Listen to this episode

How NOT to be a Vishing Victim

0:0028:02

Recorded April 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Erin, Craig, and BJ welcome back Jamel of the Gatekeeper team, who works in client success and explains how the proximity token and password management platform eliminates typed passwords. The hosts praise its mix of convenience and security, discuss a mobile app targeted for quarter two at the time of recording, and mention planned automatic password rotation.

The news discussion covers the Morgan Stanley breach, which Erin clarifies involved vishing, with scammers impersonating Morgan Stanley to trick clients into surrendering sensitive information, and a cyber attack against European satellite internet on the day the war in Ukraine began, which BJ says was attributed to Russian military hackers. Craig argues that password managers reduce phishing risk, that attackers are turning to vishing and smishing, and that banks could partner with Petronella Technology Group to issue Gatekeeper tokens to customers. BJ relays the Cybersecurity and Infrastructure Security Agency director's warning about possible Russian cyber attacks on US critical infrastructure, and the group debates cyberwar definitions, NATO policy, satellite vulnerabilities, and defense industrial base security. Jamel closes by saying most customers simply want help managing passwords.

Worth remembering

Key takeaways

  1. Craig says using a password manager instead of typing URLs or clicking email links keeps you safer from phishing.
    “what I like about gatekeeper is if you can get in the habit of not typing. Or manually typing the URL or clicking on any kind of links in the emails and you just use your gatekeeper solution.”
  2. Jamel warns that reusing one strong password across accounts creates a vector where hacking one gives access to all, so uniqueness matters.
    “But really all you're doing is leaving a potential vector point where someone can now hack one and get access to all.”
  3. Craig advises never clicking links, auto denying calls from numbers outside your contacts, and engaging your phone provider's filtering options.
    “never click on any links. Try to not accept calls, auto deny calls out of your contact list and engage your phone provider to help with some filtering options that they have.”
  4. Craig argues attackers are turning to vishing and smishing because phishing emails get caught by filters, and texts have much higher open rates.
    “I think the problems that they're having, or they're going to spam or getting caught by some of these phishing filters. So if they do that at the phone level, most likely they're going to get through.”
  5. BJ and Craig note that a Gatekeeper user could not simply hand over credentials to a vishing caller, since the token is also required.
    “If they would've done this vishing to someone who had gatekeeper and they would have asked for credentials and they would have been like, honestly, I don't know.”
  6. BJ relays the Cybersecurity and Infrastructure Security Agency director's message that the US government is preparing for a possible Russian cyber attack on critical infrastructure.
    “Basically she's saying that the U S government is making preparations in face of a possible Russian cyber attack on us critical infrastructure and businesses.”
  7. Jamel says the main reason people contact Gatekeeper is that they are tired of typing passwords, with compliance a secondary factor.
    “Honestly, the main reason is they're tired of typing passwords.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

A number of Morgan Stanley clients fell victim to a Vishing scam. "What is a vishing scam?" you ask… Great question! But if Morgan Stanley wasn't breached (this time), how exactly did the hackers know who to target?

Join the Petronella Technology Group team, along with Jamel from Gatekeeper, as we explore these questions and discuss what actions you can take to keep yourself safe from a vishing scammer.

Host: Craig Co-Hosts: Erin & BJ Special Guest: Jamel, Director of Client Success at GateKeeper***

If you are interested in GateKeeper's password management system for your home or business, please call us at 877-468-2721.

***Mention this podcast to get a FREE 30-Day Trial!***

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.