Tag Archives: data breach

Sharing personal information plays part in Neiman Marcus hack

Data that you share on social media could end up for sale on the Dark Web.

Adjust your privacy settings on social networks. You never know who may be watching!

Adjust your privacy settings on social networks. You never know who may be watching!

The luxury retailer Neiman Marcus is the latest victim of a data breach. At the end of January, Neiman Marcus notified their online customers that unauthorized individuals attempted to access customer’s online accounts by trying various login and password combinations using automated attacks. The hackers were able to accurately guess the username and password combinations and access some online accounts. Neiman Marcus reported that only a small number of these accounts were used to make unauthorized purchases.

Personal information shared on social sites combined with Personally Identifiable Information (PII) and username and passwords for sale on the Dark Web, are making data breaches of this type more common.  Cybercrooks, terrorists, and nation states buy information from shady sites, then use it to break into banks, launder money, or make trouble for big U.S. companies like Neiman Marcus Group.

“These bad guys are assembling portfolios of individuals,” said Avivah Litan, an analyst at Gartner in an interview with DataBreachToday about the breach. “They’ve got a big database of American citizens and all the data associated with their identity, and lots of different people are buying up this data on the Dark Web. And they’re using this data to get to their targets.”

Unsafe practices make hacker’s jobs easier

Responsibility for customer safety belongs heavily with the organization. They should encrypt any customer contact information and use stronger authentication methods than just a username and password. But, we as consumers make the hacker’s job easier by using the same username and password on multiple accounts. Once one set of credentials is compromised, then hackers will test them to get access to other websites.

We can take steps that make it harder for a cybercrook to gather information on us and break into our accounts.

Clean up those passwords

One of the simplest ways to protect yourself against online threats is to use strong passwords for each of your accounts. Yesterday in the Avast blog, we told you how Avast Passwords can help you manage multiple accounts across the web and create encrypted, strong, unique passwords. Every Avast Antivirus customer can use this feature for free.

Avoid oversharing on social sites

Social media is fertile ground for cybercrooks to gather personal information. Sharing something seemingly innocent like your dog’s name, your birthday,  or your mother’s maiden name can give insightful crooks the answers to security questions of your bank account. Put that together with PII and they’re in.

  • Lock down your social profiles. Each social site has security settings so you can have more control over who sees what you share. Use these direct links to update your privacy settings on popular devices and online services.
  • Limit the number of online quizzes you take. Yes, they are popular and fun but these quizzes can gather information about you, your interest, and your life assisting bad guys in creating an online portfolio of user information.

Password Security — Who's to Blame for Weak Passwords? Users, Really?

The majority of Internet users are vulnerable to cyber threats because of their own weaknesses in setting up a strong password. But, are end-users completely responsible for choosing weak passwords?

Give a thought.

Recently we wrote an article revealing the list of Worst Passwords of 2015 that proved most of us are still using bad passwords, like ‘123456’ or ‘password,’ to secure our

Casino Sues Cyber Security Company Over Failure to Stop Hackers

IT security firm Trustwave has been sued by a Las Vegas-based casino operator for conducting an allegedly “woefully inadequate” investigation following a network breach of the casino operator’s system.

Affinity Gaming, an operator of 5 casinos in Nevada and 6 elsewhere in the United States, has questioned Trustwave’s investigation for failing to shut down breach that directly resulted in

Internet of Things: What you need to do to protect yourself

The Internet of Things (IoT) join together physical devices that we use every day with information technology.

Make sure your Internet of Things is secure

We can use devices to monitor our health and fitness, our houses, our environment, and our factories and cities.

Using internet-connected devices expands our ability to control and monitor in the real world.  The IoT is literally changing our lives.

The Internet of Things has the potential to fundamentally shift the way we interact with our surroundings. The ability to monitor and manage objects in the physical world electronically makes it possible to bring data-driven decision making to new realms of human activity – to optimize the performance of systems and processes, save time for people and businesses, and improve quality of life.” ~ McKinsey Global Institute study

The potential economic impact of the IoT is astounding  – as much as $11.1 trillion per year by 2025 for IoT applications, projected by the same study.

But is there a downside?

In many people’s minds, surveillance, privacy issues, and data breaches seem to be someone else’s problem. “Should I be concerned about all of this?,” people who have “nothing to hide” think. Recently, we published how the Internet of Things can be hacked and what issues arise from the fact that we’re almost 100% online and connected.

Nowadays, all this technology passes through very well-known and yet problematic points: Our home network security. When our early version of Avast 2015 was released, we published many articles about Home Network Security. During the past year, we gathered lots of proof and conducted social experiments to show that…

Your security is as strong as your network security

To protect your security and privacy, you must assure that your network and communications are safe. Although this seems like rocket science, some basic – but effective – measures can and should be taken. It’s really not rocket science, so even us common folk can follow the steps below to make sure we’re prepared to a secure our IoT life.

  1. 1. Device protection: Install security software on all your connected devices. Avast is a worldwide leader in providing security for Windows, iOS, and Android devices. They can stop malicious actions and make all the difference when you’re online. Your device protection also depends on its own installed software security, thus, keep all your apps and operational system up-to-date.
  2. 2. Network protection: Not all antivirus software provides for proper network protection. If a cybercrook invades one of your devices –most commonly the router – all your network, devices, and data could be compromised. Avast has unique features to allow you to scan your network and find if there is any open door to hackers. 
  3. 3. Security best practices: There are numerous “best” practices, some of which will save you a lot of headaches. The most important is using different passwords for each online service or site and protecting yourself in open or public Wi-Fi networks.  Avast Passwords to manage all your passwords and Avast SecureLine to safely connect you to Wi-Fi, will give you peace of mind.

Avast premium versions include all the protection you need including Home Network Security. You can download and test them for free from the Avast website.


 

Follow Avast on Facebook, Twitter, YouTube e Google+ where we keep you updated on cybersecurity news every day.

191 Million US Voters' Personal Info Exposed by Misconfigured Database

BREAKING: A misconfigured database has resulted in the exposure of around 191 Million voter records including voters’ full names, their home addresses, unique voter IDs, date of births and phone numbers.

The database was discovered on December 20th by Chris Vickery, a white hat hacker, who was able to access over 191 Million Americans’ personal identifying information (PII) that are just

Hyatt Hotel Says Payment Systems Hacked with Credit-Card Stealing Malware

Hyatt Hotels Corporation is notifying its customers that credit card numbers and other sensitive information may have been stolen after it found malware on the computers that process customer payments.

“We recently identified malware on computers that operate the payment processing systems for Hyatt-managed locations,” the company announced on Wednesday. “As soon as we discovered the