Cyber Mondays have been gaining more and more strength in Latin America in recent years; and with the pandemic, digital services gained significant momentum making online purchases a sales channel that increasingly attracts both businesses and consumers themselves, but as with physical purchases, the risks of theft or fraud are present.
According to Milena Delvalle, SISAP Country Manager, online purchases have had significant increases throughout Latin America, and Panama has not been the exception.: ”Before, online purchases increased on Black Friday and Cyber Monday, but after the pandemic our shopping habits changed thanks to the digitization of commerce, to the point of even making supermarket purchases online. So well, businesses that failed to maintain their commercial premises have migrated to virtual stores, so the invitation is to lose fear of electronic commerce and adopt online shopping in a safe way.
The best way to be prepared and avoid cyber fraud is to find out about the protection mechanisms that institutions have made available to users, for this José Amado, Director of Cybersecurity Outsourcing at SISAP, a leading company in Cybersecurity in Latin America, gives us these tips :
Recommendations for consumers
- Do not use public or free internet (WiFi): using the internet of restaurants, shops or hotels to make purchases online where you will transmit your credit / debit card numbers and confidential data, it is high risk since cyber criminals connect to free internet services with the purpose of finding victims vulnerable and intercept sensitive information such as credit cards and credentials (usernames, passwords).
- Shop at reputable sites: Do not get carried away by irresistible offers and too low prices from stores where you have not bought before and do not have a good reputation, they can be a scam where your credit card and personal data will be captured.
- Caution with offer emails: This season emails with offers wanting to get your attention will increase, many of these emails will look legitimate, be very careful when opening them and especially if they have attachments. These can be Phishing emails that can steal your credentials.
- Make sure the sites you buy from start with HTTPS and not HTTP: verify that the start of the site where you are going to buy starts with HTTPSthe difference is the S in the end. Which indicates that it has an additional level of security and means that the site has gone through certain validations and that it is safe to make purchases, although it does not guarantee a safe purchase, it is a good indicator.
- Updates: It is important that your mobile devices and laptops have all the latest updates, including the browser (Chrome, Safari, Edge); as attackers exploit these vulnerabilities. Remember that in seasons of high online shopping transactions, attackers are also more active.
- Use biometrics to access your financial services: If a cybercriminal managed to obtain your credentials, it would be a very high level of difficulty to be able to circumvent the security of biometrics, using biometrics (facial recognition or fingerprint) is more secure than using only a password.
- Monitor and report: monitor your credit card transactions, pay attention to notifications and immediately report any anomalous transaction to your bank.
- Prioritize the use of credit card over debit cards: Bank credit cards often offer anti-fraud purchase insurance, so this could add a higher level of security to the buyer, so we recommend checking with your bank for the level of protection they offer for greater security.
- Do not save credit card numbers on shopping sites: If the site where you are shopping has the option to save credit card, don’t do it. It is preferable to enter the credit card number each time you go to buy, if the credit card number is stored in several places it will be very difficult for you to identify where a fraud could have come from.
Recommendations for businesses
The recommendations for businesses are more technical and complex, since the level of knowledge required is more advanced for businesses that already have an online payment platform with a credit or debit card.
- stress tests: Due to the high transaction volume of the season, it is important to carry out stress tests to ensure that the platform will support the expected high volume of transactions and will not suffer an interruption due to overload of online buyers.
- Vulnerability scan: It is important to run a vulnerability scan on the applications that support e-commerce, to ensure that everything is up to date and well configured, ready for the busiest days.
- Constant monitoring: In high seasons, monitoring of threats and electronic fraud must be increased, as well as the entire incident response team being prepared for any eventuality.
- Avoid significant changes: avoid making significant changes to applications or the network in the days leading up to or during peak season; Generally, significant platform changes or system adjustments require several days of monitoring to ensure that everything works correctly.
- Consult with professionals in Cybersecurity: Cybersecurity companies such as SISAP Application Systems provide organizations with different levels of protection such as vulnerability scanning and detection, 24/7 monitoring, incident response, stress tests, among others.