Identity Theft Alert: FBI, HHS Warn of Emerging Fraud Schemes Involving COVID-19 Vaccines

Cyber criminals routinely incorporate the “crisis-du-jour” into scams to increase their likelihood of success. COVID-19, it seems, is no exception. In a single week, Google saw 18 million coronavirus-related malware and phishing emails…per day! It’s gotten so bad that the Federal Bureau of Investigation, the Department of Health and Human Services and the Centers for Medicare & Medicaid Services found it necessary to warn the public about emerging fraud schemes related to COVID-19, particularly those involving COVID-19 vaccines.

According to the HHS Office of Inspector General, criminals are using calls, text messages, social media and even door-to-door visits to perpetrate their crimes. They offer vaccine-related benefits in exchange for personal information. HHS warns, however, that these benefits are unapproved and illegitimate and that scammers use your personal information to fraudulently bill federal health care programs and commit medical identity theft.

To protect against these schemes, authorities urge everyone to be on the lookout for potential indicators of fraud, including the following.

  • Advertisements or offers for early access to a vaccine upon payment of a deposit or fee.
  • Requests for cash payments to get vaccinated or to be put on a COVID-19 vaccine waiting list.
  • Offers to undergo additional medical testing or procedures when obtaining a vaccine.
  • Offers to sell or ship doses of a vaccine (domestically or internationally) in exchange for payment of a deposit or fee.
  • Unsolicited emails, texts, calls or personal contact from someone claiming to be from a medical office, insurance company or COVID-19 vaccine center requesting personal or medical information to determine eligibility to participate in clinical vaccine trials or obtain the vaccine.
  • Claims of FDA approval for a vaccine that cannot be verified.
  • Advertisements for vaccines through social media, email, phone, texts, online or from unsolicited or unknown sources.
  • Individuals contacting you in person, by phone or by email to tell you the government requires you to receive a COVID-19 vaccine.

Cyber criminals are nothing if not creative. They are constantly hatching new schemes to stay a step ahead of the authorities. Fortunately, HHS offers a simple, yet effective tip for protecting you and your family from cyber criminals and identity thieves—do not share your personal information with those who are unknown or unsolicited.

When preventative measures fail, insurance is available to help victims through the expensive and time-consuming process of recovery. Please contact us if you would like more information about insurance specifically designed to protect against identity theft.

Don’t Let Weak Site Security Compromise Your Business’s Cybersecurity

Setnor Byer Insurance & Risk

Small businesses spend a lot of time and money to protect their sensitive and confidential information, and rightfully so. Data breaches can lead to crippling, often insurmountable financial and reputational harm. Unfortunately, many businesses overlook the most basic security measures. Cyber criminals, for example, pose the biggest threat to data security, so most businesses focus almost exclusively on cybersecurity while paying little or no attention to physical (site) security. This can prove disastrous because sophisticated firewalls and advanced security software cannot stop someone from stealing a flash drive or paper file containing sensitive information.

According to the Federal Trade Commission, cybersecurity begins with strong physical security that effectively protects sensitive or confidential information in paper files and electronic devices (hard drives, flash drives, laptops, point-of-sale devices, etc.). The FTC offers the following tips for maintaining physical security.

  • Store paper files and electronic devices containing sensitive information in a locked cabinet or room to keep them secure.
  • Train employees to put paper files in locked file cabinets, log out of networks and applications before leaving and never leave files or devices with sensitive data unattended.
  • Limit physical access to records or devices containing sensitive data to only those who need it.
  • Keep track of documents and devices containing sensitive data so they can be handled accordingly.

To protect sensitive data stored on devices,

  • Require passwords that are long, complex and unique.
  • Require multi-factor authentication, like a password and a temporary code, to access sensitive information.
  • Limit the number of incorrect login attempts allowed to unlock devices.
  • Encrypt portable media, including laptops and thumb drives, that contain sensitive information.

Sensitive and confidential business data can be stolen online or onsite, so businesses must make physical (site) security a key component of their cybersecurity protocols. Since security measures aren’t always enough, small and medium-sized businesses should have Cyber Perils Insurance Coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws. Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches

Ransomware Attacks Are Becoming More Common and More Expensive

Setnor Byer Insurance & Risk

Did you know that the average ransomware demand in the first quarter of 2020 was $111,605? Ransomware is a type of malware that encrypts critical data so it cannot be accessed without a decryption key. Victims must, you guessed it, pay a ransom to get the key. The costs associated with a successful attack, which can far exceed the ransom, typically include investigation and remediation expenses and lost revenue due to downtime. Ransomware can also inflict insurmountable brand damage and reputational harm.

