Did
you miss any of my posts on Facebook or Twitter this week for Stay Smart Online
Week? Don't worry if you did, because I've added them all to a Listly
list and you can access them all from the links below:
Showing posts with label Scams. Show all posts
Showing posts with label Scams. Show all posts
06 June 2014
Online threats - how to stay up to date
Access to
the internet has become something we rely on, for shopping, banking, education,
and communication. However, the more
time you spend on the internet, the greater the chance of being exposed to
cyber security threats and scams that put your personal information and your
money at risk.
It is
essential that you keep up to date with the latest threats, and the Australian
Government has made that easy with their Stay Smart Online Alert Service. It’s a free subscription based service, where
you can choose the topics you want to receive email alerts about – software
updates, social media scams, online security issues and the Stay Smart Online
newsletter. You’ll also receive general
tips on how to stay safe online.
Sign up for your subscription here
If you suspect a scam, whether that is from an email or phone call you've received or something you've come across while online, visit the SCAMwatch website to help you confirm whether or not it is safe. SCAMwatch is run by the Australian Competition and Consumer Commission (ACCC) with the aim of providing a place where consumers and businesses can learn how to recognise scams, and avoid and report them. When you visit the website you'll see links down the left side of the screen where you can find information on particular types of scams - just click on the category you need to see if what you've found really is a scam.
Sign up for the SCAMwatch alert service and you'll receive an email when there's any increase in activity of a particular type of scam, or when a new scam is detected.
Visit SCAMwatch here
Labels:
Cyber Safety,
Scams,
Security
01 May 2013
Facebook scam - Like Farming
We've all seen them….. the Facebook
posts asking us to ‘Like’ a story about a bully who stood up for himself - or a
brother who wants ‘Likes’ so his Down Syndrome sister will know she’s beautiful
- or an inspirational quote asking you to ‘Like’ if you want world peace. How about Apple has found a pile of iPhones in
the back of a factory and if you Like that particular ‘Apple’ Page you’ll get
one! Or click on this photo, comment
within 10 seconds and watch what happens!
Who wouldn't ‘Like’ those posts?
Actually, none of us should be ‘Liking’ them!
All those posts are just a few of the
many I've seen my friends Like in the past month.
‘Like Farming’ is a Facebook scam that
has been around for a few years, but lately it seems to be seeing a resurgence –
with my friends anyway.
How does this scam work?
- A Facebook Page is created
- Scam posts are created – something tragic or inspirational (usually using stolen photos) asking you to Like, Comment or Share the post, or page
- The Page creators share their posts among Facebook users with high profiles, which means the posts gradually work their way around the world via Facebook
- People start liking, commenting and sharing
It doesn't take long before those posts
are being Liked all over the world and that Page is getting quite a bit of
exposure, because as you know, the more Likes, Shares and Comments a Page gets,
the higher its ranking with Facebook and the more often its posts will appear
in News Feeds.
That Facebook Page is then sold for big
money, to a buyer who now has a ready-made list of potential clients. The Page is altered to suit the new owner – a
new About, new cover photo - and that new owner then starts creating their scam
posts, and the cycle starts again.
How do you know if a post is a
scam? One giveaway is the number of
Likes – when I see a post has 200,000 or so Likes I figure it doesn't need
mine! If you’re not sure if it’s a scam
try copying a chunk of the post into Google and see what comes up, or go to the
Scam Watch page on www.facecrooks.com
and you’ll find a list of the latest scams.
Next time you're about to automatically 'Like' a post or a page - STOP and think - what are you really Liking?
Labels:
Scams,
Security,
Social Media
29 August 2012
Facebook tagging and a new Facebook scam
Have you ever had a
friend tag you in a photo on Facebook?
Maybe it wasn’t quite the best photo ever taken of you, or worse, you
were doing something that you really didn’t want to be reminded of, or want
anyone else to see – especially your boss, mother-in-law, or future employer?
You can stop this
happening with a little tweak to your Facebook settings. These changes will mean than if your friends
try to tag in a photo you will have the final say on whether it is published to
your Timeline. It also works where a
friend has tagged a photo that they think is you – it may not even be you!
- Go to Privacy Settings
- Click on Edit Settings next to Timeline
and Tagging
- Click on the arrow next to Review posts
friends tag you in before they appear on your Timeline
- Change the setting from Disabled to Enabled
- Click Back and verify that the setting
now shows On
This won’t stop tagged pictures or posts appearing
elsewhere on Facebook but at least it will give you a chance to approve them
before they appear on your own Timeline.
