Are people “targeted” by hackers?
Many people think that they will not be hit by a cyber attack because they are not a “target.” It’s important for people to understand how many people find themselves victims of cyber events. It is often not “targeted.”
Especially for individuals, cyber attacks are mostly opportunistic. The analogy I often use is a robber having a technique to pick a certain type of lock on a house. The robber is going to go through the neighborhood and look for doors with this particular lock to rob. The robber is not going to try and build a technique to break into every house with every different type of lock when he can just target the houses that match the profile of those he already knows how to get into. Hackers look for weaknesses like this lock that can be easily be cracked. They develop exploits which are like this technique to break into this weak lock.
Rather than driving around a neighborhood looking for these houses like a robber would, a hacker scans devices exposed to the internet to try and find devices that have this vulnerability. The internet is amazing in the fact that it allows people to communicate and interact with each other all the way across the world. However, this connectivity is also a risk of the internet. A hacker does not have to be physically present with these devices to discover them, see if they are vulnerable, and exploit them if they are connected to the wider internet.
A hacker does not have to be in the same physical location as these devices to discover them, see if they vulnerable, and potentially exploit the device if it is exposed to the internet. It is important to understand that being connected to the internet does not necessarily mean that a device is exposed to the internet. For example, your laptop, phone, printer, and smart TV might all be connected to your home Wi-Fi and have access to the internet. That does not mean that someone on the internet can automatically connect directly to each of those devices. The goal is to understand which devices and services actually need to be accessible from the wider internet and avoid exposing things unnecessarily.
So what should you do about this?
Regularly update your systems: Attackers often look for software that is outdated that they have an exploit against. They will scan the internet, looking for these kinds of out of date systems. It is important to ensure you are updating your systems to avoid fitting the profile attackers are looking for.
Be cautious about what you expose to the internet: Not everything needs to be publicly accessible. Many devices and services have settings that determine whether they can be reached from the wider internet. When possible, avoid exposing devices or services to the internet unless there is a specific reason to do so. If you don't need something to be accessible from anywhere in the world, don’t. For example, you don’t need to remotely access your smart toaster (I’m guessing you don’t need to be able to start toasting from anywhere in the world. How would you even enjoy your delicious creation?). You can access this while at home on your network and not expose this to the wider internet where it could potentially be exploited.
Use a strong password: If a device is connected to the internet, an attacker will often look for ways to try and login to that system with common credentials. Using a strong password helps prevent attackers from logging into a system that is internet accessible.
Cybersecurity can be overwhelming when you look at all the items you can implement. However, the approach I try and help people take is to take small, incremental steps to continue to raise the bar around your security. This can help avoid these kinds of opportunistic attacks hackers will often carry out. It’s like the saying, “You don’t have to outrun the bear, you just have to outrun the slowest person.” If the bar to attack you is greater than the potential gain, an attacker will move on.