Tech Insight : How to Avoid Being “Doxxed”

In this article, we look at what doxxing is, some examples of doxxing, and what can be done to protect ourselves and our businesses from being ‘Doxxed’.

What Is Doxxing?

Doxing is a 90s hacker term meaning for dropping (personal) dox where ‘dox’ is a slang term for documents. Doxxing is a malicious act where a person/persons use a variety of methods to find previously private personal information about an individual or organisation, and then publicly reveal/expose that information to all, usually over the Internet. The type of information released could be anything from simple personal details (real name, home address, workplace), to much more personal, embarrassing, and damaging information.

Why?

Doxxing is used as a method of attack, primarily for punishment or revenge and can lead to acts of extortion.

What Details?

The kind of personal details and information that doxxers may collect about a person, business, or organisation may include name, telephone number, address, personal photographs, videos, comments and quotes, email content, account numbers, and more.

Where From?

Doxxers can collect different snippets of information about their targets from a number of sources including hacks, social engineering, social media accounts, getting access to a target’s email account, WHOIS lookups, using an IP logger to trace online activities, reverse mobile phone lookup, tracking usernames, using GDPR  subject access requests, collecting information that has been sold across the Web by data brokers, accessing details from hacks/sold hacked details, and more.

Is It Illegal?

Although doxxing is malicious and can be very harmful, it is generally not illegal because much of the information is gathered from what is considered as the public domain. However, the legality also depends upon whether details were obtained using legal methods, and doxxing treads a fine line between what is legal and not, sometimes entering into the illegal worlds of stalking, harassment, and more. If the threat of doxxing is used to extort money then this is, of course, blackmail. In many cases, at the very least, doxxing often violates many websites’ terms of service.

Some Examples of Doxing

Just some of the many examples of doxing that have made the news include:

– December 2011 – the hacking group Anonymous exposed detailed information online about 7,000 law enforcement agents as revenge for investigations into hacking activities.

– In 2013, hackers posted Kim Kardashian’s Social Security number, credit report, address (+ six previous addresses) online.

– In 2016, while Donald Trump was campaigning for the US presidency, Anonymous posted his Social Security number and phone number, as well as the contact information for his agent and lawyer online.

– In 2017, the Russian (Moscow) hacker group Turla hacked the Instagram account of Britney Spears, and used it to post secret, cryptic comments.

How To Protect Yourself and Your Business From Being Doxxed

Some of the measures you can take to help protect yourself/your business from falling victim to doxxing include:

– Using a VPN to protect your IP address.

– Using strong passwords, avoiding password sharing, and using 2FA or multi-factor authentication where possible.

Keeping anti-virus software and patches up to date and installing antimalware to combat doxware.

Removing personal data from apps, and from gadget/device settings.

– Setting up different email addresses for different uses e.g., professional, personal, and spam.

– Maximising your social media privacy settings and being careful what is shared i.e., bearing in mind GDPR, consent, personal details and privacy matters when sharing anything relating to staff.

– Hiding domain registration information from WHOIS.

Avoiding logging into a website through Facebook or Google.

– Asking Google to remove any personal information that you are concerned about.

– Keeping up with good general online security practices and be careful what information you share via social media.

– Deleting old online accounts.

– Using the legislation available to tackle doxxers. For example, Hong Kong introduced a new anti-doxing law in October 2021 (The Personal Data (Privacy) (Amendment) Ordinance 2021), mainly to prevent details of members of the authorities from being posted online and, perhaps, to crack down on criticism. The law could, however, be used by citizens and businesses to combat malicious doxxing acts. The law amendment gives Hong Kong’s Privacy Commissioner for Personal Data the right to conduct criminal investigations and institute prosecution related to doxxing. Also, under UK GDPR, persons have the ‘right to be forgotten’ i.e., requesting that a business/organisation removes/deletes all data collected about them.

