{"id":70920,"date":"2024-01-12T14:49:26","date_gmt":"2024-01-12T21:49:26","guid":{"rendered":"https:\/\/in.nau.edu\/news\/?p=70920"},"modified":"2024-01-12T14:53:51","modified_gmt":"2024-01-12T21:53:51","slug":"rise-in-modern-cybersecurity-risks","status":"publish","type":"post","link":"https:\/\/in.nau.edu\/news\/rise-in-modern-cybersecurity-risks\/","title":{"rendered":"Are you prepared for the rise in modern cybersecurity risks?"},"content":{"rendered":"<p><span data-contrast=\"auto\">A new wave of cybersecurity risks is threatening the NAU community\u2019s personal, academic and professional lives.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">A new AI-based phone scam is being reported at NAU in increasingly large numbers, and ITS is encouraging the NAU community to be aware of this threat so they can identify the warning signs and respond appropriately before being scammed.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">These attacks\u00a0use AI to clone an individual\u2019s voice from a short audio clip of an individual speaking. These audio clips can be garnered from content posted publicly online such as on YouTube, TikTok or Instagram, or by recording the individual while having them respond to questions on a fake call. NAU is monitoring a recent rise in malicious phone calls around campus.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">These phone-based AI scams may take multiple forms and present a danger to you and those around you, who may receive calls and think you are in danger or in need of help. These scams normally use pressure tactics such as urgency, desperation, fear, punishment or financial repercussions if you do not act immediately. If you believe at any point during a call that you are not actually talking to the person who identified themselves, <\/span><b><span data-contrast=\"auto\">hang<\/span><\/b><b><span data-contrast=\"auto\"> up <\/span><\/b><b><span data-contrast=\"auto\">and call them back on a number that you <\/span><\/b><b><span data-contrast=\"auto\">know<\/span><\/b><span data-contrast=\"auto\">, or the main number listed on their official website if you are interacting with a business. Never call the person or company back from a number that they provide over the phone or via email.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<h2><b><span data-contrast=\"auto\">How is NAU affected?<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">NAU sees many forms of phishing and email attacks targeting both students and employees. Every year at this time, we see an elevated number of job-related, W-2 and tax scams, as well as other time-sensitive scams seeking personal information and threatening financial repercussions.\u00a0<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">People fall victim to these scams for a number of reasons. Many individuals do not believe they personally have anything to lose, are too busy or too stressed to recognize the warning signs or feel scared and pressured into responding to the malicious entity. If a malicious entity accesses your account, an attacker can possibly access your personal data, steal your paycheck, access your bank account, attack other systems impersonating you, and steal the personal information of students and other staff members at the university. <\/span><b><span data-contrast=\"auto\">Because of the danger presented by responding to these types of scams by clicking on false links, replying to attackers or providing information to a malicious entity, NAU must take a strong stance and suspend your NAU account immediately to protect you, as well as the rest of the campus community.<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In December, more than 257,000 malicious, phishing or threatening emails were blocked or removed from NAU email accounts. Last year, 318 campus community members had their passwords secured after responding to malicious entities, and 358 individuals were required to reset their Two-Step Verification after allowing a malicious or unauthorized entity into their NAU account. This represents only a small portion of threats that the university faces daily. <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">At this time, approximately 10 percent of campus community members do not successfully decipher phishing emails and, with the rise of Artificial Intelligence (AI), attacks are rapidly evolving and putting you at even more risk. While NAU is constantly working on improving our security practices, introducing new security features and updating policies to better protect both you as an individual and the campus community, your vigilance is our greatest defense.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Some of the most prolific cyber threats that plague our campus include:<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Phishing and social engineering: Deceptive attempts to manipulate individuals into revealing confidential or sensitive information through fake emails, phone calls, text messages and in-person communication.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Two-Step\/Multi-Factor Authentication (MFA)\/DUO Spamming: Attempts to bombard or overwhelm an individual with MFA notifications, causing fatigue and ultimately an MFA prompt approval.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">Malware and ransomware: Malicious software attacks that infect systems stealing information, slowing down systems, or locking files until a ransom is paid.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">AI phone scams\/deepfakes: Automated calls using artificial intelligence to impersonate real people or organizations.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"1\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"5\" data-aria-level=\"1\"><span data-contrast=\"auto\">Zero-day exploits: Vulnerabilities in software and operating systems that may allow malicious entities the remote ability to install malware, steal data or otherwise disrupt the operation of a system.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\">Accounts compromised by one of these phishing attacks can be leveraged by malicious entities to attack more individuals across campus and the university system.