Thursday, December 29, 2011

Android vs iPhone vs Blackberry: Which is most secure?

It seems like everyone has a smartphone or tablet computer these days, making them attractive targets for hackers.  Which platform is most secure against threats?  A recent report from Neohapsis Labs, an independent security think tank, did a deep dive into the question.  You can read their initial report here: Android vs iOS vs BlackBerry: Which is the most secure holiday gift? 

Their results confirm what many people have believed (see my previous blog on the subject).  Apple's iOS software (iPhone, iPad, iPod Touch), although not perfect, is much more secure than Android.  Blackberry is also very secure, although it is targeted at large enterprises with full-time IT departments, so it may be more difficult for individual users to manage.  Android lags far behind the others in security, with many examples of apps being released with malicious content that can do things like record keystrokes or steal passwords.

If you're looking for the most secure platform and aren't part of a large enterprise, iOS is still the way to go.  But you'll pay a price.  Apple tightly controls what apps are available, with each app being released only after it has been analyzed by Apple engineers.  Apple also doesn't let you run Flash, which will prevent you from having full access to many websites.  Android is a much more flexible platform, with new apps being released every day without any kind of vetting process.  If you decide to go with an Android product, be cautious about loading unfamiliar apps, and consider adding anti-virus protection from a well-established company.

Tuesday, November 22, 2011

Android Malware Epidemic Looms ... Or Not

Android phone users may be on the brink of a major malware epidemic, according to a recent report from Juniper Networks that has received considerable media attention.  Since this past July, the number of malware threats on Android phones has increased 472%, according to the report.  Juniper blames the growth on Google's hands-off approach to policing Android apps.  According to Juniper, "all you need is a developer account that is relatively easy to anonymize, pay $25 and you can post your applications.  With no upfront review process, no one checking to see that your application does what it says, just the world’s largest majority of smartphone users skimming past your application’s description page with whatever description of the application the developer chooses to include."  Even if an app is eventually discovered to have malicious intent, thousands of people may have downloaded it before it is removed from the store.

Not so fast, says Chris DiBona, Google's manager of open-source programs.  "Virus companies are playing on your fears to try to sell you bs protection software for Android, RIM, and iOS.  They are charlatans and scammers."  DiBona claims that the few instances of malware that are out there for Androids are pretty rudimentary and nowhere near comparable to what is out there on Windows machines.  Safeguards in the basic Android design will keep the overall threat level low.  As for the eye-popping statistical growth of threats, it's an artifact of numbers that are miniscule.  If there was one instance of Android malware at the beginning of the measurement period and six instances a month later, that would be a 500% increase, but the total threat would still be insignificant.

To decide for yourself whether to be concerned, read the two original articles:

Mobile Malware Development Continues to Rise, Android Leads The Way

Mobile Malware Crisis? Not So Fast

Friday, October 21, 2011

New Mac Virus

Although viruses are much rarer in the Mac world than in Windows, they are not unheard of.  CNET reports that a new Trojan has been discovered that pretends to be an installer for Adobe Flash.  Once embedded, it attempts to send your personal information to remote computers.  CNET says that while this is the latest attack to surface, there are others out there as well.

Compared to Windows malware, Mac attacks are pretty rudimentary, much less common, and easier to spot.  In this case, all you have to remember is to never install Adobe Flash from a pop-up window that appears on your screen.  Instead, go to the Adobe website and get it from there.  However, it's a good idea for Mac users to install anti-virus software even though at the present, the risk of infection is pretty small.

To learn more about this latest Mac attack, check out the CNET article here.

Tuesday, October 18, 2011

Is Your Firewall Good Enough for Today's Threats?

When was the last time you thought about the firewall that protects your network from outside intrusion?  Do you even know if your network has a firewall ?  And if it does, is it good enough to protect against threats being mounted by today's hackers ?  Just what is a firewall, anyway?

In simple terms, a firewall is a device that looks at the data traffic coming into your network to detect and block unauthorized access.  It compares the data with a set of rules in its memory to reject transmissions determined to be malicious.  Firewalls can be either hardware devices or software that runs on your computer.  For a network of any size, you need a hardware firewall.  You can usually find it built into the router at the head of your network.