– For businesses – keeping an up-to-date record of processing activities, showing what data is being collected, where it’s stored, for how long, and who is being/has been shared with.

– Keeping levels of awareness and training about data protection, privacy, and threats like doxxing up to date among staff.

– Checking/monitoring compliance relating to contracts with third parties processing personal data on your/the company’s behalf.

– Using websites to help erase data about you stored around the Web / opting out of people searches. Examples (including U.S.), include https://www.beenverified.com/app/optout/searchhttps://www.instantcheckmate.com/opt-out/https://www.gov.uk/government/publications/register-to-vote-anonymously, opting out of the top 10 data brokers – https://databrokerswatch.org/top-tenhttps://joindeleteme.com/.

What Does This Mean For Your Business?

The main motives for doxxing appears to be revenge, control, or even as a way to blackmail someone. Following good general online security practices and policies is the best way to avoid giving people (e.g., disgruntled former employees/customers, hackers and others) the fuel and the openings they need to build their campaigns. Sadly, much of our data ends up being shared around the Web, perhaps to places we wouldn’t expect to go and determined doxxers may be able to find some things, despite our best efforts to maintain our privacy. That said, as highlighted in the list above there are still many proactive measures that can be taken to reduce the risk of being doxed.

Tech News : Google Changes Stance Over Legacy G Suite Account

Google has offered new alternative options to free Legacy G Suite account holders who it had previously said would have to upgrade to a paid subscription by 1 July.

What Is A Legacy G Suite Account?

Google’s free edition of G Suite, known as Workspace, was first made available to businesses, organisations, and schools from 2006 to December 6, 2012, with Google Apps. Users of this free edition of G Suite—also known as the legacy free edition could host Google accounts on custom domains for multiple users. However, this free version gave users a much-reduced set of business features.

Move To Paid Subscription

Recently however, Google informed users, who had been allowed to keep their free accounts for 10 years, that they needed to either upgrade to a paid Google Workspace subscription service to keep their services by July 1, 2022, or export their data using Google’s Takeout tool.

Backtrack – New Option

Last week, however, Google emailed users with details of a new option (also now shown on Google’s Support pages). The main new alternative is that users who don’t want to upgrade to a paid subscription will be offered a better data transfer option “in the coming months.” This new option will enable users to move their non-Google Workspace paid content and most of their data to a no-cost option. The new option won’t include premium features like custom email or multi-account management, and users will be able to evaluate the option prior to July 1, 2022, and prior to account suspension.

Another Lifeline

Google also appears to be offering another lifeline to those who have a G Suite legacy free edition account that’s purely for personal use and who don’t want to upgrade to a Google Workspace subscription. Google has invited these account holders (with ten users or less) to use a feedback form to provide more information. Google says that if they don’t want to upgrade to Google Workspace, they will still be allowed to keep their access to additional Google services (YouTube, Photos, Maps, Pay, Books etc) and any paid content purchased through non-Google Workspace services made with their legacy account e.g., any movies purchased on Google Play.

What Does This Mean For Your Business?

It appears Google’s first announcement of a deadline to either start paying by July or export your data out may have ruffled a few feathers and highlighted some of the different needs of Legacy G Suite account holders who may require a bit more help, including the fact that some people have content they’ve purchased through Google that they don’t want to lose. Although Legacy G Suite account holders are likely to appreciate that they enjoyed 10 years for free, they may also have assumed that Google would continue to take the same generous approach when the time for change approached rather than essentially being emailed with a deadline. For Google, it’s at least been a way to get the attention of account holders and help funnel users towards Google’s aim of ramping up its ‘Workspace’ to create something that Google hopes will seriously challenge Microsoft’s Office/365 dominance.

Tech Tip – An Easy Way To Transcribe Your YouTube Videos

If you’d like an easy way to get a text transcript of your YouTube videos, try using YouTube’s built-in transcript tool. Here’s how:

– Log in to YouTube and go to YouTube Studio.

– Select Subtitles from the sidebar (left).

