During the COVID-19 pandemic, people are not traveling much – if at all. As a result, people could be more susceptible to travel loyalty account takeover (accounts that may include large amounts of personally identifiable information like driver’s license and passport numbers). They could also be more vulnerable to attacks because of past breaches and exposures like MGM, Marriott, Choice Hotels and Carnival Cruise Line, to name a few. Many experts are predicting a long, slow recovery to reach a sense of normalcy, while others believe “normal” will never be quite the same. One of the most impacted areas where that is expected is the travel industry.

With a 95 percent drop in passenger travel and most air passengers flying only in emergency situations, it could be hard for some to envision a speedy recovery for the travel and hospitality industries. For that reason, there is another precaution that consumers need to take in this time of quarantine: monitoring their travel loyalty accounts.

COVID-19 could make it easier for fraudsters to steal consumers’ credit card information, passport information, names, dates of birth, along with any other information included in a travel loyalty account. It could also allow scammers to steal credits and travel funds. In fact, one source cited an estimated fourteen trillion flight and hotel miles already go unused each year. That means a lot of travelers are saving up their bonuses or banking credits for unused trips but not cashing them in at the moment, which could attract hackers to travel loyalty accounts as a means to get their hands on PII as well as cash equivalent benefits.

Travel loyalty account takeover has been a problem for a long time. However, with people putting a halt to their travel plans for the immediate future, identity theft advocates like the Identity Theft Resource Center worry that those unmonitored accounts could be vulnerable to an attack due to lack of use or oversight. Account-holders need to protect themselves, and their accounts, in a variety of ways.

Fortunately, the steps that can help people protect their travel loyalty accounts are identical to the actions that users can take to secure any account type. First, people should monitor their account routinely for any signs of suspicious activity and report the activity immediately. Next, people need to be very cautious about clicking any links in emails, even ones that appear to pertain to travel loyalty credits or funds. Finally, people should secure their account with a strong, unique passphrase—one that is not easily guessed by hacking software and that is not reused on other accounts. It is also advised to change the account passphrase from time to time to prevent credential stuffing.

Anyone who believes they have fallen victim to travel loyalty account takeover is encouraged to live-chat with an expert advisor from the Identity Theft Resource Center. Victims can also call toll-free at 888.400.5530.


You might also be interested in…

COVID-19 Catfishing Scams Make a Rebound Amid Pandemic

CashApp Scams See a Rise Due to COVID-19

A Shift in 2020 Identity Theft Trends as a Result of COVID-19

Each year, the Identity Theft Resource Center (ITRC) reflects on the previous year’s exploits and anticipates trends for the next. When we first published our thoughts on 2020 back in December, it was stated that we anticipated the identity theft trends for 2020 would include 2020 being the year for privacy. While privacy remains an important topic, the recent changes in the landscape with other cyber issues have changed the conversation.

Data Breaches in Overdrive

Data breaches have continued to occur and the ITRC believes hackers and scammers will shift things into overdrive due to the amount of money that is about to flow through the economy, creating a redistribution of assets.

The coronavirus has forced most companies and their employees to work remotely. While that used to be a luxury, it is the new normal for many who previously haven’t had the experience. That has created a whole new challenge for companies, platforms, service providers and each individual employee.

In this post-COVID-19 shift, the ITRC anticipates breaches will continue to occur at an increased rate, both the number of breaches and the number of records exposed in a single incident. Given that there are a lot of new users that are creating an increase in user-data being housed in databases, it’s easy to see why this will be a potential outcome as a result of shifting workforces.

Increase in User Vulnerabilities Exposed

Security deficiencies are exposed daily, and more rapidly, because of the sheer volume of use of platforms. No one anticipated all of the vulnerabilities that would have to be fixed due to the increase in use. The ITRC has seen a massive shift in those priorities.

