were discussed.
    8. Ask your attorney whether the mailbox held data that triggers a notification duty.

    Do I need to back up Microsoft 365?

    Yes. Microsoft keeps the service running. Retention settings and the recycle bin cover short-term mistakes. They do not protect against a deletion nobody notices for months, a malicious insider, or ransomware that syncs encrypted files. A third-party backup for Exchange, OneDrive, and SharePoint costs a few dollars per user each month.

    What mistakes do small businesses make?

    • Exempting the owner from multi-factor authentication
    • Using a Global Administrator account for daily email
    • Leaving former employees’ accounts active and licensed
    • Sharing one mailbox password among several people in place of a shared mailbox
    • Leaving “Anyone” sharing links as the default
    • Ignoring Secure Score
    • Assuming the IT provider configured everything, with nothing in writing

    How does this apply to Google Workspace?

    The same principles hold: enforce two-step verification for all users, protect administrator accounts, turn on the advanced phishing and malware settings, restrict third-party app access, limit external sharing, and publish SPF, DKIM, and DMARC.

    Your next step

    Sign in to the admin center today and answer one question: does every account, including the owner’s, require multi-factor authentication? Then open Secure Score. Cerberus Cybersecurity reviews Microsoft 365 configurations as part of our risk and compliance assessments and writes the access policies behind them. Contact us for a review, or see our training to prepare your staff.

  • Unpaid Toll Text Scams: What Is Smishing and How Do You Stop It?

    By J. Mesa

    A text arrives: you owe $12.51 in unpaid tolls, and a $50 late fee applies unless you pay today. A link follows. You have not driven a toll road in months, but the amount is small and the deadline is close. That is the design. On April 12, the FBI’s Internet Crime Complaint Center warned that it had received more than 2,000 complaints since early March about texts posing as road toll collection services in at least three states.

    What is smishing?

    Smishing is phishing by text message. The word combines SMS and phishing. The message poses as a company or an agency you trust and pushes you to tap a link, call a number, or reply with personal details.

    How does the toll text scam work?

    1. The scammer sends the same message to thousands of phone numbers, without knowing who drives where.
    2. The text names a toll service and claims a small unpaid balance.
    3. It threatens a late fee to create urgency.
    4. The link leads to a website that copies the look of the real toll agency.
    5. The site asks for your name, address, and card number to “settle” the balance. Some versions ask for a driver’s license number as well.
    6. The scammer uses or sells the card and the personal details.

    The FBI notes that the texts use nearly identical wording, and that the link changes to imitate the toll service of whichever state the message claims to come from. The small dollar amount is deliberate. People argue with a $900 bill. They pay $12 to make a problem go away.

    What other smishing texts are common?

    • Package delivery. “Your package could not be delivered. Confirm your address.” These pose as the Postal Service, UPS, or FedEx.
    • Bank fraud alerts. “Did you attempt a $1,200 purchase? Reply YES or NO.” A reply triggers a call from a fake fraud department.
    • Account problems. Messages that pose as Amazon, Apple, Netflix, or PayPal and claim a locked account or a failed payment.
    • The boss. A text from an unknown number opening with “Hi, it’s owner’s name]. Are you free?” This leads to a [gift card request.
    • Wrong number. A friendly “Is this Sarah?” that turns into a long conversation and, weeks later, an investment pitch.
    • Job offers. Unsolicited offers of remote work with high pay for little effort.
    • Verification codes. A text or call asking you to read back a code you just received. The scammer is logging in to your account at that moment.
    • Prizes and refunds. You won, or you are owed money. Tap here.

    Why do text scams work so well?

    • People open nearly every text, and most within minutes.
    • A phone shows little of a web address, which hides a fake domain.
    • Email has spam filters built over decades. Text messaging has far fewer.
    • A text feels personal and urgent in a way email does not.
    • Legitimate companies do send texts about deliveries and fraud, so the fake ones fit an expected pattern.

    How do I spot a fake text?

    • You did not expect it. You ordered no package, drove no toll road, and made no purchase.
    • It creates urgency. A fee, a deadline, a locked account.
    • The sender looks wrong. A full ten-digit number, an email address, or an international number, where a real company would use a short code.
    • The link looks wrong. Odd endings, extra words, hyphens, or a shortened link that hides the destination.
    • It asks for payment or personal details through the link.
    • It tells you to reply “Y” and reopen the message to activate the link. That instruction exists to get around a phone’s link protections.

    What should I do if I get a toll text?

    The FBI’s advice is direct.

    1. Do not tap the link.
    2. Check your account through the toll service’s real website, which you type in yourself, or call the customer service number printed on your statement or transponder.
    3. Report the text at ic3.gov, and include the phone number it came from and the website in the link.
    4. Delete the text.

    How do I report and block scam texts?

    • Forward the message to 7726, which spells SPAM. This reports it to your carrier at no charge.
    • Use the report option in your messaging app: “Report Junk” on an iPhone, “Block and report spam” on Android.
    • Block the number.
    • Report to the FTC at ReportFraud.ftc.gov.
    • Do not reply, not even with “STOP.” A reply confirms that a person reads the number.

    Turn on the filters your phone already has. On an iPhone, enable “Filter Unknown Senders” in the Messages settings. On Android, enable spam protection in the Messages app.

    What should I do if I tapped the link?

    It depends on how far you went.

    • You tapped and entered nothing. Close the page. Clear your browser history and site data. Keep the phone’s software updated. You are almost certainly fine.
    • You entered card details. Call your card issuer now, dispute any charges, and ask for a new card number.
    • You entered a password. Change it right away, and change it anywhere else you used it. Turn on multi-factor authentication.
    • You entered personal details such as a driver’s license or Social Security number. Freeze your credit and watch your accounts.
    • You installed something. Remove the app, update the phone, and if the phone holds work email, tell your IT contact.

    How does smishing threaten a business?

    Your employees carry work email, files, and authentication apps on the same phone that receives these texts.

    • Stolen work logins. A text that poses as IT or as Microsoft sends an employee to a fake sign-in page. The phone sits outside your office firewall and web filter.
    • Stolen verification codes. An attacker who has a password texts or calls the employee and asks for the six-digit code.
    • Fake executives. Texts that pose as the owner ask for gift cards, a wire, or a quick call.
    • Payroll diversion. A text that poses as an employee asks HR to change a direct deposit account.

    How do I protect my business?

    • Add texts to your training. Most programs cover email and stop there. Show staff real examples of smishing. Our cybersecurity training includes them.
    • Set a rule: IT and leadership never ask for passwords or codes by text.
    • Verify by voice. Any request for money, gift cards, or a change to payroll or bank details gets a call to a known number.
    • Use stronger multi-factor methods. An authenticator app with number matching or a security key resists code theft better than a text message.
    • Set minimum standards for phones that hold work data: a screen lock, current software, and no unknown apps.
    • Make reporting simple. Tell staff to screenshot a suspicious text and send it to one named person.

    How can I tell whether a text from a company is real?

    Assume it is not, and check another way. Open the company’s app or type its web address. Call the number on your card or your bill. Legitimate banks, carriers, and agencies will have the same alert waiting in your account if it is genuine. No real company loses patience because you chose to verify.