According to the Federal Trade Commission (FTC), hackers try to exploit network or server vulnerabilities to access a target’s data, but the malicious code used to launch ransomware attacks is often installed on devices and networks by:

  • scam (phishing) emails that appear legitimate;
  • infected websites; and
  • online ads, which often appear on websites you know and trust.

The FTC recommends the following measures to reduce the risk of a successful ransomware attack.

  • Have a Plan. Businesses need a plan to remain operational after a ransomware attack. Plans should be written and shared with those needing to know.
  • Back up Data. Regularly save important data to a drive or server that’s not connected to a network. Make this part of your routine business operations.
  • Update Security Software. Always install the latest patches and updates. Consider adjusting your settings to update automatically.
  • Train Staff. Train all employees how to identify and avoid common threats. Provide examples of the most common ways devices and networks become infected.

If your business experiences a ransomware attack, the FTC recommends taking the following steps.

  • Limit the damage. Immediately disconnect infected devices from your network.
  • Contact Authorities. Immediately report the attack to local and federal authorities (local FBI office).
  • Provide Required Notices. If data has been exposed, compromised or stolen, notify authorities and affected individuals pursuant to any applicable data breach notification laws.

Preventative measures can effectively reduce the risk of a ransomware attack, but they’re not foolproof. Every business should have Cyber Perils Insurance Coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws. Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

October is National Cybersecurity Awareness Month

Cybersecurity Awareness Month was launched in 2004 to promote online safety and security. This is particularly important in 2020 because so many things took a back seat when coronavirus disease 2019 arrived. COVID-19 may dominate the headlines, but data security breaches continue to pose a serious threat to small businesses nationwide. According to the Federal Trade Commission, cyber criminals target businesses of all sizes, so all are encouraged to take advantage of Cybersecurity Awareness Month 2020.

This year’s theme, “Do Your Part. #BeCyberSmart,” is intended to empower individuals and organizations to own their role in maintaining cybersecurity. The key message in 2020 emphasizes the importance of doing your part. “If you connect it, protect it.” Small businesses can reduce the risk of a cybersecurity incident by educating employees about basic cybersecurity measures and putting them in practice. The FTC suggests various measures that every small business should have in place.

  • Update Software. This includes apps, web browsers and operating systems. Set updates to happen automatically.
  • Back Up Files. Regularly back-up important files (offline, external hard drive, in the cloud, etc.).
  • Require Strong Passwords. All devices should be password protected. A strong password is at least 12 characters that includes numbers, symbols and capital and lowercase letters. Never reuse or share passwords.
  • Encrypt Devices. Encryption protects information from unauthorized access. Any devices containing sensitive information should be encrypted. This includes laptops, tablets, smartphones, removable drives, backup tapes and cloud storage solutions.
  • Use Multi-Factor Authentication. Require multi-factor authentication to access sensitive information. This requires additional steps beyond logging in with a password, like entering a temporary code or providing additional identifying information.
  • Secure Routers and Wireless Networks. Change the default name and password, turn off remote management and log out as the administrator once the router is set up. Make sure your router offers WPA2 or WPA3 encryption, and that it’s turned on.
  • Train Employees. Create a culture of security by implementing a regular schedule of mandatory employee training. Update employees about new risks or vulnerabilities.
  • Have a Plan. A response plan should be in place before a data breach happens. It should include plans for protecting and saving data, maintaining operations and notifying customers affected by the beach.

Implementing, maintaining and updating security policies and procedures is important, but it’s not always enough. Small and medium-sized businesses should have Cyber Perils Insurance Coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws. Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

Don’t Lose Sight of Security Among the Internet of Things

Did you know that there will be nearly 21 billion devices connected to the Internet by 2020?

According to Gartner, an information technology research company, 5.5 million new devices are connecting every day. This rapidly growing network of Internet-enabled physical devices capable connecting, communicating and identifying with other devices is commonly referred to as the Internet of Things. Not surprisingly, businesses are looking for ways to harness its power and potential. Unfortunately, hackers are too.

The Internet of Things adds a new security dimension that businesses must consider. A single insecure connection could expose not only sensitive information transmitted by a device, but everything else on a business’s network. Though there isn’t a one-size-fits-all approach, the Federal Trade Commission has identified various security measures that businesses can generally adopt to help minimize the risks created by the Internet of Things.

Encourage a culture of security. Designate senior executives who are responsible for security. Since most security breaches are avoidable, train staff to recognize and report vulnerabilities. Address security expectations and requirements in contracts with service providers.

Adopt a risk-based approach. Direct attention and allocate resources to protect network connections that are most vulnerable and sensitive information.

Consider (and reconsider) the need to collect or retain sensitive information. Steps must be taken to protect sensitive information that is collected and retained out of business necessity. Unnecessary sensitive information should not be collected or retained at all.

Manage passwords.Implement an effective way to manage passwords. Do not rely on default passwords.

