Skip to content

How secure are your company’s social media, really?

Social media — the missing piece in a cybersecurity puzzle

When asked about why cybercriminals target passwords, most people typically think of common motives like stealing sensitive data, hijacking accounts for ransom, or infecting systems with malware to disrupt operations. But in an exclusive interview for NordPass, Dennis-Kenji Kipker, a Professor of IT Security Law and Research Director at cyberintelligence.institute, brought to light a sometimes overlooked aspect — that some attackers may steal credentials just to get access to a company’s social media platforms and wreak havoc. He said:

 

As an attacker, I could also try to attack the whole social media system of a company and have the company’s communications under control. […] Data, if disclosed, could cause very considerable damage not only to the company as an abstract legal entity, but also to all people involved in business relationships with that company and, of course, the employees.

Dennis-Kenji Kipker

Professor of IT Security Law and Research Director at cyberintelligence.institute

Simply put, Professor Kipker points out that mishandling passwords for social media accounts can lead to more than just losing access. It can also result in losing the trust of partners and customers, which can then lead to financial losses. How do we know things like these could happen? Because similar incidents have occurred in the past.

Real-life examples of huge social media takeovers

A major corporation stuns everyone by announcing its acquisition by a primary rival; a government agency spreads fake news causing chaos in the cryptocurrency market; a renowned music label reports the passing of one of its top artists — these are not plot ideas for the next season of Black Mirror. They are real instances where false information was shared through the official social media channels of popular organizations, leading many people to believe it was true.

That’s right. The first situation refers to the 2013 Twitter hack of Burger King, where cybercriminals seized control of the company’s Twitter account to spread false news alleging that Burger King had been acquired by McDonald’s. The second incident occurred in 2024 and involved the Twitter hack of the Securities and Exchange Commission (SEC). In this case, cyber attackers exploited the SEC’s account to falsely announce the approval of spot-Bitcoin exchange-traded funds, leading to a significant surge in Bitcoin’s price. The third example pertains to the 2016 incident involving the hacking of Sony Music’s Twitter account, during which cyber attackers circulated a hoax about the death of the pop star Britney Spears.

While not officially confirmed, it’s widely suspected that these social media takeovers stemmed from compromised passwords or actions leading to password breaches, such as phishing or malware. As expected, each incident damaged the affected company’s reputation, occasionally resulting in significant consequences and, at other times, causing less severe repercussions.

Of course, as you can imagine, these are but three out of hundreds, if not thousands, of other similar cases. This begs the question: why did these events occur in the first place? 

Why do social media takeovers happen?

The first reason, as hinted earlier in this article, is that businesses often overlook the security of their social media accounts. While they focus on protecting their internal systems from malware and other threats, they sometimes neglect the security of their social media presence.

Another factor may be businesses’ tendency to prioritize their core operations over social media security, assuming these platforms are inherently safe and require no additional steps to safeguard against potential risks.

The next critical aspect is when organizations overlook the necessity of removing access to social media accounts when employees leave their positions. This creates a dual risk: first, if ex-employees are dissatisfied, they can post damaging content, harming the company’s reputation. Second, inactive accounts can become targets for hackers, allowing them to use them as gateways to take over the company’s social media channels.

Then, there’s the issue with passwords. At NordPass, we use the phrase, “For almost every task at work, there’s a password.” This rings true as most business operations necessitate the use of password-protected accounts. However, as highlighted in our Top 200 Most Common Passwords report, many individuals — regardless of their job title or position within the company — use weak passwords that can be easily cracked. Moreover, many employees use the same password across multiple accounts and services, amplifying the risk of a breach.

We also need to touch upon the irresponsible sharing of passwords among company members, often done through chat, email, or… written notes (yikes!). If some business leaders were to inquire about how their staff members share passwords for company social media accounts like LinkedIn, Instagram, or Facebook, they might be alarmed by the lack of security practices in place.

Of course, losing access to company social media accounts can also happen due to phishing, malware attacks, or other cyber intrusions targeting unsuspecting employees. However, ensuring passwords are strong and securely managed at all times decreases the chances of falling victim to such cyber threats, thus protecting the integrity and security of company social media accounts.

What if your company’s social media gets hacked?

Although it’s not overly challenging to imagine the outcomes of a social media takeover, being informed about the potential consequences can provide stronger motivation for us all to take action. 

First and foremost, a social media takeover can lead to severe reputational damage. Malicious actors have the power to tarnish an organization’s reputation by posting damaging content or spreading false rumors. This could result in the loss of key business partners and clients. Even when it’s clear that the content in question is the work of cybercriminals, rebuilding relationships with partners and customers can be more challenging than expected.

