High-net-worth individuals (HNWI) are pursued by cyber criminals due to their status within a large corporation, or their financial worth. The home network often serves as a gateway to sought-after assets, and a successful breach may lead to the unauthorized disclosure of sensitive personal or corporate information. The initial foothold within this network is often obtained via devices used by family members.
For this reason, the family is a first line of defense against a cyber attack.
Social engineering, a manipulation technique used to perform malicious activities through human interaction, is the primary means of accessing the home network. Cyber threat actors are deceptive and patient, conducting reconnaissance to reveal family dynamics, online behaviors and personal facts. As an example, a threat actor may gather intelligence to design an email and domain resembling a child’s school. The actor then sends an email stating, “Please fill out the attached survey regarding remote learning.”
The survey is clicked. Downloads. Runs. An initial foothold is now established.
Wireless router attacks are much less common, but may also provide a foothold when the router is attacked from the wide-area network (WAN) side, or the side attached to the Internet. Once an attacker has infiltrated the home network, entertainment and internet of things (IoT) devices can serve as mechanisms to enable persistence, or the ability for the threat actor to re-obtain entry over time. Sometimes an attacker will breach a home network only to patiently linger until the sought-after data becomes available.
It is critically important for HNWIs to implement positive security practices in their own households. Children in particular are vulnerable. Just like running a fire drill, breach simulations can be run across scenarios. The school science fair, for example, provides a prime opportunity for a threat actor to approach a child in a trusting environment. Seemingly benign questions can actually reveal valuable information to aid a cyber campaign, and role playing these scenarios is invaluable.