{"id":895953,"date":"2019-06-04T11:26:52","date_gmt":"2019-06-04T17:26:52","guid":{"rendered":"https:\/\/www.myconstructionexpert.com\/blog\/?p=895953"},"modified":"2019-06-04T11:27:01","modified_gmt":"2019-06-04T17:27:01","slug":"construction-cybercrime-match-made-in-cyber-hell","status":"publish","type":"post","link":"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/","title":{"rendered":"A Match Made in Cyber Hell"},"content":{"rendered":"\n<p>Tom Sawyer and Jeff Rubenstone | <a href=\"https:\/\/www.enr.com\/articles\/46832-construction-cybercrime-is-on-the-rise\">Engineering News-Record<\/a> | May 8, 2019<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Construction Cybercrime Is On The Rise<\/h4>\n\n\n\n<p>Cybercriminals find the construction world a rich phishing ground with fat prey and soft targets. At the end of April, just as St. Ambrose Roman Catholic Church in Brunswick, Ohio, neared the close of a five-month-long, $5.5-million renovation, Father Bob Stec, the parish pastor, was surprised to hear that the contractor, Marous Brothers Construction, Willoughby, Ohio, had not received a $1.7- million payment.<\/p>\n\n\n\n<p>&nbsp;\u201cWe were paying our bills. At some point somebody was able to get into our email system and in the course of that, changed the routing numbers for the wire transfers,\u201d the pastor told local reporters. The $1.7 million disappeared.<\/p>\n\n\n\n<p>The story follows a typical pattern of cybercrime impacting construction, starting with the use of email to divert funds, which vanish. But it also fits a pattern of victims declining to share details about how it happened. Neither Stec nor Marous Brothers responded to multiple requests from ENR to recount what happened. Most construction victims of cybercrime, including Turner Construction Co.\u2014which had sensitive personnel data stolen in 2016\u2014offer limited descriptions of the incidents and stress the steps they have taken to remediate. To be fair, the Federal Bureau of Investigation is on the case of the church building fund loss in Ohio, which means all parties have been told to clam up. But when it comes to spreading the warning to others, secrecy often prevails.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><br><strong>Big Worries<\/strong><\/h3>\n\n\n\n<p>Contractors, construction managers and owners worry about cybercrime, and with good reason. Their complex projects, with myriad data exchanges among partners and subs, regulators and suppliers, software and systems\u2014and now the internet of things\u2014are tempting targets for hackers. The specific risks are too many to name and evolve constantly. They run the gamut from stolen or locked data to financial theft, sabotage, and destruction of hardware and equipment.<\/p>\n\n\n\n<p>\u201cHacking is not just something happening in a distant land or like it is in the movies,\u201d says Greg Young, vice president of cybersecurity at computer security firm Trend Micro. \u201cHacking today is not just getting free long-distance calls, it\u2019s all about money.\u201d<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u201cThey do not realize how precarious their situation is.\u201d<\/strong><\/h4>\n\n\n\n<p><strong>\u2013 John G. Voeller, Retired CTO And CKO, Black &amp; Veatch<\/strong><\/p>\n\n\n\n<p>Young says that many hackers are trained for cyberwarfare by state-sponsored agencies and then go into business for themselves. \u201cThese guys are not paid well, so they go off at night and do ransomware, they do for-hire work. If someone wants something to fail, it\u2019s easy to hire super capable hackers,\u201d Young says.<\/p>\n\n\n\n<p>Phil Weaver, senior director of IT at Warfel Construction, a construction firm with 230 employees and $235 million in revenue based in East Petersburg, Pa., thinks the industry is unprepared. \u201cI don\u2019t think GC\u2019s and CM\u2019s are worried enough about the impact a cyber incident can have,\u201d he says. \u201cI think there is just a lack of understanding or realization that it can happen to us.\u201d<\/p>\n\n\n\n<p>John G. Voeller, retired senior vice president, chief technology officer and chief knowledge officer for Black &amp; Veatch, has a very big picture view, having been drafted over the years by think tanks and the government to help scope risk to critical infrastructure. And from where he sits, the view is bleak.<\/p>\n\n\n\n<p>\u201cSome construction executives are worried, but too large a number of them do not understand the situation well enough, and their risk managers are too often not technical enough, or connected to their [chief security officer] strongly enough, to really see how many holes there are in their dike\u2014and how few thumbs they have that are effective,\u201d Voeller says. \u201cThey do not realize how precarious their situation is.