{"id":19690,"date":"2020-07-13T08:00:32","date_gmt":"2020-07-13T12:00:32","guid":{"rendered":"https:\/\/www.thundercloud.net\/infoave\/new\/?p=19690"},"modified":"2020-07-13T15:06:00","modified_gmt":"2020-07-13T19:06:00","slug":"youre-not-the-target-youre-just-a-victim","status":"publish","type":"post","link":"https:\/\/www.thundercloud.net\/infoave\/new\/youre-not-the-target-youre-just-a-victim\/","title":{"rendered":"You&#8217;re Not the Target, You&#8217;re Just a Victim"},"content":{"rendered":"<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 24pt;\"><strong>You&#8217;re Not the Target, You&#8217;re Just a Victim<\/strong><\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Most everyone is afraid of having their computer hacked. But it&#8217;s very unlikely that your PC will ever be hacked. <\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">If I had a dollar for every person who wrote to us saying they have been hacked, I&#8217;d have at least $5000 in my pocket by now. But seriously, big-time hackers and scoundrels don&#8217;t care about you personally. They have bigger fish to fry. But even if you&#8217;re not the target, that doesn&#8217;t mean you can&#8217;t be a victim.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">First, it&#8217;s very unlikely that a hacker is going to take the time and effort to hack Alice or Jack&#8217;s PC. What I\u00a0 mean is, home users like you and me aren&#8217;t worth the time and effort it takes to hack us. It takes a lot of effort to hack a computer and miscreants aren&#8217;t stupid. They are not going to figure, against all odds, that maw and paw users like you and I are worth millions of dollars. It would be a very poor strategy indeed to assume most home users are worth millions. In short, it would generally be a huge waste of a hacker&#8217;s time.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">But there are banks, retailers, websites, government sites, Internet service providers, credit card and financial services sites, and so on who are worth millions and\/or offer a potential treasure trove of user data.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">And while a hacker targeting your home PC is hugely unlikely, credential-stealing malware and phishing campaigns as well as a plethora of trojans and keyloggers have the express purpose of tricking users into voluntarily giving away their usernames and passwords all hoovered up by the villains behind the software. The techniques of tricking users into voluntarily giving up their username and passwords are eclectic&#8230; and new pieces of malware surface regularly.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 18pt;\"><strong>Most online thieves don&#8217;t hack &#8211; they buy<\/strong><\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">The following image from Digital Shadows shows you how much your information is worth on the &#8220;Dark Web&#8221;.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" src=\"https:\/\/thundercloud.net\/infoave\/images\/2020\/darkweb1a.png\" alt=\"Cloudeight Internet - Keeping you informed\" width=\"692\" height=\"367\" \/><\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Hackers steal large databases and then sell login pairs to other hackers. It&#8217;s a lot easier to buy filched information than it is to steal the information by doing the hacking yourself.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">In the screenshot above from DigitalShadows, you can see what cyber-thieves are willing to pay for information.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\"><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/over-15-billion-credentials-in-circulation-on-hacker-forums\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bleeping Computer<\/a> points out that&#8230; <\/span><\/p>\n<blockquote><p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">&#8220;Login pairs from accounts for non-financial services (cable, social media, streaming, VPN services, file sharing, video games, adult) are the cheapest and cybercriminals give away many of them. Those for sale have an average price of $15.43.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">From advertisements analyzed by data loss detection firm Digital Shadows, one in four offers accounts related to banking and other financial services. These come at a higher average price, $70.91 each.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">However, a confirmed balance for an online banking account, availability of personally identifiable information, and freshness can drive the price up to $500.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">In many cases, cybercriminals use them for money laundering to cover their tracks, or for cash-out schemes.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Several markets exist that rent access to an account without triggering an alarm. Some have botnets of info-stealing malware that collect fingerprint data (cookies, IP addresses, time zones) that once injected, make it look like the legitimate owner logged in&#8230;<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Depending on the type of access they want to rent, cybercriminals can pay less than $10 to log into an account for a limited period using the victim\u2019s fingerprint data.