Tips for Small Businesses

Small Business Tips Archive | For current postings, visit the blog

Have Your Passwords Been Compromised? Find Out Here.

Date: January 27, 2015

pwnedIt seems like every day we read about another big company falling victim to a hacking or malware attack that results in the compromise of massive amounts of customer information. In fact, according to an Identity Theft Resource Center report, in 2014 there were 783 data breach incidents, which accounted for the compromise of 85,611,528 records. In another study from May of 2014, it is estimated that 47% of U.S. adults have had their personal information exposed by hackers. That’s quite a bit of compromised personal information!

Now, take a moment to think about all of the online accounts you use as part of managing your small business. Then think about all of your personal accounts for everything from banking to email to social media. That’s quite a bit of personal information that could potentially be compromised!

In an ideal world, companies would notify you directly if there is even a possibility that your account credentials have been compromised, so that you can take action to protect yourself. Of course, your very first step should be to change your password for the compromised account, as well as for any other accounts that use the same User Id or email address and the same or a similar password. (See this Tip post for more on creating strong passwords.)

Unfortunately, you just can’t count on being notified every time a company suffers a data breach. While some of this may be due to the breached company being less than transparent, it is more likely due to the fact that the company doesn’t know it has been breached. According to a recent report, it takes on average 170 days for a company to realize it is the victim of a cybercrime attack, and that goes up to 259 days if the attack involves an insider.

Who does know, almost immediately, if your personal information has been compromised? Thieves who want to use it to steal your money, or your identity. In the dark underworld of the Internet there are lists of compromised user credentials dumped for the unscrupulous taking, or made available for purchase.

So, now you’re probably thinking that it would be a good idea to try to check out those data dumps of stolen credentials just to make sure that yours are not in there. PwnedList is a free service that can do just that. You can also sign up for a free monitoring account that will send you an email alert if your email address shows up on one of these data dumps.

(In case you’re wondering, the name came from the hacker slang “pwn” (typically pronounced “own”), meaning to compromise and control a computer, a gamer, a user, an iPhone, etc. The derivative “pwned” means a person or device that has been so subjugated.)

Start here, enter your email address, and click the “have you found my accounts” button. The PwnedList database goes back to 2011, and the results page will let you know if, and how many times, your email address and associated password was found in a stolen credentials list. It will also show you the last date on which your credentials were found. So if you see something recent, that is cause for concern. If you see results from 2 years ago, it is probably nothing to worry about.

For more information about compromises of your user credentials, you can sign up for a free PwnedList account. This free account lets you monitor multiple email addresses, and provides more detailed information about any compromise. Most importantly, it will show you the email address and exact associated password compromised, along with the source of the breach. Your password will either be in plain text or hashed. If it is plaintext, you can be sure that it has been compromised and you should change it immediately at the compromised site, and at any others with the same or a similar password. If it appears hashed (something like “pbljdv9SoUM=”), then only an encrypted version of your password was stolen. Of course, the thieves may be able to decrypt it, so it is still a good idea to change it.

The first email alert you get from PwnedList will likely include some very old breaches. Again, don’t worry about these (unless you haven’t changed your credentials for that account since the noted date). Any subsequent emails you get will be a result of a recent breach, and you should take action immediately.

For more information about PwnedList, check out their about page, and their FAQ. The service is free, and they don’t use your email address for anything but querying their database and sending you alerts. So, take a moment today to make sure that your credentials have not been compromised.

See weekly Small Business Tips like this one by subscribing to our blog.

Reads of the Week – Jan 23rd

Date: January 23, 2015

We know you’re busy, so we pulled together the most interesting reads of the week for topics affecting small business owners including the State of the Union, taxes, and how to read 50 books in under 10 minutes.

Read More

5 Tips to Ask Questions to Deliver the Best Service

Date: January 22, 2015

Strong communication is essential for any business. It begins with asking the questions to get the answers that will be actionable and informative.

Read More

The Art and Economics of Delegating: Help for the Small Business Superhero

Date: January 20, 2015

Small business owners are superheroes! Ask a small business owner how many hats she wears and you’re likely to get an earful. However, no matter how much you can do, you probably can’t do everything required to effectively run and grow a small…

Read More

Reads of the Week – January 16th

Date: January 16, 2015

We know you’re busy, so we pulled together the most interesting reads of the week including CES highlights, a new social co-working platform and the top 15 trend predictions for 2015.

Read More

Getting It Out: 4 Tips for Extracting Content from PowerPoint, YouTube, Acrobat, & other Files and Online Sources.

Date: January 13, 2015

Have you ever been frustrated by receiving a presentation or document from which you can’t copy a picture or video? Have you ever wanted to grab a YouTube video and use it, or a small piece of it, in an off-line presentation? Have you ever scream…

Read More

Reads of the Week – Jan 9th

Date: January 09, 2015

We know you’re busy, so we pulled together the most interesting reads of the week including getting paid, survival tactics, and some awesome podcasts.

Read More

[Infographic] Our Top 15 Small Business Trends for 2015

Date: January 07, 2015

Our new infographic brings you a summary of the top 15 happening’s in 2014 and predictions for 2015. From service business growth to crowdfunding platform surges to a shift in online and mobile payments, we predict that 2015 will be a continuation…

Read More

Small Business Optimism Looking Up for 2015

Date: January 06, 2015

Each month, the The NFIB (National Federation of Independent Businesses) Research Foundation has published the Small Business Optimism Index—a measure of how small business owners feel about current business conditions and the outlook for the upcom…

Read More

Reads of the Week – Jan 2

Date: January 02, 2015

We know you’re busy, so we pulled together the most interesting reads of the week for the beginning of 2015 including business resolutions, optimism, and eliminating junk food.

Read More