– Select a video, choose the language, and click on ‘Confirm’.

– To edit the text transcript that appears on the screen, select ‘DUPLICATE AND EDIT’ (right-hand side).

– Edit the transcription in the dialog box and click on the ‘PUBLISH’ button.

– The transcript will be lowercase and lacking punctuation so this will need to edited and amended manually.

Tech News : UK Government ‘Help to Grow’ Scheme : Software And Free Business Advice

The UK government has just announced the launch of its ‘Help to Grow’ digital scheme which offers discounted software and free advice to small businesses.

Applications Open Now

The Help to Grow scheme is designed to support smaller businesses in adopting digital technologies to help them to grow. Applications for the scheme opened on 20 January.

Free Advice and Online Support

The scheme offers access to free, impartial online support and advice about how digital technology can boost a business’s performance. The support and advice can be accessed via Help to Grow’s online platform here: https://helptogrow.campaign.gov.uk/

Discounted Software

Eligible business in any business sector can also access a discount of up to 50 per cent towards the costs of buying approved software (from a group of approved suppliers), worth up to £5,000.

The 4 criteria for eligibility for the discount are:

  1. Businesses must be based in the UK and registered with Companies House or be a registered society on the Financial Conduct Authorities Mutuals Register.
  2. Employing between 5 and 249 people.
  3. Actively trading for more than 12 months and having an incorporation date of at least 365 days prior to application.
  4. Businesses must be purchasing the approved software for the first time.

Currently Just For CRM And Digital Accounting Software

Each eligible business can receive only one financial discount towards the purchase of one approved software product up to a maximum of £5,000 (not including VAT) in the Customer Relationship Management (CRM) and Digital Accounting software product categories. The government says that other software product categories will be available with the discount soon, including e-commerce software. The discount will cover 12 months’ worth of approved software product core costs, exclusive of VAT.

What Approved Software?

At this opening stage of the scheme, the approved CRM software suppliers whose products the discount applies to are Capsule CRM, Zymplify, Livepoint Software Solutions Ltd, Gold-Vision CRM, and Deskpro Ltd. The suppliers of the digital accounting software that the discount applies to are Sage, Intuit Ltd, and Crunch.

FSB and CBI

Mike Cherry, National Chair at the Federation of Small Businesses, said of the scheme: “For those small firms who are eligible, providing the means to make improvements through projects like this will make a real difference for those that are keen to expand their knowledge and skills.”

“We’re encouraging as many eligible small firms to apply and make the most of this new scheme.”

Also, Lord Karan Bilimoria, President of the CBI, said: “The launch of Help to Grow digital will help thousands of SME businesses invest in technologies. Supporting businesses on their digital transformation journey is fundamental to unlocking economic growth, boosting productivity, and creating a more resilient future for firms.”

Help to Grow: Management Scheme

The government already offers a ‘Help to Grow: Management’ scheme launched in 2021 as part of the wider government effort to back businesses and ‘level up’ the economy.

Under the ‘Help to Grow: Management’ scheme, small businesses can access 12-weeks of learning designed to fit alongside work commitments. The scheme can help businesses to develop a bespoke business growth plan, access 1:1 support from a business mentor, and learn from peers and network with other businesses. The scheme is 90 per cent funded by the government and participating businesses only need to pay £750. More information is available here: https://smallbusinesscharter.org/help-to-grow-management/

What Does This Mean For Your Business?

