Can't find what you're looking for?
View all search resultsCan't find what you're looking for?
View all search resultsGeorge Do (Courtesy of Gojek)A recent study by accounting firm PricewaterhouseCoopers’ (PWC) cybersecurity team revealed that globally, hackers had intensified their phishing attempts by three times to exploit people’s fears and vulnerability as they were working and conducting most of their activities from home during the COVID-19 pandemic
George Do (Courtesy of Gojek)
A recent study by accounting firm PricewaterhouseCoopers’ (PWC) cybersecurity team revealed that globally, hackers had intensified their phishing attempts by three times to exploit people’s fears and vulnerability as they were working and conducting most of their activities from home during the COVID-19 pandemic. What can organizations and individuals do to shield themselves against such attacks? The Jakarta Post’s Sebastian Partogi recently spoke with Gojek’s chief information security officer, George Do, to explore the issue. The following is an excerpt from the interview, edited for length and clarity.
Question: What are among the methods hackers are using to prey on people’s fears and carry out cyberattacks during the COVID-19 pandemic?
Answer: First, everyone needs to be familiar with phishing and social engineering, and the basic understanding to never, under any circumstance, share one’s username and password with somebody else. An attacker, for instance, will send a phishing email saying “I am from the government and the government has this social assistance package that will be available to you, click on this link, register, log in and I’ll give you money in this tough situation”. Another familiar message would be from a healthcare provider and says, “hey, the building where you live has been identified as a hot spot for COVID-19, we need you to register here so we can track all the residents living in this building down”. These hackers continue to post fake news on how certain companies already have people infected in their building to gain readers’ trust and thus become more vulnerable to the phishing bait they send.
Organizations also need to be aware of malware and ransomware. For instance, several hospitals and healthcare organizations have gone through malware infections in their environments, what the malware did was encrypt their data, before sending an email “you have to pay me this amount of money so I can decrypt your data and give it back to you”. Essentially, holding another party’s data hostage is what we call ransomware. This time, hospitals and healthcare organizations need their data more than ever to take care of those who are sick.
Keeping those threats in mind, how can individuals and organizations protect their internet networks, especially when they conduct most of their activities – work and leisure – from home?
First of all, on a personal security level, step up on the security measures of your laptops and smartphones to protect against these attacks. When you work from home, maintain the basic security aspect of your Wi-Fi connection, by not using passwords that are easily guessable like "abc123" or "welcome". Be extra vigilant of messages that trick users to give away their usernames or passwords, especially messages from those disguising themselves as health care and financial service providers, as well as government bodies.
Meanwhile, on an organizational level, working from home requires a security paradigm shift. For instance, Gojek has always been a cloud company, allowing employees to interact with their devices straight to the cloud storage, therefore bypassing the security of workplace networks that utilize a virtual private network (VPN), where employees need to log in to the VPN before getting into the application you use. Thus, the security setting that we use will remain the same no matter if our employees work from home or in the office. By using multifactor authentication, user access controls, elements that are controlled within the cloud of the network, employees can freely travel anywhere and still attain the same level of security.
To secure your online conferences, especially video, go back to the basics: set a password for each participant, set up a blacklist and whitelist from your company for the conference, make parties external to your company queue in the conference virtual waiting room before you let them in. We also lock the copy-pasting feature down and disable attendees from sharing screenshots during the meeting in order to prevent them from taking over the meeting by doing that.
What are the barriers some companies face in adopting cloud technology?
Some factors that companies have taken into consideration are cost, processes and security protection issues. Once a company moves data storage to the cloud, they have to think, how can they build the same level of security with the new system and that’s not trivial, that’s why a lot of companies are still hesitant about doing that.
During the quarantine, people also conduct most of their shopping and financial transactions online from home. What can people do to prevent account takeovers?
Nowadays, almost all e-commerce and mobile banking platforms apply multifactor authentication for its users. For instance, on Gojek, besides requiring your ID and password to get in, we also use a combination of soft and hard tokens for you to get in, and we also use one-time tokens so they are not repeatable for both Gojek and Gopay services.
I also advise you to use a password manager, allowing you to manage hundreds of passwords for hundreds of different sites – banking, healthcare, shopping. When you use laptops and smartphones for work, make sure you have updated your antivirus to avoid outsiders stealing your data.
Share your experiences, suggestions, and any issues you've encountered on The Jakarta Post. We're here to listen.
Thank you for sharing your thoughts. We appreciate your feedback.
Quickly share this news with your network—keep everyone informed with just a single click!
Share the best of The Jakarta Post with friends, family, or colleagues. As a subscriber, you can gift 3 to 5 articles each month that anyone can read—no subscription needed!
Get the best experience—faster access, exclusive features, and a seamless way to stay updated.