Many small businesses use inexpensive routers/firewalls designed primarily for residential use.  Such firewalls have limited ability to detect today's sophisticated threats.  Even a business-grade firewall, especially one more than a couple of years old, may be susceptible.  As hackers become more sophisticated in their attacks, the industry has responded with next-generation firewalls that combine traditional stateful packet inspection with advanced intrusion detection capabilities.

A recent article in CSO Online magazine explains the limitations of traditional firewalls and the benefits of next-generation firewalls: Next-generation firewalls: in depth.  It's fairly technical, but the key point is that to protect against many of today's threats you need a firewall that combines traditional inspection with advanced intrusion detection techniques to perform deep packet inspection.  Such a firewall also gives you considerable flexibility in deciding who has access to which applications.  For example, your marketing department can be granted access to Twitter and Facebook to maintain your company's on-line presence while other departments are blocked from access.

Take a look at your network's firewall.  It's the first line of defense against malicious intruders, so it's not an area where you want to scrimp with your investment.  If your firewall is several years old or if it's a product more suitable for residential use, give serious consideration to upgrading to a true next-generation firewall.  And if you need help selecting and installing the right product, give TeamLogic IT a call.  We have experience with many kinds of solutions and can guide you to the best one for your network.

Wednesday, October 12, 2011

Where Do Malware Threats Come From?

Many people think that most malware gets into your system through sofware vulnerabilities that haven't yet been discovered and fixed by the manufacturer.  These kinds of attacks (called "zero-day vulnerabilities") make headlines and can lead you to believe there's not much you can do to stop them.  If the software manufacturer hasn't discovered the threat and issued a patch to fix it, what can you do?

A recent study by Microsoft found that such beliefs are largely unfounded.  Using software tools they deploy to track such events, they found that only 0.01% of all attacks exploit zero-day vulnerabilities.  Nearly 50% of attacks use social engineering techniques to trick the user into clicking a link or revealing private information (see my last blog entry for more on this story).  What can you do to protect yourself?  Besides the obvious of not clicking on suspicious links or disclosing private information to strangers, you should also make sure you are running the most recent versions of your applications.  According to outside tests, for example, Internet Explorer 9 is more resistant to malware attack than any other browser.  Here's a link to an Information Week story about the Microsoft study: Zero-Day Threats Exaggerated, Says Microsoft Report.

Sunday, October 2, 2011

Employees are a Company's Biggest Security Risk

Hackers are continually evolving the ways they attack business computer networks.  While "brute force" attacks in which the hacker makes multiple attempts in quick succession to guess a user's password are still common, sophisticated hackers have moved toward more sinister methods of attack.  Imagine getting an email from your boss, addressed to you and your closest colleagues, describing a change to the project you are working on and asking you to open an email attachment for more details.  Only the email isn't from your boss, it's from a hacker who used such resources as Facebook, Twitter, and LinkedIn to learn enough about you and your job to craft a legitimate-looking email.  Opening the email introduces a virus into the network that lets the hacker gain unchecked access.  This is just one of the ways hackers are circumventing traditional safeguards.  Here's an article from the Wall Street Journal that should be required reading for every employee in your business: What's a Company's Biggest Security Risk? You!

Thursday, September 22, 2011

Trusting the Cloud: Is It Right for Your Business?

There is little doubt that cloud computing will become increasingly important to businesses in the coming years.  If you're a business owner or an IT manager, you should take the time to learn more about cloud computing and how it may benefit your company.  But you should also know that cloud computing is not perfect.  Both Microsoft and Google have suffered cloud service outages in recent weeks, and this is not the first time it has happened.  It probably won't be the last time, either.  Does that mean you shouldn't trust your business's applications to the cloud?  Nope, it just means you need to be aware of the issues and know how to deal with them.  After all, network outages are not something new with the cloud.  With an on-site network, a server can crash, a router can fail, and a host of other problems can occur.  The difference is if your own server crashes it's a local event that doesn't make headlines.  If Microsoft's cloud crashes, businesses around the globe are affected, and that's news.  But the actual impact on your business may be less.  How long would it take you to recover if your own server crashed?  You'd need a new server (or create a new virtual server on one of your other servers), you'd need to re-install applications, and you'd need to recover data from your backups (you do have backups, right?).  This could take days.  With a good cloud service you could be back up in minutes or hours.  Don't get turned off by the idea of moving to the cloud just because of an occasional headline.  Think about it in terms of your other alternatives.

Cloud services aren't right for every business or for every application within a business.  But there are opportunities to improve efficiencies and reduce costs by deploying them judiciously.  Just use good, business-class cloud service providers and take preventative actions to minimize the impact of service disruptions.  Here's an interesting article from PCWorld that talks about the topic in more detail: Microsoft and Google Suffer Outages: Can You Trust the Cloud?

Tuesday, September 6, 2011

Five IT Trends for 2012 Every Small Business Should Know

At TeamLogic IT, we want our clients to stay on top of the latest technology trends impacting small and medium size businesses. Our corporate president, Chuck Lennon, serves as Vice Chairman of CompTIA, the IT industry’s leading trade association. It’s a role that gives us considerable insight into industry trends. Here are five trends we believe will have particular impact on small businesses over the coming year:

Cloud Services

“The cloud” is getting lots of hype these days. Microsoft even touts it in television ads. But what is it? In the simplest sense, going to “the cloud” means getting IT services on-line instead of on-site. Today you can use the cloud for everything from email to spreadsheets to data backups. You can even buy cloud-based server space to potentially eliminate the need for an on-site server. If you use Gmail, Carbonite, or Google Docs, you’re already using cloud services. But not every cloud service can meet the needs of businesses. What would you do if your email was out of service for a day or more? This happens all too often with services designed primarily for the consumer market. You need services designed for businesses. Going to the cloud also impacts the design of your network—you’ll need a fast, reliable Internet connection.

If you’re thinking of moving to the cloud, make sure you know what to watch out for with cloud services. Keep in mind that if your Internet goes down, you will be off line until it is back up. Also know that you don’t have to make a complete switch overnight. You can start gradually, perhaps with hosted email or off-site backups, while keeping business-critical software applications on in-house servers.

Mobility & Connectivity

This has been called the “consumerization” of IT.  Employees want to be connected at all times. They are buying smartphones, tablet computers, and netbooks on their own and want to use them on the company network. There’s even a term for the trend—BYOD, or “Bring Your Own Device.” But it’s fraught with perils. How can a business protect critical business data when that data resides on an employee’s personal device? What happens if the device is stolen or they leave the company?  What about the possibility that the device may be seized indefinitely if it contains data that is part of a legal dispute? And what about the extra workload thrust onto your IT technicians who now have to figure out how to securely connect a wide variety of devices to the company network? You need plans to address questions such as these before implementing BYOD.

Integration of Phones and Data

Remember when your phones and your computer network were different systems? That day is long past. Savvy businesses know they can integrate their office phones, mobile phones, and computers into a unified whole. Today you can have voice mails forwarded to you as emails, have your office phone and mobile phone ring simultaneously, and plug a company phone into your home network to use it as just another business phone extension. Some companies have switched from conventional phone systems to Voice over IP (VoIP) systems that use your computer network for calls. Two kinds of VoIP systems are common today. The first uses ordinary phone lines to deliver phone calls into your office and then distributes them via VoIP once inside. The second, known as Hosted VoIP, eliminates the phone company entirely; your calls are carried completely over the Internet. Each has advantages and disadvantages, so you will need to search to find the best solution for your business. A low-cost Hosted VoIP network designed primarily for residential users may not be adequate for a business. And you’ll need to make sure your network is up to the task. Audio quality may suffer if all traffic on your network is given equal priority. You need a router with a QoS (Quality of Service) function that puts a priority on telephone traffic. Otherwise your call may turn to gibberish when your neighbor in the next cubicle starts downloading a large data file.

