Logiq logo

See Yourself in Cyber : Jersey-based Case Studies

Logiq

Logiq News, October 19th 2022


The Importance of MFA
(Multi-Factor-Authentication)

Case Example - “It’s a Fire Sale!”

Some time ago a private user did not have any MFA enabled on any accounts. An attacker had managed to breach the users credentials and had no problem with logging into amazon.co.uk using said credentials. The attacker then locked out the legitimate user from their own accounts and proceeded to purchase as many items as possible until the legitimate users bank was declining transactions as funds had run dry.

  • LESSON - Enable MFA. All major services such as amazon and email providers support MFA. This will prevent attackers from being able to login as you, even if they have your password.


Case Example - “Wanna Go for a Drive?”

A user was buying a new sports car and dealing with an off-island dealership. Suddenly the users phone prompts them to approve a sign in. With all that was going on that day - and that the user has been signing in and out of systems all day - they automatically (almost like a reflex) approved the sign in. 

At that instant this user was compromised.


The notification was a login from Eastern Europe. The malicious attacker then managed to intercept email correspondence between the user and dealership, change the bank details on attached PDFs; compromising both Confidentiality and Integrity. The attacker was successful, as the victim wired over the money to the attacker’s bank account.

  • LESSON - Be vigilant to the Mobile Authenticator requests. Have you just this second entered your password into a login portal...?


What is MFA?

Multi-Factor-Authentication (MFA) is when you will be challenged to prove that it is you that has just attempted to sign into a system or service.

In recent years you’ve most likely noticed an increase of your company requesting that you set up Multi-Factor-Authentication with little to no understanding of the why. My hope is that the two case examples (mentioned above) of local incidents will give clarity.


Types of MFA (Multi-Factor-Authentication)

  • Text message - The original method of MFA. This is when you will receive an SMS message with a code that you are then expected to enter into a login portal.
  • Authenticator Applications - Applications that you can download from your App store, such as Microsoft Authenticator or Google Authenticator. These Applications prompt you to confirm that you have just attempted to sign in, or ask you to enter the code displayed in the authenticator app (more secure still)
  • Phone Call - Similar to ‘Text Messages’ . The least common option. The service will call your phone and readout a numerical code that you must enter into the login portal.


In Conclusion

  • Always Enable MFA for logging into anything. If the ability is there? Use it.
  • Keep personal email/website passwords different from your work passwords.
  • At the very least keep your personal email password one of a kind, unused anywhere else.


Article written by Emanuel Pontes, Junior Technical Consultant - Logiq Limited 

Logiq



Financial businesses need to comply with new digital regulation
By Channel Eye Media December 16, 2024
Channel Eye Article Featuring Logiq
Is the thought of protecting your artefacts in Microsoft 365 giving you sleepless nights?
By Logiq June 26, 2024
Many companies in recent years have adopted the move to Microsoft 365 and are left wondering why the Microsoft options for protecting their data fall a little short. Logiq have partnered with Veeam, and as an existing Microsoft Partner, we have real-world experience of how these shortfalls can be filled.
Do employees truly grasp their crucial role in maintaining IT security?
By Logiq May 26, 2024
In today's rapidly evolving digital landscape, organisations are investing heavily in cutting-edge software, robust hardware, and comprehensive policies and procedures to ensure compliance with industry standards and security frameworks.
How often do you ensure your company's computer systems has all the latest updates installed?
By Logiq April 26, 2024
In today's digital landscape, where cyber-attacks are becoming increasingly sophisticated, it's crucial to prioritize the security of your computer systems and network.
Meet the Team at Logiq: Driving innovation in IT consultancy
February 6, 2024
We were thrilled to be featured in the Channel Eye's 'Meet the Team' Series. They certainly dived right in!
Financial businesses need to comply with new digital regulation
By Channel Eye Media December 16, 2024
Channel Eye Article Featuring Logiq
Is the thought of protecting your artefacts in Microsoft 365 giving you sleepless nights?
By Logiq June 26, 2024
Many companies in recent years have adopted the move to Microsoft 365 and are left wondering why the Microsoft options for protecting their data fall a little short. Logiq have partnered with Veeam, and as an existing Microsoft Partner, we have real-world experience of how these shortfalls can be filled.
Do employees truly grasp their crucial role in maintaining IT security?
By Logiq May 26, 2024
In today's rapidly evolving digital landscape, organisations are investing heavily in cutting-edge software, robust hardware, and comprehensive policies and procedures to ensure compliance with industry standards and security frameworks.
How often do you ensure your company's computer systems has all the latest updates installed?
By Logiq April 26, 2024
In today's digital landscape, where cyber-attacks are becoming increasingly sophisticated, it's crucial to prioritize the security of your computer systems and network.
Meet the Team at Logiq: Driving innovation in IT consultancy
February 6, 2024
We were thrilled to be featured in the Channel Eye's 'Meet the Team' Series. They certainly dived right in!
By Channel Eye January 12, 2024
Logiq News as reported in Channel Eye on 10th January 2024
Successful Christmas Drinks and Office Warming Event
By info December 13, 2023
We have recently moved offices and each Christmas we take our clients out for drinks...
Partnership Spotlight: Ocorian and Logiq
November 6, 2023
We are proud not only to show off what we do through the above video with Ocorian, but to also for it to be featured in another article in Chanel Eye Media.
email signature management solutions
By Logiq October 10, 2023
Enhanced Email Branding: Exclaimer's solutions enable businesses to create and manage consistent, on-brand email signatures across the entire organization, ensuring a professional and unified image in every email. Marketing Opportunities: Leverage your email signatures for marketing purposes. Promote upcoming events, new products, or social media profiles to boost your brand's visibility.
We are thrilled to announce our new partnership with Printix
By Logiq October 1, 2023
In today's digital world, the need for efficient and secure printing solutions has never been greater. Printix offers a seamless and cost-effective way for organizations to manage their print infrastructure while enhancing productivity and reducing waste.
More Posts
Share by: