Need Help?
  • Application Remote Support
  • Infrastructure Remote Support
  • Sage HRMS Remote Support
  • Helpdesk
  • General Inquiry
1-800-719-3307
Net at Work Net at Work
  • Solutions & Services
    • ERP/Accounting

      ERP Services
      Acumatica
      NetSuite
      Sage X3
      Sage Intacct
      Sage 100 ERP
      Sage 300 ERP
      Sage 500 ERP

      CRM

      Strategic Advisory Services
      Digital Marketing Solutions
      CRM Training Camp
      Creatio
      Salesforce
      Microsoft Dynamics 365 CRM
      Sage CRM
      Infor CRM (formerly Saleslogix)

      Employee Experience

      Sage HRMS
      Rippling
      Criterion
      Miviva

      Enterprise Content Management

      Imaging / Scanning
      Document Management
      Workflow Automation
      Solutions

      Nonprofit Solutions

      Abila by Community Brands
      NetSuite
      Sage
      Salesforce

      IT and Security Services

      Managed IT Services
      Fractional CIO Services
      Cloud Services
      Cloud at Work Sage Hosting
      DR/Business Continuity Planning
      Compliance & Security
      Storage & Recovery
      Networking
      IT Security Services
      Communications

      Web Solutions

      Services Overview
      B2B Technology Suite
      Magento eCommerce
      WordPress CMS
      Systems Integration
      Website Managed Services
      Online Marketing & SEO
      ERP eCommerce Integration

      Additional Solutions

      Enterprise Business Intelligence
      Avalara Automated Tax Solutions
      Fortis Payments
      LeaseQuery Lease Accounting
      Sage Fixed Assets
      Vertex SMB Sales and Use Tax
  • Industries
    • Industries

      Chemicals
      Food & Beverage
      Healthcare
      Industrial Manufacturing & Equipment
      Medical Devices
      Nonprofit
      Wholesale Distribution
  • Learning Center
    • Online Resources

      Recorded Webinars
      Whitepapers
      Ebooks
      Success Stories

      Upcoming Events

      Live Webinars
      Seminars
      Virtual Training Courses

      Training Courses

      View all available training course options
  • Company
    • Why Us

      Who We Are
      Management
      Our Partners
      Locations
      Careers

      News

      Press Releases
      Success Stories
      Net at Work Blog

      Contact Us

      1.800.719.3307
      Email Us

      Programs

      Alliance Partnership Program
      Women at Work
      Diversity and Inclusion
  • Blog
  • Contact Us
  • Contact Us

Home » Newsletters » Employer Solutions / HRMS Newsletter – July 2018 » Cybersecurity Vulnerabilities—Why Bad Actors Target HR Departments

Employer Solutions / HRMS Newsletter – July 2018

Keeping You Up-To-Date With Information About Employer Solutions / HRMS

Cybersecurity Vulnerabilities—Why Bad Actors Target HR Departments

By: Casey Jenkins, Guest Author, Head of People Operations at Lastline

Your organization’s C-suite isn’t the only target at risk of cyberattacks. Cybercriminals frequently target human resources (HR) departments with the goal of collecting financial and personally identifiable information (PII). HR departments not only are more likely to have cybersecurity vulnerabilities but also are the keepers of a great deal of personal and confidential information. 

HR departments need to be aware that they may be the target of cyberattacks and have to be proactive about their cybersecurity. 

A Quick Look at HR-Related Attacks 

In the past few years, there have been a number of high-profile, HR-targeted attacks. Organizations have found themselves crippled by ransomware, while thousands of employees have discovered that their employer has unwittingly disclosed their personal information, leading to identity theft and financial abuse. 

In 2017, the GoldenEye Ransomware Attack targeted HR departments with fake job applications. HR departments are used to collecting large volumes of e-mail attachments, often in the form of a PDF. GoldenEye included a malicious Excel file, which did not appear to be suspicious to many HR representatives. The result was infection with ransomware: GoldenEye would encrypt a computer’s disk and request payment of up to $1,000 to unlock files. 

