Natural Disasters: A Perfect Storm for Data Breaches

The recent wildfires in California have had a devastating impact, both in terms of human life and property damage. While we are all aware of how damaging these natural disasters can be, the fraud implications of these disasters are often overlooked.

Wildfires, hurricanes and other natural disasters present opportunities for bad actors to infiltrate and exploit the relaxation of security and the human condition to help.

Malicious actors are employing sophisticated phishing tactics to take advantage of the situation. Cybersecurity researchers at Veriti have identified numerous newly registered domains closely linked to the fires. These domains, such as “malibu-firecom” and “fire-reliefcom,” mimic legitimate services, luring unsuspecting victims with promises of fire evacuation assistance, recovery permits, and even fire coverage.

Scammers are also attempting to collect money in promise of helping wildfire victims while keeping the funds for themselves, as highlighted in this news article here. FEMA also issued a warning to wildfire survivors about attempts to steal identities in order to collect disaster funds. According to FEMA, criminals are attempting to obtain names, addresses and social security numbers to fraudulently gain access to a survivor’s legitimate FEMA grants.

In addition to individual victims, organizations can also struggle in aftermath of a natural disaster as they scramble to recover their data. This is often a challenging task, as data may be damaged or lost forever, and IT systems required to utilize the data may be disrupted. In addition, organizations are forced to prioritize humanitarian relief efforts over fraud prevention and data security concerns.

This can lead to a number of fraud related risks, including:

  • Identity Theft: In the chaotic aftermath of any disaster, it can be easy for the criminal element to steal sensitive identity data. This happens through physical theft of documents, or through targeted opportunistic cyberattacks.
  • Fraudulent Insurance Claims: Scammers will often pose as victims (see Identity Theft) of a disaster in order to file fraudulent insurance claims.
  • Fraudulent Donations: Scammers often create fake websites or social media accounts to solicit donations for disaster relief.
  • Real Estate Fraud: Scammers may pose as real estate agents or contractors and offer to help people find new homes, sell their properties, or repair damaged homes. They then steal the victim’s money and disappear.
  • Fraud Involving Deceased Persons: Scammers will pose as family members of the deceased in an attempt to access the victim’s bank accounts or other financial assets.
  • Credit Card Fraud: Scammers will steal credit card information from people who were displaced by the disaster and use it to make fraudulent purchases.

The phrase “Never let a good crisis go to waste” is based on the idea that people are more likely to be vulnerable to fraud during times of crisis and chaos. It’s part of the human condition. People are naturally more vulnerable when they’re stressed, confused, and desperate.

Scammers know this and they use it to their advantage as they prey on the victims of any natural disaster. This is why it’s important to remain vigilant during a crisis and exercise the Zero Trust model—never trust, always verify.

The connection between natural disasters and cyber attacks so inherently linked that FEMA has invested over $165 million in grant funding to bolster state and local jurisdictions’ cyber preparedness over the past 10 years. FEMA has also trained more than 87,000 federal, state, local, tribal, and territorial officials on cybersecurity over that same time period.

During Hurricane Ida in 2021 there were numerous cases of fraud reported, including an insurance adjuster from Texas who was sentenced to 20 years in prison. He was found guilty of pocketing more than $200,000 in insurance payouts meant for St. Charles Parish residents who filed claims to repair damage to their property following Ida, according to the St. Charles Parish District Attorney’s Office.

There are also major physical security concerns related to the chaos that takes place before, during and ager a natural disaster.

  • Tailgating: Tailgating is when someone follows an authorized person through a security checkpoint without being properly vetted. This is a common problem for law enforcement, businesses and organizations managing the movement of people.
  • Theft of Documents: Thieves will target businesses and organizations that have sensitive documents, such as financial records or customer information. Think about what happens during an evacuation when empty businesses are cut off from physical security controls such as security personnel and electricity.
  • Unaccounted Visitors: Businesses and organizations must have a system in place to track visitors and documentation during a natural disaster. This will help to prevent unauthorized people from entering the premises and accessing sensitive data.
  • Stolen Identification: Thieves will seek opportunities to steal identification cards, such as access cards, driver’s licenses, and passports in order to commit fraud or gain access to secure facilities.
  • Social Engineering: Social engineering is a type of attack in which the attacker deceives the victim into giving up sensitive information or taking actions that harm the victim. This includes manipulating an employee into giving up their login credentials or clicking on a malicious link that downloads malware onto their computer.
  • Door to Door and Drive by Contracting and Disaster assistance. Steer clear of any contractor who asks for full payment up-front, only accepts payment in cash, or refuses to provide a written contract.

In our expanded technological world, we all have access to more information than ever before. This can be a huge advantage in the scope of responding to and managing threats related to natural disasters. Of course, there is another, ugly side to that coin. The threat actors, scammers, and fraudsters all have access to some amazing technologies.

So, what’s the recommendation? How do we curb this type of threat activity?

Awareness training and incident response exercises extend beyond the walls of our companies. It’s fair to say that private individuals need to be aware of basic threats and how to avoid threat actor activities. Here are a few basic recommendations:

  1. Don’t panic. Yes, take care of your family as a first priority. Just don’t forget to breathe and observe your surroundings. Remain suspect of the people you engage throughout the disaster.
  2. Have a personal disaster recovery plan. Know ahead of time what you will do in the event of a tornado, hurricane, fire, etc. This is an old-school approach, but know your escape (map your destination), know where you will go, and know what you will need. Then, once you’re in a safe location take inventory of your family, and your sensitive materials. Know how you will address any missing sensitive materials such as credit cards, bank account information, passports, etc. Don’t forget to test (roundtable) and communicate your plan with everyone involved.
  3. Secure all documents and sensitive data. Use a fireproof safe for physical documents you need to maintain in physical form. Use encrypted cloud storage for all sensitive content. If you use an on-premises whole-house data storage device, I recommend that it is backed up to an encrypted cloud storage solution. As a general note, use multi-factor authentication (MFA) and complex passwords for any whole-house data storage solution.
  4. This one recommendation breaks my faith in humanity, but it needs to be stated in very direct terms. Don’t trust anyone. Disasters tend to bring out the worst in people. I am not recommending that you don’t accept any assistance. I am recommending that you validate everything offered. Yes, don’t trust anything and authenticate everything!
  5. Be wary of untraceable purchases or exchanges. In a disaster, bad actors will attempt to offer assistance, make sure all transactions are documented. Do not provide cash deposits or collateral, as this is a well-practiced method of fraud, after these incidents.
  6. Be prepared and don’t let the threat/bad actors and scammers profit from your loss.

 

The article above cites the following sources for its data:

Subscribe to Our Newsletter

This field is for validation purposes and should be left unchanged.
Select the Paperclip solution you are interested in.