Another major risk, closely tied to reputational harm, is financial loss. When cybercriminals hijack a company’s social media channels and spread false information, it can cause existing customers to turn away and deter potential customers from engaging with the brand. As a result, the company may experience a significant decline in sales revenue, and face heightened difficulty in securing investments or loans. Not to mention the fact that the time and resources required to address the aftermath of a social media takeover can impede the company’s focus on growth.

A hostile social media takeover can also result in a loss of privacy for the company’s members. In other words, it opens the door to personal information being exposed or misused, potentially resulting in identity theft or attempts to exploit someone’s private image. Repairing such damage could require years of effort and resources beyond what the company initially anticipated.

Yes, social media takeovers can be prevented

Let’s shift our focus away from discussing the reasons and dangers of social media takeover and concentrate on solutions to the problem at hand — of which there are a couple.

To effectively prevent social media takeovers, a company must first recognize the threat. As highlighted earlier, many individuals may not even realize that cybercriminals target passwords to seize control of business social media channels. Therefore, the first step is to raise awareness across the organization and establish clear guidelines for accessing and sharing social media platform credentials among company members. This includes determining who can access the credentials, specifying who they can be shared with, and deciding what actions to take when a social media manager or anyone with access to company social media leaves the organization.

Step two involves utilizing today’s available technology to allow employees to securely handle the company’s social media account credentials. This can be achieved by adopting a robust password manager like NordPass. How so?

How NordPass can help your company in this regard

First, NordPass is an easy-to-use yet technologically advanced password manager that allows organization members to securely store, manage, and share passwords, passkeys, credit card details, and other sensitive information.

Beyond that, NordPass is a cybersecurity tool that allows you to monitor access to your company resources, including social media channels. Plus, it enables you to quickly identify weak, old, and re-used passwords in your company, and check whether company credentials have been compromised in a breach. 

As a result, NordPass can be a valuable tool for organizations looking to protect their social media accounts from misuse by outsiders  — all while enhancing performance and efficiency.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

ESET 針對小型及家庭辦公室 推出 ESET Small Business Security 方案

全球數位安全領導者 ESET 宣布推出 ESET Small Business Security(ESBS)方案,專為小型辦公室 / 家庭辦公室(SOHO)的網絡安全需求而設計,旨在提供無縫、用戶友好的保護,使 SOHO 客戶能夠在瞬息萬變的網絡危機中蓬勃發展。

ESBS 展現了 ESET 對創新的承諾,以及對全球 SOHO 企業增長和安全的支援。該解決方案可支持從 5 到 25 台設備,並提供一系列功能,有效保護網上交易和瀏覽、安全設備、密碼管理、保護 Windows 伺服器、加密敏感數據和抵禦網絡釣魚等威脅。

在此次發布活動中,ESET 消費者和物聯網業務部副總裁 Viktória Ivanová 表示:「在 ESET,我們深刻理解小型及家庭辦公室客戶的獨特需求,他們處於消費者和企業之間的位置。通過推出 ESET Small Business Security,可以為他們提供簡單而強大的解決方案,這個方案易於管理,高度可靠,並根據他們的需求量身定制,讓他們毋須費心網絡安全,專注業務發展。」

ESBS 包括 ESET HOME 安全管理平台,用戶可以完全掌控安全管理,獲取關於安全狀態、設備、訂閱和功能使用的便利資訊。用戶也可以通過 Web Portal 和流動應用程式隨時隨地登入 ESET HOME,以掌握設備的安全情況。

ESBS 確保可靠的安全性,佔用最小的系統空間,保證高效的保護,並在多個操作系統上兼容,包括 Windows、Android 和 macOS。用戶可以從全面的安全解決方案中獲益,包括安全的銀行活動防護、瀏覽器私隱與安全擴展、密碼管理器、安全服務器(適用於運行 Windows Server 的文件伺服器)、防盜功能、勒索軟件防護等。這個解決方案在網絡安全管理方面取得了重大進展,為 SOHO 用戶提供了無與倫比的便利和控制。

此次公告標誌著 ESET 針對 SOHO 市場提供有針對性的網絡安全解決方案的重要一步,進一步鞏固了 ESET 作為思維敏捷、以客戶為中心的數位安全領域企業的地位。

