Connect with us

San Diego, CA

This is the phishing scam that gets a San Diego identity theft expert ‘really, very angry’

Published

on

This is the phishing scam that gets a San Diego identity theft expert ‘really, very angry’


Digital thieves are nothing if not persistent and innovative.

They keep finding new ways to try to part you from your money.

Phishing — where thieves pose as trusted entities or send legitimate looking emails or messages to trick you into giving them access to your accounts — is a widespread method. And it is constantly evolving.

“We’ve seen phishing go through the roof,” said Eva Velasquez, the CEO of the Identity Theft Resource Center, a San Diego-based national nonprofit.

Advertisement

But knowledge is power. So here are three emerging phishing threats to look out for, according to internet safety experts. All three threats target key parts of people’s digital lives: email attachments that lead to fake login pages, multi-factor authentication trickery and deceptive calendar invites.

Spending a few minutes reading these pointers could help you avoid getting your ID or money stolen and save you countless hours of dealing with the fallout.

HTML attachments that open fake login pages

Imagine a busy professional who is in email action mode. In the past 30 minutes on a Saturday morning, he has filled out emailed liability waivers for his seven children’s summer camps, filed an expense report for work, answered a secure portal message from the veterinarian about his sick puppy’s prescription, skimmed 182 email subject lines and paid five bills from his email inbox, including a car insurance premium and his beloved cheese-of-the-month club.

Amid this flurry of inbound emails, ads, invoices and secure messages, he is working on autopilot: opening messages, skimming, clicking and signing in.

What a perfect opportunity.

Advertisement
Scammers prey on trust and distraction. (Adobe Stock)

Scammers are taking advantage of user distraction — and their trust — by sending emails with HTM or HTML attachments. When clicked, those open a browser file that looks like secure, familiar login page. These pages might look like secure invoice viewers, file-sharing services like DocuSign or Dropbox, or sign-in pages to platforms including Microsoft 365.

“Once the user enters their credentials, they are sent surreptitiously to the attacker’s server,” said Vlad Cristescu, the head of cybersecurity with ZeroBounce, a Florida company that helps businesses lower their rate of bounced marketing emails.

Why this method is especially insidious: “There isn’t a clickable link in the email, so standard email security filters (which scan for malicious URLs or attachments like PDFs and ZIPs) may not catch it,” Cristescu added.

To prevent this, he added, companies should “restrict HTML attachments unless essential, and users should treat unfamiliar HTML files the same way they’d treat a suspicious link — don’t open it unless you’re absolutely sure of the sender.”

If you do receive incoming communication with an HTML link or attachment, don’t engage, said Velasquez, with the ITRC.

Advertisement

“Don’t click on links, people. That’s the big, overarching message,” she said. Instead, go to the source: call the phone number on the back of your credit card, visit the bank in person.

Multifactor authentication tricks

If you are one of the many people who uses multifactor authentication, take note.

Multifactor authentication is still very helpful and should be used.

But Cristescu flagged one way that scammers are taking this tool — which is designed to make people’s online accounts more secure — and using it to slither in.

As a refresher, multifactor authentication is an added layer of protection that prevents data thieves from logging into your accounts if they have your username and password. It helps ensure that you’re the one who typed in your password when you log in, and not some scammer in the Philippines or Poughkeepsie.

Advertisement

To use multifactor authentication, you typically download an app, such as Google Authenticator or Microsoft Authenticator. You register your sensitive online accounts, such as Facebook, bank or email, with that app. Then, every time you log into a registered website, the authenticator app generates a new, random code that you enter after your password as a second layer of verification.

With the rise of this protection, a new threat has emerged: Scammers who have your username and password can send log-in requests to your authenticator app. Next, the scammer can pose as an IT expert from your workplace and ask you to approve the log-in request.

If you fall for it, then boom — the scammer is in.