Now, issues that might have been well down the road to update need immediate attention because of how organizations have had to shift their use of products and services. Also, those providing those products and services must address the issues now to maintain the integrity of their users’ data.

There are other vulnerabilities with the new remote workforce that will be exploited as they become apparent over the course of the coming weeks and months.

Cybersecurity Issues Exacerbated by Remote Work

The previous 2020 identity theft trends that the ITRC predicted, in all likelihood, will happen. What is now new are the challenges that shifting to remote work as the primary method of working due to COVID-19 entail. All of the problems like ransomware, phishing attacks and patching are still going to be issues. However, they will be exacerbated by this shift in business being done by remote individuals. People who are not accustomed to working from home will be easy prey for hackers and scammers to exploit because of their lack of familiarity with platforms and processes.

Adding to that, companies that moved to stand up a remote workforce quickly may not have the proper policies, processes and employee training in place to guide their workers.

ITRC Is Here For You

Predictions like the 2020 identity theft trends are only educated guesses, based on previous events and information. Businesses, policymakers and the public will have to wait and see how the 2020 trends for identity theft, cybercrime and data privacy play out. Regardless of what happens the rest of 2020, the ITRC will be available, working to teach each person how to fight back against the techniques scammers will use to commit identity theft and support victims through the process of regaining their identities.

For a complete look at the ITRC’s 2019 Data Breach Report, click here.


Contact the Identity Theft Resource Center for toll-free, no-cost assistance at 888.400.5530. For on-the-go assistance, check out the free ID Theft Help App from ITRC.

You might also be interested in…

UPDATED 12/8/2020- With so many people working and socializing from home, more than just businesses – employees, families and friends – are trying to find a place to gather (hold virtual meetings, religious services, game nights, birthday parties and happy hours). Zoom has become “that meeting place” for most. According to the Chief Executive of Zoom, in December the video platform had approximately 10 million users, to currently over 200 million users.

While Zoom has become popular rather quickly, some of its security vulnerabilities have taken the spotlight too. Some of the recent Zoom privacy issues have included user data being sent to Facebook and a flaw leaving Mac users vulnerable to their microphones and webcams being accessed. Another Zoom privacy issue has included a lack of password protection. That has led to some meetings being “Zoom-bombed,” like an AA meeting where trolls harassed those participating in the recovery process.

Zoom executives have come out and said they are working to address the Zoom security problems, including enabling passwords by default in all future meetings, clarifying its encryption practices, releasing fixes for Mac-related issues and more.

In the meantime, there are few things users can do to make sure their Zoom meetings are secure.

Protecting Meetings

Zoom now offers its users multiple ways to protect their meetings. Users can secure a meeting with end-to-end encryption, create waiting rooms for attendees, require a host to be present before the meeting begins, lock a meeting and more. These features can be found in the host settings. These Zoom privacy measures can also help reduce the risk of someone getting into a meeting that does not belong and “Zoom-bombing” the meeting.

Protecting Data

According to Zoom’s website, recordings can be stored locally on the host’s device with the local recording option or on the Zoom Cloud with the Cloud Recording option that is available for customers who are paying for Zoom’s services. The meeting host can manage their recording through a secured interface and the recording can either be shared, downloaded or deleted. Zoom phone voicemail recordings are also processed and stored in the Zoom Cloud and can be managed through Zoom Client. Meeting hosts can manage the Zoom data settings in the settings tab.

Protecting Privacy

Zoom currently stores user email addresses, passwords, names, company names, phone numbers and profile pictures. Company names, phone numbers and adding a profile picture are optional for users. If a user is concerned about their Zoom security, they can elect to only provide their name, email address and password. Users will not be asked to provide any personally identifiable information and should report any message asking them to do so directly to Zoom because it could be a scam.

