Category: Notice

  • Secure Our World: CISA’s 4 Steps to Stay Safe Online

    Secure Our World: CISA’s 4 Steps to Stay Safe Online

    By J. Mesa

    The Cybersecurity and Infrastructure Security Agency (CISA) is the US government’s lead agency for cyber defense. Its public campaign, Secure Our World, became the theme of Cybersecurity Awareness Month in 2023 and has carried through each October since.

    The campaign asks everyone to adopt four habits. They are simple and free, and together they block the most common attacks. This post explains each one and how to put it in place at home and at work.

    What is Secure Our World?

    Secure Our World is CISA’s cybersecurity awareness program for the public, small businesses, and families. It replaces a long list of advice with four actions:

    1. Use strong passwords and a password manager.
    2. Turn on multi-factor authentication.
    3. Recognize and report phishing.
    4. Update your software.

    CISA chose these four because most successful attacks exploit one of them. A weak password, a missing second step at login, a convincing email, or an old piece of software gives an attacker the way in.

    Step 1: How do I use strong passwords?

    A strong password is long, random, and unique to one account. CISA’s guidance sets the bar at 16 characters or more.

    Nobody can remember dozens of passwords like that, so use a password manager. It creates a strong password for each account, stores them, and fills them in for you. You remember one long passphrase that unlocks the manager.

    • Make the master passphrase four or more unrelated words.
    • Never reuse a password across accounts.
    • Change a password when a site reports a breach.

    Step 2: What is multi-factor authentication, and why turn it on?

    Multi-factor authentication (MFA) asks for a second proof that you are you. After your password, you approve a prompt in an app, enter a code, or touch a security key.

    MFA matters because passwords leak. With MFA on, a stolen password alone does not open the account.

    The options rank like this, from strongest to weakest:

    1. A physical security key or a passkey
    2. An authenticator app
    3. A code sent by text message

    Any of them beats a password alone. Turn MFA on first for email, banking, and social media, then for every account that offers it.

    Step 3: How do I recognize and report phishing?

    Phishing is a message built to trick you into clicking a link, opening a file, or giving up information. It arrives by email, text, phone call, or direct message.

    Look for these signs:

    • Pressure to act right now
    • A request for a password, a code, or a payment
    • A sender address that is close to a real one and slightly off
    • A link that goes somewhere other than what the text says
    • An attachment you did not expect

    When you spot one, don’t click and don’t reply. Report it with the “Report phishing” button in your email program, tell your IT contact at work, and then delete it. Reporting helps your email provider block the same message for other people.

    If a message claims to come from your bank or a vendor, contact them through a phone number or website you already trust.

    Step 4: Why do software updates matter?

    Software has flaws. Vendors fix them with updates. Attackers read those update notes too, and they build tools to attack anyone who has not installed the fix.

    • Turn on automatic updates for your computer, phone, and browser.
    • Update apps, routers, and smart devices as well.
    • Replace devices that no longer receive security updates.
    • Restart when an update asks you to. Many fixes don’t take effect until you do.

    How does this apply to a small business?

    The same four steps work for a company. They need a little structure.

    • Passwords. Give every employee a password manager and set a minimum length.
    • MFA. Require it for email, payroll, banking, and remote access.
    • Phishing. Train your team at least once a year and make reporting easy and blame-free.
    • Updates. Assign one person to check that devices and software are current each month.

    CISA also offers small businesses free resources, including guides and a vulnerability scanning service for internet-facing systems.

    What is Cybersecurity Awareness Month?

    Cybersecurity Awareness Month takes place every October. The President and Congress first declared it in 2004, and CISA leads it with the National Cybersecurity Alliance. Schools, businesses, and agencies use the month to teach safe online habits.

    You don’t have to wait for October. The four steps work on any day of the year.

    Do these four steps stop every attack?

    No. They stop the common ones. A determined attacker has other methods, and businesses with sensitive data need more: backups, access controls, monitoring, and an incident response plan. The four steps are the floor. Build on them.

    Where can I learn more?

    CISA publishes tip sheets, videos, and a toolkit at cisa.gov/secure-our-world. The materials are free to share with your staff, your family, and your community.

    What mistakes do people make with these four steps?

    • Using a strong password twice. One breach then exposes both accounts.
    • Approving an MFA prompt they did not start. Attackers send repeated prompts and hope you tap “Approve” to make them stop. Deny any prompt you did not trigger, then change that password.
    • Trusting a message because it looks polished. Criminals copy logos and signatures. Judge the request, not the design.
    • Postponing the restart. An update that waits for a restart protects nothing.

    How long does it take to set up all four?

    Plan on an hour for one person. Install a password manager and move your most important accounts into it, which takes about 30 minutes. Turn on MFA for email and banking in 10 minutes. Switch on automatic updates in 5. Spend the rest learning where your email’s “Report phishing” button lives.

    Your next step

    Pick one of the four steps and do it today. Turning on MFA for your email takes five minutes and blocks the attack I see most often.

    If you want training for your team built around these habits, Cerberus Cybersecurity offers cybersecurity training for every audience, from the sales floor to the executive team. Contact us to set up a session.

  • Cybersecurity Awareness Month: What It Is and How to Take Part

    Cybersecurity Awareness Month: What It Is and How to Take Part

    By J. Mesa

    Every October, governments, schools, and businesses set aside time to talk about staying safe online. Cybersecurity Awareness Month is the reminder most of us need, because the habits that protect us are simple and easy to put off.

    This post explains what the month is, which threats deserve your attention, and how to use four weeks to make your home or business harder to attack.

    What is Cybersecurity Awareness Month?

    Cybersecurity Awareness Month is an annual campaign held each October in the United States. The President and Congress first declared it in 2004. The Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance lead it together.

    The goal is to give everyone practical steps to protect their accounts, devices, and data. Many other countries run similar campaigns in the same month.

    Why does it matter?

    Technology sits in the middle of daily life. You bank, shop, work, and talk to family through it. Criminals follow the money and the data, and they count on people being too busy to take precautions.

    An awareness month works because security depends on habits. One person who pauses before clicking a link can stop an attack that software missed.

    What are the biggest cyber threats right now?

    • Phishing. Fake emails, texts, and calls trick people into clicking malicious links, opening files, or sharing passwords.
    • Ransomware. Malware encrypts your files and holds them until you pay.
    • Data breaches. Attackers steal personal and financial records, which leads to identity theft and fraud.
    • Supply chain attacks. Attackers break into a supplier to reach that supplier’s customers.
    • Internet of Things weaknesses. Cameras, smart appliances, and industrial controls often ship with weak security and rarely receive updates.

    What can a cyberattack cost?

    • Money. Stolen funds, ransom payments, recovery fees, and lost sales add up fast.
    • Reputation. Customers leave a business that loses their data.
    • Essential services. Attacks on hospitals, utilities, and local government put public safety at risk.

    Island communities feel this more than most. When a single hospital, utility, or bank serves everyone, an outage reaches every household.

    What are the best practices to follow?