You can also protect your friends too, by giving
you the final say when another friend comes along and wants to tag someone in
one of your photos. Facebook allows you
to review those tags before they get added to your posts.
- Click on the arrow next to Review tags
friends add to your own posts on Facebook
- Change the setting from Disabled to Enabled
- Click Back and verify that the setting
now shows On
With these settings in
place Facebook will send you an email notifying you whenever a friend wants to
tag you in a photo, or add a tag to one of your photos. There’ll be a link where you can view the
photo and then you can give approval for it to be published – or not.
Facebook uses face recognition to automatically
suggest adding a tag when a photo that looks like you is uploaded. If you don’t want your name to be suggested,
then you can turn auto tag suggestion off.
- Click on the arrow next to Who sees tag
suggestions when photos that look like you are uploaded?
- Change the setting from Friends to No
One
- Click Okay
Once you’ve finished with those settings, click Done.
Scam Warning!
Now that you’ve made
those changes, you need to be aware of a new scam that is trying to trap those with
these tagging settings.
A new strain of malware
has been identified circulating Facebook.
The scam involves you being sent an email notifying you that a friend
has tagged you in a photo, and it looks like the normal Facebook email. There’s a link to ‘view photos as an
attachment’. This link is actually a ZIP
file containing malware allowing hackers to gain control over Windows
computers.
There is a way to
differentiate between the real and the fake emails. Real Facebook notification emails tell you
which friend has tagged you in a picture; while the scam email states “one of
your friends added a new photo with you to the album.” Here is a look at what the fake email message
looks like.
If you receive one of
these emails, do not click on that link – just delete the email immediately.
Labels:
Scams,
Security,
Social Media
12 June 2012
National Cyber Security Awareness Week
National Cyber Security Awareness Week is running from 12 to 15 June, so this week I'll be posting tips about how you can stay safe online.
Top 5 Social Media Scams
Facebook
has over 175 million logins every day, but with this tremendous popularity
comes a dark side as well. Virus writers and other cybercriminals go where the
numbers are -- and that includes popular social media sites. To help you avoid
a con or viral infection, you need to be aware of the top five social media
scams.
·
Chain Letters
You’ve likely seen this one before -- the dreaded chain letter has returned. It may appear in the form of, "Retweet this and Bill Gates will donate $5 million to charity!" But hold on, let’s think about this. Bill Gates already does a lot for charity. Why would he wait for something like this to take action? Answer: He wouldn’t. Both the cause and claim are fake.
You’ve likely seen this one before -- the dreaded chain letter has returned. It may appear in the form of, "Retweet this and Bill Gates will donate $5 million to charity!" But hold on, let’s think about this. Bill Gates already does a lot for charity. Why would he wait for something like this to take action? Answer: He wouldn’t. Both the cause and claim are fake.
So why would someone post this?
Good question. It could be some
prankster looking for a laugh, or a spammer needing "friends" to hit
up later. Many well-meaning people pass
these fake claims onto others. Break the
chain and inform them of the likely ruse.
·
Cash Grabs
By their very nature, social media sites make it easy for us to stay in touch with friends, while reaching out to meet new ones. But how well do you really know these new acquaintances? That person with the attractive profile picture who just friended you -- and suddenly needs money -- is probably some cybercriminal looking for easy cash. Think twice before acting. In fact, the same advice applies even if you know the person.
By their very nature, social media sites make it easy for us to stay in touch with friends, while reaching out to meet new ones. But how well do you really know these new acquaintances? That person with the attractive profile picture who just friended you -- and suddenly needs money -- is probably some cybercriminal looking for easy cash. Think twice before acting. In fact, the same advice applies even if you know the person.
Picture this: You just received an urgent request from one of your real
friends who "lost his wallet on vacation and needs some cash to get home.
" So, being the helpful person you are, you send some money right away,
per his instructions. But there’s a
problem: Your friend never sent this request.
In fact, he isn’t even aware of it.
His malware-infected computer grabbed all of his contacts and forwarded
the bogus email to everyone, waiting to see who would bite.
Again, think before acting. Call your friend. Inform him of the request and see if it's
true. Next, make sure your computer
isn't infected as well.
·
Hidden Charges
"What type of STAR WARS character are you? Find out with our quiz! All of your friends have taken it!" Hmm, this sounds interesting, so you enter your info and cell number, as instructed. After a few minutes, a text turns up. It turns out you’re more Yoda than Darth Vader. Well, that’s interesting … but not as much as your next month’s cell bill will be. You’ve also just unwittingly subscribed to some dubious service that charges $9.95 every month.