Oversharing

While Zoom has taken responsibility for its security issues, it is important users do their part. Oversharing their meeting information on social media can lead to some scary consequences, making it easier for others to join what was intended to be a private Zoom meeting. It could also lead to information in someone’s profile settings being stolen. To prevent oversharing, users should not post meeting information on any of their social media platforms. Instead, send the invitation directly to the person they would like to invite. Also, consider revisiting what level social media privacy and security settings are set – otherwise, users may be sharing more information than they intended with people they shouldn’t.

Avoiding Zoom Scams

Security issues are not the only problem Zoom is running into. Zoom phishing attacks are making the rounds threatening employees that their contracts will be terminated, and then asking recipients to input their login credentials in a fake Zoom login page. According to Check Point Research, scammers registered more than 2,449 Zoom-related domains from late April to early May.

There are also Zoom phishing scams saying people received a video conference invitation, like the one the Identity Theft Resource Center received that is pictured below. The email looks real because it is sent with “High Priority” as indicated by the red exclamation point. It is generically from “Zoom” and there is no name of the sender. However, if you hover over the email address with your mouse, it shows a full address that is gibberish. Do not click on links you are not expecting. Rather, go directly to your Zoom account to manage any invitations. At the bottom, there is also no contact information or business logo verifying it is the company.

Image provided by Identity Theft Resource Center

In a statement to NBC 7 San Diego, a Zoom representative said that there are three web addresses that may appear in a legitimate invitation.

  • Zoom.us
  • Zoom.com
  • Zoom.com.cn

The rest of the statement said:
Users across all services and technology platforms should be cautious with e-mails or links received from unknown senders, and they should take care to only click on authentic links to known and trusted service providers. Zoom users should be aware that links to our platform will only ever have a zoom.uszoom.com or zoom.com.cn domain name. Prior to clicking on a link, users should carefully review the URL, being mindful of lookalike domain names and spelling errors.

If anyone ever comes across a Zoom email they are not expecting, they should ignore it and go to their work manager to verify whether or not it is real.

The current times are unprecedented and people are doing what they can to stay connected. Zoom and other video conferencing platforms will continue to play a large role during these times – and beyond. However, being aware of some of the Zoom privacy pitfalls, and can be done to keep themselves and their information safe while they are on their next virtual meeting, game night or happy hour should be the first priority.

The current times are unprecedented and people are doing what they can to stay connected. Zoom and other video conferencing platforms will continue to play a large role during these times – and beyond. However, being aware of some of the Zoom privacy pitfalls, and can be done to keep themselves and their information safe while they are on their next virtual meeting, game night or happy hour should be the first priority.

If people have questions regarding their privacy settings, they are encouraged to contact the Identity Theft Resource Center through the website to live chat with an expert advisor toll-free.

For those that cannot access the website, call the toll-free hotline (888.400.5530) and leave a message for an advisor. While the advisors are working remotely, there may be a delay in responding but someone will assist you as quickly as possible.


You might also be interested in…

Due to concerns over COVID-19, more people than ever are working remotely or are furloughed temporarily. With World Backup Day coming up on March 31st, it is more important now than ever to talk about data security and backing up important systems. Usually, this is just a day set aside to understand more about personal privacy, cybersecurity and identity protection. This year, there is an additional focus on some of the lesser-known reasons for backing up those files.

Start with Strong Passwords

For many newcomers to the world of telecommuting, the tools that make it possible can be a little confusing. For World Backup Day this year, people can start by making a lockdown of their information a priority. Now is the best time to change the passwords on sensitive online accounts and to make sure that they are all strong and unique. This will help prevent data loss if a hacker takes over any accounts.

When thinking of a strong password, it’s okay for someone to make a fun passphrase. For example, the letters that spell out a favorite song or movie + the name of the account or service it provides (such as “Gmail” or just “email”) + a number that might mean something only to the person, like the first year their team won a championship or the year they got their driver’s license. Consumers can then repeat the process, changing portions for every unique account. Throw in a symbol or two, it will be virtually unguessable to a thief while giving the consumer an easy way to remember it.