    1. Use strong, unique passwords. A password manager creates and stores them for you.
    2. Turn on multi-factor authentication. A second step at login blocks most attacks that use stolen passwords.
    3. Update your software. Install updates for your operating system, apps, and devices as soon as they arrive.
    4. Watch for phishing. Treat unexpected messages with suspicion, and verify requests through a channel you trust.
    5. Use security software. Keep antivirus and anti-malware protection running and current.
    6. Back up your data. Keep a copy offline or in a separate cloud account.
    7. Teach someone else. Share what you know with family, coworkers, and neighbors.

    How can I take part? A four-week plan

    Week 1: Passwords. Install a password manager. Replace your email and banking passwords with long, unique ones.

    Week 2: Multi-factor authentication. Turn it on for email, banking, social media, and any account that holds payment details.

    Week 3: Phishing. Learn the warning signs. Find the “Report phishing” button in your email and use it. Talk with older relatives about scam calls and texts.

    Week 4: Updates and backups. Turn on automatic updates on every device. Run a backup and test that you can restore a file.

    By the end of the month you have closed the four doors attackers use most.

    How can a business take part?

    • Send a short weekly tip to all staff.
    • Run a 30-minute lunch session on phishing with real examples.
    • Send a simulated phishing email and use the results to teach, never to punish.
    • Review who has access to what, and remove accounts for people who have left.
    • Check that your backups work.
    • Recognize employees who report suspicious messages.

    Keep it positive. People report problems when they feel safe doing so.

    How can I teach kids and older relatives?

    • Keep the rules short: don’t share passwords, don’t click links from strangers, ask before you download.
    • Set up their devices with automatic updates and a password manager.
    • Agree on a family rule: any request for money or gift cards gets a phone call to confirm.
    • For our Manåmko’, practice hanging up on a caller who creates pressure, and calling back on a known number.

    Is cybersecurity only an IT problem?

    No. Cybersecurity is a shared responsibility. IT staff install the tools. Every person who uses a computer decides whether to click, whether to reuse a password, and whether to report something strange. Attackers aim at people because people are easier to fool than software.

    What happens after October?

    The risk does not stop on November 1. Pick two habits from the month and make them permanent:

    • A monthly ten-minute check that updates and backups ran
    • A yearly training session for everyone in the business

    What should I do if I think I have been scammed?

    Act fast. Speed limits the damage.

    1. Change the password on the affected account, and on any account that shares it.
    2. Call your bank or card company if you sent money or shared payment details.
    3. Report the incident to the FBI’s Internet Crime Complaint Center at ic3.gov and to the Federal Trade Commission at reportfraud.ftc.gov.
    4. At work, tell your manager or IT contact right away. A fast report gives them time to contain the problem.

    Do not feel embarrassed. Scammers fool careful people every day, and a quick report protects the next person.

    Is cybersecurity training worth the time?

    Yes. Most attacks need a person to click, reply, or pay. Training teaches people to pause at that moment. Short sessions repeated through the year work better than one long session, because the reminders arrive before the habit fades.

    Your next step

    Use this October to build your skills. Cerberus Cybersecurity runs cybersecurity training and workshops that cover current threats and the habits that stop them. Contact us to schedule a session for your team. When you understand the risks and practice the basics, you help build a safer digital world for your whole community.

  • The CrowdStrike Outage: Business Continuity Lessons for Small Businesses

    By J. Mesa

    On Friday, July 19, computers around the world crashed to a blue error screen and would not restart. Airlines grounded flights. Hospitals postponed procedures. Banks, retailers, and 911 centers lost systems. No criminal caused it. A routine update from a security company did. Microsoft estimated that 8.5 million Windows devices went down. The event offers the cleanest test in years of a question every owner should answer: how does my business run when the computers do not?

    What happened in the CrowdStrike outage?

    CrowdStrike makes Falcon, a widely used endpoint security product. Early on July 19, 2024, the company released a content configuration update for the Falcon sensor on Windows. The update contained a defect. Windows computers that received it crashed and then crashed again on every restart.

    CrowdStrike withdrew the update in a little over an hour. By then, every online Windows machine running the sensor had received it. The fix required a person to start each affected computer in a recovery mode and delete one file, which CrowdStrike identified as Channel File 291. For an organization with thousands of machines, many of them encrypted with BitLocker and spread across locations, that meant days of hands-on work.

    Was the CrowdStrike outage a cyberattack?

    No. CrowdStrike and government agencies confirmed that the outage came from a faulty update and not from an attack. Mac and Linux computers were not affected.

    Why did one update cause so much damage?

    Three reasons.

    • Deep access. Security software runs at the core of the operating system so that it can stop malware. An error at that level crashes the whole machine.
    • Speed. The update went to all customers at about the same time, with no staged rollout that would have caught the defect on a small group first.
    • Concentration. Thousands of large organizations use the same product, so one mistake landed everywhere at once.

    Were small businesses affected?

    Many were, in two ways. Some run CrowdStrike directly or through their IT provider, and their own computers crashed. Many more felt it second-hand: a canceled flight, a payment terminal that stopped working, a supplier who could not ship, a cloud service that went offline.

    That second group holds the broader lesson. You can be knocked out by a failure in a product you have never heard of.

    What is business continuity planning?

    Business continuity planning is the work of deciding, in advance, how your business keeps operating during a disruption and how it returns to normal. Disaster recovery is the part that restores your technology. Continuity covers the whole operation: people, processes, suppliers, and communication.

    The cause can be an outage, a ransomware attack, a fire, a typhoon, or a vendor failure. A good plan does not care which.

    How do I write a business continuity plan?

    A small business plan can fit in five to ten pages.

    1. List your critical functions. Taking payments, serving customers, paying staff, ordering stock, answering the phone.
    2. Set a tolerance for each. How long can it stay down before real damage begins: an hour, a day, a week?
    3. Map what each function depends on. Systems, vendors, people, and locations.
    4. Write a manual workaround for each. Paper forms, a card imprinter or a backup payment app, a printed schedule, a phone tree.
    5. Set recovery priorities. Decide which systems come back first.
    6. Build the contact list. Staff, vendors, the bank, the insurer, key customers. Include personal phone numbers.
    7. Assign roles. Name who decides, who talks to customers, and who calls the vendors.
    8. Store it offline. Print copies. Keep one at home.
    9. Test it once a year.

    How do I prepare for a mass computer outage?

    The July outage exposed gaps that are cheap to close.

    • Keep your BitLocker recovery keys where you can reach them. Many organizations could not repair their computers because the recovery keys lived on servers that had also crashed. Know where yours are stored, and keep a copy that does not depend on the systems it unlocks.
    • Keep an offline list of administrator credentials in a safe or a password manager you can open from a phone.
    • Make sure at least two people can perform a recovery. One of them should not be an outside vendor who will be swamped with every other client that day.
    • Print the essentials. The day’s appointments, key customer phone numbers, price lists, and emergency procedures.
    • Have a second way to take payments and a second way to communicate if email is down.
    • Keep a spare laptop that is set up and updated.
    • Ask your IT provider how many clients it would have to restore at once, and where you sit in that line.

    Should I turn off automatic updates after this?

    No. Unpatched software causes far more harm than bad updates do. Most ransomware and data theft exploits flaws for which a fix already existed. One faulty update in a decade does not change that math.

