Document text
Cyber threats unprecedented, exec says Jenny Menna Monday Jan 9, 2017 at 5:11 PM Jan 9, 2017 at 5:33 PM Greg Stiles Mail Tribune @GregMTBusiness Everyone knows cyber-criminals pose a multitude of threats. Some of the dangers are personal, some corporate and others are national. U.S. Bank Cybersecurity Partnership Executive Jenny Menna told a Chamber Forum audience Monday that businesses are in an unprecedented cyber-threat landscape, thanks to the ubiquitous use of laptops and smartphones. "It changes the risk for the company in that how do we know that you are you when accessing the network?" Menna said. It's one thing walking around an office and spotting someone who doesn't belong at a cubicle, she said. "But how do we know who is calling in and out? What sort of risks are posed?" Everything from refrigerators and televisions to automobiles are wired to the internet, and all the connections are vulnerable. "There are a lot of bad actors out there," ranging from insiders and fraudsters to "hacktivists" and nation states, Menna said. Fraudsters, she said, have long since eclipsed the international drug trade. "There are also massive criminal syndicates in countries in the former Soviet Union, for example," Menna said. "There may not be great legitimate economic opportunity. There is no extradition to the United States, and there is no social stigma, maybe they kinda like it they're sticking it to the Yankee. They're constantly looking at new and innovative ways to steal money." Hacktivists, she said, range from people angry about the general capitalistic system, such as Occupy and Anonymous, to the Syrian Electronic Army, which doesn't have great capability, but will deface a website or launch a denial-of-service attack. Iran, North Korea, China and Russia are well known for their cyber attacks on American companies in response to U.S. policy or corporate policy or to gain economic advantages. Likewise, phishing ploys have escalated to spear phishing, targeting people based on their interests. Corporate executives are also targets, in what is known as whaling. One CEO-email scam looks like the chief executive is demanding quick action by a CFO, treasurer or accounting office. "There is always a surge of urgency," Menna said. "Somebody is mad, you better send this wire right away, there is a supplier overdue and they're going to cut us off. People think, 'It's an email from the CEO, I'd better do it right away.' The next thing you know, the money is off in Asia or somewhere. Once it gets past a couple hoops, as our banking folks can tell you, we can't get it back. Once it's gone, it's gone." She suggested scrutinizing email addresses to see whether ".com" is ".con" or other typos appear. "Once in a while they've actually gotten into the CEO's email and are sending it out," Menna said. "Ask questions. Which would your CEO rather have happen, for you to call, 'Hey, I got this email, this is not the way we normally interact and do business. Can you verify you sent me this?' Would they rather have that challenge, or would you rather go explain to them, like a large IT company that accidentally sent over $40 million, which is now gone somewhere into the Asian crime syndicate world?" Menna suggested avoiding password reuse. "I know, it's a pain to have those 12-character passwords with exclamation points and numbers and capital letters and remember them for all the websites," she said. "The problem is the bad guys know we are lazy." If you have logged into a less secure site, using the same username and password you use for Amazon, banking or work, it's possible that information may be posted on a criminal forum on the dark web. "Even if they only get one out of 100 as a hit," Menna said, "they've still been successful."  — Reach reporter Greg Stiles at 541-776-4463 or [email protected]. Follow him on Twitter at www.twitter.com/GregMTBusiness, on Facebook at www.facebook.com/greg.stiles.31.