*For Cybersecurity Awareness Month, we have a guest blogger. Meet Alice Amiable, your friendly, local Cybersecurity lady. This month, Alice will give some very basic answers to a few questions about Cybersecurity.

 

Q: From Brian: “How can I easily recognize a malicious email before I accidentally open it?”

 

A: Well Brian, that’s a good question and the key word to think about here is: “easily”. There is no perfect and easy way to recognize malicious emails or seemingly innocuous emails with a malicious payload since the bad guys are getting so very good at disguising their evil works. You will likely want to smack me for the answer below, good thing I’m a guest blogger!

 

The old ways of recognizing malicious emails were definitely easy: if it’s an address you don’t recognize, the subject line is weird and the preview text your device likely showed you has spelling, grammar and punctuation mistakes…chances were it was malicious and/or just someone phishing. (Phishing: sending a fraudulent communication that appears legit for an endgame of stealing your money, accessing your sensitive data, stealing your login, installing malware on your device or all of the above). I still wonder if that Nigerian Prince really WAS going to send me half of his 25 billion dollar inheritance. If only I’d written him back and given him my bank info! NOT REALLY. That was one of the more famous phishing scams and probably still is bouncing around out there. I’m fairly certain the Canadian law-firm who is holding my 20 million dollar inheritance in trust until I promise to pay their fees is totally legit. Not so much. These two examples are easy to spot. No savvy Nigerian Oba would ever try to pull such nonsense and no legitimate Canadian law-firm is going to send emails, letters and faxes to everyone with a particular last name and offer them money for money.

 

So…here are some very broad suggestions since every email application and web application for checking email are different:

  • Slow down slightly: actually read the address of the sender before you open the message.
  • If it looks weird, it likely is. Don’t open it. Most devices give you 2-4 lines of preview. Scan the preview and if it looks weird, it likely is. Don’t open it.

 

Learn what settings you can change in your email applications. There are filters you can enable that will be helpful in sending the bad stuff to your spam folder or even block it completely. Be careful changing these settings though as you can lock out senders you actually DO want to hear from if you’re not careful.

 

If you DO open a message that looked legitimate but once you read it you have suspicions that it is NOT, learn how to “View Full Headers”. (I hate telling you that Brian, but it really is different for every different way of checking email). If you see something in the gobbledygook that is the “Full Header” for instance: an email address that is different from the one you first saw, or you see “.ru” or “.cn” somewhere, if you do not have friends/family or colleagues in Russia or China (two countries that are notorious for their state-sponsored hacking and other things offensive to Cybersecurity Pros and White-Hats. I’m not picking on them without reason here), with whom you regularly communicate, block that sender and run your anti-virus application that of course, you update religiously.

 

If you accidentally open a weird one AND accidentally click an attachment or link before you realize it’s likely a malicious message (kind of hard to do but it can happen)…at home: disconnect the device from the internet immediately; take a screenshot of whatever is going on (save it in case of more trouble later) and then shut down whatever the link opened ASAP; close the attachment ASAP. Run your anti-virus application and also, pay close attention to the way your device behaves after your little accidental opening. If your machine is running slow and your fans are running full blast; files are moving around when you did not move them; if family and friends start contacting you through other channels and wondering why you sent them that “Best Gifts Superstore We Made This List For You We Ship Fast” link or the picture of a burly dude sitting on a tank eating caviar and blini, contact a professional. OR: assuming you have a clean (you backed it up before the incident) backup stored on some sort of external media that has not been connected to your device post incident, completely erase the device and start over. Next, contact your email provider and tell them your address was compromised and ask for mitigation to the problem. That should get you on the road to “good”. If after all that, your device is still misbehaving, contact a cybersecurity pro (this is why you snapped that screenshot, it could be helpful in diagnosing just what the problem is). The bad nasty out there being flung by bad actors is getting more persistent and harder to eradicate, sometimes you may need little outside help.

 

If something bizarre happens after opening an odd email at work: disconnect your computer from the internet (pull the ethernet cable carefully out of your machine or turn off your Wi-Fi) and call your help desk pronto!

 

Dear Brian, I hope I haven’t irritated you beyond belief with this answer that doesn’t really seem like an answer. Trust your gut, if it looks weird, it probably is. If the weird looking one is legitimate and the sender really wants you to get the message, they will send it again and/or send it through another channel as well.

 

*Alice Avatar made with an iPhone 

Pin It on Pinterest