    What you can do is stage updates when a product allows it:

    • Apply security updates to a few test machines first, then the rest a day or two later.
    • Avoid updating every server in the same hour.
    • Keep operating system and security definition updates automatic on ordinary workstations.

    After the outage, CrowdStrike committed to more testing, staged rollouts, and giving customers more control over when content updates arrive.

    What should I ask my software vendors?

    1. How do you test updates before release?
    2. Do you roll updates out in stages?
    3. Can I control when updates install, or delay them?
    4. How do you notify customers of a problem, and how fast?
    5. What is your process for withdrawing a bad update?
    6. What does our contract say about outages?

    Ask these of your security vendor, your IT provider’s remote management tool, and any software with deep access to every computer you own.

    Does insurance cover an outage like this?

    Sometimes. Some cyber policies include “system failure” coverage for outages that are not attacks, and “dependent” or “contingent” business interruption coverage for a vendor’s failure. Many policies exclude one or both, cap them with low limits, or apply a waiting period of 8 to 12 hours before coverage starts. Read your policy or ask your broker. Software license agreements usually limit the vendor’s liability to the fees you paid.

    What scams follow a major outage?

    Criminals moved within hours. Government agencies warned of phishing emails, fake “fix” files that carried malware, phone calls from people posing as CrowdStrike or Microsoft support, and newly registered look-alike websites. The pattern repeats after every large event.

    During any outage, take instructions only from the vendor’s official website and from your own IT provider, reached at a number you already have. Tell your staff the same. Our guide to spotting a phishing email covers the signs.

    Is relying on one vendor a mistake?

    Not by itself. A small business can’t run two of everything, and a single well-run product is easier to keep secure than a patchwork. The mistake is depending on one vendor with no plan for the day it fails. We made the same point after the Change Healthcare attack. Know your single points of failure, and have a workaround written down for each.

    How do I test my plan?

    Run a tabletop exercise. Gather the owner, the office manager, and your IT contact for an hour. Pose the scenario: it is 8 a.m. on a Friday, every computer shows a blue screen, and your IT provider’s phone is busy. Walk through the day. How do you open? How do you take payments? Who calls customers? Where is the recovery key? Write down every answer that begins with “I don’t know.” Those are your action items.

    Your next step

    Find out where your BitLocker recovery keys are stored and whether you could reach them with every company computer down. Then print your contact list. Cerberus Cybersecurity writes business continuity and incident response plans for small businesses and runs the exercises that test them. See our services or contact us.

  • I Got a Data Breach Letter: What Should I Do Now?

    By J. Mesa

    On May 31, Live Nation told regulators that someone had accessed a database holding Ticketmaster customer data. A criminal group claims to hold records on 560 million customers. The data sat in a cloud environment hosted by Snowflake, and on June 10 the security firm Mandiant reported that about 165 Snowflake customers may have been exposed in the same campaign. The attackers used stolen logins on accounts that lacked multi-factor authentication. If you bought a concert ticket in the last few years, expect a letter. This guide tells you what to do with it.

    What is a data breach notification letter?

    A data breach notification letter is a notice a company must send when someone gains unauthorized access to your personal information. Every US state has a law that requires it. The letter usually states what happened, when, what types of information were involved, what the company is doing, and what it offers you.

    How do I know the letter is real?

    Scammers send fake breach notices to collect the very details a real breach exposes. Check before you act.

    • Search for news of the breach and for a notice on the company’s official website.
    • Many state attorneys general publish the breach notices filed with them.
    • Do not call the phone number, scan the QR code, or tap the link in a notice you have doubts about. Find the company’s contact details yourself.
    • A real notice does not ask you to confirm your Social Security number or pay a fee.
    • To accept free credit monitoring, type the monitoring company’s web address yourself and enter the enrollment code from the letter.

    What should I do first?

    Read the letter for one fact: which types of your information were exposed. The right response depends on that list. Then work through the matching section below.

    What if my password or login was exposed?

    1. Change the password on that account now.
    2. Change it on every other account where you used the same or a similar password. Criminals test stolen logins on other sites, an attack called credential stuffing.
    3. Turn on multi-factor authentication.
    4. Start using a password manager, so each account gets its own password.

    What if my Social Security number was exposed?

    1. Freeze your credit at Equifax, Experian, and TransUnion. It is free and blocks new accounts in your name.
    2. Get an IRS Identity Protection PIN at IRS.gov to stop a false tax return.
    3. Create your own account at ssa.gov before someone else does.
    4. Accept the free credit monitoring the company offers.
    5. Check your credit reports at annualcreditreport.com.

    You can’t change a Social Security number in any practical sense, so treat this exposure as permanent and keep the freeze in place.

    What if my credit or debit card number was exposed?

    • Review recent transactions and report anything you do not recognize.
    • Ask the issuer for a new card number.
    • Turn on alerts for every transaction.
    • For a debit card, act faster. Fraud on a debit card takes money straight from your bank account, and your legal protection shrinks the longer you wait to report it.
    • Update the new number with the services that bill you automatically.

    What if my bank account number was exposed?

    Call the bank. Ask about fraud monitoring on the account, and whether it recommends a new account number. Turn on alerts. Watch for small test withdrawals, which criminals use to check that an account works.

    What if my driver’s license or passport number was exposed?

    • Ask your state motor vehicle agency whether it will flag or reissue the license. Policies differ by state.
    • Freeze your credit, since a license number helps a thief pass identity checks.
    • For a passport, the State Department generally does not require a replacement when only the number is exposed. Watch for misuse and report it.

    What if my medical or insurance information was exposed?

    • Read every explanation of benefits statement from your insurer. Look for visits, prescriptions, or equipment you never received.
    • Ask your insurer and your providers for copies of your records, and dispute entries that are not yours. Another person’s information in your chart can affect your care.
    • Ask the insurer whether it will issue a new member number.

    What if only my name, email, phone, or address was exposed?

    This sounds minor, and it carries a real risk: targeted phishing. A criminal who knows you bought tickets, which hospital you used, or which bank you hold an account with can write a convincing message. For months after a breach, treat any email, text, or call about that company with suspicion. See our guides to phishing emails and scam texts.

    Should I accept the free credit monitoring?

    Yes. It costs you nothing and alerts you to new activity on your credit file. Enrolling does not usually waive your legal rights, though you should read the terms. Monitoring reports a problem after it happens. A credit freeze prevents the most damaging kind. Do both.

    What should I not do?

    • Do not ignore the letter.
    • Do not pay anyone who offers to remove your data from the dark web. Nobody can.
    • Do not respond to follow-up calls or texts that ask you to “verify” your information.
    • Do not assume one breach is the end of it. The same data gets resold for years.

    How do I check what has been exposed about me?

    Search your email addresses at haveibeenpwned.com. The free service lists known breaches that included each address and can notify you of new ones. Many password managers and browsers also flag saved passwords that appear in breach data.

    Can I sue, or join a class action?

    Large breaches often lead to class action lawsuits and settlements. You will normally receive a separate notice by mail or email with a claim form and a deadline. Verify that notice the same way you verified the breach letter. Keep your breach letter and records of any time and money you spent responding, since settlements sometimes reimburse those losses.

    What does this mean if I own a business?

    Three things.