The last two years have created an extremely tough business environment, particularly for small businesses and businesses from all sectors have been forced to undergo a rapid digital transformation and associated learning (and cost) curve. Tools like CRMs can be costly to small businesses, but their use can really improve efficiency and productivity. For example, Enterprise Research Centre (ERC) figures show that businesses who use CRMs see on average productivity boosts of 18 per cent, so a its possible to see how a big discount on (approved) CRM software could help with growth. Also, ERC figures show that businesses adopting digital accounting software can get an 11.8 per cent increase in employee sales over 3 years. Discounts on this type of software could also provide an extra means for small businesses to increase growth. Free help, such as that offered via the Help to Grow portal, as long as it has real value, is bound to be welcomed by small businesses at this time. The biggest help right now would, of course, be greater certainty and a real improvement globally in the COVID situation, but the government scheme is one of many small ways that eligible businesses could improve growth in the coming years. The relatively small choice of approved suppliers and software types in the current round of the scheme, however, may not suit many small businesses right now, meaning that they may need to wait longer for any value and benefit.

Tech News : Google Gives Upgrade Deadline For Legacy G Suite Accounts

Google has announced in an email that users with legacy (old) free G Suite accounts have until 1 July to upgrade to paid subscriptions or lose access to most services.

Ten Years Free

Google has said that legacy G Suite users i.e., those who have been able to use their custom domain accounts for free for ten years, must upgrade to a paid Google Workspace subscription to keep their services by July 1, 2022. The G Suite legacy free edition will no longer be available starting from that date.

Google also says on its support site that, even if users choose to wait, Google will begin upgrading subscriptions automatically on May 1, 2022. This will mean that an organisation’s account will be upgraded to a new Google Workspace subscription based on the features that the organisation currently uses.

Setting Up Billing Required

Google is, therefore, asking Legacy G Suite account holders to set up Google Workspace billing before July 1, 2022, or the Google Workspace subscription will be suspended until this is set up. If users still haven’t set up their billing account for Workspace after 60 days, Google says that those users will no longer have access to Google Workspace core services, such as Gmail, Calendar, and Meet.

What Is The Legacy Free G Suite Account?

Google’s free edition was first made available to businesses, organisations, and schools from 2006 to December 6, 2012, with Google Apps. The free edition of G Suite—also known as the legacy free edition of Google Apps— gave users a reduced set of business features.

What Is Google Workspace?

Google Workspace, introduced in 2020 as part of a new brand identity, is Google’s cloud-based, collaborative working platform. Workspace, Google’s answer to competing products like Microsoft 365 with its ‘Teams’ app (and competitors like Zoom), is where its productivity apps (Gmail, Calendar, Drive, Docs, Sheets, Slides, Meet, and more), and core communication and collaboration tools (chat, email, voice and video calling, content management) are grouped together. Workspace gained huge popularity during the pandemic lockdowns when demand surged for cloud-based platforms that enabled remote and hybrid working. Google Cloud claims that Workspace now has more than 3 billion active monthly users!

How Much Will It Cost To Upgrade To A Google Workspace Account?

The basic Business Starter subscription costs £4.60 per user per month (currently discounted to £4.14) and offers 30 GB of Drive storage, 99.9 per cent uptime guaranteed, and increased security. Users can also bolt-on extra subscriptions as required e.g., Google Voice to get a dedicated business phone number. Business Standard, and Business Plus packages are also available. The packages can be compared at https://workspace.google.com/intl/en_uk/pricing.html

What Does This Mean For Your Business?

Google’s argument for the need to upgrade appears to be that legacy suite account holders should be pleased that they had 10 years for free, and that the legacy version never offered benefits like the Workspace platform does anyway e.g., 24/7 support, 99.9 per cent uptime and more storage. For Google, the introduction of Workspace would be a way to seriously challenge Microsoft’s Office/365 dominance and, as Javier Soltero, the VP of Google Workspace claimed in late 2020, “This is the end of the ‘office’ as we know it.” Google reported “strong” revenue growth for Workspace in its third-quarter results (October) indicating that it is a popular subscription. For those users who have enjoyed the legacy, an upgrade is clearly an additional cost, but there may be additional valued benefits. Those who don’t want to upgrade “may” still be able to keep YouTube and Google Photos, but Google clearly wants to strongly encourage users to at least take up a basic subscription as soon as possible.

Tech Insight : What Is A ‘Watering Hole’ Attack?