Conduct a Privacy Checkup

Next, on to security settings. People should go through their apps and favorite websites, especially social media sites, and make sure their privacy settings are set to a comfortable level. If that was last done when the account was first established, it’s long past due time for a checkup. While people are at it, they can also back up all of their pictures and videos, any game information or recipes and anything else that they might have tucked away in an app but do not want to lose.

People should also back-up their smartphone or mobile device. By backing up all of their special photos – from their phone, their camera’s memory stick and their laptop – and securing them on an external storage solution, they will be protecting them from harm. Bonus: pass the time reminiscing while sifting through pics while saving them.

The Final Round

Finally, it’s time for people to look at their important documents like tax records, scanned images of paperwork they might need, any medical records that might have been emailed to them, and more. By saving all of those critical files to an external source, consumers will be better prepared to stop a ransomware attack. If a consumer is ever infected with ransomware, rather than paying the hackers money, they can put it towards safeguards knowing that all of their important content is safe.

Good Identity Hygiene Means People Can Relax a Bit

Even if people are not leaving their homes these days, they still need time to relax. So, kick back, settle in on the couch with a snack and favorite binge show and clear out the DVR if they have one. They can save anything they want to keep for later but can get rid of the rest and make room for more great content. While settled in, people can also pick up their phone and get to work backing up their stored data. They will be glad they did if something happens to their phone.

For more tips, hints, stats and other important points, consumers can check out this link to World Backup Day.

If you think you may be a victim of identity theft or need tips to help protect yourself, contact the Identity Theft Resource Center for toll-free, no-cost assistance at 888.400.5530. You can also live chat with one of our expert advisors. Find more information about current scams and alerts here. 


You might also like…

As the COVID-19 pandemic continues to grow and seriously impacts everyone across the country, so do the number of COVID-19 scams that will pop-up trying to get access to personally identifiable information (PII) and finances. It can be difficult to decipher which emails, phone calls, social media posts or text messages are scams versus legitimate ones. Scammers will always take advantage of new opportunities in a time of crisis like evictions and foreclosures assistance, unemployment benefits, stimulus payments, etc. Here are some tips to help navigate those emails, text messages and voicemails:

Go to the source

Unsure if something is legitimate? Go to the source of the potential assistance. That means if the offer of unemployment benefits seems to be uncharacteristic, go directly to the employment development department and check their website. If it has to do with housing – whether that’s eviction or foreclosure assistance – head to that source (local housing commission, banking institution, etc.). Don’t trust an inbound message that isn’t verifiable.

Unsure of how a fraudster might try to get consumers to self-compromise?

Based on experience, the ITRC anticipates that they will give these a go:

1. Government Checks: Consumers receiving an email or phone call from someone that claims they can ensure a check from the government for an individual right now; it is likely a COVID-19 scam. The government is still working on the details of how these funds will be made available as of the original date of this post. For specific details, consumers can always visit local, state or federal government websites to get the most accurate information.

2. Asking for Verification of PII: If someone calls asking for a Social Security number, driver’s license number, credit card number or bank account information, it is a high probability that it is a scam. Say “K, Bye”, hang up and call the company directly to see if the offer is legitimate. If it is real, they will have a record of the calls and offers that were made.

3. Pay Upfront for Government Assistance: The government will not ask consumers to pay upfront to get any of the relief money. Scammers have attempted this before with the “Federal Government Empowerment Money Program” scam.

4. Social Media: If consumers receive messages on a social media platform claiming to be the government for anything regarding COVID-19, anticipate that this is a COVID-19 scam, too. Report it to the social media platform and block the sender. The government does not contact individuals through social media. Additionally, posts or messages enticing individuals to “sign-up” to receive more information on how to get access to more information or funds should be considered gateways to compromising PII.