    Your customers will get letters from you one day if you are unprepared. Every state requires notification, and the deadlines are short. Know what personal data you hold, where it lives, and which laws apply. Write an incident response plan before you need one.

    The Snowflake cases carry a plain lesson. According to Mandiant, the attackers did not break Snowflake’s own systems. They signed in to customer accounts with usernames and passwords that information-stealing malware had captured from infected computers, some of them years earlier. The affected accounts had no multi-factor authentication. A stolen password should never be enough to reach your customer data.

    • Require multi-factor authentication on every cloud service that holds business data.
    • Change passwords after any malware infection, including infections on a contractor’s or an employee’s personal computer.
    • Keep work logins off personal and shared home computers.
    • Limit cloud access to known networks or managed devices where the service allows it.
    • Ask your vendors the same questions.

    Your employees are breach victims too. A staff member dealing with identity theft loses time and focus. Share this guide, and consider it part of your security awareness training.

    Your next step

    If you have a breach letter on the counter, read it tonight and list what was exposed. Then freeze your credit. If you own a business, list every cloud service that holds customer data and confirm each one requires multi-factor authentication. Cerberus Cybersecurity helps small businesses assess their data protection and write breach response plans. See our services or contact us.

  • Unpaid Toll Text Scams: What Is Smishing and How Do You Stop It?

    By J. Mesa

    A text arrives: you owe $12.51 in unpaid tolls, and a $50 late fee applies unless you pay today. A link follows. You have not driven a toll road in months, but the amount is small and the deadline is close. That is the design. On April 12, the FBI’s Internet Crime Complaint Center warned that it had received more than 2,000 complaints since early March about texts posing as road toll collection services in at least three states.

    What is smishing?

    Smishing is phishing by text message. The word combines SMS and phishing. The message poses as a company or an agency you trust and pushes you to tap a link, call a number, or reply with personal details.

    How does the toll text scam work?

    1. The scammer sends the same message to thousands of phone numbers, without knowing who drives where.
    2. The text names a toll service and claims a small unpaid balance.
    3. It threatens a late fee to create urgency.
    4. The link leads to a website that copies the look of the real toll agency.
    5. The site asks for your name, address, and card number to “settle” the balance. Some versions ask for a driver’s license number as well.
    6. The scammer uses or sells the card and the personal details.

    The FBI notes that the texts use nearly identical wording, and that the link changes to imitate the toll service of whichever state the message claims to come from. The small dollar amount is deliberate. People argue with a $900 bill. They pay $12 to make a problem go away.

    What other smishing texts are common?

    • Package delivery. “Your package could not be delivered. Confirm your address.” These pose as the Postal Service, UPS, or FedEx.
    • Bank fraud alerts. “Did you attempt a $1,200 purchase? Reply YES or NO.” A reply triggers a call from a fake fraud department.
    • Account problems. Messages that pose as Amazon, Apple, Netflix, or PayPal and claim a locked account or a failed payment.
    • The boss. A text from an unknown number opening with “Hi, it’s owner’s name]. Are you free?” This leads to a [gift card request.
    • Wrong number. A friendly “Is this Sarah?” that turns into a long conversation and, weeks later, an investment pitch.
    • Job offers. Unsolicited offers of remote work with high pay for little effort.
    • Verification codes. A text or call asking you to read back a code you just received. The scammer is logging in to your account at that moment.
    • Prizes and refunds. You won, or you are owed money. Tap here.

    Why do text scams work so well?

    • People open nearly every text, and most within minutes.
    • A phone shows little of a web address, which hides a fake domain.
    • Email has spam filters built over decades. Text messaging has far fewer.
    • A text feels personal and urgent in a way email does not.
    • Legitimate companies do send texts about deliveries and fraud, so the fake ones fit an expected pattern.

    How do I spot a fake text?

    • You did not expect it. You ordered no package, drove no toll road, and made no purchase.
    • It creates urgency. A fee, a deadline, a locked account.
    • The sender looks wrong. A full ten-digit number, an email address, or an international number, where a real company would use a short code.
    • The link looks wrong. Odd endings, extra words, hyphens, or a shortened link that hides the destination.
    • It asks for payment or personal details through the link.
    • It tells you to reply “Y” and reopen the message to activate the link. That instruction exists to get around a phone’s link protections.

    What should I do if I get a toll text?

    The FBI’s advice is direct.

    1. Do not tap the link.
    2. Check your account through the toll service’s real website, which you type in yourself, or call the customer service number printed on your statement or transponder.
    3. Report the text at ic3.gov, and include the phone number it came from and the website in the link.
    4. Delete the text.

    How do I report and block scam texts?

    • Forward the message to 7726, which spells SPAM. This reports it to your carrier at no charge.
    • Use the report option in your messaging app: “Report Junk” on an iPhone, “Block and report spam” on Android.
    • Block the number.
    • Report to the FTC at ReportFraud.ftc.gov.
    • Do not reply, not even with “STOP.” A reply confirms that a person reads the number.

    Turn on the filters your phone already has. On an iPhone, enable “Filter Unknown Senders” in the Messages settings. On Android, enable spam protection in the Messages app.

    What should I do if I tapped the link?

    It depends on how far you went.

    • You tapped and entered nothing. Close the page. Clear your browser history and site data. Keep the phone’s software updated. You are almost certainly fine.
    • You entered card details. Call your card issuer now, dispute any charges, and ask for a new card number.
    • You entered a password. Change it right away, and change it anywhere else you used it. Turn on multi-factor authentication.
    • You entered personal details such as a driver’s license or Social Security number. Freeze your credit and watch your accounts.
    • You installed something. Remove the app, update the phone, and if the phone holds work email, tell your IT contact.

    How does smishing threaten a business?

    Your employees carry work email, files, and authentication apps on the same phone that receives these texts.

    • Stolen work logins. A text that poses as IT or as Microsoft sends an employee to a fake sign-in page. The phone sits outside your office firewall and web filter.
    • Stolen verification codes. An attacker who has a password texts or calls the employee and asks for the six-digit code.
    • Fake executives. Texts that pose as the owner ask for gift cards, a wire, or a quick call.
    • Payroll diversion. A text that poses as an employee asks HR to change a direct deposit account.

    How do I protect my business?

    • Add texts to your training. Most programs cover email and stop there. Show staff real examples of smishing. Our cybersecurity training includes them.
    • Set a rule: IT and leadership never ask for passwords or codes by text.
    • Verify by voice. Any request for money, gift cards, or a change to payroll or bank details gets a call to a known number.
    • Use stronger multi-factor methods. An authenticator app with number matching or a security key resists code theft better than a text message.
    • Set minimum standards for phones that hold work data: a screen lock, current software, and no unknown apps.
    • Make reporting simple. Tell staff to screenshot a suspicious text and send it to one named person.

    How can I tell whether a text from a company is real?

    Assume it is not, and check another way. Open the company’s app or type its web address. Call the number on your card or your bill. Legitimate banks, carriers, and agencies will have the same alert waiting in your account if it is genuine. No real company loses patience because you chose to verify.

    Does my business text its own customers?

