Who Can You Trust? 'Not Even the Trusted'

LAS VEGAS—There’s a strong likelihood you are reading this on a device that already has malware installed on it and by the time you see a demand that ransom be paid to free up your data—if you ever see it at all—it may be weeks or months after that malware was installed.

Even more disconcerting is that the malware was likely to have been stealthily installed on your device thanks to a person or a website you “trusted,” according to one expert.

In remarks to NACUSO’s Network Conference, security expert and professional white hat hacker Jim Stickley, known for his firm Stickley on Security but who has just been named CEO of Mahalo Technologies, offered a sobering assessment of ransomware and what can be done to protect one’s self.

Stickley acknowledged people are being ransomware-warned “to death,” but stressed, “I don’t think people are getting the right information. Ransomware isn’t just one thing. There are literally millions of variations.

‘Not the Way Anymore’

“Paying to get your data back was what ransomware was about,” continued Stickley. “That’s not the way anymore. Ransomware isn’t just this one thing. There are literally millions of variations of ransomware. It’s morphing so fast, and I think people focus on the wrong thing.”

Ransomware is no longer about being locked out of files and then paying to get access back, according to Stickley. Instead, it’s about penetrating a device and then lurking there to grab increasing amount of data while using that device to then infect others.

To gain access to an entire credit union, said Stickley, “only takes one.”

Stickley cautioned his audience to watch out for knockoff websites that closely resemble the site the consumer is looking for. And consumers are likely to land on the scam site after linking from a legitimate site.

‘Exploit a Lot of Things’

“You can exploit a lot of things by getting people to go to a malicious website,” said Stickley. “It’s a zero-day vulnerability, which means it’s being exploited in the market today and there is no patch available.”

Stickley cautioned that users of the Google Chrome browser—which had been very secure at one point—has seen 16 patches so far this year to address zero day vulnerabilities. 

That malware is often installed due to what’s been dubbed “malvertising”—a term Stickley said he “hates”—a hybrid term for malicious advertising.

“This is something criminals have latched on to because it’s so easy to do,” said Stickley. “Often, it  happens as a result of companies using third-party vendors to manage their sites. Criminals buy legitimate ads and then allow you to edit the ad if you want. When this becomes dangerous is when it starts to really impact a lot of other organizations. Ad servers can be breached, and each of those may represent hundreds of companies.”

The Lock is No Lock

Stickley stressed that no comfort should be taken in seeing an the “s” in the “https” of the URL, which at one point meant added security, but no longer does.

“It used to mean there was some sort of verification. All of that is gone now,” he said. “You can pay $7.99 and it takes about 10 minutes to get yourself a security certificate. Never base your trust on this.”

Stickley said that the safest strategy is not to click on an ad to get to a company’s website, but to instead to search Google for the link as long as it’s not a sponsored link.

“Google ads are a nightmare. There is no authentication or verification on those,” he said. “They last for a day or two before they are taken down, and that’s plenty of time.”

What Can Be Done

What should a credit union do?

Jim Stickley speaking to NACUSO meeting in Las Vegas.

Stickley advises all companies to limit employee access to web browsing. Employees should either be prohibited from accessing any sites, or be limited to just those sites they need as part of their jobs, he said. 

“I know some of you will say employees will rebel. I say, no, they will have their phones out. More importantly, just change your policy moving forward with new employees. And once you have all these new employees, go back to your older employees and tell them it works for them, now it works for you.”

To boost security, he advises giving employees tablets, mobile devices and Chromebooks (totally different than the Chrome browser). “Chromebook is really killing it on security. It’s completely different than a PC. And Macs have a ton of vulnerabilities, too,” said Stickley.

Spreading the Love

While the perception is ransomware is installed, files are locked and a ransom notice appears on screen immediately, the reality is new ransomware often won’t show up right away, said Stickley. The computer won’t slow down, even as malware is “coming to life and going through a lot of stuff,” he said.