In this tech insight, we look at what a watering hole attack is, some examples of such attacks, and how businesses can defend against this threat.

Poisoning The Water

A watering hole attack is a targeted, ‘supply chain,’ cyber-attack strategy, similar to spear phishing. With this strategy, the attacker identifies a website that’s frequented by users of a targeted organisation, or entire sector. The attacker then infects the website(s) with malware and identifies weaknesses in the main target’s cyber-security. The attacker then manipulates the ‘watering hole’ site to deliver that malware, such as a Remote Access Trojan (RAT), so that it can exploit these weaknesses.
When a member of the target organisation’s device becomes infected (like drinking from a poisoned watering hole, hence the name) in a way that the target will not notice (also known as ‘drive by’), the attacker can then gain access to the infected device. This can, in turn, enable the attacker to access the target organisation’s network

Stealing and Spying

The goal(s) of this strategy, as with other strategies is/are to steal personal information, banking details, and intellectual property, and/or to conduct espionage. Also, it can enable the attacker to access corporate systems and assets, and potentially gain further details for even more cyber-attacks.

Examples

Examples of watering hole attacks include:

– The VOHO multi-phase Campaign. Back in 2012, attackers compromised a local government website in Maryland and a regional bank in Massachusetts, along with other sites related to the promotion of democracy in oppressed regions. The targets were organisations related to financial services, government agencies, and the defence industry, and the attack involved the use of re-directs and infection by Gh0st RAT malware. The attack saw 32,000 visitors from 731 unique global organisations being re-directed to an exploit site where around 4,000 hosts are believed to have downloaded exploit files, leading to a staggering 12 percent success rate for the attackers.

– From 2017 to 2018, a country-level watering-hole attack was launched in China by the “LuckyMouse”/ “Iron Tiger” group. This espionage campaign was reported to have targeted a national data centre of an unnamed central Asian country. The attackers injected malicious JavaScript code into the official government websites.

– The 2019 ‘Holy Water’ attack targeted Asian religious and charity groups. The attackers used an Adobe Flash update prompt to trigger the malware download. Although the motive was unclear, the attack may have been used for espionage.

How To Protect Your Business From Watering Hole Attacks

Ways that you can protect your business from watering hole attacks include:

– Keep anti-virus and software patches up to date.

– Use browser-based security tools to inform users of bad sites (bad reputation) and extra malware protection.

– Have a good email protection solution and consider using a secure web gateway (SWG) to filter out suspect traffic.

– Regularly inspect and monitor websites that are most visited by employees with a focus on malware detection. Also, have a procedure in place to quickly inform employees not to visit sites that have been identified as compromised.

– Check traffic from all third party and external sites before allowing employee access.

– Assess, know, and control the full extent of your supply chain (a watering hole attack is a supply chain attack).

– Educate/inform and train employees about the nature of the threat and how to avoid it.

– Never click on unknown/suspect links in emails or websites and exercise caution at all times when browsing.

– Consider adopting a ‘zero trust ‘security approach for the business/organisation.

What Does This Mean For Your Business?

This is broadly a supply-chain related attack (web resources) where instead of actively hacking or sending phishing emails, the criminals set traps for unsuspecting victims to walk into. In this respect, it is less obvious for businesses to spot. The first step is recognising and raising awareness of the threat. Following normal security good practice is always helpful plus some additional measures in this case such as identifying, regularly inspecting and monitoring websites that are most visited by employees and focusing on what additional malware protection can be added to employees’ browsers and devices. With an increasing number of more complex and inventive attack methods, many businesses are shifting to a complete ‘Zero Trust’ approach for their IT security. A more a data-centred rather than ‘moat and castle’ view of IT security gives companies greater holistic control and reduces the potential for the kind of gaps that cyber criminals can exploit with strategies like watering hole attacks.

Each week we bring you the latest tech news and tips that may relate to your business, re-written in an techy free style. 

Archives