(Image via thesafetymag.com)
Volunteer Writer: Akshit Bagga
Email: abagga@umassd.edu
Staying connected, updated, and bridged through the internet and the web is one of the most magnificent things technology has blessed us with in these modern times. Any information you need is a search away. Any message you want to convey is a send away, And any update you want to share with the world is just a post away.
With all these interconnectivities, making the Internet a safe place becomes a shared responsibility of everyone who uses it.
Sometimes, malicious entities misuse this excellent platform for personal or financial benefit. These entities can range from individuals to organizations that may use the place for personal or to serve some paid benefit.
Attacks on organizations and individuals who hold valuable information or host several users are becoming common these days. Some general methods of attacks that threatening entities use are phishing, hacking, and similar techniques.
The most common method these days is phishing, where victims receive communication or go on a website that looks authentic but may contain malicious links or URLs that compromise the victim’s information or security when clicked. According to Astra Security, 3.4 billion phishing emails are sent daily.
In the wake of recent phishing attacks on UMass Dartmouth’s domain, let’s look at some tips to identify safety.
- Verify The Sender: Always know who the sender is and if they intend to send the communication. Organizations that distribute email IDs with domains use an external sender tag to indicate if the sender is not on their list or has a different domain name. Check for the yellow tag explaining the sender is an external entity. If so, be cautious, as the email may become a gateway for cybercriminals to your organization.

- Verify The Site’s Security: If you are on a website where the internet server uses a secure channel, you can trust it. To check this, ensure the website uses an HTTP protocol. Most companies with public-facing websites have transitioned to a more secure protocol: HTTP. The protocol comes with a digital certificate indicating the website’s authenticity. You could also look for the padlock on the website to ensure the internet channel is secure.

- Avoid Connecting To Unsecured Or Open Networks: Specific Wi-Fi networks that are open to the public and may be insecure are available all around us. Anyone with access to a Wi-Fi network card has the total capacity to see the internet transactions taking place between IPs. Additionally, free tools and applications are available to record all packets (internet transactions) sent using a particular network card. Once registered, it lists all the IPs involved, the time it took, and the information sent. Someone watching over your activity could be your worst nightmare.
- Check for Spelling Errors: If you see an unexpected communication in your inbox, check for spelling errors and strange characters. It is most likely that the domain has been compromised. As CITS says, misspellings are a telltale of phishing attacks.

- Think Before You Click: If it’s too good to be true, it may be a phishing attack. If you know the website link in an email, it may be okay to click it and go through. In case you see an unexpected communication or email link, it could be there to violate your security. The best way to deal with an unknown link is to first hover over the link, see the internet address that shows up, and think whether it leads to the place that appears to be what it is intended for. If you have doubts, the best way is to go directly to the source rather than click on the potential danger.
- Keep Your Browser Up To Date: Internet browser companies constantly update security patches to ensure users have a safe environment. Security patches are released to tackle a security loophole that was recently discovered. If you see an update notification in your browser, do it, and don’t delay.

- Ensure The Website Is Not Masqueraded: Cybercriminals use website masquerading as a technique to lure users to their destination. A masqueraded website may look like the original one but isn’t the original one. Check the domain; it could be a different spelling leading you there or a pop-up. Sometimes, cybercriminals register similar-sounding names and masquerade them. An example of masquerading could be “gooogle.com” instead of “google.com.” To avoid this issue, sometimes big companies try to register similar-sounding domains (like in the above case) and work towards preventing cyber attacks on their websites.
Always remember, there is no foolproof way to prevent cyberattacks. The best way to secure yourself and avoid a cyberattack is to be aware when using the internet.
It is okay to ask or not click something if you do not know it. A wrong step may lead to attacks or downtimes.