Security

With the prevalence of laptops, smartphones, tablet computers, etc., in the business world, the risk of data loss has dramatically increased. And the sensitivity of data stored on mobile devices is growing. Employee records, social security numbers, credit card numbers, and passwords are just a few kinds of sensitive data that may be stored on mobile devices. The penalties for unauthorized disclosure of sensitive data can be severe. If you’re in the healthcare industry, for example, penalties for unauthorized disclosure of patient records can range from $50,000 up to $1.5 million, depending on the level of your neglect. You must also notify patients of any unauthorized disclosures, a potential PR nightmare. The Payment Card Industry has similar penalties for unauthorized disclosures of credit card information. To minimize the risk of data on mobile devices being compromised, it is critical that these data files be encrypted. Robust encryption algorithms will prevent anyone from viewing the data without an encryption key. As a further level of protection, you should implement a remote-wipe process that lets you quickly disable any lost or stolen mobile device.

Integration of IT and AV

With the growing use of video conferencing, webinars, and distance learning, audio-visual services are becoming increasingly important to the business world. Traditional video projectors are giving way to large, highly-interactive video interfaces such as the InFocus Mondopad, billed as a “55-inch tablet computer.” In times past, the technician who serviced your audio-visual equipment needed different skills from the technician who supported your IT network.  Now, everything is part of the same network.  Rather than contracting with a separate AV tech, you need an IT tech who knows how to support all the devices attached to your network.

Whether you need a server in the cloud, a modern VoIP phone system, a compliant security strategy, or just a knowledgeable, reliable IT company who can reduce downtime on your existing computer network, TeamLogic IT can help. Our certified technicians understand how to assess and solve your IT challenges. They are familiar with the latest technologies and can sort through the myriad of conflicting information to determine the best IT strategy for your business. Give us a call and let us show you how we can help.

For more information contact:
TeamLogic IT
200 Montgomery Drive, Suite C
Santa Rosa, CA
                                                                                                         707-293-9525

Saturday, September 3, 2011

TeamLogic IT Exec Named Top Managed Services Executive

Each year, MSPmentor, a publication of Nine Lives Media Inc.,  identifies the world’s top IT managed services experts, which according to their site include, "professionals who have mastered business leadership, marketing, sales, technology, coaching and other areas within the managed services market."  We're happy to announce that Chuck Lennon, President of the national TeamLogic IT, Inc., was once again named a top IT expert.  You can read about it here and see the full list here.

It's been a busy year for Chuck.  He was also recently named Vice Chairman of CompTIA, the industry's leading trade association.  Chuck's leadership role helps assure that all TeamLogic IT offices stay current with the latest industry trends to better serve our clients.  I'll cover some of those trends in my next blog entry.

Wednesday, July 27, 2011

Hackers Step Up Attacks on Small Businesses

Think hackers only attack large multinational companies like Sony or Citibank?  Think again.  Here at TeamLogic IT, we recently had to defend one of our clients against a major brute force attack by an unknown hacker.  They were a new client, and we had just put them on our Managed Services solution, SystemWatch IT.  We quickly discovered that an outside computer was blasting their network with a never-ending stream of usernames and passwords in an attempt to break in.  It's not something our client would have noticed in the normal course of business, but SystemWatch IT alerted us nearly immediately.  We made a few changes to improve security of the client's network and the attacks quickly stopped.  Fortunately the company had a sound password management strategy that enforced the requirement for strong passwords.  A less strict company may well have been successfully hacked before we ever took over managing their network.

What we experienced is becoming more commonplace throughout the world.  Hackers are starting to realize it's easier to break into small businesses, who often don't have robust security measures, than large companies with  highly skilled IT departments.  The rewards might not be as great, but it's much easier to do.  The Wall Street Journal recently published a disturbing article about this new trend in hacking.  You can read it HERE.

If you capture any kind of confidential information in your network—credit card information, client data, trade secrets, company financial information, etc.—take the time to assess the quality of your network's security.  If you have any doubts, have an IT professional do a thorough security audit for you.

Monday, June 20, 2011

How Long Will Your Digital Photos Survive?