Where GoldenEye focused on ransomware, other attacks have focused on collecting information. In 2016, the Internal Revenue Service (IRS) sent out a notice warning HR departments of phishing schemes that were designed to collect personal information from employees. Phishing e-mails appeared to be from company executives and requested items such as copies of employee W2s. Many HR managers would simply forward these documents, leading to wide-scale breaches of Social Security numbers, dates of birth, and addresses that could be used for identity theft. 

In 2014, bad actors began to target HR departments with Gameover ZeuS Malware. Gameover ZeuS was a malicious program that was designed specifically to capture banking data. HR became a target for social engineering, as hackers were able to look at sites such as Monster and CareerBuilder to identify spear-phishing targets. From there, the criminals were able to install the ZeuS Trojan that was able to capture information from website forms, implant fake employees, and target HR-related bank accounts. 

These three attacks are very different, with their objectives ranging from ransoms to capturing employee data to stealing the financial data of the organization directly. The only common element of these attacks is that they target cybersecurity vulnerabilities in HR departments. 

But why are bad actors so interested in HR? 

Why Target HR’s Cybersecurity Vulnerabilities? 

HR departments are the gatekeepers of a significant amount of personal data. W2s, 1099s, and other employee records can all contain not only PII but also financial information. Any company that maintains direct deposit for payroll, for instance, will have financial information readily available. Bad actors target HR departments simply because it is the most expedient way to collect the data that they need. 

However, this isn’t the only reason why HR is targeted. As GoldenEye showed, HR is considered to be a weak point within many organizations from a security perspective. HR departments are designed and predisposed to collect outside information—to continue their hiring processes, they need to accept and open files from strangers outside of the network. Many HR managers are accustomed to opening strange documents and may often see files in unusual formats from applicants who choose nonstandard file types to submit their résumé or portfolio of work. 

Additionally, HR departments aren’t prime candidates for the best technologies. HR is more likely to be using older applications designed specifically for HR purposes, which may not have been updated with current antivirus programs or definitions. In addition, HR managers and team members aren’t always the most knowledgeable about cybersecurity best practices. HR managers may not be able to identify common phishing attempts and may not be up to date on current attack trends. 

What HR Departments Can Do about Cyberattacks 

While training is always important, technology is a better way to defend against these types of cyberattacks. HR departments need to be able to interact with the outside world, and many of them may not have a cybersecurity background. 

Information security training likely will not prevent an HR professional from clicking on an innocent-looking e-mail with the subject line of “my résumé.” The system itself needs to be able to protect the company from the risk of an HR representative clicking on the wrong link. With as many files as HR departments generally receive, it is not realistic to expect the employees to catch every malicious attack. 

To start, departments can route application traffic through a single workstation, isolating this station from the network and, therefore, minimizing risk. If a malicious program like GoldenEye gets on such a device, nothing of value will be lost; the encrypted machine can simply be reset. As it simply isn’t possible for most HR departments to stop accepting files, they need to be able to do it in the most convenient and lowest-risk fashion. Isolating HR computers from the network as a whole can prevent the propagation of malware. 

When malicious programs do get into the HR department’s machines, or when routing all traffic to a single system isn’t possible, advanced malware detection technology can identify and mitigate malware-based threats before any real damage is done. Many of the newer cyberattacks are developed so that they cannot be identified through traditional means. 

Antivirus programs cannot use signatures (static analysis) to identify these attacks because the criminals automatically modify their code so signatures immediately become outdated. Instead, advanced malware detection programs use dynamic analysis to identify the behaviors engineered into malware programs that are being submitted as attachments to HR. These technologies can tell when an application, attachment, or webpage is acting in a malicious fashion, regardless of the file type being used, and can quarantine the item. 


Sage HR & Payroll Summit session – our Cybersecurity partner along with representatives of the US Secret Service will review the risks of cyberattacks on businesses and provide insight as to how businesses can minimize the risk of a cyberattacks and what to do if you experience an attack. 

