{"id":40138,"date":"2021-06-24T09:37:40","date_gmt":"2021-06-24T08:37:40","guid":{"rendered":"https:\/\/www.intelligentcio.com\/africa\/?p=40138"},"modified":"2023-05-25T10:58:19","modified_gmt":"2023-05-25T09:58:19","slug":"inside-the-mind-of-a-cyber-criminal","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2021\/06\/24\/inside-the-mind-of-a-cyber-criminal\/","title":{"rendered":"Inside the mind of a cyber criminal"},"content":{"rendered":"\n<p>Cyber criminals come in many different flavours, but the majority of them are in it for one thing: financial pay-off. They want the money that comes with offering their tools or services, selling stolen data, extortion like ransomware or plain fraud. And they all have one thing in common \u2013 your organisation is on their radar.<\/p>\n\n\n\n<p>Which is why, said Anna Collard, SVP Content Strategy and Evangelist, KnowBe4 Africa, it is critical to understand how cyber criminals operate the tools they use and the approaches they take to embed robust security within the organisation.<br>\u201cWith ransomware going rampant and victim organisations paying up to millions of US dollars to the extortionists, this problem is just going to get worse. The US government recently announced that ransomware is a national cybersecurity challenge and that there will be serious implications for anyone attacking the United States or their critical infrastructure.<\/p>\n\n\n\n<p>\u201cThis may lead more criminals to shift their attention towards the emerging economies like Africa, where we do not have the government\u2019s support or capacities to stop and prosecute cyber criminals, making it a safer place to operate,\u201d said Collard.<\/p>\n\n\n\n<p>Social engineering or people hacking is a popular way to distribute ransomware \u2013 predominately by tricking people into falling for their phishing scams.<\/p>\n\n\n\n<p>\u201cAnother technique to be aware of is password spraying. This is when the bad actor selects a common password, like the organisation\u2019s name, followed by the year and tries it against every user in the organisation. They scrape names of employees from LinkedIn and then using this information, try the possible password against the list of names. Then it keeps on cycling until it hits a winning entry. This is a solid case for ensuring that every single employee uses proper passwords or a password manager and multi-factor authentication where possible,\u201d she explained. \u201cThis level of attack really underscores how important it is to undertake consistent employee training and security skills development. No matter how secure your perimeter, no matter how much money is spent on high-end security systems, one poor password can open the doors to threat actors.\u201d<\/p>\n\n\n\n<p>Multi-factor authentication and robust training are not just invaluable for employees in the office, they are even more critical today as people work from home and multiple locations \u2013 particularly as employees migrate to coffee shops for power and Wi-Fi during load-shedding. Public Wi-Fi is wide open and home networks with poor passwords or out of date software are open doors.<\/p>\n\n\n\n<p>Collard added that: \u201cIt is also really important to make sure that employees use a VPN, although that is also not a guaranteed protection as a recent report by the Orange Cyber Defence team explained. With home routers being vulnerable due to people not configuring them correctly or updating them, it might be worthwhile sending pre-configured routers and firewalls to employees\u2019 homes, especially for those who access highly confidential information.\u201d<\/p>\n\n\n\n<p>Another challenge for the organisation is keeping up with vulnerabilities and patch management, which is a complicated task in bigger environments.<\/p>\n\n\n\n<p>\u201cLeading hackers and experts like Kevin Mitnick are drawing lines under the importance of putting people\u2019s understanding of these threats at the forefront,\u201d she said. \u201cMake sure that passwords are secure, that they are not stored in diaries or on open platforms like Slack or Google Hangouts, that they understand how to identify social engineering attacks and keep security hygiene at the forefront of all communication. People need to know what is out there, and that they have the skills to play an important role in protecting themselves and the organisation.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cyber criminals come in many different flavours, but the majority of them are in it for one thing: financial pay-off. They want the money that comes with offering their tools or services, selling stolen data, extortion like ransomware or plain fraud. And they all have one thing in common \u2013 your organisation is on their [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":40139,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4950,4525,5,6,36,9056,9059,13],"tags":[385,95,12057,14530,1240],"class_list":["post-40138","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analysis","category-cats","category-enterprise-security","category-insights","category-intelligent-technology","category-regions","category-south-africa","category-top-stories","tag-africa","tag-cyber-criminals","tag-knowbe4-africa","tag-orange-cyber-defence","tag-vpn"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/40138","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=40138"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/40138\/revisions"}],"predecessor-version":[{"id":40142,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/40138\/revisions\/40142"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/40139"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=40138"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=40138"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=40138"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}