"What type of STAR WARS character are you? Find out with our quiz! All of your friends have taken it!" Hmm, this sounds interesting, so you enter your info and cell number, as instructed. After a few minutes, a text turns up. It turns out you’re more Yoda than Darth Vader. Well, that’s interesting … but not as much as your next month’s cell bill will be. You’ve also just unwittingly subscribed to some dubious service that charges $9.95 every month.
As it turns out, that "free, fun service" is neither. Be wary
of these bait-and-switch games. They tend to thrive on social sites.
·
Phishing Requests
"Somebody just put up these pictures of you drunk at this wild party! Check 'em out here!" Huh? Let me see that! Immediately, you click on the enclosed link, which takes you to your Twitter or Facebook login page. There, you enter your account info -- and a cybercriminal now has your password, along with total control of your account.
"Somebody just put up these pictures of you drunk at this wild party! Check 'em out here!" Huh? Let me see that! Immediately, you click on the enclosed link, which takes you to your Twitter or Facebook login page. There, you enter your account info -- and a cybercriminal now has your password, along with total control of your account.
How did this happen? Both the email and landing page were fake. That
link you clicked took you to a page that only looked like your intended social
site. It's called phishing, and you've just been had. To prevent this, make
sure your Internet security includes antiphishing defenses. Many freeware
programs don't include this essential protection.
·
Hidden URLs
Beware of blindly clicking on shortened URLs. You'll see them everywhere on Twitter, but you never know where you're going to go since the URL ("Uniform Resource Locator," the Web address) hides the full location. Clicking on such a link could direct you to your intended site, or one that installs all sorts of malware on your computer.
Beware of blindly clicking on shortened URLs. You'll see them everywhere on Twitter, but you never know where you're going to go since the URL ("Uniform Resource Locator," the Web address) hides the full location. Clicking on such a link could direct you to your intended site, or one that installs all sorts of malware on your computer.
URL shorteners can be quite useful. Just be aware of their potential
pitfalls and make sure you have real-time protection against spyware and
viruses.
Bottom
line: Sites that attract a significant number of visitors are going to lure in
a criminal element, too. If you take security precautions ahead of time, such
as using antivirus and anti-spyware protection, you can defend yourself against
these dangers and surf with confidence.
From
Norton Cybercrime News June 2012
08 June 2012
LinkedIn Hack - what should you do?
Yesterday
it was announced that LinkedIn had been hacked and that the passwords for
nearly 6.5million members had been published on a hacker’s site. Most of the passwords were still encrypted, although
some have already been cracked. So far
no email logins or usernames have been released, which either means that the
hackers didn’t manage to download them or they are keeping the usernames to
themselves. Either way, if you have a
LinkedIn account your private data may be at risk. The worst case scenario is that the hackers
would have control of your account and contacts. If you use the same username and password
combination on other sites, then there is a risk that those accounts could be
compromised too.
What
should you do if you have a LinkedIn account?
1.
Change your LinkedIn password.
2.
LinkedIn has announced that it will email all users
whose accounts were affected and give them instructions as to what to do next.
3.
Don’t click on any email links asking you to change
your password, as that could be someone attempting to
steal your information – some phishing attacks have already been reported. Which seems to me to indicate that the hackers do have the email logins.
4.
If you have used
the same username and password on other accounts it’s probably a good idea to
change the password on those accounts.
Read more about storing your passwords in my post from last week here.
30 April 2012
Have some fun with the scammers
Last week I mentioned about the latest version of the PC phone scam. Unfortunately, once you've received one of these calls, you're likely to receive more. Rather than getting frustrated and annoyed, why not have a bit of fun - and maybe just get yourself off their calling list at the same time.....
From George Abel - PC User magazine
On answering the phone, don't swear at the caller or mention scamming. Instead, sound a bit puzzled and suggest that you have been having some sort of trouble and could this (the alleged symptoms being 'it's been taking a long time to boot up') be the problem about which they are calling? Ask if you should switch on the computer and they can advise on what to do next.
Of course, your computer will be in another room and you ask the caller to be patient while you make your way to it. While on your way, indulge in some lighthearted banter to keep the conversation friendly. When you get to it (you're on a walking frame remember), switch on the computer and the sound. This is important as the scammer can then hear the Microsoft start up melody. Yes, it will take a long time to boot up.