  • July 19th |  Boston MA
  • August 23rd  | Tampa FL
  • September 12th  | Atlanta GA

Sign up for HRMS & Payroll Summit

« Return to Newsletter

In This Issue
  • From the Desk of the Employer Solutions Practice Director
  • Impact of Good On-Boarding
  • Cybersecurity Vulnerabilities—Why Bad Actors Target HR Departments
  • Emerging Cybersecurity Threats: What You Need to Know
  • Payroll Fraud: The Need for Checks and Balances is Greater Than Ever
  • Payroll Continuity: Who Is Running Payroll Now?
  • Employer Solutions Employee Spotlight

  • Live Webinars

    Performance Management Strategies – Bringing Together ERP & HR Systems for Actionable Data
    Date: May 25, 2022
    Time: 2pm – 3pm ET
    Learn More / Register

    Hosting Your Sage HRMS in the Cloud
    Date: June 1, 2022
    Time: 2pm – 3pm ET
    Learn More / Register

    Best Practices: Creating Amazing Employee Experiences through Purposeful Employee Engagement
    Date: June 8, 2022
    Time: 2pm – 3pm ET
    Learn More / Register

    Employer Solutions/HR – Live Webinar Calendar
    Browse webinars, register now, or mark your calendar for future scheduled sessions.
    Learn More / Register

    Popular Recorded Webinars

    New Options from the Premium Version of Sage HRMS and More

    Building a Business Case for Next Gen HR Technology

    How Learning Management Systems are Changing the Way People Learn, Everywhere

    Next Generation Human Capital Management Systems

    HRMS Support

    Helpdesk:
    P: 888.494.9479
    E: helpdesk@netatwork.com

    HRMS Knowledge Center

    Sage HRMS Online Training Center
    See more courses and gain knowledge about Sage HRMS business topics important to you without committing a full day or more!

     Refer a friend, get a $100 Gift Card!

    Submit a Referral / Learn More!
    Do you have a friend or colleague whose company might benefit from utilizing a Net at Work service or solution? If so, refer them to us below and receive a $100 gift card or donation to your charity of choice!

    HRMS Resource Archive

    View our library of Employee Solutions / HR resources.

    HRMS Newsletter Archive

    Read our previous Sage HRMS Newsletters here

    Connect With Us

    Business Applications

    • Overview
    • ERP/Accounting
    • Cloud ERP
    • CRM
    • Employee Experience
    • ECM
    • Nonprofit Solutions

    Learning Center

    • White Papers & Guides
    • Ebooks
    • Training Courses
    • Virtual Training Courses
    • Success Stories
    • Live Webinars
    • Recorded Webinars
    • Trials

    Infrastructure Solutions

    • Managed IT Services
    • Fractional CIO & Advisory Services
    • Cloud Services
    • Cloud at Work Sage Hosting

    Support

    • Application Remote Support
    • Infrastructure Remote Support
    • Sage HRMS Remote Support
    • General Inquiry
    • Helpdesk

    Web Development

    • Services Overview
    • Magento eCommerce
    • WordPress CMS
    • Systems Integration
    • Website Managed Services
    • ERP eCommerce Integration

    Company Information

    • Why Us
    • Alliance Partnership Program
    • Women at Work
    • Diversity and Inclusion
    • Partners
    • Careers
    • News
    • Blog
    • Privacy Policy
    • Contact Us

    Additional Solutions

    • Enterprise Business Intelligence
    • Avalara Automated Tax Solutions
    • Fortis Payments
    • LeaseQuery Lease Accounting
    • Sage Fixed Assets (Sage FAS)
    • Vertex SMB Sales and Use Tax

    Industries

    • Chemicals
    • Healthcare
    • Food & Beverage
    • Industrial Manufacturing & Equipment
    • Medical Devices
    • Nonprofit
    • Wholesale Distribution
    Net at Work
    Net at Work (HQ)
    575 8th Ave
    New York, NY 10018

    P: (800) 719-3307
    info@netatwork.com
    Locations Across North America »
    Visit our sister companies:
    Cloud at Work - Sage Application Hosting
    Pixafy - An eCommerce Agency
    Docutrend
    WordPress Image Lightbox Plugin