Public urged to be aware of post-data breach scams

29 Jan 2021 11:19 AM

New NCSC guidance helps people stay safe online when cyber criminals use information from data breaches to try and steal sensitive personal data.

CYBER security experts have today issued new guidance to help individuals avoid being scammed following data breaches against organisations.

With nearly half of UK businesses reporting a cyber breach or attack in the past year, the National Cyber Security Centre (NCSC) – a part of GCHQ – has produced guidance to help individuals and families stay safe in the aftermath of a breach.

Criminals can use information taken from a breach, such as email addresses, to send phishing messages to try and trick people into handing over sensitive personal data like credit card details.

The guidance – published on international Data Privacy Day – explains what data breaches are, how they can affect people, and steps to take if their data may have fallen into the hands of cyber criminals as a result of a breach.

For example, if people receive a message that includes a password they have used in the past, the recommendation is to change the password immediately to one that uses 3 random words.

The majority of scams against individuals can be defended against the majority of the time by following the six behaviours set out in the cross government Cyber Aware campaign – and the NCSC is encouraging people to follow the advice set out at www.cyberaware.gov.uk.

Sarah Lyons, NCSC Deputy Director for Economy and Society, said:

“With so many aspects of our lives now managed online, people understandably want to know that their personal data is secure.

“Data breaches against organisations might seem like distant events, but they can have real-world consequences to individuals.

“I encourage everyone to follow the steps in our ‘Data Breaches: Guidance for Individuals and Families’ to help you stay secure online.”

The guidance, Data breaches: guidance for individuals and families, sets out the steps to take if your data may have fallen into the hands of cyber criminals as a result of a breach, including

Alongside the new advice, the NCSC is encouraging anyone who receives a suspicious text message – such as those relating to the NHS coronavirus vaccination campaign - to forward it to 7726. Suspicious emails should be forwarded to report@phishing.gov.uk.

Those who do fall victim to online fraud should contact their bank immediately and report it as a crime to Action Fraud.

The NCSC is also delivering the cross government ‘Cyber Aware’ campaign aimed at helping people in the UK to stay as secure as possible when online.

The Cyber Aware campaign encourages the public and small businesses to adopt six behaviours to protect their online accounts and devices. These are:

The campaign is supported by leading organisations such as Microsoft, Vodafone, BT, ASOS, Barclays and Citizens Advice, who are actively helping their customers adopt Cyber Aware’s key behaviours.

* Cyber Security Breaches Survey 2020