Posted by KWIL on 11/01/2019 15:12:10:
What am I doing correctly?, I rarely get scam emails or phone calls as described in this thread!!
Luck perhaps? Despite keeping a low profile and having a hardened system I get dodgy emails – they started after a friend forwarded one of those 'joke' emails to me and a bunch of other mates. By sending the email all our addresses were blind copied to the original sender, who sold them on. Please don't copy funny ha ha email junk to your friends!
A colleague who ran his own mail server was able to use a slightly different address each time he shared on the internet. By monitoring which aliases got spammed he was able to identify which businesses were selling his details on. (Later this became illegal) In addition, many legitimate companies have lost customer details to hackers, as in this example. Don't use free wifi access to conduct sensitive business without a VPN – wifi hot points are easily monitored. Don't use unencrypted wifi at home either.
There isn't a policeman patrolling the internet unless you're buying guns, drugs or porn. In the UK the Information Commissioner chooses not to act proactively – they intervene AFTER your data has been lost, and are unsupportive if you ask for confirmation that an organisation actually has appropriate security in place. As good security is expensive it's common for IT systems to be inadequately protected at any of several key points – risk assessment, policy, design, build, maintenance, networking, processes, management, ethics, or staff management. Hackers are rather expert in exploiting IT weaknesses caused by corner cutting.
Safe enough with reasonable precautions but the price of peace is eternal vigilance.
Dave