For this project I researched recent news pertaining to cybersecurity. I researched what type of attack happened, who was affected, and how we can prevent similar things from happening to us. Additionally, I evaluated my sources to ensure their credibility.
For the other part of the project I did the CCBC cybersecurity training to earn a certificate.
I learned about different ways in which people are hacking or exploiting in modern times. Hackers have become creative in both their methods and who they target. For example, I read about a group of hackers who have been using impersonation tactics to trick help desks into giving them access to organizational information. This is an interesting way of hacking because they are exploiting not only the company's cybersecurity measures but also the people they hire to help customers. It is a very unique process. I also learned the importance of having unique passwords for different accounts, as a teen was able to access 60,000 Draftkings accounts which enabled him to steal $600,000 before being caught.
Over the past year, a hacking group known as the "Scattered Spider" group has been stealing data from and extorting American organizations. Their tactics involve impersonation through the use of fake profiles to trick organizational help desks into giving them access to organizational information. They also use their access to track Slack, Microsoft Teams, and Microsoft Exchange channels to see whether or not the organization is communicating that they have noticed their activities. Â
Who published the content? Zeba Siddiqui
Where was it published? Yahoo Finance
When was it published? November 16, 2023
The truthfulness and integrity of the facts: Accurate; quotes from the FBI and CISA regarding what should be done and the overall information used from the article.
How is it written and presented? Written to inform and warn organizations of potential attempts that could be aimed at them. Only a few ads.
Links and Citations: No outside links or direct citations. They just reference the FBI and CISA as being their sources.
A teen from Michigan stole the user information for about 60,000 Draftkings Fantasy Sports accounts, 1,600 of which he drained all funds from. In total, he stole about $600,000 worth of funds. The computer that authorities seized had about 40 million username and password combinations. They described the programs he used as being similar to those used for credential stuffing hacks. In order to reduce the risk of something similar happening, users should use multi-factor authentication, unique and strong passwords, regularly monitor account activity, and be aware of the risks associated with using the same password on multiple platforms. The teen faces up to 5 years in prison for conspiring to commit computer intrusion.
Who published the content? Dan Mangan
Where was it published? CNBC
When was it published? November 15, 2023
The truthfulness and integrity of the facts: The facts are backed up with links to prior articles and documents showing complaints and other legal actions.
How is it written and presented? The article is written in a straightforward manner; clearly written to inform the reader of the updated situation regarding the case.
Links and citations: Link to the filed complaint, link to original article (when charges were announced), and links to articles discussing Draftkings' revenue.
In order to earn this certificate I did the CCBC cybersecurity training and had to get all questions correct. I learned a lot of things I did not know previously.