5. Emails: There are loads of phishing emails under the guise as COVID-19 help. If an email arrives that wasn’t expected, ignore it and go directly to the source to determine whether or not it is legitimate. Under no circumstances should consumers click on any links or open any attachments from unanticipated emails or texts. COVID-19 scams via phishing emails are going around right now attacking both businesses and consumers.

6. Phone Calls: COVID-19 phone scams are beginning to gain steam and something else consumers should be aware of. The advice for phone scams is pretty similar to email scams. Don’t answer calls from numbers you do not recognize and do not return calls from voicemails if you aren’t completely sure from whom the call originated. Should a call regarding COVID-19 assistance inadvertently get answered, say “K, Bye!,” hang up and directly call the source. Verify the legitimacy of the call.

7. Grandparent Scams: Grandparent scams have been around for a long time and play on the fear of loved ones. Recently, scammers have been posing as family members that are sick and need money to pay their medical bills. It is important for people to resist the urge to act, no matter how dramatic the story is. People should also never make a payment over email or the phone to someone they were not expecting to hear from. Instead, they should hang up and reach out to the mentioned loved one directly to see if they are okay.

Scammers Take Advantage of Public Events

Every time there is a crisis, natural disaster or newsworthy event, expect scammers to come out in full force looking to take advantage and play on the public’s fear of the unknown. It is important to not let scammers take advantage of us while scared and unsure of what to do. These tips should help reduce the risk of falling victim to a COVID-19 scam.

Contact ITRC For Free Assistance

You can call the Identity Theft Resource Center toll-free if you think you may have been a victim of any type of scam at 888.400.5530. You can also live chat with one of our expert advisors for assistance.

Don’t forget to download the ITRC’s ID Theft Help App to help in managing your identity crime case should you find that you are a victim of a scam.


Read more:

As news of a COVID-19 outbreak continues to grow, companies large and small are requiring more employees to work from home in an effort to create social distance. However, that is leading to an increase in the risk of COVID-19-related cyberattacks.

Potential Risks of Teleworking: Higher Rates of Phishing/Cyberattacks

With more than 10,000 breaches tracked since 2005, the Identity Theft Resource Center anticipates a rise in the cyberattacks on business infrastructure as more of their employees potentially work remotely from home. In 2019 alone, “hacking” accounted for 39 percent of all breaches.

Working Remotely Cybersecurity Tips

While people are working remotely, especially during an event like the COVID-19 outbreak, it is critical they follow the same security policies at home that they would at work.

1. Update all of your software including the operating system (Ex: Mac, Windows, Linux, Chrome) & applications; turn-on “auto-update” if you have not already

Hackers use known flaws that have not been fixed to break into business networks and home accounts. Keeping software updated prevents many attacks.

2. Add a stronger passphrase to your home Wi-Fi & wired networks

Many home wireless routers (and other Internet of Things or IoT devices) have easy-to-guess default passwords. Update them to stronger passwords, or use an even stronger passphrase (see below).

3. Update account passwords to a passphrase of at least 10 characters and give each account a unique passphrase you can remember

Gone are the days of changing our password every 30 days and Us1ng a C0mP1ex set of characters as your password. Current recommendations are to use a memorable phrase that you can easily remember – like a book title or movie quote.

4. Keep your work passwords and personal passwords separate to limit the potential of “credential stuffing attacks”  

Hackers use stolen passwords from data breaches to break into computer systems because they know the vast majority of people reuse the same passwords for both work and home accounts. Using the same password for your work accounts as your personal accounts could translate into fraudsters gaining access to one from the other.

5. Do not click on any email, attachment, text, social media post or weblink unless you know the source is real

Phishing attacks are not just for email anymore. And, hackers use near-flawless copies of real materials to fool people into clicking on the fake, but dangerous links or attachments.

6. Check websites and email addresses thoroughly to ensure it is the actual address of the company who sent it

The best way to avoid a phishing attempt is to verify the web or email address to make sure it comes from a legitimate company.