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

ESET 針對小型及家庭辦公室 推出 ESET Small Business Security 方案

全球數位安全領導者 ESET 宣布推出 ESET Small Business Security(ESBS)方案,專為小型辦公室 / 家庭辦公室(SOHO)的網絡安全需求而設計,旨在提供無縫、用戶友好的保護,使 SOHO 客戶能夠在瞬息萬變的網絡危機中蓬勃發展。

ESBS 展現了 ESET 對創新的承諾,以及對全球 SOHO 企業增長和安全的支援。該解決方案可支持從 5 到 25 台設備,並提供一系列功能,有效保護網上交易和瀏覽、安全設備、密碼管理、保護 Windows 伺服器、加密敏感數據和抵禦網絡釣魚等威脅。

在此次發布活動中,ESET 消費者和物聯網業務部副總裁 Viktória Ivanová 表示:「在 ESET,我們深刻理解小型及家庭辦公室客戶的獨特需求,他們處於消費者和企業之間的位置。通過推出 ESET Small Business Security,可以為他們提供簡單而強大的解決方案,這個方案易於管理,高度可靠,並根據他們的需求量身定制,讓他們毋須費心網絡安全,專注業務發展。」

ESBS 包括 ESET HOME 安全管理平台,用戶可以完全掌控安全管理,獲取關於安全狀態、設備、訂閱和功能使用的便利資訊。用戶也可以通過 Web Portal 和流動應用程式隨時隨地登入 ESET HOME,以掌握設備的安全情況。

ESBS 確保可靠的安全性,佔用最小的系統空間,保證高效的保護,並在多個操作系統上兼容,包括 Windows、Android 和 macOS。用戶可以從全面的安全解決方案中獲益,包括安全的銀行活動防護、瀏覽器私隱與安全擴展、密碼管理器、安全服務器(適用於運行 Windows Server 的文件伺服器)、防盜功能、勒索軟件防護等。這個解決方案在網絡安全管理方面取得了重大進展,為 SOHO 用戶提供了無與倫比的便利和控制。

此次公告標誌著 ESET 針對 SOHO 市場提供有針對性的網絡安全解決方案的重要一步,進一步鞏固了 ESET 作為思維敏捷、以客戶為中心的數位安全領域企業的地位。

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

Set and protect. A cybersecurity road map for small and home offices

In the evolving world of cyberthreats, small and home offices share a single need: a reliable security solution.

If you’re leading a small office, you are likely no stranger to working 12 hours a day. It might even feel like 24/7, doing taxes, communicating with clients, and marketing your business on social media platforms.

You likely have also personally installed a firewall on your laptop, but still, one day, you find out that your bank account got breached or your business data has been compromised. This might mean losing money or the trust of your clients, and it definitely means losing precious time to put the wheels back on your business. 

Today, basic protection doesn’t just mean having a firewall; it requires endpoint security with scanning tools, a password manager, and data encryption. Simply put, many businesses who invested into separate products over time to address basic risks just aren’t equipped to handle today’s threats.

This is the reality for a massive number of small offices/home offices around the world that face growing risks from digital threats.  For example, 31% of businesses with fewer than 10 employees surveyed in the UK during the winter of 2022-2023 experienced a cyber-attack or a security breach. To understand the full scope of the situation, there are 5.28 million such businesses in the UK.

These cyberthreats leave users facing a diversity of complex security challenges – challenges for which individual solutions like firewalls, well-suited to block malicious traffic, are simply not built to counter. Today’s online tools and business processes require cybersecurity solutions that layer multiple advanced technologies for detection, browsing protection, anti-phishing, and botnet protection, as well as exploitation, ransomware, and network protections supported by artificial intelligence and machine learning to stop threats.

The backbone of the economy makes for an interesting target

The small offices and home offices discussed in this blog are tiny when taken individually, but collectively, they comprise a massive workforce. For example, according to the latest data gathered back in 2019, 78.5% of U.S. businesses had 1-9 employees.

The situation is similar elsewhere. Businesses with 1-9 employees make up 74.1% of Canadian businesses and 82% of all UK businesses.

This makes these small offices/home offices sit nicely in the sweet spot user group for ESET’s Small Business Security offering; they’re the second largest source of wealth, right behind home equity. This also means that this group is substantial enough to factor into cybercriminal campaigning and simultaneously poses easy targets even for what have become common risks like simple password spraying attacks.

These businesses are often easy targets for cybercriminals because:

• They do not believe they are an interesting target for cybercrime because they are too small.

• They believe they cannot afford comprehensive high-tech security solutions.

• They often use outdated and unsupported software.

• Heads of small offices/home offices often don’t have IT education, don’t have time for cybersecurity awareness trainings, and lack finances to hire IT staff.