    If you send appointment reminders, invoices, or delivery notices by text, scammers can imitate you. Tell customers what you will and will not send. Use a consistent number or short code. Keep links on your own domain, and never ask for card details or passwords by text. In the United States, carriers now require businesses that send texts from standard ten-digit numbers to register their brand and their messaging campaigns. Unregistered traffic gets blocked.

    Your next step

    Show the toll text to your staff and your family this week, and make sure each person knows the number 7726. For training that covers text, phone, and email scams together, see our services or contact Cerberus Cybersecurity.

  • The Change Healthcare Attack: Lessons for Every Small Practice and Business

    By J. Mesa

    For three weeks, medical practices across the United States have struggled to get paid. Pharmacies have had trouble checking insurance coverage. Billing staff have gone back to paper forms and phone calls. None of those practices was hacked. Their vendor was. The attack on Change Healthcare is the clearest lesson in years about what happens when a business depends on a single outside company.

    What happened to Change Healthcare?

    Change Healthcare, a unit of UnitedHealth Group’s Optum division, operates one of the largest clearinghouses for medical claims and pharmacy transactions in the country. On February 21, 2024, the company discovered an intruder in its systems and disconnected them to contain the damage.

    The shutdown cut the link between providers and insurers. Claims could not be submitted. Payments stopped flowing. Pharmacies could not process prescriptions through insurance in the usual way, and some patients paid cash or went without.

    Who is behind the attack?

    UnitedHealth has attributed the attack to the ransomware group known as ALPHV, or BlackCat. In early March, news outlets and blockchain researchers reported that a payment of about $22 million in bitcoin had moved to a wallet tied to the group. UnitedHealth has not confirmed whether it paid a ransom.

    What is the impact so far?

    • Hospitals, physician groups, dentists, therapists, and pharmacies nationwide have reported delayed claims and payments.
    • Small practices, which hold little cash in reserve, have borrowed money or delayed their own bills to make payroll.
    • The federal government has offered advance payments to Medicare providers, and UnitedHealth has set up a temporary funding assistance program.
    • On March 13, the Office for Civil Rights at the Department of Health and Human Services opened an investigation into the incident, citing its unprecedented scale.

    The company is restoring services in stages. The full count of affected patients and the method of entry have not been made public as of this writing.

    Why did one vendor’s outage hurt so many?

    Concentration. Change Healthcare sits in the middle of an enormous share of the country’s medical claims. Thousands of practices relied on it, often through their practice management software, without ever choosing it by name. Many did not know they depended on it until the day it stopped.

    Security people call this a single point of failure. When one supplier handles a function that nothing else can perform, its bad day becomes yours.

    I do not work in healthcare. Why should I care?

    Because every business has its own Change Healthcare. Ask yourself what would happen if one of these went dark for a month:

    • Your payment processor
    • Your payroll service
    • Your accounting or invoicing platform
    • Your email and file storage provider
    • Your scheduling or point-of-sale system
    • Your IT provider
    • The one supplier whose portal you order everything through

    If the honest answer is “we could not take money” or “we could not pay staff,” you have found a dependency worth planning for.

    How do I find my critical vendor dependencies?

    Spend an hour on this exercise.

    1. List your core business functions: getting paid, paying staff, serving customers, ordering supplies, communicating.
    2. For each function, write down every outside company it relies on.
    3. Ask the vendors that matter most which companies they rely on. The clearinghouse behind your billing software, the cloud host behind your records system.
    4. Mark any function with only one path and no backup.
    5. For each one, estimate how many days you could operate without it.

    How do I prepare for a vendor outage?

    • Identify a backup. For claims, enroll with a second clearinghouse now. For payments, keep a second processor or a manual method ready. Setting up an alternative during a crisis takes weeks.
    • Write the manual procedure. How do you take a payment, record an appointment, or submit a claim on paper? Store the forms and the instructions where staff can find them.
    • Build a cash cushion or a credit line. The practices suffering least this month had reserves or an open line of credit. Arrange the credit before you need it.
    • Keep your own copy of your data. Export customer lists, schedules, and financial records on a schedule, so a vendor outage does not leave you blind.
    • Know your contacts. Keep vendor support numbers, account numbers, and your insurance agent’s number on paper.
    • Check your insurance. Ask whether your cyber policy includes contingent or dependent business interruption coverage, which pays when a vendor’s outage halts your income. Many policies limit or exclude it.

    What should I ask my vendors?

    1. What is your plan if you suffer a ransomware attack?
    2. How long would it take to restore service, and have you tested that?
    3. Do you require multi-factor authentication on every remote access system?
    4. How and when will you notify us of an incident?
    5. Do you hold our data, and how is it protected?
    6. Which other companies do you depend on to deliver our service?
    7. What does our contract say about outages and data breaches?

    A vendor that can’t answer has told you how prepared it is.

    What should I do if a vendor of mine is attacked?

    1. Disconnect from the vendor’s systems until it confirms the connection is safe. Many providers cut their links to Change Healthcare within hours, which protected their own networks.
    2. Change the passwords and keys tied to that vendor.
    3. Switch to your backup process.
    4. Get facts in writing and watch the vendor’s official status page. Be wary of emails and calls that claim to come from the vendor. Scammers exploit every major outage with fake “support” and “payment update” messages.
    5. Call your insurance carrier and your attorney.
    6. Document your losses from the first day: lost revenue, extra labor, loan costs.
    7. Tell your customers or patients what is happening and what you are doing about it.

    What does HIPAA say about a breach at a business associate?

    Change Healthcare acts as a business associate for many providers and as a clearinghouse in its own right. Under HIPAA, a business associate must notify the covered entity of a breach, and the covered entity carries the duty to notify affected patients, though the two can agree that the business associate will send the notices. The Office for Civil Rights has said its investigation centers on Change Healthcare and UnitedHealth, and it reminded providers of their obligations to have business associate agreements in place and to make sure breach notifications happen.

    If you are a provider, find your business associate agreements now and talk with your attorney about how notification will work once the facts are known.

    What security lessons apply to my own systems?

    The public does not yet know how the attackers entered. The basics that stop most ransomware remain the same:

    • Multi-factor authentication on every remote access point
    • Prompt patching, starting with internet-facing systems
    • Offline, tested backups
    • Endpoint detection and response on servers and workstations
    • A written incident response plan
    • Trained staff

    Your next step

    Write down the one vendor whose outage would stop your income. Then call a competitor of that vendor and ask what it takes to set up a standby account. Cerberus Cybersecurity helps small businesses and practices map vendor dependencies, write continuity procedures, and meet HIPAA requirements. See our services or contact us.

  • What Is Credential Stuffing? The 23andMe Breach Explained

    By J. Mesa

    In early October, 23andMe told customers that someone had accessed user accounts and compiled profile information from its DNA Relatives feature. The company said its own systems were not broken into. The attackers signed in through the front door, with usernames and passwords that customers had also used on other websites. That technique has a name, and it works against any business with a login page.

    What happened at 23andMe?

    On October 6, 2023, 23andMe published a notice describing the incident. According to the company, attackers used recycled login credentials to get into individual accounts. From inside those accounts, they collected information that other users had chosen to share through DNA Relatives, an optional feature that connects genetic matches. A seller on a hacking forum then advertised lists of profile data.

