Hurricane Harvey
A National Weather Service radar image of Hurricane Harvey.

Editor’s note: Wired for Safety is a column on cybersecurity and other tech issues. Duane Dunston is an assistant professor of cybersecurity and networking at Champlain College. He received his bachelor’s and master’s of science from Pfeiffer University. From 2001 to 2011 he worked in cybersecurity for NOAA. He is a doctoral student at Northeastern University with a concentration in Curriculum, Teaching, Learning, and Leadership. His other activities include “You Have A Voice,” a project to develop an electronic screening assessment to identify human trafficking victims.

[O]ne type of warning of online security I dislike having to remind people of is when there is a disaster to be careful choosing organizations to donate to. I do not mean to be heartless or undermine anyone’s giving spirit. Rather, I want to prevent someone from being victimized by cybercriminals that take advantage of your compassion and empathy. These times are when those with giving spirits are most susceptible to being victimized by cybercriminals.

What should you not do?

Duane Dunston. Courtesy photo

It is recommended that you don’t follow links in email or over the phone soliciting donations. If you are surfing webpages and a pop-up asks for a donation to help those affected, it is best not to input your information in those sites for a donation.

I am not implying all organizations are trying to steal your data or access your financial information. It is just a lot of work to verify if the pop-up is legit and from the site it claims to be. It is not difficult to make a website or popup look like a legitimate website.

What should you do?

Donate to well-established organizations. Visit their websites directly (by manually typing it in) and not clicking a link in an email. Visiting the website manually can provide higher assurance you are visiting the legitimate website.

Use the service provided by charitynavigator.org to determine if an organization is legitimate.

• Be careful of email messages that claim to have photos, videos, recent updates, etc. regarding any major events and require you to click on the link.

Recommendation:

• Don’t read or forward email messages regarding the event, especially ones that have a weblink AND don’t follow the weblink.

• Don’t forward or open attachments related to the event. An email attachment that appears to be a photograph may be more than you expect. It could also lead to you potentially infecting someone else’s computer.

• Visit reputable news sites if you want to receive the latest information or check your local news or radio station.

• Be cautious of “new” charities formed after an event.

• Don’t give cash or write checks to an individual.

• Be careful of charities that ask for money and require you to donate using your credit card via their website.

Also, be cautious of people on the street collecting “Donations” to the victims and survivors of the tragedy. They may use all sorts of psychological tricks, including having photos or other visual reminders to spark a reaction or solicit stories from you or have you ‘think of your own family being affected.’ Well-established charities don’t use aggressive techniques.

Recommendation:

•  During a major event, check with the local Red Cross or the Red Cross website or the Salvation Army for official ways to assist those in need.

• The Better Business Bureau has a scam tracker website where you can drill down by state and see the amount lost and comments by those that lost money or didn’t lose money.

 

Duane Dunston is an assistant professor of cybersecurity and networking at Champlain College. He received his bachelor’s and master’s of science from Pfeiffer University. From 2001 to 2011 he worked...