What threats are out there?

The complexity and scale of these threats are global, but let’s take Australian farmers as an example. In the first half of 2022, farmers fell victim to a series of cyberattacks with an accumulated loss of AUD 1.2 million (USD 792,026).

Some of those farmers fell victim to fake livestock sellers on Facebook or phishing websites pretending to sell machinery, while in reality farmers were sending money for nothing.

Here are some of the most common attacks threatening small offices and home offices:

  • (Banking) Data breaches – Losing sensitive data, especially banking and payment information, is the most feared cyberattack among small offices/home offices participating in an ESET internal survey. This can often happen due to phishing or an account breach.     
  • Compromised personal devices – Attackers can abuse employees’ personal devices to compromise business systems. According to the Samsung 2023 survey, 48% of organizations with a Bring Your Own Device (BYOD) policy witnessed malware introduced through an employee’s personal phone.
  • Physical theft – Almost 60% of small offices/home offices participating in an ESET internal survey expressed concerns about lost devices and data. Over 2 million laptops are reported stolen each year in the U.S., with the associated data losses estimated at over $7 billion.

Setting up defenses

Such a long list of threats can be a headache considering how much should be done to protect your business: backing up your data, protecting servers, having a good password policy ideally combined with MFA, installing endpoint protection on all your devices, an anti-theft solution, and taking cybersecurity awareness training to identify common red flags for prevalent scams.

However, alongside their normal duties and responsibilities, it is quite understandable that small offices/home offices don’t find time to worry about cyberattacks. And trying to deal with all these threats by setting up a VPN, password manager, firewall, mobile security solution, data encryption, and banking protection in a piecemeal fashion is unsustainable.

Some of those businesses openly admit this: “We’re a small company. The biggest issue is trying to survive on a week-by-week basis. We can’t afford to allocate sums to cybersecurity. I’ll spend it as and when I have it, or when I need to,” said a participating managing director surveyed by the UK Department for Science, Innovation & Technology in 2023.

But there is a better way. Digital security doesn’t have to mean a long and complicated shopping list composed of individual cyber defenses. You can get one affordable subscription that covers them all.

ESET Small Business Security presents an all-in-one solution coming with ESET HOME as the complete security management platform and support that won a 2023 SC Award for delivering best-in-class customer support and services.

ESET Small Business Security offers:

  • Reliable, easy-to-use security, with a minimum system footprint
  • Multi-OS protection including Windows, Android, MacOS and Windows Server
  • Safe Banking
  • Safe Browsing
  • Password Manager
  • VPN
  • Ransomware Shield
  • Anti-Theft
  • Botnet Protection
  • Network Inspector
  • Safe Server – The protection of company and customer data stored on a file server running on Windows Server operating system; it also automatically scans all inserted USB flash drives, memory cards, and CDs/DVDs
  • Support for 5 up to 25 devices

Let someone else put in the effort

Considering the previously mentioned surveys, it is safe to say that globally, millions of small offices/home offices fall victim to cybercrime every year. And it looks like some of those people just accept their fate. The truth is that when businesses put effort into cybersecurity, it is rarely ever appreciated. However, when something goes wrong, that failure is always criticized.

However, there is a way to mitigate those cyber risks without spending too much time and money. ESET can put in the effort instead of you with its reliable and multilayered functionalities all packed in one solution. Simple, isn’t it?

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

24.3.5 Voyager released

Changes compared to 24.3.4

Enhancements

  • Added retrying for intermittent errors that occur when restoring data to UNC paths

Bug Fixes

  • Fixed sorting of logs on the Server Logs page on the Comet Server web interface
  • Fixed an issue which caused the user detail page to fail to load for usernames with certain lengths in the Comet Server web interface
  • Fixed an issue where the Comet Server web interface failed to remember column selections for usernames containing an @ symbol
  • Fixed an issue with missing hints for valid usernames in the Comet Server web interface
  • Fixed a cosmetic issue with missing or misplaced loading animations in the Comet Server web interface
  • Fixed an issue with remote-controlled restores from the Comet Server web interface being unable to write to user home directories
  • Fixed an issue with backup job progress bars being left below 100% after the job completed
  • Fixed an issue with searching for items in Office 365 backup snapshots
  • Fixed an issue with unusable content when attempting to restore EFS-encrypted files to an archive
  • Fixed an issue with failing to restore directory timestamps
  • Fixed a cosmetic issue with EFS-encrypted files appearing as directories in the Comet Server web interface

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.