    The reach extended beyond the accounts with reused passwords. Each compromised account could see the shared profile details of its DNA matches, so one weak password exposed information about many people who had done nothing wrong.

    23andMe responded by resetting passwords and, starting November 6, requiring two-step verification for all customers. The investigation continues as of this writing.

    What is credential stuffing?

    Credential stuffing is an attack in which criminals take usernames and passwords stolen from one website and try them, by the million, on other websites. It works because people reuse passwords.

    The attacker does not guess. The attacker already holds your real password from an old breach, and bets that you used it somewhere else.

    How does credential stuffing work?

    1. Collect. Criminals gather username and password pairs from past breaches. Billions of them circulate on criminal forums, many for free.
    2. Automate. Software feeds those pairs into the login page of a target site. The tools route attempts through thousands of IP addresses to look like ordinary customers.
    3. Sort. The software records each pair that works.
    4. Cash out. The attacker drains stored value, steals personal data, places orders, or sells the working logins to someone else.

    The success rate per attempt is low, often well under one percent. At a million attempts, that still yields thousands of open accounts.

    Why does credential stuffing work so well?

    Because of one habit. Surveys keep finding that a majority of people reuse passwords across accounts. A password you created for a forum in 2014 may still guard your email today. When the forum was breached, that password stopped being a secret. See our post on the most compromised passwords.

    How is it different from a brute force attack?

    A brute force attack guesses many passwords against one account. Password spraying tries a few common passwords, such as “Winter2023,” against many accounts. Credential stuffing uses known, real pairs. It is quieter and more efficient than either, because each account sees one or two attempts.

    How do I know whether my password was in a breach?

    • Search your email address at haveibeenpwned.com, a free service run by a respected security researcher. It lists the known breaches that included your address.
    • Use the password checkup built into your password manager or your browser. Chrome, Edge, Safari, and Firefox all flag saved passwords found in breach data.
    • Watch for signs: password reset emails you did not request, login alerts from unfamiliar places, and orders or messages you did not send.

    How do I protect my own accounts?

    1. Use a different password for every account. This single step defeats credential stuffing. A password stolen from one site then opens nothing else.
    2. Use a password manager to create and remember them. Nobody can memorize a hundred unique passwords.
    3. Turn on multi-factor authentication wherever a site offers it, starting with email, banking, and any account that holds sensitive data. An attacker with the right password still lacks the second step.
    4. Change reused passwords now, beginning with your email account. Email is the key to every other account, because password resets go there.
    5. Close accounts you no longer use. Each one is a copy of your data waiting for a breach.

    What does this mean for sensitive accounts?

    Think about what an account holds, not how often you use it. A genetic testing account contains information you can never change. The same goes for health portals, tax software, and financial accounts. Protect those with your strongest settings even if you sign in once a year, and review what you have chosen to share with other users.

    How do I protect my business from credential stuffing?

    Your staff reuse passwords too, and their work email address appears in breach lists.

    • Require multi-factor authentication on email, remote access, payroll, banking, and every cloud application that supports it.
    • Provide a business password manager and require unique passwords for work accounts.
    • Block known-breached passwords. Microsoft 365 and other identity systems can refuse passwords that appear in breach lists.
    • Turn on sign-in risk alerts. Have someone review alerts for logins from unfamiliar countries and for impossible travel.
    • Set lockout and throttling rules to slow automated attempts.
    • Turn off old sign-in methods. Legacy email protocols such as POP and IMAP with basic authentication bypass multi-factor authentication. Disable them.
    • Disable accounts when people leave.
    • Train your staff on why a work password must never match a personal one. Our cybersecurity training covers this.

    What if my business has customer logins?

    If customers sign in to your website, store, or portal, you carry the 23andMe problem in miniature.

    • Offer multi-factor authentication to customers, and require it for accounts that hold sensitive data.
    • Add rate limiting and bot detection to the login page.
    • Check new and changed passwords against lists of breached passwords.
    • Email customers when a login occurs from a new device.
    • Limit what one account can see about other users.
    • Monitor for spikes in failed logins.

    When customers lose data through your login page, they hold your business responsible, whoever chose the weak password.

    Is the company at fault, or the customer?

    Both carry part of it. A customer who reuses a password leaves the door unlocked. A company that holds sensitive data and makes two-step verification optional has decided to accept that risk on its customers’ behalf. Regulators and courts increasingly expect a business to anticipate reused passwords and defend against them. Plan as if your users will reuse passwords, because many will.

    What should I do if I have a 23andMe account?

    • Change the password to one you use nowhere else.
    • Turn on two-step verification.
    • Review your DNA Relatives and profile sharing settings, and reduce what you display.
    • Change the password on any other account that shared the old one.
    • Be alert for phishing emails that mention your ancestry or relatives. Attackers use stolen details to make messages convincing.

    Your next step

    Search your work and personal email addresses at haveibeenpwned.com today. Then change every password you have reused, starting with email. For help setting password and access policies across your business, see our services or contact Cerberus Cybersecurity.

  • The MGM and Caesars Hacks: What a Help Desk Phone Call Teaches Small Businesses

    By J. Mesa

    Slot machines went dark on the Las Vegas Strip this week. Guests at MGM Resorts properties waited in long lines to check in, digital room keys stopped working, and the company’s websites went offline. MGM disclosed a “cybersecurity issue” on September 11. Three days later, Caesars Entertainment told regulators that it, too, had been breached. The early reporting on both cases points to the same weak spot, and it is one your business shares.

    What happened at MGM and Caesars?

    MGM Resorts. The company announced on September 11, 2023 that it had identified a cybersecurity issue and shut down certain systems to protect them. The outage reached hotels and casinos in several states. As of this writing, MGM is still restoring operations.

    Caesars Entertainment. In a filing with the Securities and Exchange Commission on September 14, Caesars disclosed a social engineering attack on an outsourced IT support vendor. The attackers copied data that included the company’s loyalty program database, with driver’s license and Social Security numbers for a large number of members. News outlets report that Caesars paid a ransom of about $15 million. The company’s filing says only that it took steps to ensure the stolen data is deleted and that it can’t guarantee that result.

    How did the attackers get in?

    MGM has not published the details. Security researchers and news reports attribute the attack to a group known as Scattered Spider, working with the ALPHV ransomware operation, and describe a simple method: the attackers found an employee’s information on LinkedIn, called the IT help desk, posed as that employee, and talked the help desk into resetting access. Treat that account as reported, not confirmed.

    Caesars confirmed its own version in writing. The attack began with social engineering of an IT support vendor.

    Neither story involves a brilliant piece of code. Both involve a person on a phone who wanted to be helpful.

    What is help desk social engineering?

    Help desk social engineering is an attack in which a criminal contacts IT support, pretends to be an employee, and asks for a password reset or a new multi-factor authentication device. If the support person agrees, the attacker receives a working login and bypasses every technical control in front of it.

    The attacker prepares first. Names, job titles, managers, and office locations come from LinkedIn and company websites. Dates of birth, addresses, and the last four digits of Social Security numbers come from old data breaches. Armed with those, the caller can answer the standard verification questions better than the real employee could.

    Who is Scattered Spider?