    Does my business text its own customers?

    If you send appointment reminders, invoices, or delivery notices by text, scammers can imitate you. Tell customers what you will and will not send. Use a consistent number or short code. Keep links on your own domain, and never ask for card details or passwords by text. In the United States, carriers now require businesses that send texts from standard ten-digit numbers to register their brand and their messaging campaigns. Unregistered traffic gets blocked.

    Your next step

    Show the toll text to your staff and your family this week, and make sure each person knows the number 7726. For training that covers text, phone, and email scams together, see our services or contact Cerberus Cybersecurity.

  • The Change Healthcare Attack: Lessons for Every Small Practice and Business

    By J. Mesa

    For three weeks, medical practices across the United States have struggled to get paid. Pharmacies have had trouble checking insurance coverage. Billing staff have gone back to paper forms and phone calls. None of those practices was hacked. Their vendor was. The attack on Change Healthcare is the clearest lesson in years about what happens when a business depends on a single outside company.

    What happened to Change Healthcare?

    Change Healthcare, a unit of UnitedHealth Group’s Optum division, operates one of the largest clearinghouses for medical claims and pharmacy transactions in the country. On February 21, 2024, the company discovered an intruder in its systems and disconnected them to contain the damage.

    The shutdown cut the link between providers and insurers. Claims could not be submitted. Payments stopped flowing. Pharmacies could not process prescriptions through insurance in the usual way, and some patients paid cash or went without.

    Who is behind the attack?

    UnitedHealth has attributed the attack to the ransomware group known as ALPHV, or BlackCat. In early March, news outlets and blockchain researchers reported that a payment of about $22 million in bitcoin had moved to a wallet tied to the group. UnitedHealth has not confirmed whether it paid a ransom.

    What is the impact so far?

    • Hospitals, physician groups, dentists, therapists, and pharmacies nationwide have reported delayed claims and payments.
    • Small practices, which hold little cash in reserve, have borrowed money or delayed their own bills to make payroll.
    • The federal government has offered advance payments to Medicare providers, and UnitedHealth has set up a temporary funding assistance program.
    • On March 13, the Office for Civil Rights at the Department of Health and Human Services opened an investigation into the incident, citing its unprecedented scale.

    The company is restoring services in stages. The full count of affected patients and the method of entry have not been made public as of this writing.

    Why did one vendor’s outage hurt so many?

    Concentration. Change Healthcare sits in the middle of an enormous share of the country’s medical claims. Thousands of practices relied on it, often through their practice management software, without ever choosing it by name. Many did not know they depended on it until the day it stopped.

    Security people call this a single point of failure. When one supplier handles a function that nothing else can perform, its bad day becomes yours.

    I do not work in healthcare. Why should I care?

    Because every business has its own Change Healthcare. Ask yourself what would happen if one of these went dark for a month:

    • Your payment processor
    • Your payroll service
    • Your accounting or invoicing platform
    • Your email and file storage provider
    • Your scheduling or point-of-sale system
    • Your IT provider
    • The one supplier whose portal you order everything through

    If the honest answer is “we could not take money” or “we could not pay staff,” you have found a dependency worth planning for.

    How do I find my critical vendor dependencies?

    Spend an hour on this exercise.

    1. List your core business functions: getting paid, paying staff, serving customers, ordering supplies, communicating.
    2. For each function, write down every outside company it relies on.
    3. Ask the vendors that matter most which companies they rely on. The clearinghouse behind your billing software, the cloud host behind your records system.
    4. Mark any function with only one path and no backup.
    5. For each one, estimate how many days you could operate without it.

    How do I prepare for a vendor outage?

    • Identify a backup. For claims, enroll with a second clearinghouse now. For payments, keep a second processor or a manual method ready. Setting up an alternative during a crisis takes weeks.
    • Write the manual procedure. How do you take a payment, record an appointment, or submit a claim on paper? Store the forms and the instructions where staff can find them.
    • Build a cash cushion or a credit line. The practices suffering least this month had reserves or an open line of credit. Arrange the credit before you need it.
    • Keep your own copy of your data. Export customer lists, schedules, and financial records on a schedule, so a vendor outage does not leave you blind.
    • Know your contacts. Keep vendor support numbers, account numbers, and your insurance agent’s number on paper.
    • Check your insurance. Ask whether your cyber policy includes contingent or dependent business interruption coverage, which pays when a vendor’s outage halts your income. Many policies limit or exclude it.

    What should I ask my vendors?

    1. What is your plan if you suffer a ransomware attack?
    2. How long would it take to restore service, and have you tested that?
    3. Do you require multi-factor authentication on every remote access system?
    4. How and when will you notify us of an incident?
    5. Do you hold our data, and how is it protected?
    6. Which other companies do you depend on to deliver our service?
    7. What does our contract say about outages and data breaches?

    A vendor that can’t answer has told you how prepared it is.

    What should I do if a vendor of mine is attacked?

    1. Disconnect from the vendor’s systems until it confirms the connection is safe. Many providers cut their links to Change Healthcare within hours, which protected their own networks.
    2. Change the passwords and keys tied to that vendor.
    3. Switch to your backup process.
    4. Get facts in writing and watch the vendor’s official status page. Be wary of emails and calls that claim to come from the vendor. Scammers exploit every major outage with fake “support” and “payment update” messages.
    5. Call your insurance carrier and your attorney.
    6. Document your losses from the first day: lost revenue, extra labor, loan costs.
    7. Tell your customers or patients what is happening and what you are doing about it.

    What does HIPAA say about a breach at a business associate?

    Change Healthcare acts as a business associate for many providers and as a clearinghouse in its own right. Under HIPAA, a business associate must notify the covered entity of a breach, and the covered entity carries the duty to notify affected patients, though the two can agree that the business associate will send the notices. The Office for Civil Rights has said its investigation centers on Change Healthcare and UnitedHealth, and it reminded providers of their obligations to have business associate agreements in place and to make sure breach notifications happen.

    If you are a provider, find your business associate agreements now and talk with your attorney about how notification will work once the facts are known.

    What security lessons apply to my own systems?

    The public does not yet know how the attackers entered. The basics that stop most ransomware remain the same:

    • Multi-factor authentication on every remote access point
    • Prompt patching, starting with internet-facing systems
    • Offline, tested backups
    • Endpoint detection and response on servers and workstations
    • A written incident response plan
    • Trained staff

    Your next step

    Write down the one vendor whose outage would stop your income. Then call a competitor of that vendor and ask what it takes to set up a standby account. Cerberus Cybersecurity helps small businesses and practices map vendor dependencies, write continuity procedures, and meet HIPAA requirements. See our services or contact us.

  • Antivirus vs. EDR: What Is the Difference, and Which Does Your Business Need?

    By J. Mesa

    Your cyber insurance renewal form asks whether you run EDR on all endpoints. You run antivirus. Are those the same thing? They are not, and the gap between them explains why businesses with up-to-date antivirus still get hit by ransomware.

    What is antivirus?

    Antivirus is software that scans files and programs for known malicious code and blocks or removes what it finds. Traditional antivirus works from signatures. A signature is a fingerprint of a known piece of malware. The vendor updates the list, and the software compares each file against it.

