CERT-In warns of phishing campaign targeting CrowdStrike users after Microsoft outage: How to stay safe online | Mint
Active Stocks
Mon Sep 16 2024 14:59:54
  1. Tata Steel share price
  2. 154.20 0.52%
  1. Wipro share price
  2. 552.15 0.27%
  1. Tata Motors share price
  2. 988.10 -0.40%
  1. ICICI Bank share price
  2. 1,260.35 0.79%
  1. State Bank Of India share price
  2. 784.85 -0.72%
Business News/ Technology / News/  CERT-In warns of phishing campaign targeting CrowdStrike users after Microsoft outage: How to stay safe online
BackBack

CERT-In warns of phishing campaign targeting CrowdStrike users after Microsoft outage: How to stay safe online

A Microsoft outage on July 19 led to a phishing campaign targeting CrowdStrike users with fake emails, calls, and malware. CERT-In warns users to verify communications, avoid unverified software, use official updates, be cautious of links, and report suspicious activities to stay secure.o

CERT-In's website states that there are reports of an ongoing phishing campaign targeting CrowdStrike users leveraging this issue.Premium
CERT-In's website states that there are reports of an ongoing phishing campaign targeting CrowdStrike users leveraging this issue.

After the Microsoft outage on July 19, a global crisis struck Windows users, disrupting critical services like airports, banks, and telecommunications. This chaos stemmed from a defective update issued by CrowdStrike via its Falcon platform. The issue left Linux and Mac users unaffected.

Promptly, Microsoft and CrowdStrike identified the problem and released a fix. However, the aftermath has left CrowdStrike users vulnerable. The Indian government’s cybersecurity agency, CERT-In, has alerted the public to a phishing campaign exploiting this vulnerability.

CERT-In's website states, "There are reports of an ongoing phishing campaign targeting CrowdStrike users leveraging this issue."

The agency detailed several tactics used in the phishing attack, including fraudulent emails posing as CrowdStrike support, phone calls impersonating CrowdStrike personnel, sale of fake software scripts claiming to automate recovery from the update issue, and the distribution of trojan malware disguised as recovery tools.

In essence, this phishing campaign deceives CrowdStrike users with fake emails and calls, bogus recovery software, and malicious malware posing as legitimate recovery tools.

CERT-In warns, “These attack campaigns could entice unsuspected users to install unidentified malware, leading to sensitive data leakage, system crashes, and data loss."

To safeguard against this phishing campaign, follow these precautions:

  1. Verify Communications: Always confirm the legitimacy of emails and calls purporting to be from CrowdStrike support by contacting CrowdStrike directly through official channels.
  2. Avoid Unverified Software: Refrain from downloading or installing software scripts or tools unless they are verified and sourced directly from CrowdStrike.
  3. Verify official updates: Use updates and recovery tools exclusively from CrowdStrike or Microsoft’s official channels.
  4. Be Cautious of Links: Avoid clicking on links or downloading attachments from unsolicited emails or messages.
  5. Utilize security software: Make sure your system is equipped with the latest antivirus and anti-malware programs.
  6. Report Suspicious Activity: Report any suspicious communications or unusual activity to CrowdStrike and your cybersecurity team immediately.

By adhering to these steps, CrowdStrike users can better protect themselves from the ongoing phishing threat and ensure their systems remain secure.

 

 

3.6 Crore Indians visited in a single day choosing us as India's undisputed platform for General Election Results. Explore the latest updates here!

Catch all the Business News , Technology News , Breaking News Events and Latest News Updates on Live Mint. Download The Mint News App to get Daily Market Updates.
More Less
Published: 29 Jul 2024, 03:45 PM IST
Next Story footLogo
Recommended For You