\u201d<\/p>\n\n\n\n<p>Voeller points to the growing activity of state actors and cyber warfare agents, whose tentacles are infiltrating industries and utilities, and whose actions are beginning to move from disruption to\u00a0outright destruction.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><br><strong>Wire Fraud<\/strong><\/h3>\n\n\n\n<p>At the moment, many security experts are focused on phishing attacks like the one at St. Ambrose and their potential to put companies out of business. \u201cPhishing is the biggest risk because there are many financial transactions conducted over electronic communications,\u201d says Everardo Villasenor, construction IT leader and chief information security officer at DPR. \u201cCyberattacks occur where there are bigger opportunities for financial returns.\u201d<\/p>\n\n\n\n<p>David Sheidlower, chief information security officer at Turner, notes the\u00a0FBI reports\u00a0that more than $1.2 billion was lost to email-centered crimes against businesses in 2018. \u201cSo, we know the risk is real,\u201d Sheidlower says. \u201cThat\u2019s why Turner devotes such a high level of attention to raising awareness of the risks among our employees and our partners.\u201d<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><br><strong>Taking Action<\/strong><\/h3>\n\n\n\n<p>A cybercrime is often a trigger to action. In March 2016, a Turner employee fell for a phishing email and sent tax information on current and former employees to a fraudulent email address. \u201cWe notified federal, state and local law enforcement and involved legal, law enforcement, information technology and security experts,\u201d says Chris McFadden, vice president for communications. \u201cWe secured identity monitoring services at no cost to all impacted employees, including their spouses or partners, for an original term of ten years. Since then, we expanded coverage to all Turner employees, who now have access to identity protection services, which are designed to recognize signs of unauthorized use of personal information and help our people respond.\u201d<\/p>\n\n\n\n<p>Turner also has put in place an employee resource site with answers to commonly asked questions, data security tips and links to training material and available external resources on the subject of cybersecurity and protecting personal information. The company also has a cybersecurity awareness outreach program for companies it does business with to arm them with information.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u201cI don\u2019t think we know the size of the threat because it\u2019s not properly recorded.\u201d<\/strong><\/h4>\n\n\n\n<p><strong>\u2013 Everardo Villasenor, CIO, DPR<\/strong><\/p>\n\n\n\n<p>Security consultant Scott Takaoka, a vice president at Aon Cyber Solutions, says wire fraud incidents, like the theft of payments, often begin with hackers picking through stolen Gmail or Yahoo credentials, which can be bought in bulk on the dark web.<\/p>\n\n\n\n<p>Takaoka says hackers use those credentials to peruse accounts and to find people mingling business with personal email, and sometimes using the same login credentials for both, which can let hackers into corporate email systems. Takaoka says hackers play a long game and research target individuals on sites like LinkedIn to suss out corporate hierarchies and identify people likely to be approving transactions.<\/p>\n\n\n\n<p>\u201cThey will watch and monitor and wait for the right time,\u201d Takaoka says. \u201cTo some extent they have to have the context of the transaction, but once they understand the context, they know when to strike.\u201d<\/p>\n\n\n\n<p>He says the emails that trick people into clicking on malicious attachments or links, or into rerouting payments to bogus accounts, often appear to be genuine and from people the victim is accustomed to dealing with. They also may come at just the moment a transaction is expected to occur\u2014in the right context\u2014with a message about the recipient having a new account number, and asking to route it there.<\/p>\n\n\n\n<p>Takaoka says such phishing emails often show up late on a Friday afternoon when those who might verify the information can be expected to have left for the weekend, so the victim takes the bait and wraps up his or her workday by clicking \u201csend.\u201d<\/p>\n\n\n\n<p>Says DPR\u2019s Villasenor, \u201cbasically, someone is vulnerable and gets hacked, and you didn\u2019t even notice. And all of the sudden you have someone in between. It\u2019s very lucrative. They get in the middle and say, \u2018By the way, we changed our account, can you send it to this one?