Back in the days when photographers used to shoot with film cameras, we would worry about the archival quality of our photos.  How long would they survive before fading away into oblivion?  We ourselves might only live another 40 or 50 years, but such a short lifespan for our photos would be unthinkable.

Looking back at color prints from the 1960s and 1970s, our fears were well-founded.  Old Ektacolor prints have long since faded and shifted color toward the yellow.  Cibachrome prints and Kodachrome slides are much better, but not immune.  Whole collections of what were once professional-quality photos are now just interesting anachronisms.

The new generation of photographers, accustomed to shooting only digital, may laugh at such worries today.  If a photo print fades, just fire up your computer and print another.  Why worry?  Digital ones and zeroes don't fade with time.

But there's a whole body of research that suggests such complacency is unfounded.  Digital photos may fade away even faster than photographic prints; it's just that the failure mechanisms are different.  Here's a link to an interesting article from an unlikely source that describes the problems with digital photography in some detail:

Long-term archiving: digital photography's Achilles' heel

Tuesday, May 31, 2011

Small Businesses Moving to the Cloud -- But Slowly

Wondering about whether your small business should be moving to cloud computing?  You're not alone.  More and more businesses are looking to the cloud for at least some of their needs, whether it be email through a service like GMail, word processing or spreadsheets through Google Docs, or on-line backups through services like Carbonite or Mozy.  But a recent survey by CDW, a major electronics distributor, found that cloud adoption was lower than what industry buzz would lead you to expect.  Although many companies use cloud services on an ad-hoc basis, fewer had any kind of corporate cloud strategy.  Only 21% of small businesses were using the cloud in any kind of planned way (CDW didn't consider ad hoc usage by single individuals as being part of a business's cloud strategy).  Security questions continue to be a major impediment.  Nevertheless, most businesses see the cloud as having a place in their future strategy, although few expect it to completely replace on-premises services.  Here's a link to the article: http://www.echannelline.com/usa/story.cfm?item=26853

If you'd like help understanding how cloud services might benefit your company, which vendors are best, and which to avoid, give TeamLogic IT a call.

Monday, May 16, 2011

Microsoft, Google Stumble in the Cloud

Anyone who watches TV these days has probably seen Microsoft's "To the Cloud" ad campaign.  The promise of easy, instant access to content whenever and wherever you want is definitely appealing.  But it's significant to note that most of their ads relate to consumer uses of the Cloud--a couple at an airport watch TV while waiting for their delayed flight; a mother edits a family picture to ensure everyone is smiling.  You might wonder how useful Cloud computing is in the business world.

The short answer is that if you recognize and accept its limitations, it can be very powerful.  First, you need an Internet connection for it to work.  If you're a frequent flyer, don't expect to get much work done in-flight if your office applications reside in the Cloud.  You also need to be selective about which service providers to use.  Microsoft and Google both play heavily to Cloud users, but they are really geared more for consumers.  Neither would be my first choice for business users as both still have service outages too frequently (although I will be quick to point out I use Google's Blogger for this blog--a non-business-critical application).  Here's a link to an Information Week article about their latest problems from just last week:

http://www.informationweek.com/news/cloud-computing/software/229500599

If you're thinking about moving your business's computing power to the Cloud, you have numerous options.  If you're not sure how to proceed, give us a call and see how TeamLogic IT might be able to help.

