Cyber Safety Net Cyber Safety Net Cyber Safety Net Cyber Safety Net
Navigation
  • Home
  • Artificial Intelligence
  • Cybersecurity Solutions
    • x360 Recover Gets You Back in Business FAST After Disasters or Ransomware
    • Rise of Ransomware Contact
    • Disaster Recovery Test Lets You Stop Worrying
    • Ransomware Recovery Test Lets You Stop Worrying
    • HIPAA
    • Training
    • Protection
    • PCI-DSS Audit
    • 14 Ways to Protect Your Practice from a Cyber Attack
    • 14 Ways to Protect Your Business from a Cyber Attack
    • Penetration Testing Authorization
    • Red Flags of Rogue URLs
  • Blog
  • About
    • Certifications
    • Rise of Ransomware Contact
    • Contact
    • Security Contact
Cyber Safety Net - keeping you safe online.

Learning a $120K Lesson From a Hacked Email Account

Business manager had a hacked email account The bank isn’t always responsible for making you whole after a business email compromise. Indiana’s Lake Ridge Schools lost more than $120,000 from a seven-million-dollar construction fund established to build an athletic complex. The funds were stolen via a wire transfer ordered through a hacked email account. That account belonged to a business manager who was authorized to request payments. The money was requested in the form of wire transfers to several people thought to be contractors on the project. At the time the wire transfers were requested, the business manager was on vacation and the bank, BNY Mellon had received an out-of-office notification days before. Email had a different font Lake Ridge Schools sued BNY Mellon, alleging that the bank’s failure ... Read More
February 7, 2025Mark Anthony Germanos
Watch for fake security alerts

The Government May be Shut Down, but Internet Thieves are Still Working

Government shut down does not stop the thieves Once again we are starting tax season, and Internet thieves are spinning up phishing campaigns to exploit the myriad opportunities afforded by this annual ritual to trick unsuspecting users into coughing up their money, identities, and the credentials to online accounts. Curiously, these campaigns are proceeding even though the U.S. government is partially shut down, causing widespread confusion over whether the IRS will be sufficiently operational to process tax returns and issue refunds. The bad guys, of course, appear to be facing no operational difficulties and are more than happy to step in to take your refunds, your bank accounts, and your identity. Although we have not as yet seen the now infamous W-2 phishing campaigns that have plagued previous tax seasons, they are almost ... Read More
February 7, 2025Mark Anthony Germanos
Cyber Safety Net - keeping you safe online.

CEO Fraud Attacks are Citing the California Wildfires

California wildfires used for social engineering Internet thieves are using the California wildfires as a social engineering tactic to trick you into buying gift cards supposedly intended for victims of the disaster, according to James Linton at Agari. The scammers send emails to employees of organizations posing as their CEO. These CEO Fraud emails target employees who work in accounting, finance, or administration, and tell their recipients to purchase gift cards worth hundreds of dollars to be sent to clients affected by the fires. The employees are instructed to send photos of the codes on the purchased cards, after which the criminals can use online services to convert them into regular currency. Scammers exploit tragedies One of the demoralizing byproducts of large-scale tragedies is the tendency for scammers to exploit people’s charitable ... Read More
February 7, 2025Mark Anthony Germanos
Protect your patients' charge card and debit card data. Perform PCI-DSS audits annually and vulnerability scans quarterly.

HHS Accounces New Final Rule Protecting HIPAA Entities and Individuals

HHS announces new rules The federal Office for Civil Rights (OCR), part of the Department of Health and Human Services, announced today the issuance of the final conscience rule that protects individuals and health care entities from discrimination on the basis of their exercise of conscience in HHS-funded programs. Just as OCR enforces other civil rights, the rule implements full and robust enforcement of approximately 25 provisions passed by Congress protecting longstanding conscience rights in healthcare. The final rule fulfills President Trump’s promise to promote and protect the fundamental and unalienable rights of conscience and religious liberty, a promise he made when he signed an executive order in May 2017 protecting religious liberty.  In October 2017, the Department of Justice issued guidance encouraging other Departments, including HHS, ... Read More
October 8, 2024Mark Anthony Germanos
Watch for fake security alerts

Office Depot Used Fake Malware Scans to Sell Unneeded $300 Services

Office Depot found malware in scans...not really Office Depot and its tech partner tricked customers into buying unneeded tech support services by offering malware scans that gave fake results, according to the FTC (Federal Trade Commission). Consumers paid up to $300 each for unnecessary services. The FTC yesterday announced that Office Depot and its software supplier, Support.com, have agreed to pay a total of $35 million in settlements with the agency. Office Depot agreed to pay $25 million while Support.com will pay the other $10 million. The FTC said it intends to use the money to provide refunds to wronged consumers. Office Depot caught claiming out-of-box PCs showed “symptoms of malware” Between 2009 and 2016, Office Depot and OfficeMax offered computer scans inside their stores using a "PC Health Check" ... Read More
September 30, 2024Mark Anthony Germanos
Save money. Do not fall for this rip off.