Stickley walked his audience through an example of how one employee can send an email containing a link to another employee, and thanks to what’s known as an email man-in-the-middle attack, the malware intercepts the email and turns it into an agent for malware.

“Of anything I show you today, you should be most concerned with this,” said Stickley. “When the original emailer sent the email, the malware recognizes there is a link and makes minor modification to the link.”

The only way to know it’s happened, said Stickley, calling it little more than a “branch to cling to,” is there will be a delay in the page load.  

“It’s not just malicious links. It also applies to attached files, such as PDFs, Excel docs and Word docs,” said Stickley. “If you use Adobe Acrobat just be aware they have a vulnerability about every month, every other month. “What this means is no email is safe.”

The Next Best Options

Unfortunately, said Stickley, there is very little that can be done. But the “next best options,” if there are any, he include:

  • Don’t use a PC or Mac
  • Confirm rollover links in emails with the sender
  • Maintain the latest security patches
  • Keep anti-virus software active and current
  • Don’t assume trust from “internal” emails. 

“One thing to be clear about is by the time you see the message, ‘You need to pay ransom,’ generally most of the damage has already occurred,” said Stickley. “Don’t just assume that if you got the ransomware notice that it just happened.”

Online Banking Risks

Stickley warned credit unions as both organizations and CU execs as individuals to be very wary anytime an attempt is made to log-in to online banking and a message is received—after personal information is entered—that indicates the site is down for a period of time.

Due to man-in-the-middle attacks, the fraudster has captured the log-in information and is even able to duplicate the two-factor authentication, because he/she is lurking between the home banking site and the member.

“Once compromised, nothing is secure on the computer,” said Stickley. “Anything you see can be modified. Anything you can do can be recorded. I hack into a company (that has retained his services) and turn on the microphone in the board room and listen to those discussions. It’s not just online banking, its email accounts, security services, camera systems, VPN solutions and more.”

Stickley also cautioned credit unions that malware is no longer about locking up individual computers on a network. Fraudsters now lock up a core system “and a backup site won’t help,” he said.

“Before you can bring anything back you need to know how did they got in,” he said. “Systems that don’t come back up for months isn’t because they can’t, it’s because they can’t do so until they are sure the criminals are out.”

Steps To Take

Stickley offered this advice, as well:

  • Check your host file and security certificates on your computer
  • Be really suspicious about websites that don’t respond as expected. Use a mobile device or separate computer to confirm a similar response. “If that one gets in and yours doesn’t, that’s a red flag.”
  • Never store confidential, private data that is not encrypted.
  • “If something seems weird, get assistance.”
  • Pay attention to lower level providers and the risk of supply chain attacks. “If they get into a core system, they can push out malware to every organization using that core or provider. Solarwinds has become the blueprint.”
  • If you have a Guest Network at home, put all your devices on the guest network. 

Free Resource

While noting the irony that it’s available as a PDF, Stickley is offering a free document containing security strategies at www.StickleyHelp.com. 

Stickley Named CEO

On the same day Stickley was speaking to the NACUSO meeting, Troy, Mich.-based Mahalo Technologies announced he had been named as the company’s new CEO.

Stickley will replace Mahalo President/CEO Alan Augustine, who will be stepping down at year end for family reasons.

Stickley has been serving as chairman of the board and is a longtime advisor of Mahalo Banking. 

“Mahalo is a unique company and myself and the rest of the board felt it was extremely important to find a replacement CEO that not only understood the credit union space but also would fit the Mahalo culture,” says Augustine, who will remain will the company as a board member. “As luck would have it, the perfect candidate was already onboard – Jim Stickley. Based on personally knowing Jim and his professional track record, I could not think of a better person to step in and continue to lead this company going forward.”

Section: Standard
Word Count: 1866
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto.flux5.ccplatform.net/THE-feature/Who-Can-You-Trust-Not-Even-the-Trusted