ISLAMABAD – At least 69.5% of employees and business owners in Pakistan faced a situation when colleagues (39.5%), friends or relatives (30%) made jokes with their unlocked computer, according to the Kaspersky survey.
These jokes include sending funny messages or emails on behalf of the account’s owner, placing a screenshot of the desktop as a desktop background, and leaving unexpected pictures or notes in the files.
Cyber attackers also use similar tricks. For example, a phishing website may open in a new window in full-screen mode, making the original browser bar with the phishing URL invisible. Instead, the attackers replace it with an image of the browser bar with the official link of a well-known organisation. This image may display various messages (both visual and audio), such as warnings that the computer has been blocked and a fine must be paid.
If the user does not know how to exit full-screen mode in the browser, they may think their computer is really locked. To escape such a trap, users can press F11 or Alt+F4 on Windows, or Cmd+Ctrl+F on a Mac, to exit full-screen mode and regain control.
Short links and QR codes should always be treated with vigilance, as they may lead to unexpected downloads or websites, not only claiming to be a friend’s joke. QR code phishing, known as Quishing, has been a growing concern in recent years.
Cybersecurity solutions help with a built-in QR scanner that lets users check the link and warns users about landing on a dangerous website. Additionally, hovering over a short link (without clicking) can sometimes reveal the true destination URL in the browser’s status bar, offering a quick safety check.
Safety Measures:
Lock your computers and other devices when leaving them unattended. Use strong passwords and do not write them down near your computer. Using a different password for each device and service is recommended. Password manager solutions can be of great help. Educate yourself on how to recognise phishing emails by looking for such signs as the sender’s address, executable files, or files with macros in attachments.
Only open attachments and click links if you are confident in the sender’s legitimacy. If the sender seems legitimate, but the content of the message looks strange, it is worth contacting the sender via an alternative means of communication. Specialised courses, such as Kaspersky Automated Security Awareness Platform, can help organisations educate their employees, including through phishing simulators. Use a protection solution, such as Kaspersky Next for businesses or Kaspersky Premium for individual users, that warns about potential dangers.

