How IT horror stories can help your business

Nobody – no matter how big you are – is ever 100% safe from an IT disaster.

Some of the most famous names in business have been hit with epic data breaches over the years.

Every day is a learning experience and with IT, you can’t be too careful when it comes to the security of your data.

There are several precautions you can take to secure your important business records to reduce the risks of a data breach or other preventable disasters.

7 Ways to prevent phishing and cyber attacks on your business

Sadly, throughout history, it was too late for some of these companies, who took a hit at the time.

But you can hopefully learn from their mistakes or oversights.

Social media breaches

Facebook

Phone numbers, full names, locations, some email addresses, and other details from user profiles were posted to an amateur hacking forum in 2021. The leaked data includes personal information from 533 million Facebook users in 106 countries.

Yahoo

In 2014, Yahoo! suffered a massive attack which leaked the real names, email addresses, dates of birth and telephone numbers of 500 million users. Yahoo revised that estimate in 2017 to include all of its 3 billion user accounts. The breaches cost the company an estimated $350 million.

MySpace

In 2016, the world learned 360 million MySpace user accounts were leaked onto LeakedSource and put up for sale on dark web market The Real Deal with an asking price of 6 bitcoin. The breach related to passwords created in 2013.

LinkedIn

In 2012, the business networking site said 6.5 million passwords were stolen by attackers and posted onto a Russian hacker forum, selling for 5 bitcoin.

Dubsmash

In 2018, US video messaging service Dubsmash had 162 million email addresses, usernames, password hashes, and other personal data such as dates of birth stolen. The data was put up for sale on the Dream Market dark web market. The company advised users to change their passwords.

Sina Weibo

Chinese social site Sina Weibo said 538 million real names, site usernames, gender, location, and – for 172 million users – phone numbers were posted for sale on dark web markets in March 2020.

Zynga

In 2019, 218 million Zynga users were targeted by a hacker who hit the Draw Something and Words with Friends player databases. The hacker stole email addresses, passwords, phone numbers, and user IDs for Facebook.

Payment site breaches

eBay

A 2014 attack on eBay exposed its entire account list of 145 million users, including names, addresses, dates of birth and encrypted passwords. The auction giant said hackers used the credentials of three corporate employees to access its network and had complete access for 229 days.

Equifax

A breach in 2017 compromised the personal info (including the social security numbers, birth dates, addresses, and in some cases drivers’ licence numbers) of 147.9 million customers of US credit bureau Equifax.

Dating site breaches

Adult Friend Finder

In 2016, the FriendFinder Network, which included casual hookup and adult content websites like Adult Friend Finder, Penthouse.com, Cams.com, iCams.com and Stripshow.com, was breached. The stolen data spanned 20 years on six databases and included names, email addresses and passwords, and  was protected by the inadequate SHA-1 hashing algorithm.

Ashley Madison

In 2015, a hacking group stole more than 60Gb of company and user data of Ashley Madison, a site enabling extramarital affairs. The group threatened to release users’ names and personally identifying info if Ashley Madison would not immediately shut down. Resignations, divorces and suicides followed.

MeetMindful.com

In January 2021, a hacker leaked the data of 2.28 million users of dating website MeetMindful that includes real names, Facebook account tokens, email addresses and geo-location information. The  1.2GB file was shared as a free download on a public hacking forum.

Productivity site breaches

Adobe

In 2013, 153 million usernames and passwords were stolen from Adobe. The hack exposed customer names, IDs, passwords and debit and credit card information. The breach cost Adobe $2.1 million.

Canva

In May 2019, Aussie graphic design tool website Canva was attacked. Exposed were email addresses, usernames, names, cities of residence, and passwords of 137 million users. Canva says the hackers managed to view, but not steal, files with partial credit card and payment data.

Hospitality site breaches

Marriott International

In 2018, Marriott International was reportedly hit by Chinese hackers who stole the data of approximately 500 million of its customers. The breach was believed to have started in 2014 and was not discovered until September 2018.

