Introduction

Cyber criminals have been carrying out technical support scams for over a decade. As technology evolves, so do the techniques of fraudulent tech support scammers, making it difficult for people to discern whether the technical support team they’re speaking to is legitimate. Technical support scams are so common that the FBI’s Internet Crime Report of 2022 reported that ‘Tech Support Crime’ had over 30,000 recorded victims in 2022.  

Summary of a technical support fraud

Technical support scammers use many different techniques to trap people and gain access to their computers and other devices. After they convince you that there is a problem, they request an exorbitant fee in return for their help. Here are two of the most common methods technical support scammers use to trick their victims:

  1. Phone calls, emails and text messages – Technical support scammers may call, email or send a text message and pretend to be a computer technician from Apple, Microsoft, or any well-known technology company. They will assure you that there is a problem with your computer, and request that you give them remote access to your computer to help remediate the issue.
  2. Pop-up warnings – Technical support scammers may trick you with pop-up windows; it may look like an error or warning message from your device, and it may use similar graphics from trusted websites. The pop-up will often provide a phone number that you can call to get help. The phone number will lead to a fraudulent tech support worker.

Recommendations

  1. Stay Informed – Always be skeptical of unsolicited calls, emails or text messages that report a problem with your device.  
  2. Prevent Remote Access – When a technical support scammer has you on the line, they will convince you to provide them remote access to your device in order to run diagnostic tests. Do not provide remote access to your device.  
  3. Trust Your Instincts – If you are suspicious about an unexpected message, call, or request for personal information or money, it is safe to assume it may be a scam.  
  4. Stay Educated – Participate in security awareness sessions provided by your Richter Guardian team, your bank or other trusted organizations.  

We understand that misleading pop-ups or warnings about your device through a call can cause uncertainty. Richter Guardian’s monitoring system and concierge service can give you peace of mind.

Your onboarded mobile and endpoint devices can be monitored by us. If there is a problem with your device, we will contact you to provide specific details about any potential alerts. Our experts can help you remediate the issue.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Digital protection tips
Subscribe to newsletter

Subscribe to receive our latest news and insights in your inbox each week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Protect your digital life by detecting risks before they escalate

Richter Guardian gives you enterprise-level cybersecurity tailored for individuals, families, and executives.

24/7 monitoring & threat intelligence
Identity theft & impersonation detection
Fast incident recovery & expert guidance
Have questions after reading?
Blog

Related posts

Article illustration: Protecting Our Clients with Richter Guardian

Protecting Our Clients with Richter Guardian

A client fell victim to an Apple Support impersonation scam after a pop-up and remote access. See how Richter Guardian onboarded her, secured her devices, and restored her peace of mind.

The challenge

In our modern digital landscape, cybersecurity threats are an equal-opportunity challenge that can impact anyone, anywhere. As our world becomes more interconnected through technology, it’s crucial to recognize that cybersecurity isn’t just a concern for tech experts; it’s a shared responsibility that affects us all.

In one such case, a client found herself facing a daunting cybersecurity challenge. While browsing the internet, she received a pop-up message claiming that her computer was compromised by a virus. The message instructed her to call a specific number, which were impersonating Apple Support. Unfortunately, she fell victim to this scam, leading to a compromise of her computer.

The root cause analysis suggests that her computer might have been compromised during the installation of browser filters to block ads, where cybercriminals took possession of her computer system for 45 minutes. The client was distressed upon receiving a fraudulent invoice, wondering how this happened to her. This case study highlights the importance of cybersecurity and how Richter Guardian can offer a solution.

The solution

Richter Guardian, a comprehensive cybersecurity service offered by Richter, was instrumental in addressing this client’s situation. When the client reached out to Richter, our team quickly assessed the situation and took immediate action.

First, we onboarded the client to the Richter Guardian service, which includes social media protection, endpoint protection for devices (laptops, desktops, and mobile devices), and monitoring for compromised credentials on the dark web. This multi-layered approach ensured comprehensive protection for the client.

In addition to onboarding the client to Richter Guardian, we conducted a thorough analysis of her compromised computer. We also extended the protection to her mobile devices, ensuring her entire digital presence was safeguarded.

Furthermore, we educated the client on cybersecurity best practices, including the importance of strong, unique passwords and the use of two-factor authentication. We worked closely with her to ensure that her online accounts and data remained secure.

The result

The results of our intervention were significant. The client experienced several benefits from our Richter Guardian service:

Peace of Mind: The client no longer felt vulnerable to cyber threats. She gained confidence in her ability to navigate the digital landscape safely.

Device and Data Protection: All her devices, including her compromised computer, were fortified against potential threats. Her sensitive data was secure, and she no longer worried about cyberattacks.

Reputation Protection: Richter Guardian helped protect her online reputation by proactively monitoring for impersonation attempts and taking swift action to remove any fraudulent accounts.