This can take as long as you like or are prepared to spend wasting their time. After five minutes or so, ask what to do next. Whatever you are advised to do, don't! Just keep clicking your mouse or keyboard as if you are working the computer and sound bewildered. Then, make surprised sounds that you have never seen that before and tell the caller you have a pop-up reading: "They are trying to scam you. Tell them to "$@&* off" or words of your own choosing.
You will have the warm satisfaction of cheating the crooks as well as some great fun at the same time.
If my 2 year old son is home, I just say “Here’s someone more qualified to talk to you” and hand it to him. I don’t get why when I clearly get that it’s a scam that they keep calling.
Play along far enough to get the logmein ID code, then from that point whenever they ask you something just respond, “I like cheese.” When they finally hang up, report them to logmein with the ID number. Last time I did that I got put onto the manager, then put back to the first person who firmly rebuked me for not taking them seriously. The saddest thing was it ended up being the most fun I had that week, and I’m kinda hoping they’ll call again in this new spate…
Got a whistle next to the phone. I figure I should talk quietly for a little while, make sure they’re “all ears” before using it.
all from www.lifehacker.com.au
Have you ever tried having some fun with scammers?
From George Abel - PC User magazine
On answering the phone, don't swear at the caller or mention scamming. Instead, sound a bit puzzled and suggest that you have been having some sort of trouble and could this (the alleged symptoms being 'it's been taking a long time to boot up') be the problem about which they are calling? Ask if you should switch on the computer and they can advise on what to do next.
Of course, your computer will be in another room and you ask the caller to be patient while you make your way to it. While on your way, indulge in some lighthearted banter to keep the conversation friendly. When you get to it (you're on a walking frame remember), switch on the computer and the sound. This is important as the scammer can then hear the Microsoft start up melody. Yes, it will take a long time to boot up.
This can take as long as you like or are prepared to spend wasting their time. After five minutes or so, ask what to do next. Whatever you are advised to do, don't! Just keep clicking your mouse or keyboard as if you are working the computer and sound bewildered. Then, make surprised sounds that you have never seen that before and tell the caller you have a pop-up reading: "They are trying to scam you. Tell them to "$@&* off" or words of your own choosing.
You will have the warm satisfaction of cheating the crooks as well as some great fun at the same time.
If my 2 year old son is home, I just say “Here’s someone more qualified to talk to you” and hand it to him. I don’t get why when I clearly get that it’s a scam that they keep calling.
Play along far enough to get the logmein ID code, then from that point whenever they ask you something just respond, “I like cheese.” When they finally hang up, report them to logmein with the ID number. Last time I did that I got put onto the manager, then put back to the first person who firmly rebuked me for not taking them seriously. The saddest thing was it ended up being the most fun I had that week, and I’m kinda hoping they’ll call again in this new spate…
Got a whistle next to the phone. I figure I should talk quietly for a little while, make sure they’re “all ears” before using it.
all from www.lifehacker.com.au
Have you ever tried having some fun with scammers?
Labels:
Scams
24 April 2012
Microsoft Scam Update
Last year I wrote a post on my old blog about the Microsoft Scam. I'm going to republish it here as it's still happening and if you're not aware of it you should be. However, there's now a new version, so read below this first post for details of the newer version to watch out for.
Originally posted 17 September 2011
You may have heard about the Microsoft Scam that's been around for about a year now. It's looks like it's heating up again and more people are getting caught out by it.
The scam starts with a call from India saying “I’m calling from Microsoft. We’ve had a report from your internet service provider of serious virus problems on your computer” or something like this. You are then told that your computer is going to fail, lose all your data or something will go very wrong if the problem goes unsolved.
If they’ve succeed in convincing you to keep talking, you’ll be directed to your computer and asked to open a program called “Windows Event Viewer”. To the average user, it looks like a long list of errors, some labelled “critical”.
The caller then offers to guide you through fixing the problems. You'll be directed to a website and told to download a program that hands over remote control of your computer and the caller 'installs' various 'fixes' for the problem. Then you'll be asked to pay for this service by credit card.
Of course, there was never anything wrong with your computer and the caller does not work for Microsoft. Microsoft does not know if you have a problem with your computer and wouldn't call you if you did. Unfortunately, anyone falling for this will have handed over enough personal information on their computer to enable identity theft -bank details, Internet site passwords and much more.
