Protecting Public Utilities: Bergen County Officials and Federal Partners Mobilize Against Cyber Threats
the staff of the Ridgewood blog
PARK RIDGE, N.J. — As digital threats targeting critical infrastructure continue to escalate nationwide, federal, state, and local leaders gathered in Park Ridge to spotlight new federal initiatives aimed at safeguarding municipal water and electric systems from cyber-attacks.
The AI Phishing Trap: Why the Upper Saddle River Police Are Warning You to Think Before You Click
the staff of the Ridgewood blog
Upper Saddle River NJ, In the quiet streets of Upper Saddle River, a new kind of predator is emerging—one that doesn’t need to break into your home to steal your most valuable possessions. The Upper Saddle River Police Department and the NJCCIC are sounding the alarm on a sophisticated wave of AI-powered cybercrime that is making traditional “red flags” a thing of the past.
NJ Cybersecurity Alert: Feds Warn of SSN Scams, Hidden Malware, and a Spiking Unemployment Fraud Wave!
the staff of the Ridgewood blog
UPPER SADDLE RIVER, NJ – The digital threat landscape in New Jersey is heating up, with new reports from the NJCCIC (New Jersey Cybersecurity and Communications Integration Cell) warning of sophisticated attacks targeting both public sector employees and citizens. From a surge in fraudulent unemployment claims to malware hidden in calendar apps and highly convincing phishing campaigns, here is what you need to know to stay safe online this week.
HAMILTON NJ, following Governor Phil Murphy’s proclamation recognizing October as Cybersecurity Awareness Month, the New Jersey Office of Homeland Security and Preparedness (NJOHSP) and the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) are ramping up efforts to promote cyber safety across the Garden State this month and beyond.
Ridgewood NJ, as Valentine’s Day approaches, threat actors may attempt to prey on individuals seeking companionship or romance. The NJCCIC continues to receive reports of sextortion incidents in which victims are threatened with the release of compromising or sexually explicit photos or videos if they do not pay an extortion demand. Some sextortion threats are not credible, as threat actors are unable to provide proof of such photos or videos. However, there is an increase in reported sextortion incidents in which threat actors pretended to be trusting potential love interests. In several recent incidents, threat actors posed as attractive females to target their victims, build trust, and convince them to send compromising or sexually explicit photos or videos.
Ridgewood NJ, Data Privacy Week is a global effort to empower individuals and encourage organizations to respect privacy, safeguard data, and enable trust. Every year, the National Security Alliance dedicates a week to recognizing the importance of data privacy and being informed about how information is used, collected, or shared in our digital culture. This year’s theme is to “take control of your data.” Online activity produces a wealth of data, which is collected by websites, apps, devices, services, and organizations all around the world. Although we cannot control every piece of information collected, users still have a right to data privacy.
Ridgewood NJ, according to Department of Homeland Security’s (DHS) 2024 Homeland Threat Assessment in the past month, there has been an uptick in reported ransomware incidents as threat actors continue to target New Jersey private organizations and the public sector, including school districts and local municipalities. The threat actors exploited security vulnerabilities and misconfigured devices to infiltrate systems and networks and encrypt them with ransomware variants, such as Cl0P, BlackCat, LockBit, and Akira. As a result of the attacks, files were at risk of exfiltration and contained personally identifiable information (PII) of users and customers of the victim organizations.
Ridgewood NJ, the NJCCIC observed multiple banking-themed phishing campaigns attempting to be delivered to New Jersey State employees to steal account credentials or personally identifiable information (PII). In one campaign, threat actors spoofed the display name for Customers Bank, which has multiple locations in the United States and New Jersey; however, the sender’s email address was unassociated to the bank. The subject lines may contain keywords such as notification, alert, action required, important verification, and important notification. The non-personalized email informs the target that a temporary hold has been placed on their account due to a failed identity verification. The target is then advised to click a link included in the email, which has been identified as phishing and malicious by VirusTotal.
Ridgewood NJ, in light of recent bank failures, the Cybersecurity and Infrastructure Security Agency (CISA) released an alert warning consumers to beware of potential scams requesting your money or sensitive personal information. Exercise caution in handling emails with bank-related subject lines, attachments, or links. In addition, be wary of social media pleas, texts, or door-to-door solicitations relating to any failed bank.
Ridgewood NJ, the Affordable NJ Communities for Homeowners & Renters (ANCHOR) program was developed to offset both the high costs of living and property tax burden, replacing the Homestead Benefit program and expanding the number of eligible taxpayers. Nearly 1.7 million New Jersey citizens applied for the ANCHOR property tax relief program by the February 28 filing deadline. The NJCCIC detected a series of phishing emails attempting to steal New Jersey residents’ ANCHOR program ID and PIN. These emails originated from similar IP addresses and the same subject line “ANCHOR Program Request for ID/PIN,” with some of the messages containing attachments. Further analysis also identified telephone-oriented attack delivery (TOAD) phishing attempts containing similar subject content as well as attempts to redirect payments. Recent open-source reporting indicates that threat actors may have filed fraudulent claims purporting to be NJ taxpayers.
Trenton NJ, on January 6, the NJCCIC observed a phishing campaign targeting New Jersey government employees. In this campaign, the sender claims to be from the employee’s human resources department announcing an annual vacation plan. A link leads to a phishing website where the employee is prompted to log in with their government email credentials. These emails spoof the display name of the sender email address to match the domain of the recipient, making the messages appear to come from a legitimate source in their organization. However, the sender’s hostname originates from the domain sumltomocorp[.]com, a website known for marketing spam URLs. Additionally, the link contains the recipient’s email address in the URL in another attempt to add legitimacy to the message.
Trenton NJ, Governor Phil Murphy today announced that the State of New Jersey has issued a cybersecurity directive to prohibit the use of high-risk software and services, including TikTok, on State provided or managed devices. The New Jersey Cybersecurity and Communications Integration Cell (NJCCIC), in collaboration with the Office of Information Technology (OIT), will maintain a list of technology vendors and software products and services that present an unacceptable level of cybersecurity risk to the State. The Directive will apply to all departments, agencies, commissions, boards, bodies, or other instrumentalities of the Executive Branch of New Jersey State Government.
Ridgewood NJ , New Jersey Cybersecurity and Communications Integration Cell also known as the New Jersey Office of Homeland Security and Preparedness’ Division of Cybersecurity, is warning residents businesses and organizations over multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code executionin the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
Ridgewood NJ, cybersecurity warn over New Jersey residents of Instagram accounts being hacked blocking access for the account holder. Additionally, maintain awareness of current tactics and techniques used to compromise online accounts which helps to Increase your Instagram likes with iDigic.