Scammers use a variety of ways to fool victims, including phone calls, texts, email and pop-ups that "appear to be legitimate communications from a bank, family member or government agency. officials said. Getty images
When you get an email you didn’t initiate, reach out to the number on the back of your card, experts say. Do not engage with that email. (Getty Images)

This technique “exploits a user’s frustration and trust in IT. If you’re receiving multiple (authenticator) prompts you didn’t initiate, that’s not a glitch – it’s an attack,” Cristescu said. He recommends pausing, never approving these unexpected requests and flagging the interaction with IT.

Velasquez added that if you get an authenticator notification and you didn’t just log in yourself, “That is a huge red flag. Stop and address it. Don’t ignore it.”

Anytime you interact with IT, be sure you’re the one initiating that contact, she added. If someone from IT calls or emails you, disconnect and reach back out using a trusted method, such as the same phone number you always dial.

Advertisement

Fake calendar invites

A third technique data thieves are using is calendar invites.

“I just get really very angry about this one,” Velasquez said. “It is super hard to detect.”

Here’s what to look out for. If you use an online calendar like Google calendar or the native iPhone calendar app, you might receive an invitation to an event you didn’t see coming. Sometimes these meetings are legitimate. Sometimes, they are not.

Scammers “are now sending meeting requests with malicious links embedded in the invite or ‘join’ button. These invitations sync directly into calendars and often go unquestioned,” according to ZeroBounce.

Scammers use calendar invites because they have “built-in credibility – they’re not usually scrutinized like emails,” Cristescu said. Look for meeting requests from unknown senders and vague event names like “Sync” or “Project Review,” he added.

Advertisement

In some jobs or roles, meetings routinely get added to calendars by other people — clients, prospects, coworkers, bosses, peers.

“I have gotten these repeatedly,” said Velasquez, with the ITRC. “Depending on your lifestyle and your job and how you work, these are going to be particularly challenging. They are real calendar invites. The problem is they have malicious software embedded in them — so when you click on portions of them, ‘Click to join,’ it’s like opening an attachment (or) clicking on a suspicious link. It’s the same principle.”

Cristescu, with ZeroBounce, shared this tip: “Treat those just like a phishing email. Disable auto-accept where possible and review every invite manually before clicking anything.”

Never stop questioning what lands in your inbox or calendar, Cristescu added. “Always verify the sender’s email address, ensure that any link you click matches the legitimate domain, and look out for subtle red flags like spelling errors or unusual formatting.”

A big picture pointer

“All three of these (scams) are so common that it has probably happened to every single person reading the article — at least one of them. That’s how ubiquitous these are,” Velasquez said.

Advertisement

She shared this broader thought: It’s less important to know how to respond to each scenario and more important to pause, be skeptical, double check.

It’s important to be ever more skeptical, because AI makes it easier and easier for thieves to create convincing ruses, Cristescu and Velasquez both said.

AI “really helps with making these phishing offers look and sound so much more legitimate,” Velasquez said. “And with the amount of data that is out there from public sources and from data breaches, it’s very easy to see what relationships people have.” Where you bank, where you do business — that is all fodder for someone to create a copycat page designed to trick you into logging in.

Adopt an “investigator mindset,” Velasquez said. Use this helpful reminder: the acronym STAR, which stands for Stop. Think. Ask questions or ask for help. Reassess.

The ITRC nonprofit can answer questions, for free, through phone and live chat. Toll-free phone: 888-400-5530. Live chat staffed by people, not bots:  https://www.idtheftcenter.org/victim-help-center/

Advertisement



Source link

San Diego, CA

Southern California’s Jewish community reacts to war in the Middle East

Published

on

Southern California’s Jewish community reacts to war in the Middle East


The Jewish community in Southern California is sharing their fears and hopes following the weekend’s strikes on Iran and retaliatory attacks on Israel, U.S. military bases and other targets in the Middle East.

The exchange of missiles in the Middle East is having a devasting effect on Iran’s defense capability, but retaliatory strikes in the region are taking a toll. 

“Weapons of enormous capacity that are targeting civilian areas,” said Elan Carr, CEO of Los Angeles-based Israeli American Council.

Carr says toppling the Iranian regime, taking out its nuclear capabilities and freeing the Iranian people from this oppressive rule should have been done decades ago.

