2011’s ‘most dangerous’ holiday gifts

From security firm F-Secure:

F-Secure is announcing today its Cyber Monday Cyber-Watch List, its annual compilation of the most ‘dangerous’ holiday gifts to be encountered while shopping online this year based on the prevalence of ‘poisoned’ search results on the web.

Cyber Monday, the unofficial beginning of the holiday shopping season online, will occur this November 28, 2011, bringing with it throngs of Internet shoppers on the hunt for the best deals and hottest products. Unfortunately, the period also brings with it a similarly motivated group of cybercriminals targeting unassuming shoppers as they use search engines to find gifts for their loved ones.

Google search results for products often include links to ‘poisoned’ sites, or malicious websites that can infect an unsecured computer with viruses, worms and other malware, putting one’s personal and financial information at risk.

The more popular an item is, the more likely it will attract a dangerous search result, which could lead to malware or an unreliable merchant. Here are the products we anticipate will be targeted by cybercriminals this holiday season:

1. Apple iPhone 4S
2. Harry Potter and the Deathly Hallows, Part 2 DVD
3. Angry Birds: Knock on Wood Game
4. Steve Jobs biography
5. Fijit Friends Willa Interactive Toy
6. Michael Buble ‘Christmas’ album
7. Apple iPad 2
8. Kindle Fire tablet
9. Silver ‘Heart’ pendants
10. Call of Duty: Modern Warfare 3

Here are three tips from F-Secure to ensure you stay safe while shopping online this Cyber Monday, and throughout the 2011 holiday season:

  • Visit retailers’ websites directly if possible (e.g., www.amazon.com vs searching ‘Amazon’ on Google)
  • Use Internet security software that features browsing protection (or check links with F-Secure’s free Browsing Protection)
  • Always check a site’s URL before making any purchase (look to make sure you’re at the correct online store and that the page URL begins with https://, which means it’s secure)

5 holiday cyber scams to avoid

As you and your family kick off the holiday shopping season, it’s a good time to review the common scams that circulate this time of year.

Unless you live in a cave, you probably know today is Black Friday, the day when stores try and lure in early shoppers with great sales on many popular items. It is followed by Cyber Monday, the first Monday after the Thanksgiving break when many workers return to their office computers and, presumably, start their holiday shopping online.

But each year, cyber criminals find new ways to try and ensnare consumers with a number of sneaky tricks. Here are some common ones to keep your eye out for, and to warn your older, tech-savvy kids about, as they are also likely to come across them in the coming weeks, as well.

Holiday ‘giveaways’

No, you are not going to get a free iPad or iPhone. Nor is Southwest Airlines going to give you free round-trip airfare. These are the kinds of scams we see on Facebook year round, but they are often repackaged with holiday wrapping and a pretty bow this time of year to seem like holiday-related give-aways. They are no different, or less malicious, than any other Facebook scam making the rounds all year.

What to do? Avoid them. If you see something on Facebook that claims you will get something amazing simply by clicking “like” or by sharing it with other friends? Don’t. Just don’t. Remember my mantra: If it sounds too good to be true, it is. Instead of a free iPad, if you click on a link, there is a good chance you have just downloaded some kind of malware onto your computer that can be used to steal data from you.

Fake sales

Hot items, like Apple devices or popular video games and consoles, provide holiday opportunities for crooks to fools consumers. This time of year, ads claiming to have a popular item at a deeply discounted rate can be found. Just because you found it with a Google search doesn’t mean it’s legit. Criminals have been poisoning search results for years now with the hope of getting their fake ads to show up when someone searches for a popular term.

Your best bet? Go directly to reputable web sites, such as Amazon.com or Best Buy or Target. DO NOT purchase an item from a web site you are not familiar with, or even follow a link to a sale that claims to take you to a reputable dealer. Instead of the item, you can end up paying for something you never receive. And since you have likely passed on your credit card information, it sets you up for further fraud down the road.

Bad QR codes

A QR code, or Quick-response code, are those nifty barcodes that are popping up everywhere, attempting to get you to scan them and then find out more about a product or service.

But, of course, now that they are popular, malicious web sites containing QR codes for mobile apps starting cropping up earlier this year, too. The bad codes are being used to lure people into downloading malicious apps. So far, it has been seen primarily on the Android platform.

What can you do? Think twice about QR codes. If you really want to use them, be savvy. There is a free app called Red Laser that you can download and use to check out the web site that the QR code takes you to. If it is a web site with an .exe in the address, do NOT go there.

Bank/credit account alerts

“Your Bank of America account has been compromised! Your Paypal account has been suspended!” the alerts will scream. But have they? Doubtful. It’s just another ruse to get you to “click” on a bad link that will take you to a phishing site. Here they will ask you to enter your account number, password and everything else they need to get the keys to your financial kingdom. Don’t do it. If you think your account has been compromised, look up the bank’s number yourself (do NOT use the phone number the email has provided) and speak to customer service. Don’t click on any links contained in emails warning you your account has been compromised.

Shipping notifications

“Fed Ex deliver failed.” I get these in my spam folder all the time. Do you? It’s another common ruse – but it upticks this time of year, when folks are expecting shipments. Continue to ignore. Please. Don’t worry. If Fed Ex (or UPS, or DHL, etc.)was unable to ship something to you, they will try again.

Blog at WordPress.com.

Up ↑