    Modern products, often sold as next-generation antivirus, add machine learning and behavior checks that catch some malware nobody has seen before.

    What is EDR?

    EDR stands for endpoint detection and response. An endpoint is any device that connects to your network: a laptop, a desktop, a server. EDR software records what happens on each endpoint, looks for suspicious behavior, alerts you, and gives you tools to investigate and contain an attack.

    Think of antivirus as a lock that keeps known burglars out. EDR is a camera system with a guard: it watches what happens inside, notices someone acting wrong, and lets you lock the room they are in.

    What is the difference between antivirus and EDR?

    • What it looks for. Antivirus looks for bad files. EDR looks for bad behavior.
    • When it acts. Antivirus acts at the moment a file arrives or runs. EDR keeps watching after that moment.
    • What it records. Antivirus logs a detection. EDR records processes, network connections, logins, and changes, so you can trace how an attack unfolded.
    • How you respond. Antivirus quarantines a file. EDR lets you isolate a computer from the network, stop a process, and in some products roll back changes.
    • Who it needs. Antivirus runs with little attention. EDR produces alerts that a trained person must review.

    Why is antivirus no longer enough?

    Attackers changed their methods.

    • Stolen logins. Many break-ins use a real username and password. No malicious file exists for antivirus to catch.
    • Living off the land. Attackers use tools already built into Windows, such as PowerShell and remote administration utilities. To antivirus, those look like normal programs.
    • Fileless attacks. Malicious code runs in memory and never touches the disk.
    • Custom malware. Criminals alter their code for each victim, so no signature matches.
    • Hands-on attacks. In a modern ransomware case, a person works inside the network for days: stealing data, finding backups, and disabling security tools before the encryption starts. Each step is a chance to catch them, and antivirus sees few of those steps.

    EDR is built to notice that chain. A word processor that launches a command prompt, which downloads a tool, which starts copying password data, tells a story no single file reveals.

    What is MDR?

    MDR stands for managed detection and response. It is EDR software plus a team of security analysts who watch the alerts for you around the clock, investigate, and act.

    For a small business this matters more than the software. EDR raises an alert at 2 a.m. on a Saturday. Someone has to see it, decide whether it is real, and isolate the machine before the attack spreads. Few small businesses have that person. An MDR provider does.

    What is XDR?

    XDR, or extended detection and response, widens the view beyond endpoints to include email, identity systems, cloud services, and the network. It connects events across those sources. An XDR tool might link a suspicious sign-in to your email with odd activity on a laptop an hour later. Many EDR vendors now sell XDR as the next tier up.

    Does my small business need EDR?

    In most cases, yes. Choose EDR or MDR if any of these apply:

    • You hold sensitive data: patient records, financial records, card data, or client files
    • A regulation such as HIPAA, PCI DSS, or the FTC Safeguards Rule covers you
    • You are applying for or renewing cyber insurance
    • You run servers or have staff working remotely
    • Downtime of a few days would threaten the business

    A very small office with a few computers, everything in the cloud, and no regulated data can start with the protection built into Windows, turned on and kept current, alongside multi-factor authentication and backups. Revisit that choice each year.

    Do cyber insurers require EDR?

    Many now do. Applications ask whether EDR runs on all workstations and servers, and some carriers decline or surcharge businesses without it. Answer accurately. If the form says EDR covers every endpoint and a claim investigation finds half your machines unprotected, the insurer has grounds to contest the claim.

    How much does EDR cost?

    Prices vary by vendor and volume. Rough ranges for a small business:

    • Business antivirus: $3 to $6 per device per month
    • EDR software: $5 to $15 per device per month
    • MDR, with monitoring included: $10 to $30 per device per month

    Many managed IT providers bundle EDR or MDR into their monthly fee. Ask yours what you have today.

    Is Microsoft Defender good enough?

    Be precise about which Defender. The name covers several products.

    • Microsoft Defender Antivirus comes free with Windows 10 and 11. It is a solid antivirus. It is not EDR.
    • Microsoft Defender for Business adds EDR features for companies with up to 300 users. It is included in Microsoft 365 Business Premium and sold on its own.
    • Microsoft Defender for Endpoint is the enterprise product.

    If you already pay for Business Premium, you own an EDR tool. Someone still has to deploy it to every device and watch its alerts.

    How do I choose an EDR or MDR product?

    Ask these questions.

    1. Who watches the alerts, and during what hours?
    2. What actions will the provider take without calling me first, and which ones need my approval?
    3. How fast do they respond to a serious alert?
    4. Does the product cover Windows, Mac, and servers?
    5. Can it isolate a device and roll back ransomware changes?
    6. How does it perform in independent tests, such as the MITRE ATT&CK evaluations?
    7. Can someone with administrator rights on a computer turn it off? Good products resist tampering.
    8. What reports will I receive, and can I show them to my insurer or an auditor?
    9. Does it work with my IT provider’s tools?

    Can I run antivirus and EDR together?

    Most EDR products include their own antivirus component and replace the old one. Running two antivirus engines side by side causes slowdowns and conflicts. Follow the vendor’s guidance, and remove the old product fully before installing the new one.

    Does EDR replace my other protections?

    No. EDR detects and limits an attack in progress. You still need the controls that prevent one and the ones that let you recover:

    • Multi-factor authentication
    • Prompt software updates
    • Tested, offline backups
    • Email filtering
    • Limited administrator rights
    • Staff training, since many attacks start with a phishing email

    What are the common mistakes?

    • Installing EDR on workstations and skipping the servers, where the valuable data lives
    • Leaving a few “problem” computers unprotected
    • Sending alerts to an inbox nobody reads
    • Running the product in alert-only mode, so it reports attacks and blocks nothing
    • Assuming the IT provider monitors alerts without confirming it in writing
    • Buying the tool and never testing whether anyone responds

    Your next step

    Ask your IT provider three questions this week: which endpoint protection do we run, is it on every computer and server, and who responds to an alert at night? Cerberus Cybersecurity reviews endpoint protection as part of our risk and compliance assessments and helps you answer insurance applications with evidence. Contact us to schedule a review.

  • How to Freeze Your Credit: A Step-by-Step Guide

    By J. Mesa

    Data Privacy Week arrives at the end of January. Mark it with one action that takes fifteen minutes and costs nothing: freeze your credit. After years of large breaches, assume your Social Security number and date of birth are already for sale. A freeze makes that stolen information far less useful to a thief.

    What is a credit freeze?

    A credit freeze, also called a security freeze, blocks lenders from viewing your credit report. Lenders check that report before they approve a new account. With the report locked, a criminal who applies for a loan or a credit card in your name gets declined.

    Is a credit freeze free?

    Yes. Federal law has required the three national credit bureaus to place and lift freezes for free since September 2018. Do not pay anyone for one.

    Does a credit freeze hurt my credit score?

    No. A freeze has no effect on your score. You can keep using your existing cards and loans as usual. Your current lenders can still see your report, and you can still pull your own.

    How do I freeze my credit?

    You must contact each of the three bureaus separately. A freeze at one does not carry over to the others.