This scam has been going since 2008 and has grown hugely this year. It is being run from call centres based in Kolkata, by teams believed to have access to sales databases from computer and software companies, and also getting names to call from the White Pages.
My father has received two of these calls in the past month, and he doesn't even have the internet connected- which he had great pleasure in telling them after they had told him that he had a problem with the internet!
The Microsoft website states that “Microsoft does not make unsolicited phone calls to help you fix your computer".
If you receive an unsolicited call from someone claiming to be from Microsoft Tech Support, hang up on them immediately.
This company even gives you a local phone number so you can call them back. If you try to check them out and use that number you'll be redirected to an overseas call centre, where you'll be told that the company is called Service Centre for Windows Operating Systems, located in Sydney. You'll be given a very professional spiel about how they provide online technical support by connecting to the user's computer, after obtaining permission, and the average charge is $100 to $300. They also sell software 'if the customer needs it'.
No matter how convincing they sound, do not allow them to access your computer. No reputable company will phone you unannounced to let you know there's something wrong with your computer or offer to fix it.
If you are not sure about a company do a search for the company name for a web site (although having a web site doesn't guarantee it's legitimate). I'll often do a search for the company name with the word 'scam' after it. You could also check if they are listed in the White Pages www.whitepages.com.au.
You may be sure you won't get caught out by these scams, but if you have any older or less-tech-savvy family members or friends let them know what they need to look out for.
Originally posted 17 September 2011
You may have heard about the Microsoft Scam that's been around for about a year now. It's looks like it's heating up again and more people are getting caught out by it.
The scam starts with a call from India saying “I’m calling from Microsoft. We’ve had a report from your internet service provider of serious virus problems on your computer” or something like this. You are then told that your computer is going to fail, lose all your data or something will go very wrong if the problem goes unsolved.
If they’ve succeed in convincing you to keep talking, you’ll be directed to your computer and asked to open a program called “Windows Event Viewer”. To the average user, it looks like a long list of errors, some labelled “critical”.
The caller then offers to guide you through fixing the problems. You'll be directed to a website and told to download a program that hands over remote control of your computer and the caller 'installs' various 'fixes' for the problem. Then you'll be asked to pay for this service by credit card.
Of course, there was never anything wrong with your computer and the caller does not work for Microsoft. Microsoft does not know if you have a problem with your computer and wouldn't call you if you did. Unfortunately, anyone falling for this will have handed over enough personal information on their computer to enable identity theft -bank details, Internet site passwords and much more.
This scam has been going since 2008 and has grown hugely this year. It is being run from call centres based in Kolkata, by teams believed to have access to sales databases from computer and software companies, and also getting names to call from the White Pages.
My father has received two of these calls in the past month, and he doesn't even have the internet connected- which he had great pleasure in telling them after they had told him that he had a problem with the internet!
The Microsoft website states that “Microsoft does not make unsolicited phone calls to help you fix your computer".
If you receive an unsolicited call from someone claiming to be from Microsoft Tech Support, hang up on them immediately.
The latest version of this scam may claim to be from Telstra, Bigpond, or another well known company. However, they don't even need a recognisable name to try to catch you out....
You may receive a call from Windows Computer Management (this one is supposed to be based in Martin Place, Sydney). They will tell you that they have detected viruses on your computer and that you should switch the computer on so they can talk you through the process to remove them.
You may receive a call from Windows Computer Management (this one is supposed to be based in Martin Place, Sydney). They will tell you that they have detected viruses on your computer and that you should switch the computer on so they can talk you through the process to remove them.
This company even gives you a local phone number so you can call them back. If you try to check them out and use that number you'll be redirected to an overseas call centre, where you'll be told that the company is called Service Centre for Windows Operating Systems, located in Sydney. You'll be given a very professional spiel about how they provide online technical support by connecting to the user's computer, after obtaining permission, and the average charge is $100 to $300. They also sell software 'if the customer needs it'.
No matter how convincing they sound, do not allow them to access your computer. No reputable company will phone you unannounced to let you know there's something wrong with your computer or offer to fix it.
If you are not sure about a company do a search for the company name for a web site (although having a web site doesn't guarantee it's legitimate). I'll often do a search for the company name with the word 'scam' after it. You could also check if they are listed in the White Pages www.whitepages.com.au.
You may be sure you won't get caught out by these scams, but if you have any older or less-tech-savvy family members or friends let them know what they need to look out for.
Labels:
Scams
Subscribe to:
Posts (Atom)