Take advantage of readily available security tools.There’s a tool out there for a number of basic security testing tasks, such as scanning networks for open ports, reverse engineering of programming code or decompiling, checking password strength and scanning for known vulnerabilities. Many of these tools are free, and some of them work automatically.

Protect interfaces between devices and servers. Weaknesses are often found at the point where a device communicates with servers. The interface between a mobile device and the cloud, for example, could create an opening for hackers to access an entire network. There are a number of ways to test entry points for weaknesses. “Fuzzing” is a method that sends a device or system unexpected input data to detect possible defects. Businesses should use manual and automated tools to test interfaces.

Limit permissions. Access to sensitive information should be limited to only those who actually need it. Limiting access to the lowest level that will allow for normal functioning is known as the principle of least privilege. To maximize effectiveness, permission limits must strike a balance between utility and security.

Utilize encryption. Standard encryption techniques are available to protect sensitive data that is stored on devices and transmitted to networks. Not all encryption is created equal, so stronger encryption methods should be selected over weaker ones.

Emphasize authentication. Security starts by making sure people are who they say they are. The importance of proper authentication has magnified the Internet of Things. An authentication failure involving a single connected device could expose the entire network to which the device connected. Depending on the nature of a business or its sensitive information, additional authentication measures may be necessary. For example, a two-factor authentication process that requires a password and a secure token.

Finally, businesses must remember that data security is a dynamic process that requires constant attention and frequent adjustments. Since hackers are constantly adapting, so must security measures. Nevertheless, it’s impossible to protect against every cyber threat or prevent every data breach, so business should seriously consider Cyber Liability Insurance. Unlike traditional business insurance policies, Cyber Liability and Security Breach (Cyber Perils) Insurance policies protect against privacy injuries, such as identity theft, and cover the cost of complying with data breach notice laws.

Given the complexity of the risk and the absence of one-size-fits-all coverage, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. Please contact us if you would like more information about insurance specifically designed to protect against cyber threats.

Additional information is also available in our weekly Risk Management Newsletters.

Want to Get Away This Summer? Your Local Burglars Hope You Will

Are you planning a summer getaway? The American Automobile Association reports that over half of U.S. drivers are planning a road trip this summer. With over 650 million long distance trips made each year between Memorial and Labor Day, many of us are looking forward to some much needed time away. Unfortunately, so are robbers and thieves.

According to the Department of Justice, rates of household larceny and burglary are highest during the summer. To avoid becoming a statistic, summer vacation preparations must include preventative measures to protect your home. Here are some simple and effective ways to secure your home while you are away, many of which take only minutes to complete.

  1. Lock and secure all doors and windows. Deadbolt locks make it harder and more time-consuming for someone to break in. Doors with glass panels should be secured with a deadbolt lock that can only be opened with a key from the inside.
  2. Place a pipe or piece of wood in the tracks of sliding glass doors.
  3. Unplug automatic garage door openers.
  4. Ask the post office to hold your mail or have a friend or neighbor pick it up everyday.
  5. Use automatic timers to turn lights, TVs and radios on and off at appropriate times of the day. Lights that are always off (or on) make it obvious that no one is home.
  6. Hire a landscaper to tend to the lawn while you are away.
  7. Have a trusted neighbor park in front of you house.
  8. ‘Case’ your home from the street like a potential burglar might to identify potential weaknesses and to make sure valuables are not plainly visible.
  9. Let trusted neighbors know that you will be away and ask them to keep an eye out for any suspicious activity.
  10. Remove the spare key you have hidden outside your home.
  11. Depending on the size of your city or town, consider notifying the police if you’re going to be gone for longer than a week.
  12. Turn off and disconnect your computer from the Internet. In case your computer gets stolen, use security features to make it difficult for thieves to access any personal or sensitive data stored on the device.
  13. Lock away (or at least hide) valuables .
  14. Have someone pick up the newspaper or any other items delivered to your house.
  15. Have someone put trash containers out for pick-up and bring them back again.
  16. Activate your home security system. Make sure the alarm is functioning and that authorities are immediately notified if someone breaks in.
  17. Bring valuable outdoor items indoors.
  18. Lock and secure cars, recreational vehicles and boats.
  19. Tell only people you trust that you are going away.
  20. Think twice before posting vacation pictures on Facebook, Twitter or other social media sites.

Vacations are supposed to be fun, relaxing and carefree, which is why we spend so much time preparing for our time away from home. Since all vacations must end, time should also be spent preparing for our return home. After all, nothing erases pleasant vacation memories faster than returning to a burglarized home.

Please contact us to discuss whether your insurance can protect you while you are away.

To receive regular updates about developments which may affect your business, subscribe to Setnor Byer Insurance &Risk’s weekly risk management news brief.