Northwest Arkansas Democrat-Gazette

Small businesses on defense after Equifax breach

- JOYCE M. ROSENBERG

NEW YORK — The Equifax breach is reminding small business owners that they could be vulnerable to cybercrimi­nals.

Companies that provide security and other technology services to small businesses say they’ve had an increase in calls from customers since Equifax revealed that the personal informatio­n of 143 million Americans had been exposed. The hack galvanized some owners into dealing with long-delayed problems.

“A customer called me today wanting to replace their one remaining XP computer,” says Bob Herman, owner of IT Tropolis, a tech service company in Fountain Valley, Calif. Microsoft stopped providing security updates for XP models three and a half years ago.

Small businesses often lag behind big companies in data security, not believing they might be targets. But 61 percent of the victims of breaches in 2016 were businesses with fewer than 1,000 employees, according to a Verizon survey. And experts say small companies are being targeted more because they don’t have the sophistica­ted defenses that big corporatio­ns do.

Still, Equifax says its systems were breached after it failed to correctly install a software patch designed to eliminate a vulnerabil­ity. Applying patches as soon as they’re available and watching for new ones are critical for a company to protect itself, experts say.

But many small business owners, sidetracke­d by other problems, don’t pay enough attention, says Diana Burley, a George Washington University professor whose expertise is internet security. Many don’t have staff members or vendors to monitor technology, and no plan to improve their security.

“When you’re in a crisis situation is not the time to develop a plan,” Burley says.

Small businesses can be harmed by cybercrimi­nals in a variety of ways. Here are some companies’ experience­s:

Towne & Country Building Inspection downloaded several apps to enhance the Google calendar the company uses for customer appointmen­ts. In July, owner Scot McLean noticed some glitches — an appointmen­t might disappear, or show up on another day. The problems persisted for about a week, stopped and started again. Then suddenly, four weeks of appointmen­ts vanished.

McLean’s staff member in charge of technology determined that the apps were vulnerable to hacking, and someone was able to log in and erase the appointmen­ts.

“The hack cost us thousands of dollars in lost revenue,” McLean says. Towne & Country was able to re-create part of the calendar, but most of the appointmen­ts were lost. Some frustrated customers didn’t rebook, turning instead to other inspection services.

The Bayside, Wis., company eliminated all apps as well as plug-ins that added features. It changed its passwords and set up two-step verificati­on, which requires a password and a single-use numerical code to log in.

Reuben Kats clicked on an attachment in an email nearly a year ago and soon found all the files of his website design business were encrypted and unable to be used. Grabresult­s.com was the victim of ransomware, or malicious software that hackers plant, hoping to extort money by holding a user’s files hostage until the hackers receive a ransom.

Kats avoided paying

because the Los Angelesbas­ed company’s files were backed up on a secure online service. Although infected computers can be fixed by returning them to factory condition, erasing all contaminat­ed files, he chose to buy a new one.

Kats realizes the culprit email had a phony address. Now he checks before he clicks.

“I make sure all emails are sent from the actual company domain name,” Kats says.

Hackers got into the website of Hyannis Whale Watcher Cruises in March 2016, just a month before the company’s seasonal boat trips were scheduled to start.

When website manager Melissa Marchand called the company that hosts the website, she learned there were 100,000 pages of pornograph­y on the site. This was a crisis: 90 percent of the Barnstable, Mass., company’s tickets are sold online.

Marchand contacted a computer security company that began removing malware from the website, a process that took two days. By the third day, the cruise company was selling tickets again. Marchand estimates it took six weeks for the number of visitors to the site to return to normal.

“Fortunatel­y, it was very early in the season. If this had happened in July, it would have been hundreds of thousands of dollars in revenue lost,” she says. The security firm now monitors the site, watching for signs of another attack.

Small businesses can become victims after hackers invade larger retailers such as Target or Staples and steal credit card data, or if informatio­n is stolen in other ways. A customer took a laptop to New York Computer Help in Manhattan for a screen repair and paid with a credit card, signing on an electronic signature pad. That night, owner Joe Silverman got a text from someone else asking why his card had been charged. The card was counterfei­t, and Silverman was out $650.

Silverman says he’s careful with emails that likely have phishing links or that ask if he’ll do cash transactio­ns, a hallmark of fraudsters. His website has safeguards against credit card crime. After this incident — not the first time he has been a fraud victim — Silverman and his staff are monitoring transactio­ns closely, including sending test charges to card issuers to be sure a card is legitimate.

Managers at Boom-sourcing got a notificati­on via one of its software programs in May that someone was trying to access its data without authorizat­ion. None of the business software company’s informatio­n was stolen, but “it woke us up to the vulnerabil­ities that a small business has,” manager David Hyde says.

 ?? AP/MORRY GASH ?? Towne & Country Building Inspection owner Scot McLean looks at his calendar outside his Fox Point, Wis., home last month. In July, Towne & Country was hacked, wiping out its reservatio­ns calendar.
AP/MORRY GASH Towne & Country Building Inspection owner Scot McLean looks at his calendar outside his Fox Point, Wis., home last month. In July, Towne & Country was hacked, wiping out its reservatio­ns calendar.

Newspapers in English

Newspapers from United States