Wednesday, April 13, 2011

Protecting Your Business from Cyber-Criminals

If your company uses computers for things like email, web browsing, accounting, online banking, inventory management, or payroll, you need to know how to protect yourself from cyber-criminals. One recent government study showed that an unprotected Windows computer taken right out of the box and connected to the Internet was typically hacked within 20 minutes.
Many business owners don't realize that as a business, you don't have the same legal protection as a consumer.  If hackers break into your business network and drain your bank account because you didn’t implement adequate security, your bank is under no obligation to reimburse you.  There are numerous stories of banks refusing to reimburse businesses that lost hundreds of thousands of dollars to cyber-criminals because they didn't take sufficient security precautions to prevent the thefts.
The small business owner who recognizes the threat of computer crime and takes steps to prevent hackers from breaking in is less likely to become a victim. Here are seven things every business should do to protect its computer network:
1.       Use a firewall. This is the first line of defense for your system.  Firewalls scan all traffic into and out of your network to block unauthorized access.  There are two kinds of firewalls: software and hardware. Software firewalls such as Windows Firewall run directly on your computer.  Hardware firewalls are separate boxes that sit at the junction between the Internet and your local network. While hardware firewalls are preferred for business-grade security, either is much better than the alternative of doing nothing.  Your Internet Service Provider might include a firewall as part of their DSL or cable modem.
2.       Use anti-virus and anti-spyware software and keep it updated.  A firewall won’t block every threat.  Anti-spyware software looks for programs that secretly enter your computer and collect bits of information about you.  This could include such things as the websites you visit or the keys you type to enter a password.  Anti-virus software scans all your files, looking for known or suspected malicious code—viruses, worms, or Trojans.  Although each differs in its details, all can be serious threats.  The anti-virus software scans for them all.  Files considered threats are identified, where you can quarantine or delete them.  If you think the suspect file isn’t truly a virus, put it into quarantine.  Otherwise delete it.  In order to be effective, you need to keep anti-virus and anti-spyware software up to date.  New viruses are constantly being released by hackers, and the best AV and AS vendors issue updates to detect the latest threats at least daily.
3.       If you use a wireless network, be sure it is configured for secure encryption.  By default, a wireless router is not set up for encryption.  This means that once you turn on your WiFi, anyone with a computer who is in range of its signal can access your network.  Not only can they connect to the Internet and potentially slow down your system, they can also access your private files and secretly track your passwords, credit cards, and on-line banking information.  It is imperative you turn on encryption so that only authorized users can gain access.  Modern routers offer 3 different kinds of encryption: WEP, WPA, and WPA2.  Always use WPA2, as the others are more vulnerable to hackers.
4.       Use highly secure passwords. What are the worst passwords?  Here are a few of the most common: 123456, password, qwerty, letmein, abc123, and a few obscene words I won’t repeat here.  Do a Google search on “worst passwords” and you’ll see a complete list.  The best passwords are at least 14 characters long, don’t include any words found in the dictionary (including spelled backwards) and use a combination of uppercase and lowercase letters, numbers, and punctuation marks.  Some sources advocate using a different password for every account and changing it regularly.  At the very least you should use several different passwords for different kinds of business and personal accounts, and never share your passwords with anyone else.  If anyone else learns your password, change it immediately.
5.       Keep your operating system updated with the latest security patches. If you use a Windows computer, turn on automatic updates or go to www.update.microsoft.com/microsoftupdate to install the latest updates (but don’t turn on automatic updates for servers).  If you use a Mac, don’t assume you are invulnerable to hackers.  Accept all new security patches when they are issued.
6.       Be cautious opening email attachments and clicking embedded links.  Most viruses infect your computer because you opened an email attachment.  Don’t think an attachment is automatically safe just because it came from someone you know.  Scan it with an anti-virus software program before opening.  For the ultimate in security, use a remote anti-virus solution that scans all your emails and blocks any viruses before they ever get into your network.  Also be careful about clicking on a Web link in an email.  Rather than clicking the link, manually type the URL into your browser.
7.       Back up your data regularly.  You never know when a hard drive will crash or your laptop will get stolen.  Don’t wait for disaster to strike before you think about backing up your data.  You can purchase a hard drive specifically for backing up your data or you can use an online service.  Just make sure you do it regularly—at least daily for business data.  You might also consider doing what is known as a “full image” backup.  If your computer’s hard disk crashes or your laptop is stolen, this allows you to quickly restore your entire computer—programs and settings as well as data files—onto a new computer from the backup copy.
While there can never be a 100% guarantee that you won’t be hacked, following all seven of these steps will dramatically reduce the probability you will be a victim of a cyber-crime.  If you’re not sure how to do all this yourself, consider contracting with an expert like TeamLogic IT to assess your vulnerabilities and take appropriate steps to correct them.  TeamLogic IT is a nationwide network of computer consultation and managed services businesses that addresses the IT needs of small- to medium-sized businesses.  We provide customers with quick-response troubleshooting and repair of desktops, servers and online systems, and we offer a variety of consultation and maintenance services that previously have only been available to larger organizations.
In addition, TeamLogic IT focuses on preventing IT disasters through a proactive approach to managing IT services using state-of-the-art technology.  We provide networking services, security services, data services, email services, and we can procure hardware and software at competitive prices due to our national buying power.  In Sonoma County, find out more by contacting us at 707-293-9525 or emailing shinch@teamlogicit.com.

