时间:2026-05-25 09:18:37 来源:网络整理编辑:知識
There's been a lot of talk about Russian hackers infiltrating the Democratic National Committee's se
There's been a lot of talk about Russian hackers infiltrating the Democratic National Committee's servers and then leaking sensitive emails via WikiLeaks.
The breach, which happened in June but was revealed this week, may sound like a high-level hacking plot by international spies that doesn't have anything to do with your personal cybersecurity. We are here to tell you, that is incorrect.
SEE ALSO:Hackers have found a way to turn WikiLeaks into a weaponIn times like this, it is good to remember Russia, or any government for that matter, could turn its attention to you -- if, for some reason, they decided you had some information they needed to obtain. Perhaps you work for an important company or you are the love child of a Soviet spy. Whatever the reason, it is a good time to consider your privacy online.
The attack on the DNC was investigated by cybersecurity firm CrowdStrike, which not only claimed the Russian government was behind the hack but also noted it was due to "spear phishing." And they are not referring to the sport.
Spear phishing is the term for when a hacker sends you an email that pretends to be from someone you trust, but is in fact a scammer. "The spear phisher thrives on familiarity. He knows your name, your email address, and at least a little about you," security firm, Norton, warned.
In other words, these scammers are getting smarter and they may be using you to get into your company's networks. So how do you prevent being the one that exposes your company to an attack? There are a few crucial things you can do.
Knowledge is power when dealing with hackers. Understanding a little about how hackers think will put you ahead of the pack when it comes to protecting yourself.
"Get educated on exactly what spear phishing is," Steve Morgan, Cybersecurity VenturesCEO and founder, said in an email toMashable. "First off, a spear phishing email has a spoofed (forged) address and appears to be coming from a trusted source -- for instance a co-worker or manager -- when in fact it is coming from a malicious person (hacker)."
In the case of the DNC attack, there were two groups that infiltrated the systems. The first group, codenamed "Cozy Bear" for no obvious reason, is known for its use of a spear phishing method that sends a person web links to programs which install themselves on your computer. These programs normally include sophisticated tools that allow the hacker to remotely access your computer, CrowdStrike's Dmitri Alperovitch wrote in a blog post.
The second group, "Fancy Bear," is a little more detailed in its approach. With groups using this method, you really need to be on the look out. Fancy Bear registers domain names that resemble ones of the legitimate organizations they plan to target, according to Alperovitch. The group then copies the look of the victim's email service and goes in for the kill.
"When it comes to phishing scams, attackers look to the emotional aspects of human decision making to execute their attacks."
"When it comes to phishing scams, attackers look to the emotional aspects of human decision-making to execute their attacks," a spokesperson from Norton Security told Mashable. "Cyber criminals will use social engineering as a method to try and get people to divulge sensitive information or install malicious malware onto their computers."
Social engineering includes hackers researching the victim by looking at their social media profiles and online activity to find out everything they can about them and the organization.
When you receive an email from someone who knows who you are, appears to be from your organization or is someone you trust and is asking for an urgent response, it is much easier to respond without paying much attention. This is their evil plan. Next thing, you are exposed.
Firstly, don't have your cat's name, your mum's home and your friend's engagement splashed all over Facebook. Try and keep as much private as you can, especially when signing up to websites. It can all be pieced together to make an in-depth profile of who you are, where you live, who you are friends with and what you do. If you want to freak yourself out over your social media sharing, a visit to TakeThisLollipop.com should do the trick.
To check how vigilant you have been, do a Google search of yourself and see what you can find. Terrifying.
Passwords can not be the same for multiple sites. They should also be super difficult and preferably not contain the word "password." Use a program such as LastPass or any of these brilliant tools to generate and store the most difficult passwords you can imagine.
If you can remember it, it can probably be easily hacked. Throw in a couple of exclamation points for good measure.
You should also turn on two-step authentication. Even though it's the most annoying thing on Earth, think of the security it brings. Google made it a little bit easier recently by adding a one-click verification option. For instructions on getting it set up, check out this link.
If your friend or brother's cousin is asking you to wire transfer them money via email, alarm bells should go off. That is the most obvious example, though, and the people doing the phishing at the level of the DNC attacks are way more sophisticated than that.
Be on the lookout for anything suspicious in an email. If your friend is writing in a slightly different tone, give them a call or a text to check it is them. The same goes for dealing with organizations you are familiar with. If you aren't expecting an email, be cautious about downloading attachments.
In other words: be alert, all the time.
