Opens in a new tab
vmblog logo 2024 wht (updated)

Businesses Need a Full Court Press on Cybersecurity During March Madness

Share: 

David Marshall | Published: March 11, 2022

 

March Madness is almost here. The official kickoff starts with Selection Sunday this weekend and the beginning of the Round of 64 next week.

March Madness is one of the most watched, and anticipated, sporting events every year here in the US. What makes it most intriguing is that it’s the only major sporting event in the US that traditionally falls during our business day and those who participate in viewing and playing in their “office pools”, are susceptible to a variety of security threats, especially those dreading phishing lures. The same goes for those who utilize online sportsbooks taking bets on the games.

Cybercriminals will use any major event or tragedy that has captured the attention of the general public as bait for attacks. While folks are caught up in the excitement of the games and their brackets, bad actors will be plotting to steal your credentials, lure you into fake websites and deploy ransomware that could wreak havoc on you, or your organization, long after the conclusion of this year’s tournament. The increased interest from users and the dramatic spike in emails, links and other communications related to the event make it much easier for these actors to blend in.

++

Jasmine Henry, Field Security Director at JupiterOne, a Morrisville, North Carolina-based provider of cyber asset management and governance solutions:

While all major sporting events can create a spike in phishing scams, fake domains, and adware, March Madness creates a unique amount of risk to employers since it takes place during business hours when fans are generally using work-issued devices and network resources. 

Security leaders should consider if a brief update to their acceptable use policy could lower March Madness security risks. If official NCAA and ESPN web properties are blocked on the network, sports fans will find alternative ways to watch the streams and may end up using sketchier, malware-riddled websites to get around the policy. 

Security pros should also communicate with users about which risks to look for in their inboxes and text messages, including links, attachments, and bracket invites that are sent by a threat actor instead of a colleague.

++

Hank Schless, Senior Manager, Security Solutions at Lookout, a San Francisco, Calif.-based endpoint-to-cloud security company:

March Madness is a popular time for betting pools and bracket challenges. Employees often use websites, online platforms, or shared spreadsheets to organize. There are countless ways that an attacker could entice an individual to engage with them including the promise of bigger winnings or insider information about teams. Threat actors could see this as low-hanging fruit for social engineering and phishing by simply spoofing the URL of popular sports and betting websites like ESPN, DraftKings, and FanDuel. There have also been recent reports of attackers using fake share links from Google Drive and Office 365 to trick enterprise users into giving up their login credentials, which is a tactic that could realistically be used here as well. 

Phishing has become the most popular way for attackers to gain initial access to corporate infrastructure. Heavy reliance on the cloud means users can log in from anywhere, which is great for enabling productivity but introduces risk if your IT and security teams don’t have visibility into the context under which users access apps and data. Attackers use events like March Madness as a way to entice their targets and get them to overlook any red flags that indicate malicious intent. When it comes to phishing for credentials, a simple text or social media message can be highly effective. 

In order to protect against the risk of unauthorized users gaining access to sensitive data, it’s important to be able to detect and block phishing attacks as well as inspect web traffic from any device to cut connections to malicious sites. In addition, you need to have visibility into the context under which users are logging in to your infrastructure and access data. Anomalous locations, devices, and number of login attempts can all be signs of compromised credentials.

++

Ray Kelly, Fellow at NTT Application Security, a San Jose, Calif.-based provider of application security:

The chaotic atmosphere of March Madness provides the perfect cover for bad actors looking to commit cyber crimes. Popular sports and betting apps typically do a good job of remediating critical vulnerabilities as soon as they are identified. However, fans of March Madness need to make sure to update mobile apps often, as security fixes are deployed within these updates via the App Store, Google Play, etc…

Users are more likely to have their personal information compromised through targeted email or SMS phishing campaigns. It’s relatively easy for hackers to create emails or landing pages that look legitimate and lure users to enter their personal information into a malicious site. A good rule of thumb is to never open links sent via email. Rather, it’s much safer to always go directly to the website or mobile app.

++

Joseph Carson, chief security scientist and Advisory CISO at Delinea, a Redwood City, Calif.-based provider of privileged access management (PAM) solutions:

With March Madness nearly upon us, working professionals and sports fans alike are starting to prepare schedules to fill out their bracket and stream the games online.  

We are a society of clickers; we like to click on things. Hyperlinks for example. Always be cautious of receiving any messages with a hyperlink. Before clicking, ask yourself – “Was this expected?”, “Do I know who is sending this?”. On occasion, check in with the actual person whether they actually did send you an email before you aimlessly click on something in which might be malware, ransomware, a remote access tool or a virus that could steal or access your data. Before clicking, everyone needs to stop and think. Check the URL, make sure the URL is using HTTPS, also that this URL is coming from a legitimate source. Discover where the hyperlink is taking you before you click on it as you might get a nasty surprise.   

Stay safe while watching March Madness and avoid becoming the next victim of cybercrime. This year’s tournament should be a time to relax, enjoy the amazing games and making sure that you always stop and think will help prevent you from a cybersecurity nightmare.

++

Richard Fleeman, Vice President, Penetration Testing Ops at Coalfire, a Westminster, Colorado-based provider of cybersecurity advisory services:

Here are a few tips:

  1. Consider managing office pools via the old school methods of manual tracking and utilize one person to coordinate. If you use a document to track, consider sharing that document via Box, Google Docs, etc…
  2. Consider using known and trusted platforms for March Madness brackets, tracking, bets, and spreads. Stick with the known Yahoo, ABC, ESPN, etc.
  3. Continue to maintain proper cyber hygiene – use multifactor authentication, use a password vault to generate unique passwords,  take time to inspect email headers, URL links, do not open unknown attachments, bookmark and log directly into the online platform rather than clicking links in an email etc. 
  4. Be wary of applications leveraging common authentication frameworks and third party trust – i.e. do not hastily allow applications to utilize common authentication frameworks such as Google auth or Facebook without inspecting the elements that the application is requesting access or trust to. Blindly permitting access and trust could potentially open your accounts to compromise.

##