\u2019 Companies can even go out of business when they are victims of this.\u201d<\/p>\n\n\n\n<p>\u201cI saw this kind of action first take place in real estate transactions with escrow accounts,\u201d Takaoka says. \u201cThen I saw that same play happening with heavy machinery\u2014especially in international transactions with high transaction dollar amounts.\u201d With high stakes like that, hackers are willing to invest the time to watch and find the best time to spring, Takaoka says.<\/p>\n\n\n\n<p>The most sinister variant of phishing emails are not fake emails from outside servers disguised to look genuine \u2014 spoofs \u2014 but emails from genuine accounts that have been hacked. \u201cIt\u2019s a hack, versus a spoof,\u201d says Danielle Roth, a cyberclaims manager with AXA Catlin, a division of AXA XL Insurance. \u201cMicrosoft Office 365 mailboxes are controlled by password and credentials, and if a hacker can get that, they can use that to actually gain access from someone\u2019s account. The email will look correct\u2014and it is correct\u2014but it is controlled by someone who is not the user.\u201d<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><br><strong>How Bad Is It?<\/strong><\/h3>\n\n\n\n<p>Cybersecurity vendor Symantec, which claims to have the largest civilian threat-intelligence network in the world, issued its latest global internet security&nbsp;<a href=\"https:\/\/www.symantec.com\/about\/newsroom\/press-kits\/istr-24\" target=\"_blank\" rel=\"noreferrer noopener\">threat report<\/a>&nbsp;on Feb. 20. The annual review finds that attackers are enhancing proven tactics, including spearphishing, hijacking legitimate software tools and distributing malicious email attachments. Ransomware infections\u2014which make data unreadable\u2014of individual computers are trending down, but enterprise ransomware attacks were up by 12% in 2018, \u201cdemonstrating ongoing threats to organizations,\u201d the security vendor says in the report.<\/p>\n\n\n\n<p>Theft drives most of the action, with the diversion of electronic payments to bogus accounts creating a significant threat for construction, the report states. The Symantec data reveals that one out of every 39 construction industry email users gets targeted by phishing, but the rate of phishing emails in construction is only one out of every 3,960 emails, which suggests it is being used selectively and with specific individuals in the crosshairs\u2014spearphishing.<\/p>\n\n\n\n<p>Symantec reported that one out of every 382 emails exchanged in the construction industry in 2018 had malicious content, but attackers are trending away from embedding malicious urls in favor of malicious attachments. The company found that Microsoft Office files accounted for 48% of the malicious email attachments tracked by its telemetry in 2018, up from 5% in 2017, and notes that small companies are most at risk from malicious content.<\/p>\n\n\n\n<p>Another technique expanding rapidly is \u201cformjacking,\u201d in which malicious code infiltrates a web server used for collecting form data for financial transactions. The malware skims the account and payment information. Although primarily used to attack the retail sector, it is increasingly being seen as potentially jeopardizing any supply chain.<\/p>\n\n\n\n<p>Symantec also found a growing interest among attackers in compromising operational and industrial control systems, \u201cwith the potential for sabotage,\u201d its report said.<\/p>\n\n\n\n<p>\u201cI don\u2019t think we know the size of the threat because it is not properly recorded\u201d says DPR\u2019s Villasenor. \u201cI think the number of incidents is increasing, increasing risks to companies and projects.\u201d<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><br><strong>End Points<\/strong><\/h3>\n\n\n\n<p>Security vendor Sophos, which specializes in end point detection and response technologies, or EDR, commissioned a\u00a0global study\u00a0by an outside research firm, Vanson Bourne. It surveyed 3,100 IT managers across the globe in December 2018 and January of this year, including 203 in the construction sector. It found that 68% had been victims of cyberattacks in the previous year\u2014meaning they were unable to prevent the attacker from entering their networks and endpoints \u2014 with larger organizations seeing more attacks (73%) than smaller ones (63%).<\/p>\n\n\n\n<p>The researchers suggested that there are two likely reasons for the difference: Larger companies are considered to be more lucrative targets, or larger organizations are just more aware that they have been hit and more likely to have to resources to detect and investigate.