Improve Your Defence Against Password Attacks
- MARCH 25TH, 2024
- 1min read
Introduction
The internet is increasingly facing threats from malicious actors. Credentials are the most common targets for hackers. Password-based attacks have become increasingly dangerous and common due to easy accessibility to password attack tools.
Recent significant incidents, such as the Microsoft data breach in January 2024, the RockYou2024 in July 2024 where about 10 billion passwords were leaked in plain text, and the Snowflake password leak in May 2024, highlight the critical importance of strong password security measures.
Password and Account Protection
- Use strong passwords and policies: Minimum 12 characters with uppercase/lowercase letters, numbers, and symbols.
- Avoid password reuse: Create unique passwords for each platform.
- Change passwords periodically: Organizations should enforce 90-day expiration policies.
- Do not share passwords: Avoid sharing with tech support, coworkers, or family.
- Avoid writing passwords: Do not store passwords on physical/digital notepads.
- Enable MFA: Add an extra security layer wherever possible.
- Use 2FA methods: SMS codes, email OTPs, hard/soft tokens, or biometrics.
- Zero trust policy: Never trust users/devices by default; always verify.
Additional Best Practices
- Beware of phishing: Avoid suspicious emails/links requesting credentials.
- Protect devices: Use antivirus software and keep OS/apps updated.
- Secure Wi-Fi networks: Use VPN on public Wi-Fi; protect home networks with strong passwords.
Explore more CIL Advisories
Phishing Emails
IntroductionPhishing attacks are becoming increasingly sophisticated, with malicious actors exploiting current events like the Paris 2024 Olympics Games to run…
DECEMBER 16TH, 2024
Read More
Preventing Deep Fake Scams
IntroductionMalicious actors always find creative ways to defraud unsuspecting individuals; deep fake scams are one of the latest ways with…
DECEMBER 9TH, 2024
Read More
Trouble Looms: Ransomware Attacks on the Rise
IntroductionRansomware is a type of malware which prevents you from accessing your device and the data stored on it, usually…
DECEMBER 2ND, 2024
Read MoreNever miss a CIL Security Advisory
Stay informed with the latest security updates and insights from CIL.