Business travellers, ideal targets for cybercriminals

Phishing, public WiFi hijacking, hard drive copying... Business travellers are exposed to a wide range of risks. What preventive measures should be taken? Here are some answers.
cybercriminals-travel-business
Song_about_summer / Shutterstock.com

If we were to draw up a profile of the ideal prey for cybercriminals, it would be very similar to that of a business traveller. Not least because, while on the move, they have access to sensitive data while no longer protected by their company's firewall. According to David Grout, Technical Director for Europe at FireEye, mobile workers are exposed to several major families of threats. The first, and most radical, is the risk of inspection at border crossings: "Depending on local regulations, some countries, such as China, may inspect mobile terminals, and even copy the hard drive."he explains.

Also in China, the province of Xinjiang requires tourists and business travellers alike to install a tracking application that is presented as an emergency alert service, but which in fact also allows contacts to be exfiltrated from a smartphone. Didi Chuxing, the Chinese equivalent of Uber, is also said to be incorporating this type of "tracking application".spyware.

To minimise the amount of information exposed to misappropriation, David Grout advises people to travel light, especially if they are going to a high-risk country, with only the data essential to their mission: "I even encourage have two computersincluding one dedicated to travel, where the volume of on-board data will be limited."Another solution is encryption. This can involve only the hard disk, but also the files. This is known as high-level encryption. If a document is shared, your contact will need to have the password to decrypt it. Microsoft, for example, offers the BitLocker solution natively in certain versions of Windows. Note that some countries, including China, may prohibit data encryption or limit the level of encryption permitted.

Read also : "Cybersecurity: risk-proofing travel

Another risk, more clearly identified by travellers, is connecting to public WiFi or peer-to-peer networks. By way of example, state hackers, such as Russian (ATP 28 and ATP 29) and Chinese groups, have already hijacked a hotel's WiFi traffic or a trade show in order to capture data from VIPs at major international events. For Roxane Suau, Pradeo's VP Marketing, vigilance begins at the airport terminal. "Alongside the official airport WiFi, you have a myriad of networks from the shops. These can be created from scratch with a risk of data interception"she explains. "A hacker knows his target's habits. He knows which airport lounges he frequents, which hotels he stays in".adds Bastien Bobe, Lookout's Pre-Sales Manager for Southern Europe.

Business travellers must therefore disable WiFi and Bluetooth by default and use the company's virtual private network (VPN). New solutions, known as Zero Trust Network Access (ZTNA), also allow remote access - like VPN - but without incoming traffic or opening network ports. Failing that, sharing a connection from a 3G or 4G phone is preferable, especially in Europe with the end of roaming charges.

Another threat is targeted phishing, which can occur before a trip. On social networks such as LinkedIn and Instagram, the hacker examines the profile of his targets and anticipates their movements. "If the business traveller publishes a post inviting his contacts to meet him at a trade fair, the hacker will invite him to a VIP dinner at the event, for example.says David Grout. To do this, he asks them to register online with a login and password. Since people often use the same login and password, this criminal will be able to infiltrate these different accounts."

But phishing can also come from a text message, reminds Bastien Bobe: "SMS has become a priority channel, you receive a large number of notifications. All you need is the flight number of the business traveller to impersonate an airline and ask them to send a photo of their passport."A campaign of tests has shown some worrying results," he says.60 % to 80 % of users click on a link contained in a malicious SMS, compared with 20 % to 25 % for an e-mail."

The attack can also target the prey's entourage, for example a company director's assistant or press attaché. "By hacking into their smartphones, a hacker can access geolocationread messages, listen to phone calls, remotely trigger audio recording, etc.o", notes Bastien Bobe.

The risk is not just virtual. Laptops and smartphones can also be stolen. "A malevolent person entering a hotel room is not a crime. not just in spy films"warns David Grout. His advice: always keep your terminals with you or, failing that, put them in your hotel room safe. You should also systematically lock your sessions and set up two-factor authentication. Google offers a security key called Titan that connects to a USB port.

And if there is a theft, the business traveller must have been trained beforehand on what to do. According to David Grout, the company also needs to organise itself accordingly: "Take the case of a user whose mobile phone is stolen in China at 4am Paris time on a Sunday. If his employer has not set up a 24/7 serviceThe reaction will occur at best four or five hours later."Mobile fleet management solutions, known as MDM (Mobile Device Management) and MCM (Mobile Content Management), make it possible in the first case to geolocate a terminal and block it, and in the second to remotely erase data. As for EDR (Endpoint Detection and Response) technology, this involves placing an embedded agent in the machine that can detect threats in real time. This enables rapid investigation in case of doubt.

But prevention doesn't stop once the journey is over. To this end, some companies are making a "post-travel investigation"In extreme cases, it is necessary to ensure that the workstation is no longer reconnected to the company network. "A hacker may have injected malicious code and wait for the person to return to the country to activate it, thereby gaining control of the company's entire information system."concludes David Grout.

Insurance and assistance to cover cyber risksRawpixel.com / Shutterstock.com

A number of insurers, such as Marsh and Swiss Re, offer contracts for cover cyber risks. These insurers compensate companies that have suffered a data leak and provide them with IT, legal and crisis communication experts. Just over a year ago, Europ Assistance launched a personal data protection programme. Called CyberProtection by Europ Assistance, the service is based around prevention, data monitoring, alerts and 24/7 assistance.

Watch out for installed mobile applications!sipcrew / Shutterstock.com

When they are installed, some mobile applications ask for authorisation to access your personal data such as geolocation, contact list, audio and video recordings, even though they do not need this data to function. This data may be resold to partners.
By studying some fifty airline applications, Pradeo found that in 46 % of cases, they presented weaknesses in the security of data transmissionand even code vulnerabilities. "But these applications are sensitive: they record scans of your passport or even your credit card details."says Roxane Suau, VP Marketing at Pradeo.