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<h2><span data-contrast=\"auto\">Top 11 recommendations to improve cybersecurity:<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/h2>\n<ol>\n<li><b><span data-contrast=\"auto\">Password strength and reuse: <\/span><\/b><b><span data-contrast=\"auto\">STOP<\/span><\/b> <span data-contrast=\"auto\">reusing passwords or password patterns across multiple sites or applications, especially for financial institutions. The reuse of passwords and password patterns significantly decreases the security of any account. It is highly recommended that all individuals consider the use of a password manager to store unique passwords and avoid reutilization of passwords. Do not use weak passwords that rely on knowledge-based information, such as names of your pets, hometowns or graduation years. Longer passwords will remain more secure over time.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Two-Step and Multifactor Authentication (MFA):<\/span><\/b><span data-contrast=\"auto\"> MFA is like having a deadbolt on your front door. Enable it on all accounts that support it. <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Apply updates:<\/span><\/b><span data-contrast=\"auto\"> WUpdates are critical for your safety and security. No person, company or entity is perfect, so why would your software be? Updates are deployed because the software isn\u2019t perfect, but we can make our systems better and more secure by running the most up-to-date systems.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Don\u2019t use debit cards for online shopping:<\/span><\/b><span data-contrast=\"auto\"> Debit cards are a great convenience to much of the world, including attackers. As debit cards pull from available funds in accounts, there is inherent risk if an online retailer is ever compromised. Although many debit cards are backed with either zero liability or limited liability for prompt reporters, most will not cover overdraft charges, and it may take several days to recuperate any funds that were originally in the account.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Phone numbers:<\/span><\/b><span data-contrast=\"auto\"> Guard your phone number like a secret code. Avoid sharing it in emails or phone calls, especially if they seem suspicious. Instead of responding to unsolicited requests, look up official contact numbers from the company or organization&#8217;s official website. This ensures you are contacting the right people and not falling into a phone-based trap set by scammers.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Report suspicious calls and emails:<\/span><\/b><span data-contrast=\"auto\"> Be a digital detective. If you receive a call or email that smells phishy, report it. Your instincts are your best weapon against scams.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Do not open unrequested documents:<\/span><\/b><span data-contrast=\"auto\"> Treat unsolicited documents like mystery packages. If you didn&#8217;t ask for them, don&#8217;t open them. Attachments and links in unexpected emails might be a Pandora&#8217;s box, releasing malware or phishing attempts. Stay safe by only opening files from trusted sources.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Use ad blockers:<\/span><\/b><span data-contrast=\"auto\"> Ad blockers act as your personal bouncer, keeping malicious ads at bay. By blocking pop-ups and potential threats, they add an extra layer of protection while you surf the web.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Be careful what you post publicly:<\/span><\/b><span data-contrast=\"auto\"> Think of your online posts like a megaphone in a crowded square. Whatever you say is heard by many, including those with ill intentions. Be mindful of sharing personal details, travel plans or financial information publicly. Be cautious about filling out the fun online quizzes that might reveal personal information like the year you graduated from high school, your first vehicle, where you grew up, your favorite color and more, as these questions can be used for many account recovery questions or security questions elsewhere. <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Remove personally identifiable information from the Internet:<\/span><\/b><span data-contrast=\"auto\"> Think of personal information online like gold. Minimize the treasure map for cyber pirates by removing unnecessary personal details. Check your social media profiles and other online accounts to ensure you&#8217;re not unintentionally broadcasting sensitive information.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Do your research:<\/span><\/b><span data-contrast=\"auto\"> Before diving into the digital deep end, play detective. Research websites, products or offers before engaging. Check reviews, look for red flags, make informed decisions and if it sounds too good to be true, it likely is. It&#8217;s like navigating a new city\u2013know where you&#8217;re going before walking out the door.<\/span><\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p><a class=\"search-results-excerpt-link\" href=\"https:\/\/in.nau.edu\/news\/rise-in-modern-cybersecurity-risks\/\">A new wave of cybersecurity risks is threatening the NAU community\u2019s personal, academic and professional lives.\u00a0\u00a0 A new AI-based phone scam is being reported at NAU in increasingly large numbers, and ITS is encouraging the NAU community to be aware of this threat so they can identify the warning signs and respond appropriately before being&hellip;<\/a><\/p>\n","protected":false},"author":51,"featured_media":70921,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4],"tags":[],"class_list":["post-70920","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-campus-community"],"acf":[],"_links":{"self":[{"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/posts\/70920","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/comments?post=70920"}],"version-history":[{"count":0,"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/posts\/70920\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/media\/70921"}],"wp:attachment":[{"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/media?parent=70920"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/categories?post=70920"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/in.nau.edu\/news\/wp-json\/wp\/v2\/tags?post=70920"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}