{"id":1309,"date":"2010-11-23T05:57:24","date_gmt":"2010-11-23T13:57:24","guid":{"rendered":"http:\/\/blog.cosaint.net\/?p=1309"},"modified":"2023-09-18T06:32:28","modified_gmt":"2023-09-18T06:32:28","slug":"tis-the-season-for-hoaxes-and-scams","status":"publish","type":"post","link":"https:\/\/www.empowerelearning.com\/blog\/tis-the-season-for-hoaxes-and-scams\/","title":{"rendered":"&#8216;Tis the Season for &#8230; Hoaxes and Scams"},"content":{"rendered":"<p><img decoding=\"async\" class=\"wp-image-1312 size-full alignleft\" title=\"scarecrow\" src=\"https:\/\/www.empowerelearning.com\/blog\/wp-content\/uploads\/2010\/11\/scarecrow.jpg\" alt=\"\" width=\"150\" height=\"150\" srcset=\"https:\/\/www.empowerelearning.com\/blog\/wp-content\/uploads\/2010\/11\/scarecrow.jpg 150w, https:\/\/www.empowerelearning.com\/blog\/wp-content\/uploads\/2010\/11\/scarecrow-100x100.jpg 100w\" sizes=\"(max-width: 150px) 100vw, 150px\" \/>It&#8217;s that time of year again &#8211; when fraudulent and nuisance emails, and online hoaxes and scams start making the rounds even more quickly than usual.<\/p>\n<p>Sophos has posted <a href=\"http:\/\/nakedsecurity.sophos.com\/2010\/11\/22\/christmas-tree-app-virus-hoax-spreads-on-facebook\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">a warning<\/a> about one such hoax spreading rapidly on Facebook where users are warning each other about a &#8220;Christmas Tree&#8221; virus &#8211; said to be carried by a rogue Facebook application. Here&#8217;s a example of the message that&#8217;s being circulated:<\/p>\n<blockquote><p>WARNING!!!!!! &#8230;.. DO NOT USE THE Christmas tree app. on Facebook. Please be advised it will crash your computer. Geek Squad says it&#8217;s one of the WORST trojan-viruses there is and it is spreading quickly. Re-post and let your friends know. THANKS PLEASE REPOST!<\/p><\/blockquote>\n<p>A little research (perhaps a search on a reputable site like <a href=\"http:\/\/www.snopes.com\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Snopes.com<\/a>) would quickly show that <a href=\"http:\/\/www.snopes.com\/computer\/virus\/xmastree.asp\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">this is a hoax<\/a>. But that doesn&#8217;t stop the message being widely distributed by worried Facebook users, and, at this point, the hoax is probably spreading faster than reports of genuine Facebook viruses (maybe because it has an easy-to-remember name rather than the obscure names given to viruses by software companies?).<\/p>\n<p>Even if you&#8217;ve banned the use of Facebook and other social networks, similar hoaxes and scams are likely to be circulating by email in your organization. And they&#8217;re often very disruptive in the business environment if they&#8217;re distributed widely, and can also make it more difficult for you to warn users about real threats that they might face.<\/p>\n<p>So, what should you do?<\/p>\n<p><b>Two Things to Teach Your Staff<\/b><\/p>\n<p><b><i>#1 &#8211; Spotting Hoaxes<\/i><\/b><\/p>\n<p>First and foremost, you should teach your staff how to recognize a suspect email or message. There are some fairly obvious classes of scams and\/or hoaxes such as:<\/p>\n<ol>\n<li>humorous hoaxes &#8211; amusing messages which can clog the email system, but aren&#8217;t generally malicious in intent<\/li>\n<li>chain letters &#8211; generally only intended to clog up the email system, but some carry malicious messages for those who don&#8217;t forward the letters which can cause distress to some users<\/li>\n<li>nuisance hoaxes &#8211; messages intended to worry or scare users but not much more<\/li>\n<li>malicious hoaxes &#8211; messages designed to persuade users to carry out actions that could cause damage &#8211; typically to their PC<\/li>\n<li>scams &#8211; emails or other messages sent with the purpose of financial (or other) gain &#8211; includes phishing, and spear-phishing messages<\/li>\n<\/ol>\n<p>If you want some simple examples of email hoaxes and scams to educate your staff, I&#8217;ve included some taken from Cosaint&#8217;s course on &#8216;Secure Use of Email&#8221; course at the end of this blog post.