7. If anyone asks for personal data related to COVID-19, it is probably a scam

Scam artists take advantage of vulnerable people during times of crisis and they are using the current COVID-19 pandemic to get the attention of people online and on the phone. Never give personal information to any person or organization that contacts you unsolicited. 

ITRC is Available for Questions & Assistance

The Identity Theft Resource Center, based in San Diego, is operating at limited-capacity during the COVID-19 outbreak to ensure the health and safety of our staff, their families and the community. The ITRC will continue to assist individuals across the country who are victims of identity crime, data breaches and identity-based scams, including COVID-19-related scams. We are here for individuals and businesses who may have questions or need assistance with these scams. You can reach one of our expert advisors via our website Live Chat, toll-free phone number (888.400.5530) and email (itrc@idtheftcenter.org).


You might also be interested in…

Is This a Census Scam?
Fake Vendor Emails on the Rise 
Coronavirus Business Scam Targeting Employees 

There are more remote workers now than ever, either as telecommuting employees or freelancers. At the same time, more businesses than ever before are relying on these hard-working individuals to keep their companies in operation. The end result is people who don’t work in your building—or even live in your city—and who have never laid eyes on the boss may be the best line of defense when it comes to protecting your business from cybercrimes.

These remote workers can turn out to be the weakest link in the business cybersecurity chain. With their access to company servers, their connection via email to the onsite employees’ network and the fact that they are typically utilizing their own technology—whether it is virus-protected or not—these outsiders could be the avenue that savvy hackers use to deploy their malicious tactics.

Going through an outside source is nothing new for hackers. In fact, the infamous Black Friday breach of Target’s payment card system in 2013 happened because hackers sent a phishing email to a small HVAC repair company. This company had the contract to work on a number of Target locations in its area, and as such, had been connected to Target’s computer network. When hackers tricked an employee of the HVAC company into downloading malicious software on the smaller company’s network, they were able to infiltrate all of the POS systems for Target on the biggest shopping day of the year.

How can a company know that its outside freelancers or remote workers are not falling for phishing attacks? How will they know if those employees’ personally-owned computers and devices are password protected and have antivirus software installed? Without a system of checks in place, businesses are leaving a lot up to chance.

There are a lot of other hidden pitfalls these remote workers and companies face, as shown here, but fortunately, many of the same preventive measures that protect individuals can also protect businesses. Here are some tips on the employee’s end that can reduce the risk of a breach:

  • Locking down your Wi-Fi and your accounts with strong, unique passwords is crucial, and regularly changing your passwords is a good idea
  • Enabling two-factor authentication is a good idea too, as it can keep hackers out of a lost or stolen smartphone or laptop
  • Be sure that antivirus software is installed and up-to-date at all times, and consider using a VPN to hide your information when you are working online

For businesses and employees alike, the most important steps to take involve learning to spot the signs of suspicious activity. Know how to recognize a phishing email, and know what the proper steps are to avoid becoming a victim of a phishing attack. Make it a policy and all-around good habit to never click on a link, open an attachment or download a file that you were not specifically expecting. Create a workspace that rewards employees for verbally confirming even the simplest of commands and requests if there is any doubt that they are legitimate.

Companies have to work together from the top down to create a safe, effective workplace. Avoiding business cybersecurity issues can only happen when everyone works together and knows how to be safe.

If you believe you are a victim of identity theft, you can call the Identity Theft Resource Center toll free at 888.400.5530 to speak with one of our advisors or live chat with an advisor on our website. They will help you create an action plan for your case while directing you on the next steps you need to take.


For on-the-go identity assistance, check out the free ID Theft Help App from ITRC.

You might also like…

In what has become a frequent event, another company has fallen victim to exposing their sensitive company information to the entire internet, all because they failed to password-protect their web-based storage system. LimeLeads, a San Francisco-based company that matches individuals and businesses with potential leads, left its internal database of users unsecured. The LimeLeads overexposure was discovered by a hacker, who downloaded it and sold more than 49 million of the users’ information online.

