Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,152,613 members, 7,816,517 topics. Date: Friday, 03 May 2024 at 12:31 PM

Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization - Computers - Nairaland

Nairaland Forum / Science/Technology / Computers / Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization (20442 Views)

Here Is How Microsoft Wants You To Secure Your Organization Against Cyberattacks / Experience 99.95% Uptime And Have Easy Access To Your Website Now!!! / Are Users Overusing Your Organization's Internet And Making The Network Slow? (2) (3) (4)

(1) (2) (Reply) (Go Down)

Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by danski: 9:39am On Oct 05, 2021
The Customer service week which holds every 1st week of the month of October has come to be recognized as the week we celebrate the importance of customer service and importance of the people who serve and support customers on a daily basis.

However in all of these celebrations lest we get carried away, do you know that the customer service desk is one of the most vulnerable channels through which a hacker could strike an organization, company or firm as the case maybe harvesting a large amount of data and informations about workers, customers and business partners in association with the attacked entity?.

Microsoft sometime in June 2021 suffered a cyber attack in which a device used by one of its customer service agents was breached and account details of customers were stolen and used to launch “highly targeted” attacks on customers.

When hackers strike companies like this, data such as Social Security Number, National Identification number, Bank Verification Number, Date of birth, Email addresses, Financial information, phone numbers and passwords which is generally known as Personally Identifiable Information (PII) gets stolen and sold to Identity thieves who possess the ability to do and undo with the details he/she has just acquired.

As an example, a cybercriminal manages to get hold of a user’s email credentials. Unfortunately for the victim, this email also contains banking informations with which unauthorized transactions can be done. This email also contains the user’s Facebook account, which also uses the same password as his email. In a single attack, the cybercriminal already gains access to a wide array of information—enough to perform multiple types of identity fraud.

Do not feel you run a small company so you have no reason to worry about data theft, you are wrong! Are you a law firm, logistics firm, gift card trading company, online dating business website, e-commerce store, hotel owner, school owner, hospital owner, church owner etc and you one way or the other receive even the littlest of details from the general public such as name, email addresses, phone numbers etc then the protection of your customers data is your utmost responsibility and this is predicated on the CIA Triad.



MEDIUMS THROUGH WHICH CUSTOMER SERVICE STAFFS MAYBE VULNERABLE

The Phone: Attackers usually obtain phone numbers from an organization’s website, in addition to any specific routing emails used for customer support. Attackers may call from a spoofed, blocked, or private phone number. An attacker posing as a customer can usually cull enough information from social media platforms and other sites to answer simple security questions. The attacker could also ask for a password reset. They may also try to change something on a customer’s account in order to have access to it themselves. They could also pose as fellow staffs and try to gain unauthorized privilege in the name of distress.

In a Pentest I was hired to do on a company in Lagos, all it took to get the Wifi Password was a spoof call to the IT guy and i was in their network ready to scan and exploit their system. As simple as it may sound, hacking an organization may most times not require complex techniques.


Email: Opening an email attachment from an unknown recipient as innocent as it may look may not be a good idea even where it seems to be from a known recipient, it just may be a spoofed email. For the helpdesk/customer service representative, however, it may be a necessary part of their job in the process of providing customer support. The attachment may be just an innocent screenshot documenting an order or transaction details which failed. However, there is every possibility that a malware is lurking in the attachment, and a social engineering attack is in progress.

In another job I had done in Ghana, access to one of the top level staff’s company email address simply required a spoof email from a supposed Project Manager handling a project for the company.



Bring Your Own Device (BYOD): Do you really want a ‘personal device on a private network linked to customers data’s? As a company, you may think of BYOD as a cost saving method but this is also dangerous as it leaves your organization vulnerable more especially where a malicious application has been written by threat actors to get into the network of an organization and spread over a local network with the customer service staff who brought his/her device to work as the main point of distribution. A classical medium through which ransomware could also spread if you ask me.



HOW TO PROTECT YOUR CUSTOMER SERVICE DESK FROM SUCH TYPE OF EXPLOITATION

These are not foolproof methods but an extra bit of carefulness would go a long way in securing data.

Adequate sensitization should be done on a regular basis. Letting help desk staffs know about the latest happenings in the world of Cybersecurity and how APT are being perpetrated by threat actors would go a long way.

Advising staffs against clicking unnecessary links and downloading of just about any attachments from customers and even fellow colleagues.

Sensitizing staffs about how they go about giving out just about any sort of information over a phone call from a supposed customer as this could be done by a person pretending to be an owner of an account they intend to attack.

As a Company Executive, the responsibility still falls on you as well to hire Cybersecurity firms, Pentesters and Ethical Hackers to conduct a regular Penetration Test on your organization in order to uncover vulnerabilities.

Make sure to make use of up to date versions of Softwares, Antivirus and a host of other applications which would see to the protection of your network and systems. Fake antivirus abound in the market created by Hackers as seen in the fake Amnesty International Antivirus so go for known and established brands.

When a staff is relieved of his/her job, endeavor to change passwords of any company related email that was controlled by the relieved staff as well as totally closing down of the email address. Employment of the doctrine of least privilege in your organization would go a long way.

Cybersecurity is important in the emergence of cyber attacks anybody can get hacked as long as there is a system, there is a vulnerability waiting to be exploited. All hands must be on deck to see to the protection of data of staffs and customers with the customer service desk being one of the channels requiring protection, attention and dedication towards a safer company.

With this I say, Happy Customer Service week!!!