    1. Equifax. Go to equifax.com and look for “Security Freeze,” or call 1-800-685-1111.
    2. Experian. Go to experian.com/freeze, or call 1-888-397-3742.
    3. TransUnion. Go to transunion.com/credit-freeze, or call 1-888-909-8872.

    At each one:

    • Create an account with your name, address, date of birth, and Social Security number.
    • Answer the identity questions.
    • Choose the free freeze. The sites promote paid “lock” and monitoring products along the way. You can skip them.
    • Save the login or the PIN in your password manager. You will need it to lift the freeze.

    By law, a freeze requested online or by phone takes effect within one business day.

    Type the bureau addresses into your browser yourself. Search results and emails sometimes lead to look-alike sites built to steal the same details you are trying to protect.

    Should I freeze my credit at other agencies?

    For fuller coverage, add these:

    • Innovis, a fourth credit bureau, at innovis.com.
    • ChexSystems, which banks check before opening a checking or savings account, at chexsystems.com.
    • NCTUE, which phone, cable, and utility companies use, at nctue.com.

    How do I lift a credit freeze?

    When you apply for a mortgage, a car loan, a new credit card, or an apartment, lift the freeze first. Sign in to the bureau’s site and choose a temporary lift, sometimes called a thaw, for a set number of days. Online and phone requests take effect within one hour.

    Ask the lender or landlord which bureau they use, and lift only that one. The freeze returns on its own when the period ends.

    What is the difference between a freeze, a lock, and a fraud alert?

    • Credit freeze. Free, set by federal law, and blocks new creditors until you lift it.
    • Credit lock. A product the bureaus sell or bundle with their apps. It works much like a freeze with a quicker on-and-off switch, but it is governed by the company’s terms and not by the freeze law, and it may carry a monthly fee.
    • Fraud alert. A note on your report that tells lenders to verify your identity before opening an account. It is free, lasts one year, and you only need to request it from one bureau, which notifies the other two. Victims of identity theft can get an extended alert that lasts seven years.

    A freeze gives the strongest protection. A fraud alert asks lenders to be careful. A freeze stops them from seeing the report at all.

    Who should freeze their credit?

    Nearly every adult. If you do not plan to apply for credit in the next few weeks, a freeze costs you nothing and removes a major risk. It matters most if:

    • You received a breach notification letter
    • You lost your wallet or your Social Security card
    • You saw accounts or inquiries you do not recognize
    • You are older and rarely apply for new credit

    Should I freeze my child’s credit?

    Yes. Children make attractive targets, because nobody checks a child’s credit for years. A thief can use a child’s Social Security number until the child turns 18 and applies for a student loan. Parents and guardians can freeze the credit of a child under 16 for free. The process requires mailing copies of documents, such as a birth certificate and your own ID, to each bureau. You can do the same for an adult you hold a power of attorney for.

    What does a credit freeze not protect against?

    A freeze stops new credit accounts. It does not stop:

    • Fraud on the cards and bank accounts you already have
    • Tax refund fraud
    • Medical identity theft
    • Fraudulent unemployment or benefits claims
    • Phishing and account takeover

    So add these steps:

    • Check your credit reports. You can get free reports from all three bureaus at annualcreditreport.com, the only site authorized by federal law.
    • Get an IRS Identity Protection PIN. This six-digit number stops someone else from filing a tax return with your Social Security number. Since 2021, any taxpayer who can verify their identity may request one at IRS.gov. See our post on tax scam season.
    • Turn on transaction alerts for your bank and card accounts.
    • Use unique passwords and multi-factor authentication on financial accounts and email.
    • Create your own accounts first. Set up your online accounts at ssa.gov, IRS.gov, and the Postal Service’s Informed Delivery before a criminal claims them in your name.

    Do I need to pay for credit monitoring or identity theft protection?

    Monitoring tells you after something happens. A freeze prevents the most damaging kind of fraud before it happens, for free. If a breached company offers you free monitoring, accept it. Paying for a service is a personal choice. Some people value the insurance and the recovery help. No service prevents identity theft, whatever the advertisement says.

    What should I do if someone already opened an account in my name?

    1. Go to IdentityTheft.gov, the FTC’s recovery site. It builds a step-by-step plan and generates an identity theft report.
    2. Call the fraud department of the company where the account was opened. Ask them to close it and send written confirmation.
    3. Freeze your credit at all three bureaus and place a fraud alert.
    4. Dispute the fraudulent entries with each bureau, using the FTC report.
    5. File a police report if a creditor asks for one.
    6. Keep notes of every call: date, name, and what was said.

    Why should a business owner care?

    Your personal credit often backs your business. Many owners personally guarantee loans, leases, and business credit cards, so identity theft against you can damage the company’s ability to borrow. Criminals also commit business identity theft, filing false paperwork with a state agency or opening credit lines in a company’s name.

    • Freeze your personal credit.
    • Check your business credit reports with Dun and Bradstreet, Experian, and Equifax.
    • Sign up for email alerts from your Secretary of State, where the state offers them, so you learn when someone changes your business filing.
    • Share this guide with employees. Staff who suffer identity theft lose work time and focus, and a company that holds their Social Security numbers has a duty to protect them.

    Your next step

    Set aside fifteen minutes tonight and freeze your credit at Equifax, Experian, and TransUnion. Save the three logins in your password manager. If your business holds Social Security numbers for employees or customers, Cerberus Cybersecurity can assess how you protect them. See our services or contact us.

  • Gift Card Scams: Why Scammers Ask for Gift Cards and How to Stop Them

    By J. Mesa

    Your boss emails you. She is stuck in a meeting and needs five $100 gift cards for client gifts. Buy them now, scratch off the backs, and send photos of the codes. You will be reimbursed today. The email came from a stranger, and the money is gone the moment you hit send. December brings a surge of these requests, because buying gift cards looks normal this month.

    What is a gift card scam?

    A gift card scam is a fraud in which a criminal persuades you to buy gift cards and hand over the numbers and PINs. With those numbers, the criminal spends or resells the balance within minutes.

    One rule covers every version: gift cards are for gifts. Anyone who demands payment by gift card is a scammer. No government agency, utility, court, bank, or tech company accepts them.

    Why do scammers want gift cards?

    • Speed. The value moves the instant you read out the numbers.
    • Anonymity. Nobody needs an ID or a bank account to redeem a card.
    • No reversal. A gift card lacks the dispute rights of a credit card.
    • Availability. Every grocery store and pharmacy sells them.

    Criminals turn the balances into cash by buying electronics to resell or by selling the codes at a discount on online marketplaces.

    What are the common gift card scams?

    • The fake boss. An email or text that appears to come from an owner, a manager, a pastor, or a principal asks an employee to buy cards for clients or staff and keep it quiet.
    • Government impersonators. A caller claims to be from the IRS, Social Security, or a court and threatens arrest unless you pay a fine with gift cards.
    • Tech support. A pop-up or a caller says your computer is infected and takes payment for the “repair” in gift cards.
    • Utility shutoff. A caller says your power goes off in an hour unless you pay now.
    • Family emergency. A caller posing as a grandchild or a lawyer needs bail money.
    • Romance. An online sweetheart you have never met needs help with an emergency.
    • Prizes and sweepstakes. You won, and you owe “taxes” or “fees” first.
    • Overpayment. A buyer sends a check for too much and asks for the difference back in gift cards. The check bounces later.