Software faults

AT&T

In 1990, AT&T’s long-distance telephone switching system crashed. 60,000 people  lost their telephone service completely for nine long hours while 70 million phone calls went unanswered. The problem boiled down to some stray C language code in a piece of software.

The Paderborn Baskets

A German pro basketball team was relegated to a lower division due to a Windows update in 2015.

The Paderborn Baskets, a second division German basketball team, was relegated to a lower division for starting a game late, due to a necessary 17-minute Windows update to the scoreboard’s laptop.

Key things you can do to avoid an IT disaster

Can you afford to leave your network unprotected? OneCloud IT can further enhance your network security.

The sky is falling! Why you need a disaster recovery plan

Disasters sound dramatic.

If your business is ever on the receiving end of one, you can believe the pain can be crippling. Some firms never recover.

The clock is ticking on your next big disaster.

Yet, some firms keep rolling the dice in an effort to save money.

Having no disaster recovery plan in place is inviting trouble.

What is a disaster recovery plan?

A disaster recovery plan (DRP) is a documented process or series of procedures that help recover and protect your firm’s IT infrastructure in the event of a disaster.

These disasters hurt your business

Fire Disaster Recovery Plan
  • Fire
  • Flood
  • COVID-19 or other pandemics
  • Earthquakes, cyclones, etc.
  • Cyberattacks
  • Software failures
  • Hardware failures
  • Human error
  • Power failures
  • Internet outages

Brutal results of no recovery plan

  • The average small business can expect to lose $100,000 worth of revenue in unplanned downtime every year
  • 70 percent of small businesses that experience a major data loss go out of business within a year.

And even though you may have made a copy of your data, the time it takes to restore those files can be crippling in terms of downtime to your business.

Over 50 percent of businesses can only handle one hour of downtime.

How to set up disaster recovery

Assessment

Understand what areas of your business are vulnerable and get a better idea of what protections are needed to be put into place.

Planning

Figure out the best course of action which works for you to help keep your business running.

Installation

Install and configure a BCDR (business continuity and disaster recovery) solution for your business, to ensure that you have verified backups, instant virtualisation, local and cloud recovery, and restore options for any scenario. All backups need to be scanned for ransomware and mounted to ensure they are ready to restore.

Training/Testing

Brief all relevant staff on the recovery processes. Do some thorough stress-testing and run-throughs.

Implementation

You’ll need support and assistance to ensure you are able to avoid costly downtime and lost data.

It can be overwhelming.

OneCloud IT Solutions is one such firm that helps small, medium and large businesses across the Central Coast put comprehensive disaster recovery plans in place.

Benefits of a disaster recovery plan

  • The loss is minor
  • It becomes a temporary problem
  • Business operations can be restored quickly
  • You can prevent legal liability
  • Improve your security
  • Saves money and protects profits

Contact OneCloud IT Solutions to start work on your recovery plan today and start future-proofing your business from the inevitable disasters.

Related links:

NSW – Small Business Disaster Recovery Toolkit

NSW Small Business Commissioner: Building small business resilience

Case Study: Attackers try to gain vital information via email scams

The Issue

A business on the Central Coast was receiving a large number of unfiltered emails, of which many were spam – some were obvious but a lot were not.

We found that a lot of these emails were phishing attempts, so they appeared to be legitimate but were actually scammers in disguise.

What We Did

We implemented a cloud-hosted spam filter to combat a large percentage of the spam/phishing attempts.

We ensured all machines and devices were updated to the latest versions.

We made some specific changes to the devices to ensure there was an extra layer or email protection.

We sat down with the staff and trained them on what to look for to spot a phishing attempt.

Finally, we advised the client to call OneCloud if they receive anything that concerns them, and have one of our techs look at the email to determine whether it’s truly legitimate or not.

Note: User training is the most important backed by experts.

