Urgent warning to all iPhone and Android users after secret cyberattack targets millions of devices – here’s how to protect yourself

Anyone with an iPhone or Android should turn their device on and off once a week, officials say – to protect them from hackers.

The idea is to protect against zero-click exploits, which let hackers upload malicious apps, spyware and impersonation scams to devices without users clicking on links.

The National Security Agency (NSA) has urged users to reboot their phones at least once a week which would delete the massive stores of sensitive information including apps and other information that is continuously running in the background.

The NSA has also warned that users should be wary about connecting to public WiFi networks and are advised to update their phone’s software and apps regularly.

The NSA warned the advice is not 100 percent effective but will provide at least partial protection from certain malicious activity

Android and iPhone users have been told to reboot their phones once a week and turn off WiFi and Bluetooth to avoid cybersecurity attacks. Criminals can use zero-click exploits to infect a device and collect data without requiring the user to click on a link or download a file.

Android and iPhone users have been told to reboot their phones once a week and turn off WiFi and Bluetooth to avoid cybersecurity attacks. Criminals can use zero-click exploits to infect a device and collect data without requiring the user to click on a link or download a file.

An NSA document listed the many steps iPhone and Android users should take to mitigate the risk of a cyberattack.

Restarting your phone is one of the lesser-known methods for combatting cyberattacks because it prevents cybercrminals from employing a one-click exploit.

If the system isn’t turned off and on, a cybercriminal can manipulate opened URLs to run a code to take advantage of any software vulnerabilities on the device and install a malicious file.

By turning the phone off and back on, users also reduce the chance of spear-phishing – when an attacker sends targeted fraudulent emails to steal sensitive information like login credentials.

Nearly half of smartphone owners reported they rarely or never turned their cell phone off, according to a 2015 Pew Research study, while 82 percent said they never or rarely rebooted their phone.

The document also informed users that its important to frequently update software and apps to ensure your device is secure. 

Over time, hackers find new ways to break into a system, but updating old software will remove any potential flaws or loopholes they might have used to access your data.

The NSA also recommended that people disable their Bluetooth when they aren’t using it because it reduces the chance of people gaining unauthorized access to their devices.

The advice is not 100 percent effective, the NSA warned, but it should provide partial protection from certain malicious activity.

‘Threats to mobile devices are more prevalent and increasing in scope and complexity,’ the NSA warned, adding that some smartphone features ‘provide convenience and capability but sacrifice security.’ 

Users should also turn off their WiFi and delete unused networks that cybercriminals can use to target their phones.

When connecting to a WiFi network, it’s important to watch out for SSID Confusion Attacks that trick users into connecting to their hotspot instead of the establishment’s official WiFi using a similar network name.

The NSA recommended that people disable their Bluetooth when they aren't using it because it reduces the chance of people gaining unauthorized access to their devices

The NSA recommended that people disable their Bluetooth when they aren’t using it because it reduces the chance of people gaining unauthorized access to their devices

A strong lock screen with a minimum six-digit PIN will add much-needed protection when combined with the feature that prompts the smartphone to wipe itself after 10 incorrect attempts.

It further warned that people should avoid opening email attachments or links from an unknown source which could install malicious software without the person’s knowledge. 

‘Falling for social engineering tactics, like responding to unsolicited emails requesting sensitive information, can result in account compromise and identity theft,’ Oliver Page, the CEO of cybersecurity company Cybernut, told Forbes. 

‘These phishing attempts often mimic legitimate entities, deceiving individuals into divulging confidential details.

‘Trusting phone calls or messages without verification can lead to serious consequences, as scammers manipulate victims into disclosing sensitive information or taking actions that compromise their security.’

The Federal Communications Commission (FCC) also heavily warned users against dismantling any security settings that could give cybercriminals an opportunity to break into the phone.

‘Tampering with your phone’s factory settings, jailbreaking, or rooting your phone undermines the built-in security features offered by your wireless service and smartphone while making it more susceptible to an attack,’ the FCC admonished.

According to Statista, 353 million people’s data was compromised in the US last year including breaches, leaks and exposures.

***
Read more at DailyMail.co.uk