    How does the fake boss gift card scam work?

    This version targets businesses, schools, churches, and nonprofits.

    1. The scammer finds the name of the owner or director on your website, and a list of staff.
    2. The scammer creates a free email account with the boss’s name as the display name, or sends a text from an unknown number that opens with “Hi, this is [boss’s name].”
    3. The first message is short: “Are you at your desk? I need a quick favor.”
    4. Once the employee answers, the request arrives: buy gift cards, keep it confidential, send the codes.
    5. The scammer asks for more cards until the employee stops.

    It works because employees want to help the boss and because the boss is “in a meeting” and can’t take a call. New employees get targeted most, since scammers watch LinkedIn for job announcements.

    What are the warning signs?

    • Any request to pay with a gift card
    • Urgency, with a deadline measured in minutes or hours
    • A request for secrecy, or an instruction to lie to the cashier about why you are buying
    • An order to stay on the phone while you shop
    • A request to buy cards at several different stores
    • A request to photograph or read out the numbers on the back
    • An email from the boss that comes from a personal address, or a text from an unknown number

    How do I protect my business?

    • Write the rule down. The company never buys gift cards on the strength of an email or a text. Purchases follow the normal approval process.
    • Verify by voice. Any unusual request for money or cards gets a phone call to a known number, or a walk down the hall.
    • Tell every new hire in the first week. Scammers reach new staff within days of a public announcement.
    • Tag external email. A banner that marks outside messages exposes a fake boss.
    • Have the owner say it out loud: “I will never ask you to buy gift cards. If you get that message, it is not me.”
    • Limit what the website gives away. Review whether you need a full staff directory with titles and direct email addresses.
    • Cover it in training. See our post on how to spot a phishing email and our cybersecurity training.

    How do I protect my family?

    Talk about it at the holiday table. Older relatives lose the most, and many have never heard that gift card payment is the mark of a scam. Agree on a simple plan: if a caller demands money, hang up and call a family member before doing anything. Tell the grandparents that a real grandchild in trouble will still be in trouble ten minutes from now, after a callback.

    What should I do if I gave a scammer gift card numbers?

    Move fast. Minutes matter.

    1. Call the gift card company right away and say the card was used in a scam. Ask whether any balance remains and whether they can freeze it. The phone number is on the back of the card or on the company’s website. Apple, Google Play, Amazon, Target, Walmart, and the major prepaid card brands all run fraud lines.
    2. Keep the card and the receipt. You need both for the report.
    3. Tell the store where you bought the cards.
    4. Report it to the FTC at ReportFraud.ftc.gov and to the FBI at ic3.gov.
    5. Tell your employer if the request posed as your boss. Others in the company may be getting the same message.
    6. Stop responding to the scammer. Expect follow-up contacts that promise to recover your money for a fee. Those are scams too.

    Can I get my money back?

    Sometimes, if the scammer has not yet spent the balance when you call. Once the funds are used, recovery is unlikely. That is the reason criminals prefer gift cards, and the reason to call the card company before you do anything else.

    What is gift card tampering?

    A different crime hits honest shoppers. Thieves take cards from store racks, record the numbers and PINs, reseal the packaging, and return the cards to the shelf. When a shopper loads money onto the card, the thief drains it.

    Protect yourself when you buy gift cards as gifts:

    • Inspect the packaging. Skip any card with a torn, wrinkled, or resealed wrapper, or a scratched PIN cover.
    • Pick cards from behind the counter or from the middle of the rack.
    • Buy from the retailer’s own website when you can.
    • Keep the receipt and give it with the card.
    • Tell the recipient to use the card soon.

    What should retail staff watch for?

    If your business sells gift cards, your cashiers are the last line of defense. Train them to notice a customer who is on the phone while buying, seems frightened or rushed, buys large amounts, or is elderly and buying cards for a brand they would not normally use. A calm question can stop the loss: “Did someone ask you to buy these to make a payment?” Post a warning sign at the rack. Many retailers now do.

    Are other payment methods a warning sign too?

    Yes. Scammers also demand wire transfers, cryptocurrency, payment apps such as Zelle and Cash App, and cash sent by mail or handed to a courier. Each shares the traits that make gift cards attractive: fast, hard to trace, and hard to reverse. Treat a demand for any of them, from someone you did not contact first, as a scam.

    Your next step

    Send a two-line message to your staff today: “I will never ask you to buy gift cards by email or text. If you receive that request, call me.” Then make the same promise to your family. For help writing payment verification rules and training your team, see our services or contact Cerberus Cybersecurity.

  • What Is Credential Stuffing? The 23andMe Breach Explained

    By J. Mesa

    In early October, 23andMe told customers that someone had accessed user accounts and compiled profile information from its DNA Relatives feature. The company said its own systems were not broken into. The attackers signed in through the front door, with usernames and passwords that customers had also used on other websites. That technique has a name, and it works against any business with a login page.

    What happened at 23andMe?

    On October 6, 2023, 23andMe published a notice describing the incident. According to the company, attackers used recycled login credentials to get into individual accounts. From inside those accounts, they collected information that other users had chosen to share through DNA Relatives, an optional feature that connects genetic matches. A seller on a hacking forum then advertised lists of profile data.

    The reach extended beyond the accounts with reused passwords. Each compromised account could see the shared profile details of its DNA matches, so one weak password exposed information about many people who had done nothing wrong.

    23andMe responded by resetting passwords and, starting November 6, requiring two-step verification for all customers. The investigation continues as of this writing.

    What is credential stuffing?

    Credential stuffing is an attack in which criminals take usernames and passwords stolen from one website and try them, by the million, on other websites. It works because people reuse passwords.

    The attacker does not guess. The attacker already holds your real password from an old breach, and bets that you used it somewhere else.

    How does credential stuffing work?

    1. Collect. Criminals gather username and password pairs from past breaches. Billions of them circulate on criminal forums, many for free.
    2. Automate. Software feeds those pairs into the login page of a target site. The tools route attempts through thousands of IP addresses to look like ordinary customers.
    3. Sort. The software records each pair that works.
    4. Cash out. The attacker drains stored value, steals personal data, places orders, or sells the working logins to someone else.

    The success rate per attempt is low, often well under one percent. At a million attempts, that still yields thousands of open accounts.

    Why does credential stuffing work so well?

    Because of one habit. Surveys keep finding that a majority of people reuse passwords across accounts. A password you created for a forum in 2014 may still guard your email today. When the forum was breached, that password stopped being a secret. See our post on the most compromised passwords.

    How is it different from a brute force attack?

    A brute force attack guesses many passwords against one account. Password spraying tries a few common passwords, such as “Winter2023,” against many accounts. Credential stuffing uses known, real pairs. It is quieter and more efficient than either, because each account sees one or two attempts.

    How do I know whether my password was in a breach?