    Scattered Spider is a name researchers use for a loose group of young, native English-speaking attackers who specialize in social engineering. Their known methods include phone calls to help desks, text message phishing aimed at employees, and SIM swapping to intercept verification codes. Their fluency and confidence on the phone set them apart from most ransomware crews.

    Why does this matter to a small business?

    You may think a casino has nothing in common with a ten-person office. Look at the steps again.

    • An employee’s details were public.
    • Someone with the power to reset passwords took a phone call.
    • That person verified the caller with information a stranger could find.
    • An outside IT vendor held the keys.

    Most small businesses match all four. Your “help desk” may be an office manager, a part-time IT person, or a managed service provider with a call center. The question is the same: what does it take to convince that person to reset your password?

    How do I protect password resets?

    Write a reset procedure and require everyone who can reset credentials to follow it, including your outside IT company.

    1. Call back. Hang up and call the employee at the number on file in your own records. Never use a number the caller supplies.
    2. Verify with something a stranger can’t know. Dates of birth, employee numbers, and manager names fail this test. Use a video call with a manager who knows the person, an in-person visit, or a verification code sent through an internal channel the employee already uses.
    3. Require a second approval for resets of administrator accounts, finance staff, and executives.
    4. Treat multi-factor resets as high risk. Enrolling a new phone or removing a security key deserves a stricter check than a password reset.
    5. Add a delay for privileged accounts where the business can tolerate one.
    6. Log every reset and review the list each week.
    7. Notify the employee by a separate channel each time a reset or a new device enrollment occurs.

    Does multi-factor authentication stop this attack?

    Only in part. Multi-factor authentication blocks an attacker who holds a stolen password. It does nothing when the help desk enrolls the attacker’s phone as the employee’s new device. The reset process becomes the back door.

    Some methods hold up better than others. Text message codes fall to SIM swapping. Push notifications fall to “fatigue” attacks, in which the attacker sends prompts until the employee taps approve. Hardware security keys and number matching resist both. Use the stronger methods for administrators and anyone who handles money.

    What should I ask my IT provider?

    Caesars was breached through a vendor. Ask yours:

    • How do your technicians verify my employees before a password or multi-factor reset?
    • Who at my company can authorize a reset for an administrator account?
    • Do your own technicians use phishing-resistant multi-factor authentication?
    • How would you detect a new device enrolled on one of my accounts?
    • What do you do in the first hour if you suspect one of my accounts was taken over?

    Put the answers in the contract or in a written procedure both sides sign.

    How do I reduce what attackers can learn about my staff?

    You can’t hide your employees, and you should not try. You can remove the details that make impersonation easy.

    • Keep direct phone numbers, internal titles for IT administrators, and organization charts off the public website.
    • Ask staff with administrator or finance roles to limit what their public profiles reveal about the systems they manage.
    • Never use information found in public records as proof of identity.

    What should I train my staff to do?

    • Expect that someone may call pretending to be a coworker, a vendor, or IT.
    • Refuse to read a verification code to anyone, including a caller who claims to be from support.
    • Deny any sign-in prompt they did not start, and report it.
    • Report an unexpected password reset notice at once.
    • Slow down when a caller pushes urgency. A real colleague will wait five minutes for a callback.

    Give the help desk the same message from the top: nobody gets in trouble for making the boss wait while they verify. See our cybersecurity training for sessions built around phone-based attacks.

    Should a business pay a ransom?

    The FBI advises against it. Payment funds the next attack and buys a promise from a criminal. Caesars’ own filing admits it can’t guarantee the outcome. The better investment happens earlier: tested backups, a written incident response plan, and a reset procedure that a confident voice on the phone can’t talk past.

    Your next step

    Call your own IT support this week and ask them to walk you through how they would verify you for a password reset. If the answer relies on your date of birth or your employee number, you have work to do. Cerberus Cybersecurity writes identity verification procedures and trains teams to resist phone-based attacks. See our services or contact us.

  • The MOVEit Breach Explained: What Happened and What It Teaches

    The MOVEit Breach Explained: What Happened and What It Teaches

    By J. Mesa

    In late May 2023, a criminal group began stealing files from organizations around the world through a single piece of software. The software was MOVEit Transfer, and the attack became one of the largest data theft events on record.

    I first wrote about it in our June 2023 Cyber Bytes. This post is the full explanation: what happened, who was affected, and what a small business can learn from it.

    What is MOVEit?

    MOVEit Transfer is a managed file transfer product made by Progress Software. Organizations use it to send large or sensitive files in a secure way, such as payroll data, health records, and financial reports. Banks, governments, universities, and the vendors that serve them relied on it.

    That is the reason the breach spread so far. The product existed to move the most sensitive files an organization had.

    What happened in the MOVEit breach?

    Attackers found a flaw in MOVEit Transfer that the vendor did not yet know about. A flaw like that is called a zero-day, because the vendor has had zero days to fix it.

    The flaw is tracked as CVE-2023-34362. It was a SQL injection vulnerability, which means an attacker could send crafted input to the application and make its database run the attacker’s commands. Through it, the attackers installed a hidden backdoor on MOVEit servers and downloaded the stored files.

    Progress Software disclosed the flaw and released a fix on May 31, 2023. By then the attackers had already been at work for days.

    Who was behind the attack?

    A ransomware group known as Clop, also written Cl0p, claimed responsibility. In this campaign the group did not encrypt its victims’ files. It stole the data and then threatened to publish it unless each victim paid.

    Security teams call this data extortion. It works on organizations that have good backups, because a backup does not undo a leak.

    How many organizations were affected?

    Researchers who tracked the campaign counted more than 2,500 organizations and tens of millions of individuals. The victims included government agencies, banks, universities, healthcare providers, and large employers.

    Many of them never ran MOVEit. Their payroll provider, pension administrator, or other vendor did. The attackers reached those organizations’ data through a supplier.

    Was my data exposed in the MOVEit breach?

    If it was, the affected organization should have sent you a notice. You can also:

    • Search your email address at haveibeenpwned.com
    • Review letters from your employer, bank, health plan, or state agencies from 2023 and 2024
    • Take up any free credit monitoring those notices offered

    If your data was exposed, place a free credit freeze with Equifax, Experian, and TransUnion, and treat unexpected messages about your accounts with suspicion.

    Why did the attack spread so fast?

    • The software faced the internet. MOVEit servers accept connections from outside, so attackers could reach them directly.
    • Nobody had a patch. A zero-day leaves defenders with no fix until the vendor releases one.
    • The attackers prepared. They struck many servers in a short window, before word spread.
    • The data was concentrated. One server held files from many clients.

    What is a supply chain attack?

    A supply chain attack reaches you through a company you trust. You hand your data to a vendor, and the attacker breaks into the vendor.

    MOVEit showed how far that reaches. Your security depends on your own controls and on the controls of every company that holds your data.

    What should a business do after an incident like this?

    1. Find out if you run the affected product. Check your own systems, then ask your vendors.
    2. Apply the vendor’s fix right away. If you can’t, take the system offline until you can.
    3. Look for signs of intrusion. Follow the vendor’s guidance on what to check.
    4. Reset credentials that the system stored or used.
    5. Notify affected people as the law requires.

