"What If My Account Was Compromised?" AhnLab Releases Security Tips to Prevent Secondary Damage
TECHWORLD ·
✦ Resumen de IA
AhnLab released additional security tips to prevent secondary damage caused by personal data breaches.
It recommended using different passwords for each service, managing email accounts with separate passwords, and setting up multi-factor authentication(MFA·two-step verification).
It also said users should regularly check login history and security settings and be careful about clicking links from unknown sources and entering personal information.
As personal data breach incidents have been piling up lately, concerns about secondary damage are growing. In response, AhnLab on the 2nd released security tips to prevent additional damage and introduced five account protection guidelines for users.
For tip No. 1, AhnLab recommended using different, independent passwords for each service and advised against using the same password across multiple services. It cited the possibility that leaked personal data could spread to account takeovers on other services. AhnLab also stressed that email accounts need separate password management, citing how often email accounts are used to reset passwords and verify identity for other services.
AhnLab also introduced tip No. 2, which is to set up multi-factor authentication(MFA(Multi-Factor Auithentication)·two-step verification), tip No. 3, which is to regularly check login history and account security settings, tip No. 4, which is to be careful about clicking links from unknown sources and entering personal information, and tip No. 5, which is to manage accounts saved in web browsers and keep security updates current.
In the service "account" and "security" settings, activating additional authentication methods such as an authentication app and OTP is recommended. Multi-factor authentication helps reduce the risk of account takeover when a password is exposed. It is also necessary to turn on login alert features.
In addition, access history and the list of connected devices need to be checked regularly. It is also necessary to verify whether the recovery email and phone number for the account have been changed without authorization, as well as whether multi-factor authentication methods have been changed without authorization. These measures are presented as countermeasures to lower the possibility of account takeover.
If access from an unfamiliar device is detected, the user needs to log in directly through the official app or website to check the account status. The same applies when receiving a password change alert that the user did not request; users should use the official app or website instead of the link in the message or email. If any suspicious signs are found, the password should be changed, and if necessary, the "log out of all devices" feature can be used.
Users should be careful not to click links of unknown origin sent via text messages, email, or messengers. They should also avoid entering account information or personal information on pages reached through such links. Personal data breach incidents can lead to secondary damage. Even when receiving related notification messages, it is necessary to verify the facts through the official app or website instead of the link.
In environments where a public PC is used, users must log out after finishing and should not use the auto-login feature. They should also not save passwords on public PCs.
AhnLab ASEC chief Yang Ha-young said that once account information or personal information is leaked, it can lead to additional attacks by attackers, adding that strengthening basic security measures in advance to prevent this is important. She also recommended using different passwords for each service and setting up multi-factor authentication, explaining that following everyday security practices helps reduce the risk of account takeover and secondary damage.
Source: TECHWORLD · Kim Hye-jin
Original: https://www.epnc.co.kr/news/articleView.html?idxno=407764
References
This article was produced with the help of an automated content generation algorithm.
Source: TECHWORLD
Ver originalThis article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.