Watch Out for Triton, the World’s Most Murderous Malware

Triton got into a petrochemical plant In the summer of 2017, a petrochemical plant in Saudi Arabia experienced a worrisome security incident that cybersecurity experts consider to be the first-ever cyber attack carried out with “a blatant, flat-out intent to hurt people.” The attack involved a highly sophisticated new malware strain called Triton, which was capable of remotely disabling safety systems inside the plant with potentially catastrophic consequences. It all started when someone launched a spear phishing attack and someone else clicked a link they should not have clicked. Luckily, a flaw in the Triton code triggered a safety system that responded by shutting down the plant. If it hadn’t been for that flaw, the hackers could have released toxic hydrogen sulfide gas or caused explosions. As ... Read More
September 30, 2024Mark Anthony Germanos
Protect your patients' charge card and debit card data. Perform PCI-DSS audits annually and vulnerability scans quarterly.

Don’t Add Your Name to the Wall of Shame – Internet Thieves Will Find You

Phishing and File Sharing Internet thieves have long used file sharing sites and services to host their malicious files. When they do this, they typically use the underlying service to generate download links that anyone can click without logging in to the hosting service. Over the past month we started noticing apparently legitimate Dropbox emails pushing links to files with names suspiciously similar to those routinely used by the bad guys. When we clicked the links to check, however, we were greeted with a demand to log in to the service. That's typically been a sign that the files involved were legit. Still, something wasn't right here. Given the file names presented, we reckoned there was little chance those files were innocuous. So, we decided to log in to ... Read More
September 30, 2024Mark Anthony Germanos
Watch for fake security alerts

Georgia county pays $400,000 to get rid of a ransomware infection

Ransomware knocked most systems offline Officials in Jackson County, Georgia, paid $400,000 to cyber-criminals this week to get rid of a ransomware infection and regain access to their IT systems. The County hired cyber-security consultant to negotiate ransom fee with hacker group. Jackson County officials have not yet confirmed how hackers breached their network. The infection forced most of the local government's IT systems offline, with the exception of its website and 911 emergency system. "Everything we have is down," Sheriff Janis Mangum told StateScoop in an interview. "We are doing our bookings the way we used to do it before computers. We're operating by paper in terms of reports and arrest bookings. We've continued to function. It's just more difficult." Jackson County officials notified the FBI and hired a cyber-security consultant. ... Read More
September 30, 2024Mark Anthony Germanos
Watch for fake security alerts

What the Office Depot Fraud Would Look Like in Other Industries

Office Depot $300 scam - yes, it really happened I'm sure you've heard something about the Office Depot $300 fraud. For a thorough explanation, see https://cybersafetynet.net/office-depot-faked-malware-scans-to-sell-unneeded-300-tech-services/. Basically, Office Depot's malware scan reported malware on computers that did not have malware. Office Depot then sold an unnecessary $300 service. Today I am writing about how that would look in other industries. We have a high level of trust in those who provide professional services. We go to them when we sense a problem and need their training, judgement and professionalism to turn the problem into a solution. Let's see how this would play out in another industry. Electrical Your kitchen has a refrigerator, microwave oven and coffee maker. You discover that you can run two at the same time, but ... Read More
September 30, 2024Mark Anthony Germanos
Still vulnerable to cyber attacks and ransomware

New Facebook Phishing Scam is So Good It Can Fool Anybody

Is this the best Facebook phishing scam ever? Scams seeking to harvest online credentials have long tried to replicate known logon pages. But this newly found instance is just about perfect. In every scam that uses social engineering, the key is to be believable. If it looks right, feels right, has the timing right, etc., the victim is more likely to fall for it. This latest scam seeks to take advantage of a user’s desire to leverage single sign-on (SSO) via well-known websites. In this case, Facebook. Rather than creating (and remembering) countless passwords for an equivalently large number of websites, users will take advantage of identifying themselves via Facebook. Under normal circumstances, a Facebook API is called which prompts the user to authenticate. But researchers at security vendor Myki have ... Read More
September 30, 2024Mark Anthony Germanos
  • Previous
  • 1
  • ...
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • Next

Search

Recent Posts

  • AI: Do You Feel People Who Use AI Get More Done in Less Time?
  • AI for Beginners: Learn artificial intelligence now to protect your job
  • FBI Catches CEO Fraud Scammers by Giving Them a Taste of Their Own Medicine
  • Real Estate Transactions Increasingly Vulnerable to CEO Fraud
  • Judge Wants County Officials to Quit After $500K CEO Fraud Scam
  • FIRED: Two C-level Execs Who Fell Victim To A Massive $21 Million CEO Fraud
  • CEO Fraud Causes Investment Fund to Lose $6 Million – Firm Now Out of Business
  • How Hacks Happen wins Nonfiction Authors Association Gold Award
  • Avoid Free Email and Social Media Services
  • AI: Do you feel people who use AI get more done in less time?

© 2026. Cyber Safety Net. 3450 Palmer Drive #4-286. Cameron Park, CA 95682.
Full Disclosure: Some content here is generated by AI. The views expressed are the author's opinion and not legal advice. The author is not a lawyer. You are an adult and responsible for anything you do.