Human error is responsible for 95 percent of all security issues, according to IBM, so companies should step up and train their staff to be alert for phishing attacks. It's not all your fault.
"Human error is in fact simply a lack of security awareness training when it comes to hacks and data breaches."
"Human error is in fact simply a lack of security awareness training when it comes to hacks and data breaches. Users are careless and make mistakes because they have no idea what to be on guard for," Morgan said.
Organizations can also block emails from strange sources with email authentication, according to Alexander Garcia-Tobar, the CEO of email security company ValiMail, which allows a company to control who sends email using their identity.
"With email authentication properly in place these spoofed emails are blocked before end users ever see them," Garcia-Tobar explained. "Therefore, no clever con artist has the opportunity to trick well-meaning employees into giving away the company's money or secrets."
(He also noted that, according to his company's tests, the emailing domains for the RNC, DNC and Donald Trump's campaign were "wide open to phishing," while Hillaryclinton.com was protected.)
He believes that because so many threats are hard to spot with the naked eye, companies need to take responsibility for their security and not rely on humans. "Rather than attempting to train employees to detect the undetectable, companies need to eliminate these attacks in the first place with a strong email authentication system," he said.
Not exactly -- unless you work for a government agency -- but one thing Fancy and Cozy Bear have done is help raise awareness for these kinds of attacks.
"The main takeaway should be that Cozy Bear and Fancy Bear -- which are hacking groups affiliated with (and potentially sponsored by) Russian intelligence agencies aimed at political and financial espionage -- have been around for years," Morgan said.
"Unfortunately it takes a high-profile cyberattack to get the public's attention -- which is exactly what's happening with the DNC hack ... To be clear, these are not the only 'Russian Bears' the U.S. should be concerned with."
If that last sentence doesn't terrify you into being vigilant online, nothing will.
Have something to add to this story? Share it in the comments.
TopicsCybersecurity
Olympian celebrates by ordering an intimidating amount of McDonald's2026-05-25 09:16
阿根廷國家隊新帥出爐 不是西蒙尼 梅西將不會重返國家隊?(梅西還沒退役嗎)2026-05-25 09:14
c羅之利雅得勝利(c羅什麽時候加盟皇馬球隊)2026-05-25 09:13
37歲C羅掙4億,原地退役 ?(c羅加盟的尤文)2026-05-25 09:11
More than half of women in advertising have faced sexual harassment, report says2026-05-25 08:40
梅西成阿根廷隊世界杯最佳射手 ,一數據超越貝利|數說(梅西曆屆世界杯進球)2026-05-25 08:36
【波盈足球】 足球曾讓梅西動怒大飆粗口 荷蘭高壯中鋒有望效力曼聯 ( 曼聯,霍斯特 )2026-05-25 08:22
C羅決定加盟曼城,已3次“逼宮”尤文 ,忍不了2大現象(c羅加盟尤文引起轟動)2026-05-25 07:47
Olympic security asks female Iranian fan to drop protest sign2026-05-25 07:44
【波盈足球】 克國火辣爆乳女球迷 :曾有世界盃球員偷偷私訊我 ( 伊凡,西亞 )2026-05-25 07:33
We asked linguists if Donald Trump speaks like that on purpose2026-05-25 08:59
皇馬為姆巴佩準備10億歐元!姆巴佩如果加盟皇馬,能超越C羅嗎?(尤文官宣c羅正式加盟)2026-05-25 08:56
C羅將加盟沙特利雅得勝利,這是最無奈但又最明智的選擇(c羅正式加盟尤文圖斯是哪一年)2026-05-25 08:49
最新榜單!盤點身價最高足球運動員,梅西未上榜,姆巴佩不是第一(巴黎梅西最新消息)2026-05-25 08:44
Katy Perry talks 'Rise,' her next batch of songs, and how to survive Twitter2026-05-25 08:29
C羅將加盟沙特利雅得勝利 ,這是最無奈但又最明智的選擇(c羅正式加盟尤文圖斯是哪一年)2026-05-25 08:29
震驚!巴塞羅那宣布不與梅西續約 !梅西離隊了!(梅西為什麽沒有和巴薩續約)2026-05-25 08:07
忘卻失利,阿根廷將捧得大力神杯(美洲杯阿根廷主力)2026-05-25 07:27
We asked linguists if Donald Trump speaks like that on purpose2026-05-25 07:01
最新榜單!盤點身價最高足球運動員 ,梅西未上榜,姆巴佩不是第一(巴黎梅西最新消息)2026-05-25 06:35