    • Search your email address at haveibeenpwned.com, a free service run by a respected security researcher. It lists the known breaches that included your address.
    • Use the password checkup built into your password manager or your browser. Chrome, Edge, Safari, and Firefox all flag saved passwords found in breach data.
    • Watch for signs: password reset emails you did not request, login alerts from unfamiliar places, and orders or messages you did not send.

    How do I protect my own accounts?

    1. Use a different password for every account. This single step defeats credential stuffing. A password stolen from one site then opens nothing else.
    2. Use a password manager to create and remember them. Nobody can memorize a hundred unique passwords.
    3. Turn on multi-factor authentication wherever a site offers it, starting with email, banking, and any account that holds sensitive data. An attacker with the right password still lacks the second step.
    4. Change reused passwords now, beginning with your email account. Email is the key to every other account, because password resets go there.
    5. Close accounts you no longer use. Each one is a copy of your data waiting for a breach.

    What does this mean for sensitive accounts?

    Think about what an account holds, not how often you use it. A genetic testing account contains information you can never change. The same goes for health portals, tax software, and financial accounts. Protect those with your strongest settings even if you sign in once a year, and review what you have chosen to share with other users.

    How do I protect my business from credential stuffing?

    Your staff reuse passwords too, and their work email address appears in breach lists.

    • Require multi-factor authentication on email, remote access, payroll, banking, and every cloud application that supports it.
    • Provide a business password manager and require unique passwords for work accounts.
    • Block known-breached passwords. Microsoft 365 and other identity systems can refuse passwords that appear in breach lists.
    • Turn on sign-in risk alerts. Have someone review alerts for logins from unfamiliar countries and for impossible travel.
    • Set lockout and throttling rules to slow automated attempts.
    • Turn off old sign-in methods. Legacy email protocols such as POP and IMAP with basic authentication bypass multi-factor authentication. Disable them.
    • Disable accounts when people leave.
    • Train your staff on why a work password must never match a personal one. Our cybersecurity training covers this.

    What if my business has customer logins?

    If customers sign in to your website, store, or portal, you carry the 23andMe problem in miniature.

    • Offer multi-factor authentication to customers, and require it for accounts that hold sensitive data.
    • Add rate limiting and bot detection to the login page.
    • Check new and changed passwords against lists of breached passwords.
    • Email customers when a login occurs from a new device.
    • Limit what one account can see about other users.
    • Monitor for spikes in failed logins.

    When customers lose data through your login page, they hold your business responsible, whoever chose the weak password.

    Is the company at fault, or the customer?

    Both carry part of it. A customer who reuses a password leaves the door unlocked. A company that holds sensitive data and makes two-step verification optional has decided to accept that risk on its customers’ behalf. Regulators and courts increasingly expect a business to anticipate reused passwords and defend against them. Plan as if your users will reuse passwords, because many will.

    What should I do if I have a 23andMe account?

    • Change the password to one you use nowhere else.
    • Turn on two-step verification.
    • Review your DNA Relatives and profile sharing settings, and reduce what you display.
    • Change the password on any other account that shared the old one.
    • Be alert for phishing emails that mention your ancestry or relatives. Attackers use stolen details to make messages convincing.

    Your next step

    Search your work and personal email addresses at haveibeenpwned.com today. Then change every password you have reused, starting with email. For help setting password and access policies across your business, see our services or contact Cerberus Cybersecurity.

  • What Is a VPN, and Do You Need One?

    By J. Mesa

    VPN advertisements promise to make you anonymous, block hackers, and protect your identity. A VPN does none of those things on its own. It does one useful job well, and knowing what that job is tells you whether you need to pay for one.

    What is a VPN?

    A VPN, or virtual private network, is a service that creates an encrypted connection between your device and a server run by the VPN provider. Your internet traffic travels through that encrypted tunnel to the provider’s server and goes out to the internet from there.

    How does a VPN work?

    Without a VPN, your traffic passes through the local network and your internet provider on its way to a website. Each of them can see which sites you connect to. The website sees your IP address, which reveals your provider and your rough location.

    With a VPN turned on:

    1. Your device encrypts the traffic before it leaves.
    2. The local network and your internet provider see only scrambled data going to the VPN server.
    3. The VPN server decrypts the traffic and sends it to the website.
    4. The website sees the VPN server’s IP address in place of yours.

    You have moved your trust. Your internet provider can no longer see your browsing, and the VPN company now can.

    What does a VPN protect you from?

    • Snooping on untrusted networks. On hotel, airport, and coffee shop Wi-Fi, a VPN stops the network operator and other users from watching where your traffic goes.
    • Tracking by your internet provider. Your provider can’t log the sites you visit.
    • Exposure of your IP address. Websites and services see the VPN’s address.
    • Location limits. A VPN can make you appear to be in another region.

    What does a VPN not protect you from?

    This list matters more than the first one.

    • Phishing. A VPN delivers a fake sign-in page to you through an encrypted tunnel. You can still type your password into it. See our guide to spotting a phishing email.
    • Malware. A VPN does not scan what you download.
    • Weak or reused passwords. An attacker with your password signs in from anywhere.
    • Tracking by the sites you use. Google, Facebook, and advertisers identify you by your login, your cookies, and your browser, with or without a VPN.
    • Data breaches. A VPN has no effect on how a company stores your information.
    • Anonymity. The VPN provider knows who you are and can see your traffic. Websites you sign in to know who you are.

    Do I need a VPN at home?

    For security, most people do not. Nearly every website and app now encrypts its own traffic with HTTPS, the padlock in your browser. Your home network is one you control. A VPN at home adds privacy from your internet provider and little else.

    Spend the effort where it counts first: a strong, unique password for each account, multi-factor authentication, and software updates.

    Do I need a VPN on public Wi-Fi?

    It helps, and the risk is smaller than the ads suggest. Because of HTTPS, a snoop on the coffee shop network can’t read your banking session or your email. The snoop can see which sites you visit, and a fake hotspot can steer you toward a fraudulent page.

    A VPN closes those gaps. So does using your phone’s hotspot or cellular data. If you travel often and work from shared networks, a VPN is a reasonable purchase. Our post on staying safe on the go covers the rest.

    What is a business VPN?

    A business VPN serves a different purpose from the consumer products in the ads. It connects a remote employee’s computer to the company’s private network, so the employee can reach file servers, accounting systems, and other internal resources from home or the road. Your firewall or a dedicated service provides it, and your IT team controls who may connect.

    A consumer VPN hides your browsing from the local network. A business VPN extends your office network to an authorized person. Buying consumer subscriptions for your staff does not give them secure access to the office.

    How do I secure a business VPN?

    A VPN is a door into your network, and attackers know it. VPN devices sit among the most common entry points for ransomware.

    • Require multi-factor authentication for every VPN login. A VPN protected by a password alone is one stolen password away from a break-in.
    • Patch the VPN device quickly. Vendors release fixes for serious flaws several times a year, and criminals scan the internet for unpatched devices within days.
    • Give each person an account. No shared logins. Disable the account the day someone leaves.
    • Limit what the VPN reaches. A remote bookkeeper needs the accounting system and nothing else.
    • Allow company-managed devices only, where you can. A family computer full of malware should not join the office network.
    • Review the logs for logins at odd hours and from unexpected countries.
    • Replace hardware the vendor no longer supports.

