Think Like a Hacker – Act Like a Professional: Cybersecurity Expert Advice

Photo: magnific.com 

A recent cyberattack on a Latvian government information system, which resulted in the data of 1.2 million residents falling into the hands of cybercriminals, raises several important questions: How do cybercriminals obtain our data in the first place? How are attacks planned? And why does phishing remain one of the most effective ways of getting people to open the door to an attacker themselves? To find answers to these and other important questions, we spoke to our lecturer, certified ethical hacker and cybersecurity expert, Deniss Čalovskis.

The scammers are calling again. How did they get my phone number?

This is a classic scenario and nothing unusual. A website is created that operates as an online store with the aim of encouraging people to register and enter their personal data. What do cybercriminals do? They collect email addresses, phone numbers and other valuable information, then create databases and sell them to other attackers.

Such databases are in high demand because they can be used, for example, for automated calling campaigns designed to steal money, login credentials or other sensitive information. The more data attackers have at their disposal, the more convincing a story they can create.

How can a cybercriminal know that I am expecting a parcel right now?

Photo: magnific.com

In reality, the scheme is quite simple. Such a fraudulent SMS is sent to thousands of people – everyone who is included in the cybercriminal’s database. Therefore, the attacker does not need to know which individual is actually expecting a parcel, because there is a high probability that the message will genuinely be relevant to at least some of the recipients.

Why do so many people still fall for seemingly obvious scams?

Scam attempts are also often made late in the evening. Why? Quite simply, during the day we are very busy, while in the evening we are tired, which reduces our ability to concentrate. The key to phishing is creating a sense of urgency. When a request arrives, we may automatically approve it out of forgetfulness or simply because we are tired.

Are cyberattacks carefully planned, or are they more of an impulsive decision?

How long a cyberattack takes to plan depends on several factors. For example, sophisticated cyberattacks targeting a country’s critical infrastructure – water and electricity providers, the financial sector or healthcare institutions – can take more than a year and include planning, development and intrusion phases.

On the other hand, when it comes to simple, commercially motivated hacking incidents, a few hours may be enough. If cybercriminals identify potential vulnerabilities – weaknesses in a system, software or network – they will try to exploit them. Conversely, if there is no benefit to be gained, criminals will not waste their resources. Likewise, if a company successfully addresses its vulnerabilities, it will simply no longer appear to be an attractive target.

What about artificial intelligence – is it one of the most reliable tools for cybercriminals?

Photo: magnific.com

Yes, because artificial intelligence (AI) tools are not always used for good purposes. They are also actively used in cybercrime, for example, to scan networks, assess vulnerabilities and develop cyberattacks. These are time-consuming processes, but automation makes it possible to carry them out much faster.

Moreover, AI can already be used to create professional, well-designed and, most importantly, convincing and carefully crafted emails. Increasingly, attention is being paid to language quality, with efforts made to avoid stylistic and grammatical mistakes.

Another factor is engaging in conversations with victims. Hackers are willing to spend a great deal of time gathering information that can later be used to their advantage, for example, by persuading people to make investments or transfer money to fraudulent accounts.

Combining all of this with existing vulnerabilities gives attackers even more time to prepare an attack.

In my opinion, over the next two to three years, cyberattacks involving various technological solutions in their planning will become increasingly sophisticated and more difficult to detect and prevent in time.

Voice impersonation and deepfakes – one of the biggest cyber threats of the near future

Cybercriminals are becoming increasingly skilled, making voice impersonation and deepfakes another powerful weapon for financial gain and other malicious purposes.

Previously, a person receiving a fraudulent call could rely on recognizing the caller’s voice. Today, that confidence may no longer be enough. AI is capable of generating increasingly convincing voice imitations.

A striking example is the case in Singapore. It involved a highly sophisticated fraud scheme using deepfake technology. With the help of AI, scammers impersonated Prime Minister Lawrence Wong and other senior officials during a staged Zoom video conference, ultimately persuading the victim to transfer SGD 4.9 million to their account. We should expect the number of such cases to increase in the future.