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u201cPatching vulnerabilities is really the easiest way not to be the low-hanging fruit.\u201d<\/strong><\/h4>\n\n\n\n<p><strong>\u2013 Danielle Roth, Cyber Claims Manager, AXA Catlin<\/strong><\/p>\n\n\n\n<p>The study also found that most threats were discovered at the server level. It noted that modern attacks tend to start at the endpoints and move to the servers, the more high-value target, and if the attacks were being detected there, \u201cit suggests a lack of visibility into what is happening earlier in the threat chain, as well as endpoint security gaps.\u201d When respondents were asked how long the most significant cyberattack they had been hit with dwelled undetected in the system, 1,744 responded, and the average dwell time was 13 hours.<\/p>\n\n\n\n<p>The researchers acknowledge that the 13-hour average is at odds with other data-breach investigation reports, such as\u00a0Verizon\u2019s, which found that 68% of data breaches take months to discover. But they suggest the difference may be that their respondents, most of whom detected the intrusions at the server level, might simply be unaware of the full scope of their problems. It found that 17% of the IT managers didn\u2019t know how long the threat had been in their environment, and 20% didn\u2019t know how it got there.<\/p>\n\n\n\n<p>DPR\u2019s Villasenor says the sophistication of attacks and the inclusion of artificial intelligence takes threats to a new level, and keeping employees\u2019 cyber awareness knowledge current is a continuing challenge. He also warns that the increase in state-sponsored attacks has the potential for wider disruptions.<\/p>\n\n\n\n<p>\u201cAI is interesting,\u201d says Weaver. \u201cIt\u2019s a new threat vector, but also can be leveraged to help in the cybersecurity fight. You need to try to guard against them all, [but] most of the threats we see are still social engineering based.\u201d<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><br><strong>What To Do<\/strong><\/h3>\n\n\n\n<p>Aon\u2019s Takaoka says a security assessment should come first. \u201cUnderstand and have a third party come in and provide some guidance, based on your business [and] the size of the company, and come up with recommendation around the biggest areas of weakness,\u201d he says. \u201cConstruction companies need to consider remediating these areas and do it in a risk-based fashion. It\u2019s mostly about reducing the opportunities for damage, not eliminating them, and being ready if it does happen.\u201d<\/p>\n\n\n\n<p>Takaoka says contractors should make sure the basics, such as updating software, enforcing password policies and restricting approval rights and administrative privileges, are executed. \u201cYou stop forwarding emails to the outside, which is very simple and it doesn\u2019t cost.\u201d He also adds that they should get cyber liability insurance, \u201cand if you work on anything, work on your backups. Make sure you have a good backup, retain a good incident-response provider and consider retaining outside counsel.\u201d<\/p>\n\n\n\n<p>Clients will gain confidence in contractors who manage cyber risk well, Takaoka adds. \u201cThat\u2019s the reason you do that assessment by a third party, and share the results\u2014which is basically a review of your processes and controls\u2014and you provide that to the client. Either have that assessment done yourself, or expect that as time goes on customers are going to have third party assessments done of you.\u201d<\/p>\n\n\n\n<p>Turner\u2019s Sheidlower says many owners have robust cyber risk management programs and review Turner\u2019s cybersecurity protocols, which he says \u201cmitigates the risk of attack on systems and information through a comprehensive approach to the technical, physical and administrative controls\u2014coupled with training and policies that serve to raise awareness on a range of issues amongst the people who access and control the flow information.\u201d<\/p>\n\n\n\n<p>Sheidlower adds that controls are available to firms of all sizes, and those include staying current with updating software patches, requiring multifactor authentication and installing anti-malware software on all endpoints.<\/p>\n\n\n\n<p>\u201cContractors should emphasize identifying information assets, finding vulnerabilities, employing protective and detective controls and, finally, having a plan for responding to incidents in an effective manner,\u201d Sheidlower says.<\/p>\n\n\n\n<p>\u201cOn the tech side, patching vulnerabilities is really the easiest way not to be the low-hanging fruit,\u201d adds AXA\u2019s Roth.