Advertisement

“This is about seeing the most evil regime, the world chief state sponsored terrorism to no longer have the ability to do what it’s been doing,” Carr said.

Sara Brown, regional director of the American Jewish Committee, said the U.S. and Israel are concentrating strikes on Iran’s missile sites and military industrial complex. Iran’s retaliatory strikes are focused on many civilian targets.

“We are hearing from our partners from around the region, who are terrified,” Brown said. “Across the Middle East right now, I think there is a tremendous amount of fear, but also hope and also resolve.”

AJC is the advocacy arm for Jewish people globally. Many members and partner groups are in harm’s way. Brown says the risk is great, but the potential reward is world changing.

“That Iranian people will get to choose leadership for themselves, that we will finally see a pathway forward for peace across the Middle East,” Brown said.

Advertisement

If wars of the past hadn’t produced lasting peace, then why now? Carr says Iran’s nuclear capabilities are destroyed and Iran’s military and proxies are weakened after Israel’s response to the Oct. 7 Hamas ambush.

“No more terrorist network throughout the Middle East. Think of what that could mean. Think of the normalization we could see,” Carr said.

President Donald Trump expects fighting to last several weeks. Some critics are concerned about a drawn-out conflict that could spread.

Carr is not convinced.

“Who is going to enter a war against the U.S. and Israel? Russia is plenty busy. China has no interest in jeopardizing itself this way,” Carr said.

Advertisement

Besides the six Americans killed as of Monday night, government officials say 11 people were killed in retaliatory strikes in Israel.



Source link

Continue Reading

San Diego, CA

San Diego Zoo Safari Park’s Elephant Valley: Get closer to elephants

Published

on

San Diego Zoo Safari Park’s Elephant Valley: Get closer to elephants


San Diego — Before we see elephants at Elephant Valley in the San Diego Zoo Safari Park, we come face to face with destruction, only the wreckage is beautiful. A long, winding path takes guests around and under felled trees. Aged gray tree hunks form arches, for instance, over bridges that tower over clay-colored paths with hoof prints.

The design is meant to reorient us, to take us on a trail walked not by humans but traversed and carved by elephants, a creature still misunderstood, vilified and hunted for its cataclysmic-like ability to reshape land, and sometimes communities.

“It starts,” says Kristi Burtis, vice president of wildlife care for the Safari Park, “by telling the story that elephants are ecosystem engineers.”

Advertisement

Elephant Valley will open March 5 as the newest experience at the Escondido park, its aim to bring guests closer than ever to the zoo’s eight elephants, which range in age from 7 to 36, while more heavily focusing on conservation. The centerpiece of the 13-acre-plus parkland is a curved bridge overlooking a savanna, allowing elephants to walk under guests. But there are also nooks such as a cave that, while not previewed at a recent media event, will allow visitors to view elephants on their level.

In a shift from, say, the Safari Park’s popular tram tour, there are no fences and visible enclosures. Captive elephants remain a sometimes controversial topic, and the zoo’s herd is a mix of rescues and births, but the goal was to create a space where humans are at once removed and don’t impede on the relative free-roaming ability of the animals by keeping guests largely elevated. As an example of just how close people can get to the herd, there was a moment of levity at the event when one of the elephants began flinging what was believed to be a mixture of dirt and feces up onto the bridge.

“Our guests are going to be able to see the hairs on an elephant,” Burtis says. “They can see their eyes. They can see the eyelashes. They can see how muscular their trunks are. It’s really going to be a different experience.”

Elephant Valley, complete with a multistory lodge with open-air restaurants and bars, boasts a natural design that isn’t influenced by the elephant’s African home so much as it is in conversation with it. The goal isn’t to displace us, but to import communal artistry — Kenyan wood and beadwork can be found in the pathways, resting spaces and more — as a show of admiration rather than imitation.

“We’re not going to pretend that we’re taking people to Africa,” says Fri Forjindam, now a creative executive with Universal’s theme parks but previously a lead designer on Elephant Valley via her role as a chief development officer at Mycotoo, a Pasadena-based experiential design firm.

