
If we were to draw up a profile of the ideal prey for cybercriminals, it would be very similar to that of a business traveller. Not least because, while on the move, they have access to sensitive data while no longer protected by their company's firewall. According to David Grout, Technical Director for Europe at FireEye, mobile workers are exposed to several major families of threats. The first, and most radical, is the risk of inspection at border crossings: "Depending on local regulations, some countries, such as China, may inspect mobile terminals, and even copy the hard drive."he explains.
Also in China, the province of Xinjiang requires tourists and business travellers alike to install a tracking application that is presented as an emergency alert service, but which in fact also allows contacts to be exfiltrated from a smartphone. Didi Chuxing, the Chinese equivalent of Uber, is also said to be incorporating this type of "tracking application".spyware.
To minimise the amount of information exposed to misappropriation, David Grout advises people to travel light, especially if they are going to a high-risk country, with only the data essential to their mission: "I even encourage have two computersincluding one dedicated to travel, where the volume of on-board data will be limited."Another solution is encryption. This can involve only the hard disk, but also the files. This is known as high-level encryption. If a document is shared, your contact will need to have the password to decrypt it. Microsoft, for example, offers the BitLocker solution natively in certain versions of Windows. Note that some countries, including China, may prohibit data encryption or limit the level of encryption permitted.
Read also : "Cybersecurity: risk-proofing travel
Another risk, more clearly identified by travellers, is connecting to public WiFi or peer-to-peer networks. By way of example, state hackers, such as Russian (ATP 28 and ATP 29) and Chinese groups, have already hijacked a hotel's WiFi traffic or a trade show in order to capture data from VIPs at major international events. For Roxane Suau, Pradeo's VP Marketing, vigilance begins at the airport terminal. "Alongside the official airport WiFi, you have a myriad of networks from the shops. These can be created from scratch with a risk of data interception"she explains. "A hacker knows his target's habits. He knows which airport lounges he frequents, which hotels he stays in".adds Bastien Bobe, Lookout's Pre-Sales Manager for Southern Europe.
Business travellers must therefore disable WiFi and Bluetooth by default and use the company's virtual private network (VPN). New solutions, known as Zero Trust Network Access (ZTNA), also allow remote access - like VPN - but without incoming traffic or opening network ports. Failing that, sharing a connection from a 3G or 4G phone is preferable, especially in Europe with the end of roaming charges.
Another threat is targeted phishing, which can occur before a trip. On social networks such as LinkedIn and Instagram, the hacker examines the profile of his targets and anticipates their movements. "If the business traveller publishes a post inviting his contacts to meet him at a trade fair, the hacker will invite him to a VIP dinner at the event, for example.says David Grout. To do this, he asks them to register online with a login and password. Since people often use the same login and password, this criminal will be able to infiltrate these different accounts."
But phishing can also come from a text message, reminds Bastien Bobe: "SMS has become a priority channel, you receive a large number of notifications. All you need is the flight number of the business traveller to impersonate an airline and ask them to send a photo of their passport."A campaign of tests has shown some worrying results," he says.60 % to 80 % of users click on a link contained in a malicious SMS, compared with 20 % to 25 % for an e-mail."
The attack can also target the prey's entourage, for example a company director's assistant or press attaché. "By hacking into their smartphones, a hacker can access geolocationread messages, listen to phone calls, remotely trigger audio recording, etc.o", notes Bastien Bobe.
The risk is not just virtual. Laptops and smartphones can also be stolen. "A malevolent person entering a hotel room is not a crime. not just in spy films"warns David Grout. His advice: always keep your terminals with you or, failing that, put them in your hotel room safe. You should also systematically lock your sessions and set up two-factor authentication. Google offers a security key called Titan that connects to a USB port.
And if there is a theft, the business traveller must have been trained beforehand on what to do. According to David Grout, the company also needs to organise itself accordingly: "Take the case of a user whose mobile phone is stolen in China at 4am Paris time on a Sunday. If his employer has not set up a 24/7 serviceThe reaction will occur at best four or five hours later."Mobile fleet management solutions, known as MDM (Mobile Device Management) and MCM (Mobile Content Management), make it possible in the first case to geolocate a terminal and block it, and in the second to remotely erase data. As for EDR (Endpoint Detection and Response) technology, this involves placing an embedded agent in the machine that can detect threats in real time. This enables rapid investigation in case of doubt.
But prevention doesn't stop once the journey is over. To this end, some companies are making a "post-travel investigation"In extreme cases, it is necessary to ensure that the workstation is no longer reconnected to the company network. "A hacker may have injected malicious code and wait for the person to return to the country to activate it, thereby gaining control of the company's entire information system."concludes David Grout.
Dossier - Passenger safety
Security: companies face up to their duties
Security and Covid-19: going from nothing to everything
Assistance and protection for travellers: crisis measures
Safety advice
Interview: Émile Pérez, Director of Security and Business Intelligence, EDF Group
- Business travellers, ideal targets for cybercriminals























