Craig Peterson's Tech Talk

A Client Said No Twice to a VPN Prompt, and the Login Traced Back to a Chinese Net Block

Informações:

Sinopsis

On Monday, a client of Craig's was driving down the road when a prompt appeared in the authentication app on his phone: was he trying to log into the company VPN? He said no. It appeared again. He said no again. Craig's team got him on the phone, changed his passwords, and started digging. The login was coming from a data center in New York — until Craig looked at the actual net block, which traced back to China. The attacker already had the man's email address, his VPN contact information, and his password. The prompt on his phone was the only thing standing in the way, and it worked because he answered it honestly twice. Where did they get it all? Craig ran the deep dark-web research his team does for clients and found the whole set sitting there. His advice to listeners is the free version of that same check: haveibeenpwned.com, run by Troy Hunt out of Australia — type in your email address and see where your information has already been taken. Craig spelled it out on air, P-W-N-E-D. The segment opened som