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><br><strong>Scalable Security<\/strong><\/h3>\n\n\n\n<p>When asked if large operations have a better shot at secure operations than small and medium sized contractors, responses varied. Voeller\u2019s quick observation was \u201cobviously not when the largest in the world have been hacked and damaged, from Lockheed to Google to Facebook to the NSA.\u201d Disaster recovery service vendor Unitrends claimed that security is attainable with the right tools.<\/p>\n\n\n\n<p>In its description of services, Unitrends recommends a multi\u00adlayered approach, but claims that \u201cadding multiple layers to cybersecurity may look like you are adding many man-hours of labor to your already overworked IT department, [but] that does not have to be the case.\u201d It says multilayered solutions can run and report findings automatically. \u201cThe only additional labor required is when a negative finding is discovered. Plugging an open security hole is labor you should be happy to invest,\u201d the company says.<\/p>\n\n\n\n<p>\u201cThe biggest issue I see here is small and medium-sized businesses don\u2019t have the capital to properly address these issues, until they have a breach,\u201d says Warfel\u2019s Weaver. \u201cFor many SMB companies, they are much safer in the cloud than in their own environment,\u201d he says, adding, \u201cWe are one of the SMBs I am talking about, but I like to think we are at least trying to do it right.\u201d<\/p>\n\n\n\n<p>DPR\u2019s Villasenor says \u201cCybersecurity is scalable if companies start with simple controls and evolve with a good strategy. An evolving cybersecurity practice requires more investment, but based on the cyber threats, the ROI is there. Companies of all sizes have the opportunity to succeed on securing operations.\u201d<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u201cIf you don\u2019t have comprehensive security awareness and training, you are a sitting duck.\u201d<\/strong><\/h4>\n\n\n\n<p><strong>\u2013 Phil Weaver, IT Director, Warfel Construction<\/strong><\/p>\n\n\n\n<p>Villasenor says DPR\u2014a contractor with $6 billion in revenue and nearly 6,000 employees\u2014uses collaboration platforms offered by service providers operating in compliance with privacy and security standards, including NIST, ISO-27001, CSA, HIPA, SOC and others. He says contractors need to adhere to cybersecurity best practices, such as those promulgated by the Center for Internet Security, a nonprofit that \u201cworks to identify, develop, validate, promote, and sustain best practice solutions for cyber defense and build and lead communities to enable an environment of trust in cyberspace,\u201d according to its mission statement.<\/p>\n\n\n\n<p>Villasenor recommends starting with the first six of CIS\u2019 top critical security controls, which include making an inventory and securing control of hardware and software, continuous vulnerability management; controlling the use of administrative privileges; securing the endpoints; and maintaining, monitoring and auditing network activity.<\/p>\n\n\n\n<p>But Villasenor adds, \u201cYou have to enforce cyber awareness training. One of our biggest threats is our own people. They can become victims very easily.\u201d<\/p>\n\n\n\n<p>DPR uses a third-party security awareness training service, ProofPoint, also known as Wombat, for training software and materials, but schedules and runs its own sessions in house. Wombat\u2019s tools include a phish alarm button that email users can click to automatically report suspicious email to IT, but it also includes a system to check whether the sender has already been checked and added to a whitelist of trusted sources. That can save IT from being inundated with false alarms. Phishing can also be reported directly to Microsoft 365, Villasenor says. \u201cThey react very quickly. The best thing is to always report such incidents.\u201d<\/p>\n\n\n\n<p>\u201cYou are only as good as the weakest link,\u201d notes Weaver. \u201cIt\u2019s why so many of the megabreaches you read about started with a third party connection. People, processes and technology: I always oversell the people side. You can have the best controls in place, but if you don\u2019t have comprehensive security awareness and training, you are a sitting duck.\u201d<\/p>\n\n\n\n<p>But Black &amp; Veatch\u2019s Voeller points out that addressing unsafe personnel practices is not a simple matter. People change jobs and there is no motivation or reward for dealing with the drudgery of methodically cleaning up their digital traces.