This type of overexposure continues to happen because many of the systems that offer cloud-based or web-based storage to their customers have the password setting off by default. That might seem like a bad idea, given how many times in recent months this very scenario has happened. However, there are important reasons for not automatically locking everyone out of the system, especially when the company is transitioning to this service. As soon as the transition is underway, that default setting should be changed immediately to a password-protected setting.

Instead, too many companies leave it unprotected, never changing the default, which is what led to the LimeLeads overexposure. That means literally anyone who knows to look for it—or just gets curious and starts browsing around online—can find both the storage bucket and the contents. In this case, a security researcher who routinely looks for unsecured databases discovered it. Unfortunately, they did not discover it before someone else got to it first.

According to ZDNet, a hacker who goes by the name Omnichorus also stumbled upon the database. They then downloaded the contents and posted it for sale on the Dark Web. In many other events like the LimeLeads overexposure, the companies were lucky. They never found evidence that anyone else (before the security researcher who reported it) found or used the information.

Unfortunately, any time personal data is collected and stored, it is the responsibility of the new owner to keep it secure. The LimeLeads overexposure amounts to a data breach, despite the unintentional nature of the event, and those users’ records have now been compromised. Businesses must make comprehensive computer training and updates a priority in order to prevent issues like the LimeLeads overexposure.

If you believe you are a victim of identity theft, you can call the Identity Theft Resource Center toll free at 888.400.5530 to speak with one of our advisors or live-chat with an advisor on our website. They will help you create an action plan for your case while directing you on the next steps you need to take.


For on-the-go identity assistance, check out the free ID Theft Help App from ITRC.

You might also like…

A Golden Entertainment phishing attack is forcing the gaming company to see if any exposed information has been used in a harmful way and to look at ways to protect employees from possible attacks in the future.

There are many different ways that hackers can strike. From infiltrating entire networks to installing viruses and malware, their methods are varied and unfortunately, quite effective. A newly announced breach of one company’s employee email accounts shows how simple and effective it can be.

In what seems to be a phishing attack, hackers sent an email to an employee of Golden Entertainment, a company that manages casinos, distributed gaming venues and more. The email enticed the employee to follow through with some sort of instructions, which have not been released. Those instructions could have been to open an attachment, download a file, click a link or any other avenue that the hackers chose.

The end result was that the email contained malicious steps that gave the hackers access to email accounts for the employees. The report states that the unauthorized user(s) may have visited that account more than once throughout an eight-month period. As such, they were able to access sensitive emails, including some that had attachments. Those attachments included complete customer identities for some clients, including payment card data, Social Security numbers and much more.

The company has not found any evidence that the affected customers’ information was used in a harmful way, but they are being very cautious about their investigation and resulting steps.

The Golden Entertainment phishing attack is just another reminder that all companies, no matter how big or small and no matter what industry they are in, should have comprehensive employee training on how to respond to emails, messages and social media posts. Those trainings should include instructions on never opening an attachment or clicking a link that was unexpected, even if the email appears to come from a trusted sender. Instead, the employees should verify the instructions verbally before complying.

Failure to do so can lead to cybercrimes such as hacking, account takeover, ransomware and identity theft, as seen in the Golden Entertainment phishing attack. The high costs of the aftermath of these attacks can make anyone wish they had simply never clicked. Be sure you are doing all you can to protect yourself from attacks like the Golden Entertainment phishing attack by being able to spot a phishing attack and reporting it to your employer.

If you believe you are a victim of identity theft, you can call the Identity Theft Resource Center toll free at 888.400.5530 to speak with one of our advisors or live-chat with an advisor on our website. They will help you create an action plan for your case while directing you on the next steps you need to take.


For on-the-go identity assistance, check out the free ID Theft Help App from ITRC.

You might also like…