Recognizing the need to inform people about the threats facing internet users, each year attention is drawn to the most popular methods used by criminals operating online. We explain what should raise our vigilance by describing the methods used in cyberspace.
What is phishing?
A phisher—the person responsible for the fraud—usually begins an attack by sending specially prepared messages by email. The information received resembles messages used by banks, auction services or other institutions.
The messages usually claim that an account has supposedly been deactivated and must be reactivated via a link in the email. The scammer’s main goal is generally to obtain login details and credit-card information.
What are “worms” and pharming?
To obtain confidential data, criminals use malicious software known, depending on its form, as a worm, Trojan horse (Trojan) or virus. “Worms” enter our computers as independent carriers and replicate across all available networks. They can also independently destroy files or send spam email.
Scammers most often use infected websites containing catchy phrases in their descriptions or fake email messages for this purpose
A more dangerous and harder-to-detect form of phishing is pharming: scammers redirect people who enter correct addresses, such as their bank’s address, to fake websites. If we enter our data there, it will reach the criminal.
How to stay safe online?
To protect our data, we should remember the existing threats, which are often associated with downloading software from unreliable servers or replying to suspicious email.
We are increasingly likely to fall victim to online criminals on social media, by opening messages from unknown users.
What should you remember when browsing the internet?
- you should regularly update the system and software you use
- it is worth equipping your computer with antivirus software that will warn you of danger
- do not open hyperlinks directly from a received email, especially if you do not know who sent the message
- never send personal data by email—under no circumstances should you fill in forms contained in an email with personal information
- banks and financial institutions use the HTTPS protocol wherever logging into a system is required. The website address then begins with the expression https://, not https://. (If a login page does not include the HTTPS protocol name in its address, this should be reported to bank staff and no data should be entered there)
- any suspicions regarding forged websites should be reported as quickly as possible to police officers or employees of the relevant bank responsible for its online operations.
Given the widespread access to computers and mobile devices, we should be careful about whom we allow to use our accounts and equipment.
Never give your login details to third parties. If we allow other users to connect to our network, we should restrict the ability to connect external storage devices.
We should try to make regular backups and save important files on external storage devices kept in a safe place. By following a few simple rules, we can avoid becoming victims of online criminals.
How important is your password?
The password we create should be of adequate quality, which is increasingly often checked by the system we log into. The basic rules for creating a password include combining lowercase and uppercase letters, numbers and special characters, with a length of more than 8–10 characters.
Created passwords should not be connected with our personal data: first name, surname or nickname. They should not contain names associated with our immediate surroundings either, such as our workplace or a pet’s name.
A password should be unique for every website we visit. For security, it is worth changing the order of letters and characters from time to time
We should also not save important account passwords in files accessible on the computer. When installing a router, remember to configure it properly; when buying such equipment, consider whether it supports WPA or WPA2 encryption—not its price.
How to shop safely online?
During the holiday season, we often choose to buy gifts online. The availability of e-shops and auctions on popular portals grows year by year. By reducing the time spent walking around shopping centres looking for the things we need, we use simpler purchasing methods. Unfortunately, this often makes us easy targets for cybercriminals. Therefore, when ordering and receiving a selected item, pay attention to:
- the stated product price—if it is too low, this may suggest that the goods are counterfeit
- before buying, find out who the seller is—positive reviews can make us more confident about the purchase
- check how long the seller’s account has been listed on the service and how many users have used its services
- always read the shop’s terms and conditions and the description of the auction on the service we use
- demand confirmation that the shipment has been sent; do not pay before the winning bid has been confirmed
- do not delete correspondence with the seller—in the event of fraud, it is evidence confirming the purchase
- check the shipment you receive—if the goods do not match the order, inform the police.
Paying for an item and not receiving it is nothing other than extortion, or fraud. The Criminal Code provides for a penalty of up to eight years’ imprisonment for this offense.
How to keep children safe online?
Access to the internet is no longer limited to collecting and checking data used for learning. Children and young people use the internet to contact their friends and play games available on platforms, thereby gaining access to content that is not always intended for them. The first people who can ensure that children do not encounter information inappropriate for their age are their guardians. To protect the younger generation from threats, they should remember to:
- inform the child about the safe and harmful consequences of using the internet
- monitor the websites their children browse
- be able to block websites that the parent considers inappropriate
- report any disturbing content to which children may have access.
However, if as parents we are unsure how to warn a child about potential threats that may be encountered while using the internet, it is worth teaching younger children a few simple rules that can save them from unpleasant situations.
During such conversations, assure the child that they can turn to us with any problem—as guardians—as well as to a teacher or police officer, people who know what to do when safety is at risk.
People met online can often change their identities—unknown in the real world, they may claim to be someone of a different age or from another town.
We should try to protect the information we share about ourselves on portals—rather than using our first and last names, we should use an invented pseudonym.
We should ask children about websites they use, as something worth recommending. Let us take an interest in what children do in their free time on the computer; we should initiate conversations about what interests them online, what behavior they encounter and what trends are currently popular among younger users.
The internet can bring us much good—if we know how to use it.
Regardless of age, we should remember that we are not anonymous online. Everything we write and publish remains there for a long time. Therefore, we should think carefully about the information we post. Comments we leave on websites we visit should reflect well on us. Just as in everyday life, we should treat others with respect, without insults or intimidation.
Let us be aware that we ourselves create the internet; let us remember how we would like to find it and take care of our shared safety in cyberspace.