<\/p>\n<p><b><i>#2 &#8211; How to Respond<\/i><\/b><\/p>\n<p>Once you&#8217;ve taught your staff about some of the signs to look for, you should teach them what you want them to do next. Do you want them to contact your Help Desk with queries, or should they be encouraged to determine for themselves if an email or message is fake and act accordingly?<\/p>\n<p>If the latter, you should provide some suggestions for resources that will help them do this. I usually recommend <a href=\"http:\/\/www.snopes.com\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Snopes.com<\/a> but you might have other sources that you prefer &#8211; let me know if you have any suggestions, and I&#8217;ll add them to the list.<\/p>\n<hr \/>\n<p>The following materials, extracted from emPower&#8217;s &#8216;Secure Use of Email&#8217; course, are being made available to you for use in your own awareness program. Feel free to include them in your email security reminders or newsletters, or use them in staff meetings. If you&#8217;d like to see the original course, which covers this topic and much more, please <a href=\"https:\/\/www.empowerbpo.com\/contact-our-smes\/\" rel=\"nofollow noopener\" target=\"_blank\">contact emPower<\/a>.<\/p>\n<p><b><i>License for Use<\/i><\/b><br \/>\n<i>This work by <a href=\"https:\/\/www.empowerbpo.com\/blog\/\" rel=\"cc:attributionURL nofollow noopener\" target=\"_blank\">emPower, Inc.<\/a> is licensed under a <a href=\"http:\/\/creativecommons.org\/licenses\/by-nc\/3.0\/\" rel=\"license nofollow noopener\" target=\"_blank\">Creative Commons Attribution-NonCommercial 3.0 Unported License<\/a>. Based on a work at <a href=\"https:\/\/www.empowerbpo.com\/blog\/\" rel=\"dct:source nofollow noopener\" target=\"_blank\">emPower blog<\/a><\/i><\/p>\n<p><center><b>SOME EXAMPLES OF EMAIL HOAXES AND SCAMS<\/b><\/center>&nbsp;<\/p>\n<p>Sometimes you&#8217;ll get an e-mail which warns you about a &#8220;virus&#8221;. Or it might alert you to a wonderful &#8220;free offer&#8221;. Most of these hoaxes are designed to scare you and\/or to waste the time of everyone who receives them. But there are some malicious hoaxes which try to persuade you to delete a critical file on your computer. So you do need to be careful.<\/p>\n<p>Remember! The only virus warnings you should pay attention to are those sent by the Help Desk and even these should not be forwarded. So, don&#8217;t spread hoaxes. If you&#8217;re not sure whether a warning is real, ask the Help Desk.<\/p>\n<p><b>Example 1 &#8211; A Humorous Hoax &#8211; The Work Virus<\/b><\/p>\n<p>This is an example of a humorous hoax. While it&#8217;s too obviously false to worry people, we don&#8217;t recommend that you forward it to your entire email address book since it only serves to clog up email systems.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1337 size-full\" title=\"sshot_work\" src=\"https:\/\/www.empowerelearning.com\/blog\/wp-content\/uploads\/2010\/11\/sshot_work.gif\" alt=\"\" width=\"440\" height=\"600\" \/><\/p>\n<p><b>Example 2 &#8211; Another Humorous Hoax &#8211; Bad Times<\/b><\/p>\n<p>This is an example of a humorous hoax. There are various versions but all are very obviously fake! We don&#8217;t recommend that you forward it to your entire email address book since it only serves to clog up email systems.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1332 size-full\" title=\"sshot_badtimes\" src=\"https:\/\/www.empowerelearning.com\/blog\/wp-content\/uploads\/2010\/11\/sshot_badtimes.gif\" alt=\"\" width=\"440\" height=\"810\" \/><\/p>\n<p><b>Example 3 &#8211; A Chain Letter &#8211; Irish Friendship Wish<\/b><\/p>\n<p>This is a typical chain letter. The only thing that a chain letter does is to clog up email systems so you shouldn&#8217;t forward them.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1346 size-full\" title=\"sshot_irish\" src=\"https:\/\/www.empowerelearning.com\/blog\/wp-content\/uploads\/2010\/11\/sshot_irish1.gif\" alt=\"\" width=\"455\" height=\"950\" \/><\/p>\n<p><b>Example 4 &#8211; A Nuisance Hoax &#8211; Hackingburgh Virus<\/b><\/p>\n<p>In May 1997, this email circulated the internet. There are a couple of pointers that this is a hoax. Firstly, the FCC doesn&#8217;t issue virus warnings of any kind. Secondly, the supposed virus has characteristics that no known virus exhibits. Since the recommended &#8220;advice&#8221; doesn&#8217;t harm users&#8217; computers, one could classify this as a nuisance hoax.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1333 size-full\" title=\"sshot_hackingburgh\" src=\"https:\/\/www.empowerelearning.com\/blog\/wp-content\/uploads\/2010\/11\/sshot_hackingburgh.gif\" alt=\"\" width=\"450\" height=\"715\" \/><\/p>\n<p><b>Example 5 &#8211; A Malicious Hoax &#8211; SULFNBK<\/b><\/p>\n<p>This is a malicious hoax which attempted to persuade readers to delete an operating system file called Sulfnbk.exe &#8211; a Microsoft Windows 95\/98\/Me utility used to restore long file names. Sadly, many people panicked and deleted the files from their computers needlessly, causing considerable work for system administrators.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1336 size-full\" title=\"sshot_sulfnbk\" src=\"https:\/\/www.empowerelearning.com\/blog\/wp-content\/uploads\/2010\/11\/sshot_sulfnbk.gif\" alt=\"\" width=\"430\" height=\"840\" \/><\/p>\n<p><b>Example 6 &#8211; A Scam &#8211; Nigerian (or 419) Scam<\/b><\/p>\n<p>This is a form of scam that can be traced back to the 1920&#8217;s or earlier and is sometimes known as the &#8220;Advance Fee Fraud&#8221;. Someone has a large amount of money that needs to be moved and they can only do it with your help. They offer to set you up as a business partner where you set up a legitimate bank account and let them use it to transfer the cash &#8211; often millions of dollars. So all you have to do is to send them some money &#8211; maybe $10,000 or so to start the process &#8230;<\/p>\n<p>These days, the most of the scammers use email and a lot of them &#8211; albeit not all &#8211; seem to be based in Nigeria hence the name used to describe the scam. You can find out a lot more about this form of scam on <a href=\"http:\/\/en.wikipedia.org\/wiki\/Advance-fee_fraud\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Wikipedia<\/a>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1335 size-full\" title=\"sshot_nigeria\" src=\"https:\/\/www.empowerelearning.com\/blog\/wp-content\/uploads\/2010\/11\/sshot_nigeria.gif\" alt=\"\" width=\"641\" height=\"899\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s that time of year again &#8211; when fraudulent and nuisance emails, and online hoaxes and scams start making the rounds even more quickly than usual. Sophos has posted a warning about one such hoax spreading rapidly on Facebook where users are warning each other about a &#8220;Christmas Tree&#8221; virus &#8211; said to be carried [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,6],"tags":[],"class_list":["post-1309","post","type-post","status-publish","format-standard","hentry","category-education","category-infosec"],"_links":{"self":[{"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/posts\/1309","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/comments?post=1309"}],"version-history":[{"count":0,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/posts\/1309\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/media?parent=1309"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/categories?post=1309"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/tags?post=1309"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}