Educational Insights: The client received valuable insights and recommendations to enhance her cybersecurity awareness. She learned how to recognize potential threats and avoid falling victim to scams in the future.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Article illustration: AnyDesk hackers infiltrated production servers

AnyDesk reports that hackers infiltrated its prodution servers and initiated password resets

AnyDesk confirmed a breach of production systems and code-signing keys; credentials of thousands of customers were later offered for sale. We outline implications and how to protect your accounts.

Introduction​

On February 2, 2024, AnyDesk confirmed a recent cyberattack that resulted in hackers gaining access to the company’s production systems. The breach involved the theft of source code and private code signing keys. ​

AnyDesk is a widely used remote access solution that is popular among enterprises for remote support and accessing colocated servers.AnyDesk became aware of the attack after they detected an incident on their production servers. Following a security audit, they identified a compromise on their systems and implemented a response plan in collaboration with CrowdStrike.​

Following the disclosure of the breach, cybersecurity company Resecurity promptly announced that an individual is attempting to vend the credentials of over 18,000 AnyDesk customers on a well-known cybercrime forum. The seller is seeking $15,000 in cryptocurrency for the compromised credentials.​

Implications and recommendations​

Although AnyDesk claims that passwords were not stolen in the attack, the threat actors still managed to successfully breach their production systems. ​

  1. If you use AnyDesk, modify your password. ​
    ​
  2. If the same password for AnyDesk is employed on other platforms, modify your password on those platforms aswell. ​

f you receive a call from someone purporting to be technical support or receive a pop-up regarding the safety of your device and you are unsure, call us to help you determine the legitimacy of their communication.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Article illustration: BMO Scam Highlighting Vulnerabilities in Two-Factor Authentication

BMO Scam Highlighting Vulnerabilities in Two-Factor Authentication

A BMO scam exploited two-factor authentication flaws to target customers. We break down the incident, implications for 2FA trust, and recommendations—including stronger options like hardware keys.

Introduction

A recent article published by CBC news highlighted a concerning scam that involved the Bank of Montreal (BMO). The scam managed to exploit vulnerabilities associated with the two-factor authentication (2FA) system of the bank. This advisory aims to provide an overview of the issue, its implications, and recommendations.

Summary of the incident

The scam primarily targeted customers with lines of credit. Perpetrators pose as bank employees and use a combination of phishing techniques and flaws in the 2FA process to gain unauthorized access to customers’ accounts, subsequently making unauthorized transactions.

Implications

  1. The trustworthiness of 2FA is at stake. Customers generally perceive 2FA as a robust security measure, but this incident underscores potential vulnerabilities.
  2. The scam demonstrates that even with the second layer of authentication, user accounts can be compromised if the process isn’t foolproof.
  3. Potential loss of customer trust in banking institutions due to such vulnerabilities.

Recommendations

  1. Stay Informed: Regularly update oneself about the latest scams and phishing techniques. Always be skeptical of unsolicited calls or emails asking for personal or banking information.
  2. Use Advanced Security Features: Wherever possible, use advanced security features like biometric authentication or hardware-based security keys.
  3. Monitor Accounts: Regularly check bank accounts for unauthorized transactions and report any discrepancies immediately.
  4. Stay Educated: Participate in security awareness sessions provided by your Richter Guardian team, the bank or other trusted organizations.

While 2FA is an essential security feature, it is not infallible. Richter Guardian clients should be proactive in understanding its limitations and continuously seek ways to enhance their security posture.

Contact us at anytime you are unsure. If you receive a call from someone purporting to be your bank and you are unsure, call us to help you determine the legitimacy of their communication.

Table 1 – Levels of two-factor authentication that may be available to protect your bank account.  

Type of 2FA Method Description Level of Strength of Security
SMS-Based 2FA Sends a one-time code to the user’s registered mobile number, which they then input to authenticate. Moderate – Vulnerable to SIM swapping attacks and interception.
Push Notification
(e.g., through an app)
Sends a notification to the user’s registered device, prompting them to approve or deny the login request. High – More secure than SMS-based, but can still be vulnerable if the device is compromised.
Token-based Authenticator
(e.g., Google Authenticator, Authy)
Uses a time-based one-time password (TOTP) generated by an app. The user enters the code displayed on the app. High – Not vulnerable to SIM swapping; however, a device compromise could pose risks.
Hardware Tokens
(e.g., YubiKey, RSA SecurID)
Physical device that generates or holds digital authentication data. Some require a button press to display a code, while others transmit the code when plugged into a device. Very High – Not susceptible to most common cyber-attacks. Loss or theft of the device is the primary concern.
Biometric 2FA Uses the user’s unique physical or behavioral characteristics, such as fingerprint, face recognition, or voice pattern. High – Difficult to replicate but isn’t immune to all attacks (e.g., high-quality replicas or recordings). Also, concerns about data privacy persist.
Email-Based 2FA Sends a one-time code or link to the user’s registered email address, which they then use to authenticate. Moderate – Security depends on the strength and security of the user’s email account. Vulnerable to email hacking.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.