    Do small businesses still need a VPN?

    It depends on where your systems live. If your email, files, and accounting all run in cloud services such as Microsoft 365, Google Workspace, and QuickBooks Online, your staff reach them directly over HTTPS, and a VPN adds little. Protect those logins with multi-factor authentication.

    If you keep a server, a records system, or network storage in the office, remote staff need a secure way in. A VPN is the traditional answer. Never expose Remote Desktop straight to the internet as a shortcut.

    Newer “zero trust” access tools take a different approach. They verify the person and the device, then grant access to one application at a time and not to the whole network. Ask your IT provider whether one fits your size and budget.

    How do I choose a consumer VPN?

    If you decide to buy one, check these points.

    • Independent audits. Look for a published audit of the provider’s no-logs claim by a named outside firm.
    • Clear ownership. You should be able to learn who runs the company and where it operates.
    • Modern protocols, such as WireGuard or OpenVPN.
    • A kill switch that blocks traffic if the VPN connection drops.
    • A paid plan from a known provider. Running servers costs money. A free VPN often pays its bills by collecting and selling your browsing data, which defeats the purpose.
    • No outsized promises. Be wary of any product that claims to make you anonymous or “unhackable.”

    Are free VPNs safe?

    Many are not. Studies of free VPN apps have found data collection, advertising trackers, and in some cases malware. A few reputable providers offer limited free tiers supported by their paid customers. Outside of those, avoid free VPN apps, above all on a device that holds work email.

    Does a VPN slow down my internet?

    Somewhat. Your traffic takes a longer route and gets encrypted along the way. With a good provider and a nearby server, most people notice little difference for browsing and video calls.

    Is using a VPN legal?

    In the United States, yes. A handful of countries restrict or ban them, so check before you travel. A VPN does not make an illegal act legal, and it may violate the terms of a streaming service.

    Your next step

    List the systems your staff reach from outside the office and how they connect to each one. For every remote connection that relies on a password alone, add multi-factor authentication this month. Cerberus Cybersecurity reviews remote access as part of our risk and compliance assessments and writes remote work policies your team can follow. Contact us to get started.

  • The MGM and Caesars Hacks: What a Help Desk Phone Call Teaches Small Businesses

    By J. Mesa

    Slot machines went dark on the Las Vegas Strip this week. Guests at MGM Resorts properties waited in long lines to check in, digital room keys stopped working, and the company’s websites went offline. MGM disclosed a “cybersecurity issue” on September 11. Three days later, Caesars Entertainment told regulators that it, too, had been breached. The early reporting on both cases points to the same weak spot, and it is one your business shares.

    What happened at MGM and Caesars?

    MGM Resorts. The company announced on September 11, 2023 that it had identified a cybersecurity issue and shut down certain systems to protect them. The outage reached hotels and casinos in several states. As of this writing, MGM is still restoring operations.

    Caesars Entertainment. In a filing with the Securities and Exchange Commission on September 14, Caesars disclosed a social engineering attack on an outsourced IT support vendor. The attackers copied data that included the company’s loyalty program database, with driver’s license and Social Security numbers for a large number of members. News outlets report that Caesars paid a ransom of about $15 million. The company’s filing says only that it took steps to ensure the stolen data is deleted and that it can’t guarantee that result.

    How did the attackers get in?

    MGM has not published the details. Security researchers and news reports attribute the attack to a group known as Scattered Spider, working with the ALPHV ransomware operation, and describe a simple method: the attackers found an employee’s information on LinkedIn, called the IT help desk, posed as that employee, and talked the help desk into resetting access. Treat that account as reported, not confirmed.

    Caesars confirmed its own version in writing. The attack began with social engineering of an IT support vendor.

    Neither story involves a brilliant piece of code. Both involve a person on a phone who wanted to be helpful.

    What is help desk social engineering?

    Help desk social engineering is an attack in which a criminal contacts IT support, pretends to be an employee, and asks for a password reset or a new multi-factor authentication device. If the support person agrees, the attacker receives a working login and bypasses every technical control in front of it.

    The attacker prepares first. Names, job titles, managers, and office locations come from LinkedIn and company websites. Dates of birth, addresses, and the last four digits of Social Security numbers come from old data breaches. Armed with those, the caller can answer the standard verification questions better than the real employee could.

    Who is Scattered Spider?

    Scattered Spider is a name researchers use for a loose group of young, native English-speaking attackers who specialize in social engineering. Their known methods include phone calls to help desks, text message phishing aimed at employees, and SIM swapping to intercept verification codes. Their fluency and confidence on the phone set them apart from most ransomware crews.

    Why does this matter to a small business?

    You may think a casino has nothing in common with a ten-person office. Look at the steps again.

    • An employee’s details were public.
    • Someone with the power to reset passwords took a phone call.
    • That person verified the caller with information a stranger could find.
    • An outside IT vendor held the keys.

    Most small businesses match all four. Your “help desk” may be an office manager, a part-time IT person, or a managed service provider with a call center. The question is the same: what does it take to convince that person to reset your password?

    How do I protect password resets?

    Write a reset procedure and require everyone who can reset credentials to follow it, including your outside IT company.

    1. Call back. Hang up and call the employee at the number on file in your own records. Never use a number the caller supplies.
    2. Verify with something a stranger can’t know. Dates of birth, employee numbers, and manager names fail this test. Use a video call with a manager who knows the person, an in-person visit, or a verification code sent through an internal channel the employee already uses.
    3. Require a second approval for resets of administrator accounts, finance staff, and executives.
    4. Treat multi-factor resets as high risk. Enrolling a new phone or removing a security key deserves a stricter check than a password reset.
    5. Add a delay for privileged accounts where the business can tolerate one.
    6. Log every reset and review the list each week.
    7. Notify the employee by a separate channel each time a reset or a new device enrollment occurs.

    Does multi-factor authentication stop this attack?

    Only in part. Multi-factor authentication blocks an attacker who holds a stolen password. It does nothing when the help desk enrolls the attacker’s phone as the employee’s new device. The reset process becomes the back door.

    Some methods hold up better than others. Text message codes fall to SIM swapping. Push notifications fall to “fatigue” attacks, in which the attacker sends prompts until the employee taps approve. Hardware security keys and number matching resist both. Use the stronger methods for administrators and anyone who handles money.

    What should I ask my IT provider?

    Caesars was breached through a vendor. Ask yours:

    • How do your technicians verify my employees before a password or multi-factor reset?
    • Who at my company can authorize a reset for an administrator account?
    • Do your own technicians use phishing-resistant multi-factor authentication?
    • How would you detect a new device enrolled on one of my accounts?
    • What do you do in the first hour if you suspect one of my accounts was taken over?

    Put the answers in the contract or in a written procedure both sides sign.

    How do I reduce what attackers can learn about my staff?

    You can’t hide your employees, and you should not try. You can remove the details that make impersonation easy.

    • Keep direct phone numbers, internal titles for IT administrators, and organization charts off the public website.
    • Ask staff with administrator or finance roles to limit what their public profiles reveal about the systems they manage.
    • Never use information found in public records as proof of identity.

    What should I train my staff to do?

    • Expect that someone may call pretending to be a coworker, a vendor, or IT.
    • Refuse to read a verification code to anyone, including a caller who claims to be from support.
    • Deny any sign-in prompt they did not start, and report it.
    • Report an unexpected password reset notice at once.
    • Slow down when a caller pushes urgency. A real colleague will wait five minutes for a callback.

    Give the help desk the same message from the top: nobody gets in trouble for making the boss wait while they verify. See our cybersecurity training for sessions built around phone-based attacks.

    Should a business pay a ransom?

    The FBI advises against it. Payment funds the next attack and buys a promise from a criminal. Caesars’ own filing admits it can’t guarantee the outcome. The better investment happens earlier: tested backups, a written incident response plan, and a reset procedure that a confident voice on the phone can’t talk past.

    Your next step

    Call your own IT support this week and ask them to walk you through how they would verify you for a password reset. If the answer relies on your date of birth or your employee number, you have work to do. Cerberus Cybersecurity writes identity verification procedures and trains teams to resist phone-based attacks. See our services or contact us.

  • How to Spot a Phishing Email: 9 Warning Signs

    By J. Mesa

    An email lands in your inbox at 4:45 on a Friday. Your mailbox is full, it says, and you will stop receiving messages unless you sign in now. You click, type your password, and go home. By Monday, a stranger has read three months of your email and sent an invoice to your largest customer. Most break-ins at small businesses begin this way, with one message and one tired person.

    What is phishing?

    Phishing is a fraudulent message that poses as a trusted sender to trick you into giving up a password, sending money, or opening a malicious file. Email carries most of it. Text messages, phone calls, and social media carry the rest.

    How does a phishing attack work?

    The attacker wants one of three results.

    • Your credentials. The message links to a fake sign-in page for Microsoft 365, Google, your bank, or a shipping company. Whatever you type goes to the attacker.
    • Your money. The message poses as a vendor, a boss, or a customer and asks for a payment, a gift card, or a change of bank details.
    • Your computer. The message carries an attachment or a link that installs malware, including the kind that leads to ransomware.

    What are the warning signs of a phishing email?

    1. The sender address does not match the name. The display name says “Microsoft Support,” and the address behind it ends in a domain you have never seen. Click or tap the name to reveal the full address.
    2. The domain is close but wrong. Look for swapped or added characters: “rn” in place of “m,” a zero in place of the letter o, or an extra word such as “-secure” or “-billing.”
    3. The message creates urgency. Your account closes today. The invoice is overdue. The boss needs it in ten minutes. Pressure exists to stop you from thinking.
    4. The request is unusual. A vendor changes its bank account by email. The owner asks for gift cards. Payroll gets a request to move a direct deposit.
    5. The link goes somewhere else. Hover over the link on a computer, or press and hold on a phone, and read the real address. A Microsoft sign-in page does not live on a random website.
    6. The attachment was not expected. Treat surprise invoices, voicemails, scans, and shipping documents as suspect, above all files that ask you to “enable content” or sign in to view them.
    7. The greeting is generic. “Dear customer” from a bank that knows your name.
    8. The tone is off. A colleague who writes in short bursts sends three formal paragraphs. Trust that instinct.
    9. The message asks for secrets. No legitimate company asks for your password, your verification code, or your full card number by email.

    Spelling mistakes used to be a reliable sign. They are less reliable now, because attackers use better tools and copy real company emails word for word. A clean, well-written message can still be a fake.

    What are the common types of phishing?

    • Bulk phishing. One message to millions of people, posing as a bank, a streaming service, or a delivery company.
    • Spear phishing. A message written for one person, using details from LinkedIn, your website, or an earlier breach.
    • Whaling. Spear phishing aimed at owners and executives.
    • Business email compromise. A message that poses as a boss or a vendor to redirect a payment. It often contains no link and no attachment, which lets it pass through filters.
    • Smishing and vishing. The same tricks by text message and by phone.
    • Clone phishing. A copy of a real email you received before, with the link or attachment swapped.

    Our post on how hackers get in covers the psychology behind these attacks.

    How do I check a link safely?

    • Hover first, and read the address from right to left. The part just before “.com” or “.org” is the real owner. In “microsoft.com.account-verify.net,” the owner is account-verify.net.
    • Do not trust the padlock. Fake sites have them too.
    • When in doubt, skip the link. Open your browser and type the company’s address yourself, or use the bookmark you already have.
    • Be careful with shortened links and QR codes, which hide the destination.

    What should I do when I get a suspicious email?

    1. Do not click, reply, or open the attachment.
    2. Report it. Use the “Report phishing” button in Outlook or Gmail, and forward it to whoever handles your IT.
    3. Verify through another channel. Call the sender at a number you already have. Do not use the phone number in the message.
    4. Delete it.

    If the message poses as a coworker or a vendor you know, tell that person. Their account may have been hacked, and they may not know yet.

    What should I do if I clicked a phishing link?

    Speed matters more than embarrassment. Tell your IT contact right away.

    • You clicked but entered nothing. Close the page. Run a scan with your security software. Watch the account for a few days.
    • You entered a password. Change it at once from a different device. Change it on every other account where you used the same one. Turn on multi-factor authentication. Ask IT to sign out all active sessions and check the mailbox for forwarding rules the attacker may have added.
    • You opened an attachment or enabled content. Disconnect the computer from the network and call IT. Do not keep working on it.
    • You sent money or bank details. Call your bank immediately and ask for a recall, then report the fraud to the FBI at ic3.gov.

    How do I protect my business from phishing?

    • Turn on multi-factor authentication for email first, then for banking, payroll, and remote access. A stolen password alone then gets the attacker nowhere.
    • Use the email filtering you already pay for. Microsoft 365 and Google Workspace include phishing and attachment protections that many businesses never switch on.
    • Tag outside email. A banner that marks messages from outside the company exposes a fake “boss” at a glance.
    • Set a payment verification rule. No change to bank details and no new payee without a phone call to a known number and a second approver.
    • Use a password manager. It fills passwords only on the real site, so a look-alike page gets nothing.
    • Limit what staff post. Job titles, vendor names, and travel plans on public pages help an attacker write a convincing message.
    • Make reporting easy and safe. One button or one address. Thank the people who report, including the ones who clicked first.

    Does phishing training work?

    Yes, when you repeat it. A one-hour lecture once a year fades within weeks. Short sessions through the year, paired with simulated phishing emails, build the habit of pausing before a click. Track two numbers: how many people click, and how many people report. The second number matters more, because one fast report lets you warn everyone else.

    Treat a failed test as a coaching moment. Staff who fear punishment hide their mistakes, and a hidden click does the most damage. Our cybersecurity training covers phishing for every role, from the front desk to the owner.

    Can email filters stop all phishing?

    No. Filters catch most bulk phishing. Targeted messages, messages sent from a real hacked account, and messages with no link or attachment still arrive. Your people are the last check, so give them the knowledge and the permission to slow down.

    Your next step

    Forward this list of nine signs to your staff, and ask each person to find the “Report phishing” button in their mail program today. To build a training program and a payment verification policy that fit your business, see our services or contact Cerberus Cybersecurity.