This article was written by Sylvester Uduosa Esq. a Certified Ethical Hacker and founder of SLYTECH Entp. a Cybersecurity firm based in Nigeria which assists companies with Pentesting their networks and security with the sole aim of discovering vulnerabilities before criminals do and saving companies from losses that maybe incurred as a result of such vulnerability.

https://slytech.org/2021/10/04/customer-service-desk-an-easy-access-for-hackers-to-exploit-your-organization/

23 Likes

Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by Eagle360(m): 9:55pm On Oct 08, 2021
Insightful
Happy customer service week and thanks for your patronage Nairalander
1GB go for N300 this week @Obaloluwa Telecom
Twitter: ObaloluwaTel
Telegram: ObaloluwaTel

1 Like

Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by Bola146(f): 9:55pm On Oct 08, 2021
angry No where is actually safe for anyone in this country, no wonder those customer care misbehave to their customers. No smoke with fire especially money transfer and emptying innocent people's money sad

11 Likes

Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by revived: 9:56pm On Oct 08, 2021
E Go Be
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by cardoctor(m): 9:56pm On Oct 08, 2021
This has put the fear of God in me.
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by EshjayLee(m): 9:57pm On Oct 08, 2021
Okey na
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by Betterlife24(m): 9:58pm On Oct 08, 2021
I no dey like get bank issues with naija banks

6 Likes 1 Share

Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by Worldlegend(m): 9:58pm On Oct 08, 2021
Hh
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by Worldlegend(m): 9:58pm On Oct 08, 2021
Stil not bad
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by NobleAngell(f): 9:58pm On Oct 08, 2021
Wow! Interesting. I guess hacking isn't really much of a task for those that do it

2 Likes

Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by Homeboiy: 9:59pm On Oct 08, 2021
Hire a cyber security expert

Hire us
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by samtoles: 10:00pm On Oct 08, 2021
Do I have anything to say? No

So why did I comment? For the sake of commenting.
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by Imustreturn(m): 10:00pm On Oct 08, 2021
Una well done
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by kokkubabboni421(m): 10:02pm On Oct 08, 2021
Time and again, I reiterate
Almost every Nigerian have the tendency of stealing

2 Likes

Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by mayorcon(m): 10:03pm On Oct 08, 2021
If you are just joining this community, I say a very big congratulations to you because this is an immense opportunity like no other.

In the next few months to this time, this is going to become massive and highly competitive in Nigeria but you can count yourself lucky to be among the very first few that will partake in this.

So, I urge you to get prepared as you are about to add a new passive income to your portfolio.

NOTE: This is not a get rich quick scheme, so, if that is your reason for joining this group, kindly take your leave now but if you don’t mind making between #1,000 to #5,000 daily, then you are welcome to the right place.

However, there will be some guidelines that will be given, we will urge you to strictly adhere to them as they will guide you through success with this program and also, to keep the community sane.

The date and time will soon be announced for our first meeting where we will be discussing this opportunity in clear detail and where instructions and guidelines will be given.

Once again, you are welcome to the community of new moneymakers, you are welcome to WSA Partners.

I’ll talk to you again soon. Cheers.
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by merits(m): 10:03pm On Oct 08, 2021
grin
Ole gbogbo.
Ole gbe ole gba.
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by lonelydora: 10:04pm On Oct 08, 2021
A scammer hacked my sister's WhatsApp number and he is currently using the account below to collect money from her friends.

After many efforts to get back the WhatsApp account, the WhatsApp Help Desk asked us to wait for 6 days.

Please, is there anything we can at the moment?

This is the account her friends are sending money to.

Account number: Oluwasean Olasnkanmi Adekunle.
Acct number: 1484403350
Bank name: Access Bank



OAM4J and Mynd44 Please help push to front page.
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by karzyharsky(m): 10:05pm On Oct 08, 2021
Jxbx
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by Gandah(m): 10:11pm On Oct 08, 2021
shocked
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by Gidah: 10:12pm On Oct 08, 2021
Naija go also feel the wave when ordinary biscuit seller would like to operate digitally.your email and password na $1 for telegram.stay woke
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by seunlayi(m): 10:19pm On Oct 08, 2021
Alright
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by Ajenikoko89: 10:20pm On Oct 08, 2021
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by Lanre4uonly(m): 10:21pm On Oct 08, 2021
This is informative.
Happy customer service week to all our esteemed customers here on nairaland.
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by Winningbot: 10:21pm On Oct 08, 2021
sad
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by DropsMic(m): 10:23pm On Oct 08, 2021
Hmm
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by Bfss: 10:24pm On Oct 08, 2021
Ok
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by Dhavido(m): 10:29pm On Oct 08, 2021
Nice
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by drealcivilceno(m): 10:41pm On Oct 08, 2021
Good luck to y'all... Hackers and Hackees..
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by einsteine(m): 10:43pm On Oct 08, 2021
HR, Customer Service, Sales, any part of the organization where the staff have to interact with outsiders and open attachments as part of their jobs. A CV could have malware on it and the HR opens it and that's the start of an APT style attack that would be consummated some months later.
Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by tillaman(m): 10:55pm On Oct 08, 2021
shocked

1 Like 1 Share

Re: Customer Service Desk: An Easy Access For Hackers To Exploit Your Organization by Babiboy: 11:17pm On Oct 08, 2021
Yes

1 Like

(1) (2) (Reply)

How Can I Configure My Pc To Browse Using Phone As A Modem / I-worm/brontok.a Please Help Me Get Rid Of It / Will A 5000VA Voltage Stabilizer Damage Smaller Appliances Like LED TV?

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 29
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.