A trend of phishing and social engineering is emerging in the alternative investments industry, particularly targeting digital assets and funds that are looking to raise capital. Cybercriminals, masquerading as potential investors, are exploiting the trust of eager fund managers through seemingly innocuous calendar meeting links. The meeting links are then used to install malware onto a victim’s device. The cybersecurity experts at RM Cyber have some tips on what to watch for so that you can protect yourself.
While it is a common practice to have a video call to raise funds, it’s important to make sure the investor is legitimate before clicking on meeting links. Before setting up a meeting, research to verify the legitimacy of the person and the company. In one example, the malicious actor posed as an employee of a large investment firm; research the individual employee to make sure they are who they say they are.
Malicious actors prey on your excitement and urgency to connect with potential investors. When you go to join the meeting, they may claim that the original link is broken and send you a new link that asks you to run a script on your device. That script installs malware to infect your device.
Krebs on Security, an in-depth security news and investigation resource, recently released an article that details a real-world scenario of one of these scams. Read the article here for a closer look. Although this article focuses on crypto, this method applies to all investor meetings.
The best way to stop this type of phishing/social engineering attack is to stay vigilant and do your research. If anything seems odd, it probably is. When in doubt, verify before you click. A qualified investor will respect your commitment to quality to protect their investment.
If you need additional cybersecurity support for your fund, the RM Cyber team is ready to help. Reach out to Steve Vlasak for more information.