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">According to <a href=\"https:\/\/resources.digitalshadows.com\/whitepapers-and-reports\/from-exposure-to-takeover\" target=\"_blank\" rel=\"noopener noreferrer\">Digital Shadow\u2019s report<\/a>, Genesis Market is the most popular. It is not without competition, though. UnderWorld Market (formerly RichLog) and Tenebris are in the same business&#8230;<\/span><\/p><\/blockquote>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">We don&#8217;t want to bury you in geek-speak, but we do want to keep you safe. If you understand the basics &#8211; that hackers are not going to target your PC directly, but are far more likely to try to trick you and steal your personal information by using phishing emails to entice you to enter your username and password on fake banking or other financial sites, or by tricking you into installing information-stealing malware either surreptitiously, or by being tricked into installing the malware directly or downloading freeware or browser extensions bundled with the malware &#8211; then you&#8217;ll be less likely to be tricked into disclosing personal information and falling into the scoundrels&#8217; traps.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">If you know how and why so many people have their personal information stolen, the less likely you are to be fooled by the tricks criminals use to steal your information. And then you&#8217;ll also realize that VPNs and services like Norton\/Lifelock are not the answer to this problem. There is no magic elixir.<\/span><\/p>\n<p><strong><span style=\"font-family: helvetica, arial, sans-serif; font-size: 18pt;\">Things you can do to keep your personal information safe.<\/span><\/strong><\/p>\n<ol>\n<li><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Use strong passwords containing upper and lower case letters, numbers, and symbols. If available use two-factor authentication.\u00a0\u00a0<\/span><\/li>\n<li><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Change your passwords for financial sites, banks, credit card sites, government sites (tax and Social Security) every three to six months.\u00a0<\/span><\/li>\n<li><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Never click links in emails that appear to come from your bank or any other site that deals with money or highly personal information. Emails from banks, credit card companies, or government agencies will never ask you to click a link to log in.<\/span><\/li>\n<li><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Ignore emails from sites dealing with money or that appear to come from government agencies that tell you that your account may have been compromised and tell you to click a link to verify your information. These kinds of emails are almost always phishing emails.<\/span><\/li>\n<li><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Always be cautious about where you download software. Avoid downloading software from C|Net, Tucows, FileHippo, or Softonic &#8211; these sites are known to bundle software. Whenever possible download from the developer&#8217;s website or from<a href=\"https:\/\/www.snapfiles.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">\u00a0SnapFiles<\/a> or <a href=\"https:\/\/majorgeeks.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">MajorGeeks<\/a>.<\/span><\/li>\n<li><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Always use good security software like <a href=\"https:\/\/thundercloud.net\/emsisoft\/\" target=\"_blank\" rel=\"noopener noreferrer\">Emsisoft<\/a>. And when it comes to security software &#8211; more is not better. While security software cannot prevent you from being tricked, it can prevent malware from being surreptitiously installed on your device.<\/span><\/li>\n<li><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">VPNs and so-called identity theft protection programs do not keep you safe. Most often if your information is stolen, it&#8217;s not because someone or something took it- it&#8217;s because you were tricked into giving it away. i<\/span><\/li>\n<\/ol>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Being cautious and staying informed can go a long way in keeping you safe.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; &nbsp; You&#8217;re Not the Target, You&#8217;re Just a Victim Most everyone is afraid of having their computer hacked. But it&#8217;s very unlikely that your PC will ever be hacked. If I had a dollar for every person who wrote to us saying they have been hacked, I&#8217;d have at least $5000 in my pocket by now. But\u2026 <span class=\"read-more\"><a href=\"https:\/\/www.thundercloud.net\/infoave\/new\/youre-not-the-target-youre-just-a-victim\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":14573,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1669,2942,3590,1670,1656],"tags":[3986,85],"_links":{"self":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/19690"}],"collection":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/comments?post=19690"}],"version-history":[{"count":6,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/19690\/revisions"}],"predecessor-version":[{"id":19696,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/19690\/revisions\/19696"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/media\/14573"}],"wp:attachment":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/media?parent=19690"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/categories?post=19690"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/tags?post=19690"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}