<\/p>\n\n\n\n<p>\u201cIn the future, people using data will be bonded in the same manner that we bond people handling money,\u201d says Voeller. \u201cAs you hear the calls for regulation, be aware that I have been campaigning with major cyber leaders for making major data holders and creators to be treated as regulated utilities in the same manner as power, water and telecom. It is an essence of life, just like water, power and communications. Credentials will follow.\u201d<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><br><strong>Cyber Insurance<\/strong><\/h3>\n\n\n\n<p>Insurance broker Aon produced a U.S. Construction Industry Risk Outlook Report in February that claims cyber insurance options for construction are improving and, from the contractor\u2019s standpoint, it is a buyer\u2019s market.<\/p>\n\n\n\n<p>The Aon report suggests \u201cthis is a good time to lock in baseline competitive pricing before any hardening of pricing occurs.\u201d It says many construction-related firms are purchasing their first cyber policies because they are implementing technology to stay competitive and drive revenue, or are contractually obligated to have coverage, or their boards of directors are requiring it.<\/p>\n\n\n\n<p>The report notes the ironic benefit that, despite the construction industry being hit with more ransomware leading to complex network business interruptions and rising incident response expenses, the resulting claims and loss data is leading to expanded coverage offerings and improved actuarial data for loss modeling purposes. \u201cThe stratification of risk enabled by improved data and analytics leads to better outcomes for the best specific risks,\u201d the report states.<\/p>\n\n\n\n<p>The report says this has led to average premium rates for cyber insurance dropping, on a year-over-year basis.<\/p>\n\n\n\n<p>Takaoka says the end result is that \u201cin ransomware situations there seems to be plenty of coverage. [Insurers] will pay ransom, and it\u2019s pretty well known, but with wire fraud, it kind of depends.\u201d<\/p>\n\n\n\n<p>\u201cCyber insurance is a great risk transference tool,\u201d says Weaver. \u201cIt comes in very handy if you have an incident. There are many regulation, notification, legal, and fine costs. Also, it provides you with training, policies and resources to prevent an incident.\u201d<\/p>\n\n\n\n<p>But looking across the whole construction industry, sources have a bleak view of the industry\u2019s level of cybersecurity maturity, to borrow a term from Aon\u2019s Takaoka.<\/p>\n\n\n\n<p>While DPR\u2019s Villasenor is confident that his company\u2019s processes are performing well, on a scale of 1 to 10, he gives the industry as a whole dismal marks. \u201c[Construction\u2019s] cybersecurity score is low, perhaps 3 on a 10-point scale,\u201d he says. \u201cMany firms see cybersecurity as slowing operations or a high overhead cost versus perceived return on investment. Unfortunately, it has taken serious incidents for firms to truly understand the threat.\u201d<\/p>\n\n\n\n<p>Warfel\u2019s IT director Weaver was even less sanguine. \u201cTwo,\u201d he says. \u201cI think it\u2019s worse than most people know.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Tom Sawyer and Jeff Rubenstone | Engineering News-Record | May 8, 2019 Construction Cybercrime Is On The Rise Cybercriminals find the construction world a rich phishing ground with fat prey and soft targets. At the end of April, just as St. Ambrose Roman Catholic Church in Brunswick, Ohio, neared the close of a five-month-long, $5.5-million&hellip; <a class=\"more-link\" href=\"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/\">Continue reading <span class=\"screen-reader-text\">A Match Made in Cyber Hell<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[14],"tags":[9895,10818,10817],"class_list":["post-895953","post","type-post","status-publish","format-standard","hentry","category-construction-2","tag-advise-consult","tag-construction-cybercrime","tag-cybercrime","entry"],"jetpack_publicize_connections":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>A Match Made in Cyber Hell - Advise &amp; Consult, Inc.<\/title>\n<meta name=\"description\" content=\"Construction cybercrime is on the rise. Cybercriminals find the construction world a rich phishing ground with fat prey and soft targets\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"A Match Made in Cyber Hell - Advise &amp; Consult, Inc.\" \/>\n<meta property=\"og:description\" content=\"Construction cybercrime is on the rise. Cybercriminals find the construction world a rich phishing ground with fat prey and soft targets\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/\" \/>\n<meta property=\"og:site_name\" content=\"Advise &amp; Consult, Inc.