Monday, April 11, 2011

Major Security Breach at Epsilon Interactive

By now, many of you may have received emails alerting you to a security breach at Epsilon Interactive, an on-line company used by many major corporations to send marketing emails to customers. An outside hacker broke into the Epsilon network and gained access to numerous names and email addresses of their clients’ customers. Major corporations affected include Barclays Bank, Best Buy, Citibank, JP Morgan Chase, Marriott International, Target, Walgreens, Hilton Worldwide, and Disney Destinations, as well as a host of others. If you’ve received one of these emails, you might be wondering how it will affect you. I’ll try to answer that question here.

What Happened
Epsilon specializes in sending bulk marketing emails in the name of their client companies. It takes a certain amount of skill to craft personalized emails in a way that spam filters don’t block them, and this is Epsilon’s claim to fame. They send more than 40 billion emails on behalf of their clients annually to people who have provided an email address to the client company. Although Epsilon isn’t saying exactly what happened, it is clear that someone was able to hack into their network and obtain customer names and email addresses. Epsilon has stated that “approximately 2 percent of total clients” were hit, which would be about 50 companies. To date, Epsilon has not provided a detailed list of those companies, but the ones named above have notified their customers of the breach. Epsilon has made it very clear that the hackers only got names and email addresses, not any financial information. This means the information can’t immediately be used to do anything harmful, other than to send out more spam.

The Risk
Email addresses on their own aren’t all that valuable, but if you can tie a customer’s name and email account to a company they do business with, the problem becomes more serious. A hacker can create a customized email that appears to come from the client company to trick the customer into revealing sensitive information. Suppose, for example, you got an email from your bank encouraging you to sign up for a special offer. All you have to do is click on the link in the email, log into your account, and you’re all signed up. Of course the offer isn’t really from your bank, and the link takes you to a rogue website that captures your login information. Before you know it, the hacker uses it to break into your account and drain it dry.

How to Protect Yourself
The good news is that the stolen information by itself won’t let a hacker do anything harmful. As long as you practice due diligence in opening and reading emails, you should be safe. The first thing to remember is to never provide sensitive information—account names, passwords, social security numbers, etc., in response to an email request. Legitimate companies will never make such a request by email. Also be very cautious about clicking links in emails, and never enter any sensitive information onto a website you arrived at from an email link. Whenever you must enter sensitive information go to the company’s website by manually typing their web address into your browser (once you’ve done this, you can bookmark it for future use).
You may also want to consider investing in a strong spam filter for your email network, even beyond the anti-virus/anti-malware software you should all be using. There are two ways to do this, either by using a Cloud-based service or by using a hardware filter you add to your own network. Cloud-service companies such as AppRiver can filter almost all spam before it even gets into your network, or you can use a hardware email security appliance such as those offered by Barracuda Networks. Either option can significantly reduce the amount of unwanted spam clogging up your network.

Finally, make sure that access to your network is protected by strong passwords. Although we don’t know how the hacker got into the Epsilon network, we do know some of the techniques commonly used. One approach is to use a program that tries to brute-force its way into your network by automatically trying common usernames and passwords. Passwords like “1234” or the word “password” are easily hacked. At TeamLogic IT a new client recently asked us to repair damage to their network caused by a hacker. When we investigated, we discovered the break-in probably occurred because their server password was one of the most common and least secure passwords out there. Don’t let this happen to you.

To learn more about how to protect your network, including how to create strong passwords, read my previous blog entry, Protecting Your Business Against Cyber-Criminals.  And if you’d like TeamLogic IT to help improve the security of your network, just visit www.teamlogicit.com.