CryptoChameleon

By Trilogy Financial
June 7, 2024
Share on:

CryptoChameleon is a phishing-as-a-service kit that makes it easier than ever for cybercriminals to create convincing phishing campaigns. Criminals often use it to impersonate reputable companies to steal passwords, account information, and other sensitive data.

 

A recent scam using CryptoChameleon targets LastPass, a popular password manager. Scammers pretend to be from LastPass, starting with seemingly authentic support calls. They later send follow-up emails with links to fake login pages, designed to look like legitimate LastPass sites. Once victims enter their master passwords on these fraudulent pages, scammers can access their password vaults and potentially lock them out of their accounts.

 

Reputable companies will never ask for your master passwords through phone calls, emails, or text messages. To protect yourself from these scams, remember to:

 

  • Hang up immediately if you receive a suspicious call claiming to be from LastPass or another reputable company.
  • Do not press any options in automated messages or clicking on links in emails from unfamiliar sources.
  • Report suspicious activity to the reputable company, including screenshots of suspect text messages and forwarded emails.

You may also like:

By
Mike Loo, MBA
June 21, 2018

Regardless of where it comes from, getting an unexpected chunk of change usually makes for a pretty good day, week, or even year. But if you aren’t intentional about what you do with your extra cash, you could follow in the footsteps of many lottery winners who squander their winnings and end up unhappy and broke.1  Even if the gift you receive isn’t a significant amount, you’d be amazed at how some smart planning can make a big difference down the road. Let’s look at some ways you can you use your raise, refund, or windfall to get ahead financially.

  1. Pay Off Debt

Big debt, small debt, it doesn’t matter. Debt is debt. Start with high-interest debt and work your way down. Did you know that the average American household carries over $16,000 in credit card debt and pays an average of $1,292 in interest annually?2  Sure, using your extra influx of money to reduce debt isn’t as fun as going on a trip, but think of the satisfaction you’ll feel when you see your balance decrease, knowing that you are saving yourself thousands of dollars in interest in the long run.

  1. Beefing Up Your Retirement Savings

Even if you diligently contribute to a 401(k) or IRA, chances are you aren’t maxing out those accounts. Let’s say you receive a $3,120 tax refund, the average amount according to the IRS.3  You then deposit that $3,120 in an IRA and see a 7% rate of return annually. In 20 years, you will have earned approximately $8,000 on that investment due to compound interest. Let’s go a bit further. If you invest your tax refund every year for 20 years, your retirement savings could see a boost of almost $150,000! If you’ve received a raise, use some of it to increase your contribution percentage right away. That way, you won’t get used to living with that extra money and it puts you ahead for the future.

  1. Invest In Education

Most of us dream of our kids going to a great school and getting a solid foundation for their future career, but have you considered how much of an investment it will take to get them to that point? The numbers can be daunting. These days, a high school graduate can expect to pay upwards of $200,000 for an undergraduate degree at a top school4 and over $10,000 each year for in-state tuition alone at a public institution.5  The costs will vary depending on room and board and other educational costs, but either way, it’s a lot of money.

One option is to open a 529 account with your tax refund and, once again, let compound interest help you get ahead. Not only will your investment pave the way for your child’s future, but it could also give you a tax break.

  1. Build Your Emergency Fund

An emergency fund provides you with a cushion for those times when life gives you lemons. If you don’t have readily available savings, something as simple as an unexpected car repair or medical bill could derail your finances. Or, if you know you have a large purchase or a life milestone approaching, such as welcoming a baby into your family, having an emergency fund will help you avoid digging into long-term savings or going into debt to cover costs. You can’t put a price on the peace of mind that an emergency fund will give you, so think about investing some of your tax refund to boost your short-term savings.

  1. Be Generous

Giving your tax refund away may not help you get ahead, but it could make a lasting impact on someone else’s life. Find a charity or cause that is close to your heart and pay it forward. Your gift could also help you when the next tax season rolls around. Just make sure to get a receipt for your contribution and itemize your deductions.