Advertisement

“That is a slippery slope of theming that can go wrong really fast,” she adds. “How do we recognize where we are right now, which is near San Diego? How do we populate this plane with plants that are indigenous to the region? The story of coexistence is important. We’re not extracting from Africa, we’re learning. We’re not extracting from elephants, we’re sharing information.”

But designing a space that is elephant-first yet also built for humans presented multiple challenges, especially when the collaborating teams were aiming to construct multiple narratives around the animals. Since meetings about Elephant Valley began around 2019, the staff worked to touch on themes related to migration and conservation. And there was also a desire to personalize the elephants.

“Where can we also highlight each of the elephants by name, so they aren’t just this huge herd of random gray creatures?” Forjindam says. “You see that in the lodge.”

That lodge, the Mkutano House — a phrase that means “gathering” in Swahili — should provide opportunities for guests to linger, although zoo representatives say reservations are recommended for those who wish to dine in the space (there will also be a walk-up, to-go window). Menus have yet to be released, but the ground floor of the structure, boasting hut-like roofing designed to blend into the environment, features close views of the elephant grazing pool as well as an indoor space with a centerpiece tree beneath constellation-like lighting to mimic sunrises and sunsets.

Throughout there are animal wood carvings and beadwork, the latter often hung from sculptures made of tree branches. The ceiling, outfitted with colorful, cloth tapestries designed to move with the wind, aims to create less friction between indoor and outdoor environments.

Advertisement

There are, of course, research and educational goals of the space as well. The Safari Park works, for instance, with the Northern Rangelands Trust and Loisaba Conservancy in Kenya, with an emphasis on studying human-elephant conflict and finding no-kill resolutions. Nonprofits and conservation groups estimate that there are today around 415,000 elephants in Africa, and the African savanna elephant is listed as endangered by the International Union for Conservation of Nature.

Studies of the zoo’s young elephants is shared with the Reteti Elephant Sanctuary in the hopes of delivering care to elephant youth to prevent orphanage. Additionally, the Safari Park has done extensive examination into the endotheliotropic herpes virus. “The data that we collect from elephants here, you can’t simply get from elephants in the wild,” Burtis says.

One of the two entrances to Elephant Valley is outfitted with bee boxes; bees are known to be a natural elephant deterrent and can help in preventing the animals from disrupting crops or communities. To encourage more natural behavior, the plane is outfitted with timed feeders in an attempt to encourage movement throughout the acreage and establish a level of real-life unpredictability in hunting for resources. Water areas have been redesigned with ramps and steps to make it easier for the elephants to navigate.

With Elephant Valley, Forjindam says the goal was to allow visitors to “observe safely in luxury — whatever that is — but not from a position of power, more as a cohabitor of the Earth, with as much natural elements as possible. It’s not to impose dominance. Ultimately, it needed to feel natural. It couldn’t feel like a man-made structure, which is an antiquated approach to any sort of safari experience where animals are the product, a prize. In this experience, this is the elephant’s home.”

Advertisement

And the resulting feel of Elephant Valley is that we, the paying customers, are simply their house guests.



Source link

Continue Reading

San Diego, CA

Man fatally struck by hit-and-run vehicle in San Diego

Published

on

Man fatally struck by hit-and-run vehicle in San Diego


A man in the Mission Bay Park community of San Diego was fatally struck Sunday morning by a hit-and run vehicle, authorities said.

The victim was also struck by a second vehicle and that motorist stayed at the scene to cooperate with officers, the San Diego Police Department reported.

The initial crash occurred at about 2:20 a.m. Sunday in the area of West Mission Bay and Sea World drives.

The pedestrian was in the southbound lanes of the 2000 block of West Mission Bay Drive when he was struck by a silver vehicle also in the southbound lanes. That vehicle fled the scene, continuing southbound, police said.

Advertisement

A 28-year-old man driving his vehicle southbound ran over the downed pedestrian.

“That driver remained at the scene and is not DUI,” according to a police statement. “The pedestrian was pronounced deceased at the scene.”

Anyone with information regarding the initial crash was urged to call Crime Stoppers at 888-580-8477.



Source link

Advertisement
Continue Reading

Trending