    What does MOVEit teach a small business?

    • Patch fast. Install security updates as soon as vendors release them, and start with anything that faces the internet.
    • Know your vendors. Keep a list of who holds your data and what they hold. Ask each one how they protect it and how they will tell you about a breach.
    • Limit what you share and store. Send vendors only the data they need. Delete files from transfer systems once they have arrived.
    • Control access. Use multi-factor authentication and give each account the least access it needs.
    • Train your people. After a breach, criminals send phishing emails that use the stolen details. Staff who expect that are harder to fool.
    • Plan your response. Decide now who you will call and how you will notify customers.

    What questions should I ask my vendors?

    1. Which of our data do you store, and for how long?
    2. How fast do you install security updates?
    3. Do you require multi-factor authentication for your staff?
    4. How will you notify us of a breach, and within what time?
    5. Do you have an independent security report, such as a SOC 2?

    A vendor who answers these without hesitation takes security seriously. One who can’t answer has told you something too.

    Could this happen again?

    Yes. Attackers have hit other file transfer products with the same playbook before and since. Any widely used tool that holds sensitive data and faces the internet is a target. You can’t prevent a zero-day. You can limit what an attacker finds, and you can respond fast.

    Does good backup protect me from data extortion?

    No. Backups protect you from losing access to your files. They do nothing once an attacker holds a copy. The defenses against data theft are different: store less, encrypt sensitive files, restrict who and what can reach them, and watch for large transfers leaving your network. Plan for both kinds of attack, because criminal groups now use both.

    Should a victim pay the ransom?

    The FBI advises against paying. Payment does not guarantee the criminals delete the data, and it funds the next attack. Each case carries legal and business questions, so involve your attorney, your insurer, and law enforcement before you decide.

    Your next step

    Make a list of every vendor that holds your customer or employee data. If the list surprises you, that is useful to know. Cerberus Cybersecurity helps businesses review vendor risk as part of our risk and compliance assessments. Contact us to get started.

  • Log4Shell Explained: What It Is, Who Is at Risk, and How to Check

    Log4Shell Explained: What It Is, Who Is at Risk, and How to Check

    By J. Mesa

    In December 2021, security teams around the world spent their holidays hunting for one small piece of software. A flaw in a logging tool called Log4j let an attacker take over a server by sending it a single line of text. The flaw got the name Log4Shell, and attackers still use it today.

    You may never have heard of Log4j. Your business may still run it. This post explains what happened, who is at risk, and what to check.

    What is Log4Shell?

    Log4j is a free, open-source logging library for the Java programming language. Developers use it to record what an application does: who logged in, what a user searched for, which errors occurred. Thousands of commercial products include it, from web applications to network appliances.

    Log4Shell is the name for a vulnerability in Log4j tracked as CVE-2021-44228. Researchers disclosed it on December 9, 2021. It received a severity score of 10 out of 10, the highest rating possible.

    How does the Log4Shell attack work?

    Log4j had a feature that looked up information whenever it found a special instruction inside a log message. An attacker could place that instruction anywhere the application would log it: a username field, a search box, a web request header.

    1. The attacker sends text containing a lookup instruction that points to a server the attacker controls.
    2. The application writes that text to its log.
    3. Log4j reads the instruction, connects to the attacker’s server, and downloads code.
    4. The application runs that code. The attacker now controls the system.

    The attacker needs no password and no account. The industry calls this remote code execution, and it is the reason the score reached 10.

    Why was Log4Shell so serious?

    • It was everywhere. Log4j sat inside products from hundreds of vendors. Many companies did not know they used it.
    • It was easy. Working attack code spread within hours of disclosure.
    • It was hidden. Log4j often sits several layers deep inside other software, so finding it took weeks.

    The director of the US Cybersecurity and Infrastructure Security Agency (CISA) at the time called it one of the most serious vulnerabilities she had seen in her career. Criminal groups and nation-state actors both used it. Botnets such as Mirai and Kinsing scanned the internet for vulnerable servers and installed malware, cryptocurrency miners, and ransomware.

    Is Log4Shell still a threat?

    Yes. Many organizations patched in 2021 and 2022. Many forgotten or unmanaged applications still run vulnerable versions, and attackers keep scanning for them. In 2022 the US Cyber Safety Review Board called Log4Shell an “endemic vulnerability” and warned that vulnerable copies would stay in systems for a decade or longer.

    Old software does not fix itself. The server someone set up in 2019 and forgot is the one an attacker finds.

    Am I affected if my business doesn’t write software?

    You can be. You don’t need a developer on staff to run Java software. Log4j shipped inside products that small businesses buy and install, including:

    • Network and security appliances
    • Remote access and virtual desktop products
    • Backup, monitoring, and help desk tools
    • Line-of-business applications from smaller vendors

    Cloud services you subscribe to were the vendor’s job to patch. Software and devices in your own office or server room are your job.

    How do I check if I am vulnerable to Log4Shell?

    1. List what you run. Write down every server, appliance, and business application you own, with its version. You can’t patch what you don’t know about.
    2. Check vendor advisories. Search each vendor’s site for “Log4j” or “CVE-2021-44228.” Most published a statement and a fixed version.
    3. Scan. A vulnerability scan finds known-vulnerable versions of Log4j on your network. This is a standard part of a vulnerability assessment.
    4. Look for old systems. Pay attention to anything installed before 2022 that no one has updated since.

    Vulnerable versions of Log4j run from 2.0-beta9 through 2.14.1.

    How do I fix Log4Shell?

    • Update the affected product to the vendor’s fixed release. For Log4j itself, that means version 2.17.1 or later on Java 8.
    • If a vendor no longer supports the product, replace it or take it off the network.
    • Limit which servers can make outbound connections to the internet. The attack depends on your server reaching out to the attacker.
    • Watch your logs for the text ${jndi:, the marker of an attempted attack.

    What did Log4Shell teach us?

    • Know your software supply chain. You depend on code you never chose. Keep an inventory of the products you run and the components inside them.
    • Patch fast. Attackers began exploiting Log4Shell within hours. A patch process that takes months leaves the door open.
    • Detect and respond. You need a way to see an attack in progress and a tested plan for what to do next.
    • Train your people. Staff who know how to report something odd shorten the time an attacker spends inside your network.

    What should a small business do now?

    1. Build or update your inventory of systems and software.
    2. Turn on automatic updates wherever a product offers them.
    3. Schedule a vulnerability assessment at least once a year.
    4. Write a one-page incident response plan and walk through it with your team.

    What is a software bill of materials, and do I need one?

    A software bill of materials (SBOM) is an ingredient list for a piece of software. It names every component inside the product, including libraries such as Log4j. When the next Log4Shell arrives, a company with SBOMs can search them and know within minutes which products to patch.

    You don’t need to build one yourself. Ask your software vendors whether they provide an SBOM, and ask how they notify customers about security fixes. A vendor with clear answers to both questions handled Log4Shell faster than one without. Add those two questions to your checklist when you buy new software.

    Your next step

    If you don’t know whether a vulnerable system sits on your network, find out before an attacker does. Cerberus Cybersecurity runs risk and compliance assessments that include vulnerability scanning and a plain-language report. Contact us to schedule one.