Moreover, criminals are not afraid to cross moral and ethical boundaries. They are willing to imitate the voices of relatives, colleagues and even children. A parent may receive a call from an unfamiliar number, apparently from their child, asking them to urgently transfer money because something has happened.

In such a situation, it is important to keep a cool head. First and foremost, contact the person who supposedly made the call and verify whether they actually called.

The most common scenario involves being asked to transfer money, for example, to a police officer or doctor. But if we step back from such a call and consider the situation rationally, what problem could we actually solve simply by transferring money? None. Yet people often do not stop to think about this. And when the emphasis is on urgency, you should never rush into action. These are traps deliberately set by cybercriminals.

What about companies – how do criminals choose their targets?

There are two main types of attacks to distinguish here.

The first is a targeted attack against a specific organization. In such cases, attackers first conduct reconnaissance of the company, including gathering information about employees, the technologies they use and publicly available information.

The target may just as well be a specific employee – for example, an accountant or company executive. Once cybercriminals have gathered all the necessary information, they prepare an email that is designed to fit the company’s everyday communication style.

The second type of attack is much broader. Attackers scan IP addresses and search for vulnerabilities in order to gain unauthorized access to data or obtain other information of interest to them. Initially, they may not even know who owns a particular system, and that is not necessarily important. If an unpatched vulnerability is discovered, it can become an entry point for a further attack, including a distributed denial-of-service (DDoS) attack.

What should you do if you become a victim of cybercrime? Is there a way back?

Photo: magnific.com

Individuals should immediately contact their bank or the provider of their authentication service in order to stop any ongoing processes as quickly as possible. The next step is to report the incident to the police.

You should also change any compromised passwords as soon as possible, especially if the same password is used across multiple websites. It is also important to check the recovery email address linked to your accounts. If attackers have gained access to your email account, they can use it to reset passwords and thereby gain access to other accounts as well.

What should you do if one of your colleagues becomes a victim of a cyberattack?

If such a situation affects a company and an employee has clicked on a phishing link, entered a password or disclosed their own or company information, the biggest problem is that employees are often afraid of sanctions. As a result, they simply remain silent or refuse to admit what happened.

However, a potential threat can only be avoided if someone else in the company is aware of it. That is why the incident should be reported to the people responsible within the IT team as quickly as possible, so that further threats can be mitigated. In the event of a cyberattack, every minute counts.

CERT.LV specialists are taking a fairly proactive approach, both by reporting vulnerabilities and by offering their own scanning solutions. This provides a positive impetus and certainly helps strengthen resilience across Latvia’s digital environment.

What security measures should every company implement, regardless of its size?

Everyone – regardless of company size, number of employees or other criteria – should start by reviewing how their IT resources are managed, essentially looking at their “internal setup”: checking network connections and internal resources, how passwords are stored, and how quickly the company’s operations could be restored following a cyber incident.

It is recommended to conduct a vulnerability scan once a year to identify outdated software, incorrect configuration settings and other security weaknesses that cybercriminals could exploit.

Of course, a response plan should be developed in advance, with clearly defined areas of responsibility for each employee. A company cannot wait until its computers or databases have been encrypted before starting to think about implementing an incident response plan, because the consequences will be immediate and unpredictable.

In fact, many cyberattacks can be prevented simply by taking basic measures such as regularly updating the operating system.

One cybersecurity myth that is time to debunk

Unfortunately, some companies still believe that installing antivirus software and a firewall means the organization is protected from all threats. In reality, people themselves are the best firewall, which is why it is important to invest in regular employee training. Technological solutions and devices can do their job extremely well, but a person who carelessly clicks on a suspicious link or transfers money to what they believe is a legitimate account can cause lasting damage.

At BDA, we offer a wide range of professional development opportunities in cybersecurity for new specialists, experienced professionals and anyone who wants to stay up to date with the latest developments in the field.

The most in-demand training programs, with opportunities to obtain international certifications, include: