Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Monday, 20 March, 2023
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Lottery winner’s Facebook profile "wide open" as Camelot admits it does not offer security advice

by The Gurus
October 14, 2020
in Editor's News
Share on FacebookShare on Twitter

Camelot has admitted that it does not offer security advice to winners, despite a recent winner’s profile being wide open.

The winner, who did not return emails to IT Security Guru, had won a multi-million pound prize and had appeared in the national press, but his Facebook profile displayed information on his interests, family and occupation.

Speaking to IT Security Guru, Andrew Barratt, managing director, Europe for technology audit and advisory services at Coalfire, said that within seconds it was possible to determine details on his partner, children and wider family who could be an open target for interested crooks.

He said: “There was also sufficient photos of them that a meaningful criminal could have been able to recognise him, and them. He also responded regularly to his friends wishing him birthdays so it was possible to work out date of birth. His address was available from the electoral register as well. “

Barratt said that within about 30 minutes he had the winners full name, date of birth and names of his children, while his partner’s profile was also open and information could be gleaned on his playing and supporting a football team, and which pubs and restaurants he visited via check-ins.
Asked what sort of risk could be posed by this, Barratt said that as the winner is a high net individual there were all sorts of risks to him both online and physically. He said he was able to get all of this information just from assessing information in the press release and comparing it against social media.

Barratt said: “Social network settings can be complicated, but typically they are not that complicated. A simple restriction on Facebook to only allow friends to view profile details would have stopped a casual scammer.

“Whilst I’m sure the winner is looking at their next set of lifestyle changes, Camelot should really be advising on some precautionary measures to avoid them becoming an easy target. This should be done before the cash is in their account and the press releases drafted, it’s just timing really.”

A spokesperson for Camelot, who was not aware of the concept of social engineering until explained by this journalist, said that it does give some advice, but only to winners of hundreds of millons of pounds.

They said: “There is a difference between those who win £1 million and £161 million and there is difference in the advice. So in simple terms, we would advise them on Facebook security settings as each winner is different on what they choose to do with their winnings, and we simply advise them on what do with it.

“We provide access to private banking, and when they win they get what we call ‘the panel’ with a financial advisor, banking expert and a legal advisor and it is up to them if they want to use them. It is a lot of support, with a lot of sensible advice.”

They said that Camelot’s security team will advise those who have won a lot of money on how to be secure, but that is mainly for the media. “Specifically on IT security, it is not something I am aware of,” they said. “We are responsible for helping people and a we have a part to play.”

Asked if Camelot should consider offering security and privacy advice to winners along with financial advice to prevent such attacks being successful, Barratt agreed, saying that while he understood why some winners wanted to remain anonymous, for those that choose to disclose a win Camelot have a hug
e responsibility to help the winner understand potential threats.

He said: “This isn’t necessarily a time to scare them ,but to advise on sensible approaches to online privacy and public information disclosure. Even give them time and advice to set the appropriate settings on Facebook/Twitter/Instagram etc. This is even more important when amounts can be so life changing.

“One other challenge is that someone receiving a large sum of money suddenly has their ‘normality’ changed. There are plenty of examples of public lotto winners being hounded for money – even just by the general public sending begging letters, so why not take precautions against the scammers?

“There is also a risk that if compromised a scammer may take the low and slow approach. The winner is likely to be generating more in interest than they’ve ever earned before ,so may not recognise it if it is small but sizeable amounts of money being taken frequently from their account.”

FacebookTweetLinkedIn
Tags: CamelotFacebookLotteryriskSecurity Advice
ShareTweetShare
Previous Post

More than 100,000 are members of (ISC)²

Next Post

Shortage of technology a greater concern than people or budget

Recent News

Nominations are Open for 2023’s European Cybersecurity Blogger Awards

Nominations are Open for 2023’s European Cybersecurity Blogger Awards

March 20, 2023
TikTok to be banned from UK Government Phones

TikTok to be banned from UK Government Phones

March 17, 2023
New AT&T Cybersecurity USM Anywhere Advisors Service Helps to Establish and Maintain Threat Detection and Response Effectiveness

Should Your Organization Be Worried About Insider Threats?

March 17, 2023
Guild Education controls API abuse with Salt Security

Guild Education controls API abuse with Salt Security

March 16, 2023

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

This site uses functional cookies and external scripts to improve your experience.

Privacy settings

Privacy Settings / PENDING

This site uses functional cookies and external scripts to improve your experience. Which cookies and scripts are used and how they impact your visit is specified on the left. You may change your settings at any time. Your choices will not impact your visit.

NOTE: These settings will only apply to the browser and device you are currently using.

GDPR Compliance

Powered by Cookie Information