(SPOT.ph) Reports of data breaches are in the news again, though they are still unconfirmed. But as cybercriminals grow more and more sophisticated, data breaches have become a real and constant threat.
Here are some steps you could take in case a data breach has been reported in an online platform you use:
1. Check if the breach is confirmed
First off, don’t panic. Experts recommend verifying first if the breach has indeed occurred. In the case of recent reports of alleged data breaches in the Philippines, there has been no confirmation yet. You can also check your accounts for anything strange, including email notifications about your accounts being accessed in an unusual location.
In the process, make sure you don’t fall for fake breach emails, another phishing method, according to digital security firm Aura. In this modus, cybercriminals send an email claiming to be from the company with an alleged data breach, asking you to click a link or confirm your account details. These links will lead you to hackers who will eventually take your data without your consent.
2. Contain the breach
If the breach is confirmed, there are several steps you could take for your own personal protection. The United Kingdom’s Information Commissioner’s Office (ICO) says you could “contain a cyber incident by changing all passwords" and encouraging others who may have been affected to do the same.
Aura says it is best to use unique passwords for different accounts. Make your passwords difficult to crack by using 10 to 12 characters, a mix of upper case and lowercase letters, and numbers and symbols. It would also be wise to avoid using personal information in your passwords, such as your actual name, birthdate, or hometown information that may be readily available online, particularly on social media.
“If you reuse a password that is compromised in a breach, it can put multiple accounts in danger. Always use a unique password for each account to minimize what scammers can do with your information,” Aura says.
You should also start using two-factor or multi-factor authentication to ensure that your accounts are well protected.
3. Assess extent of damage
If a breach has been confirmed, check the extent to which your account has been affected.
In case your financial information has been compromised, you may call your bank or reach out to your mobile wallet to ensure your account won’t get accessed by criminals.
If your healthcare information was leaked in a breach, Aura recommends reaching out to your health insurance provider for your latest records and claims to make sure no one else is using your benefits or that there are no unknown medical procedures charged to your account.
If the information about other people in your life were affected by your data leak, be transparent and let them know. The ICO says you may also advise them to change passwords for their banking and online account, or be on the lookout for phishing emails.
4. Report to the authorities
If you believe hackers have gained access to your data, you may report the incident to the National Privacy Commission (NPC).
According to the NPC, you will need to file a formal complaint. Print the complaint form, fill it out, have it notarized (electronic submissions must have digitally signed PDFs), and then submit it to the NPC. The form can be submitted in person, via courier service, or scan and email it to complaints@privacy.gov.ph. Attach any evidence and witness affidavits as necessary.
You may also approach a Data Protection Officer (DPO) at the NPC office located in the PICC Complex, Pasay City for some guidance in filing a complaint.
5. Practice good cyber hygiene
In the wake of a data breach, Aura recommends having a good look at your digital footprint, particularly your old and dormant accounts. In case there are online accounts you no longer use, best to delete them. You may also check if the software and operating systems in your devices are up to date, as “hackers use vulnerabilities in outdated software to hack you.”
It would also be helpful to make sure you don’t give away too much information on your public posts on social media. Aura says this is where fraudsters harvest information they could use to target your accounts.
Cyberspace is rife with risks. Personal responsibility and vigilance could go a long way in protecting yourself against the dangers that lurk online.
Also Read: How to Avoid Getting Hacked