The Outcome

The company saw a large reduction of spam emails, meaning they were more efficient as they didn’t have to continually clean up their mailboxes.

Their risk of a staff member accidentally clicking on the wrong link was greatly reduced.

The staff are now very aware of what attributes to look for, they’re able to identify phishing attempts, and they have a process to reach out for help if they’re unsure.

Our client felt at ease knowing we were there to help and they could concentrate on their business rather than trying to fix it themselves.

7 Ways to prevent phishing & cyber attacks on your business

Phishing is a cyber attack that uses disguised email as its weapon of choice. While it may not attract the media attention of large data breaches, phishing scams are a serious threat to companies:

  • In 2020 Australians lost a combined sum of $141.5 million to phishing scams
  • Reports of phishing attacks in Australia were up 75% in 2020, compared to 2019
  • The most damaging types of scams included investment scams, dating and romance scams, false billing, threats to life or arrest, and online shopping scams

Source: Security Brief Australia

Phishing is a very real threat for your company, so in this article we will discuss practical steps you can take to prevent it, and save yourself from potentially losing a lot of time and money.

What is phishing?

The scammers essentially trick the email recipient into thinking the message is from a source they know and/or believe they can trust, e.g. a bank, a company the recipient normally does business with or a legitimate person or institution.

They use a deadly combination of psychology and technology to gain access to someone’s email address details so they can:

Steal personal information:

Scammers may sit and watch the recipient’s email activity (on average for 280 days) to collect data, such as login credentials, credit card and bank account details, and other sensitive information.

Gain an entry point for malware and ransomware attacks:

Once the scammers have an understanding of their recipient, they will deliver the recipient with an invitation to take an action – typically to click a link or download an attachment.

This invitation will be highly targeted and relevant to the recipient (e.g. a special offer from a company they regularly do business with, a personalised email from their bank asking them to confirm details, or unexpected news from a fake legal outfit that requires your immediate response (by clicking on a link).

Once the action is taken, the malware or ransomware is downloaded onto the computer.

How to prevent phishing

1. Check your preferences

Ensure your browsers’ anti-phishing preferences are turned on:

Phishing Preferences

Disable automatic loading of images and external content stored on remote servers:

Email Phishing Preferences

2. Check your emails more closely

To ensure your email security, it is crucial to exercise caution when encountering emails with embedded links. It is advisable to carefully scrutinise their authenticity by looking out for any grammatical or spelling errors. Additionally, it is advisable to hover your cursor over the links to evaluate the destination before clicking on them.

If you are requested to give personal information, avoid clicking on the link. Rather, go to the company’s website or call them directly; if it’s a legitimate request they will have a record and be able to deal with the issue directly.

3. Beware of pop-up screens

Pop-ups are often linked to malware and phishing attacks. You can help to protect yourself from malicious pop-ups by installing an ad-blocker software that will automatically block them. If you are asked to enter personal information via a pop-up screen – don’t do it!

4. Rotate passwords regularly

By changing your passwords on a periodic basis, you can prevent attackers from gaining unlimited access to your account and lock out potential attackers.

5. Install a third party managed spam filter

Managed spam filters add an extra layer of protection, as they’re able to block some of the phishing attempts before they get to the users.

6. Keep your updates up to date

Staying on top of your updates will ensure you stay protected against the latest cyber-attack methods, as they patch holes identified in your security. 

7. Train your team

Of course it only takes one user to compromise your entire business, so make sure your whole team understands data security and email attacks, as well as your policies and procedures. 

8. Disaster Recovery Plan

In the event of your business falling victim to a phishing scam, a disaster recovery plan will ensure you and your team know the immediate steps that need to be taken in order to minimise damage.

The ultimate prevention

Of course, the ultimate strategy is to work with IT professionals, who can set you up with all the appropriate security measures and even consistently monitor your systems to identify potential issues and ensure you’re consistently up to date.

When it comes to cyber security – prevention is most definitely better than cure. Investing in a professional security solution could save you thousands or even millions.