Have You Received Some Extra Cash?

It’s okay to treat yourself when you find yourself with excess income, but don’t splurge just because the money is there. Make a list of your financial priorities and then map out how your additional money could give your financial future a boost. If you would like guidance on how to use your raise, refund, or windfall, call my office at (949) 221-8105 x 2128 or email me at michael.loo@lpl.com.

By
June Adams
May 10, 2021

Weak passwords can compromise the best security tools and controls. With a never-ending list of applications and services that users and consumers access, people may have dozens of passwords to maintain at any given time. Often, the temptation to use familiar terms such as pet names, favorite teams or the names of children or friends can cause risk since much of those details can be discovered by a simple examination of social media.

Creating strong passwords offers greater security for minimal effort. Weak passwords can compromise the best security tools and controls. With a never-ending list of applications and services that users and consumers access, people may have dozens of passwords to maintain at any given time. Often, the temptation to use familiar terms such as pet names, favorite teams or the names of children or friends can
cause risk since much of those details can be discovered by a simple examination of social media.

Under Lock and Key
You can buy a small padlock for less than a dollar—but you should not count on it to protect anything of value. A thief could probably pick a cheap lock without much effort, or simply break it. And yet, many people use similarly flimsy passwords to “lock up” their most valuable assets, including money and confidential information. Fortunately, everyone can learn how to make and manage stronger passwords. It is an easy way to strengthen security both at work and at home.

What Makes a Password ‘Strong’?
Let’s say you need to create a new password that’s at least 12 characters long, and includes numerals, symbols, and upper- and lowercase letters. You think of a word you can remember, capitalize the first
letter, add a digit, and end with an exclamation point. The result: Strawberry1!

Unfortunately, hackers have sophisticated password-breaking tools that can easily defeat passwords based on dictionary words (like “strawberry”) and common patterns, such as capitalizing the first letter.
Increasing a password’s complexity, randomness, and length can make it more resistant to hackers’ tools. For example, an eight-character password could be guessed by an attacker in less than a day, but a 12-character password would take two weeks. A 20-character password would take 21 centuries. You can learn more about creating strong passwords in your organization’s security awareness training. Your organization may also have guidelines or a password policy in place.

Why Uniqueness Matters
Many people reuse passwords across multiple accounts, and attackers take advantage of this risky behavior. If an attacker obtains one password—even a strong one—they can often use it to access other valuable accounts.

Here is a real-life example: Ten years ago, Alice joined an online gardening forum. She also created an online payment account and used the same password. She soon forgot about the gardening forum, but someone accessed her payments account years later and stole a large sum of money.

Alice did not realize the gardening forum had been hacked, and that users’ login credentials had been
leaked online. An attacker probably tried reusing Alice’s leaked password on popular sites—and
eventually got lucky.

Guarding Your Passwords & PINS. Passwords and PINS protect sensitive data and it's critical to keep them safe. Try these best practices to stay protected.

1. Do not write them down – Many make the mistake of writing passwords on post-it notes and
leaving them in plain sight. Even if you hide your password, someone could still find it. Similarly, do
not store your login information in a file on your computer, even if you encrypt that file.
2. Do not share passwords – You cannot be sure someone else will keep your credentials safe. At
work, you could be held responsible for anything that happens when someone is logged in as you.
3. Do not save login details in your browser – Some browsers store this information in unsafe
ways, and another person could access your accounts if they get your device.
4. Use a password manager – These tools can securely store and manage your passwords and
generate strong new passwords. Some can also alert you if a password may have been
compromised.
5. Never reuse passwords – Create a unique, strong password for each account or device. This
way, a single hacked account does not endanger other accounts.
6. Create complex, long passwords – Passwords based on dictionary words, pets’ names, or other
personal information can be guessed by attackers.

 

 

 

Get Started on Your Financial Life Plan Today