\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Advise-Consult-Inc-126949043996790\/\" \/>\n<meta property=\"article:published_time\" content=\"2019-06-04T17:26:52+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-06-04T17:27:01+00:00\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@adviseconsult\" \/>\n<meta name=\"twitter:site\" content=\"@adviseconsult\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"18 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/www.myconstructionexpert.com\/blog\/#\/schema\/person\/0a11abe008083d5fb19c2b0feefe7bd7\"},\"headline\":\"A Match Made in Cyber Hell\",\"datePublished\":\"2019-06-04T17:26:52+00:00\",\"dateModified\":\"2019-06-04T17:27:01+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/\"},\"wordCount\":3672,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.myconstructionexpert.com\/blog\/#organization\"},\"keywords\":[\"Advise &amp; Consult\",\"Construction Cybercrime\",\"Cybercrime\"],\"articleSection\":[\"Construction\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/\",\"url\":\"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/\",\"name\":\"A Match Made in Cyber Hell - Advise &amp; Consult, Inc.\",\"isPartOf\":{\"@id\":\"https:\/\/www.myconstructionexpert.com\/blog\/#website\"},\"datePublished\":\"2019-06-04T17:26:52+00:00\",\"dateModified\":\"2019-06-04T17:27:01+00:00\",\"description\":\"Construction cybercrime is on the rise. Cybercriminals find the construction world a rich phishing ground with fat prey and soft targets\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.myconstructionexpert.com\/blog\/#website\",\"url\":\"https:\/\/www.myconstructionexpert.com\/blog\/\",\"name\":\"Advise &amp; Consult, Inc.\",\"description\":\"Construction Expert Witnesses\",\"publisher\":{\"@id\":\"https:\/\/www.myconstructionexpert.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.myconstructionexpert.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.myconstructionexpert.com\/blog\/#organization\",\"name\":\"Advise & Consult\",\"url\":\"https:\/\/www.myconstructionexpert.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.myconstructionexpert.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.myconstructionexpert.com\/blog\/wp-content\/uploads\/2015\/11\/AC-Red-Logo.png\",\"contentUrl\":\"https:\/\/www.myconstructionexpert.com\/blog\/wp-content\/uploads\/2015\/11\/AC-Red-Logo.png\",\"width\":162,\"height\":75,\"caption\":\"Advise & Consult\"},\"image\":{\"@id\":\"https:\/\/www.myconstructionexpert.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Advise-Consult-Inc-126949043996790\/\",\"https:\/\/x.com\/adviseconsult\",\"https:\/\/www.linkedin.com\/company-beta\/204526\/\",\"https:\/\/www.youtube.com\/user\/MrConstructionExpert\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.myconstructionexpert.com\/blog\/#\/schema\/person\/0a11abe008083d5fb19c2b0feefe7bd7\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.myconstructionexpert.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b01e71b7acadd7657af782b7ad1a30cc?s=96&d=mm&r=pg\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b01e71b7acadd7657af782b7ad1a30cc?s=96&d=mm&r=pg\",\"caption\":\"admin\"},\"sameAs\":[\"http:\/\/www.expertwitnessinconstruction.com\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"A Match Made in Cyber Hell - Advise &amp; Consult, Inc.","description":"Construction cybercrime is on the rise. Cybercriminals find the construction world a rich phishing ground with fat prey and soft targets","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/","og_locale":"en_US","og_type":"article","og_title":"A Match Made in Cyber Hell - Advise &amp; Consult, Inc.","og_description":"Construction cybercrime is on the rise. Cybercriminals find the construction world a rich phishing ground with fat prey and soft targets","og_url":"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/","og_site_name":"Advise &amp; Consult, Inc.","article_publisher":"https:\/\/www.facebook.com\/Advise-Consult-Inc-126949043996790\/","article_published_time":"2019-06-04T17:26:52+00:00","article_modified_time":"2019-06-04T17:27:01+00:00","author":"admin","twitter_card":"summary_large_image","twitter_creator":"@adviseconsult","twitter_site":"@adviseconsult","twitter_misc":{"Written by":"admin","Est. reading time":"18 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/#article","isPartOf":{"@id":"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/"},"author":{"name":"admin","@id":"https:\/\/www.myconstructionexpert.com\/blog\/#\/schema\/person\/0a11abe008083d5fb19c2b0feefe7bd7"},"headline":"A Match Made in Cyber Hell","datePublished":"2019-06-04T17:26:52+00:00","dateModified":"2019-06-04T17:27:01+00:00","mainEntityOfPage":{"@id":"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/"},"wordCount":3672,"commentCount":0,"publisher":{"@id":"https:\/\/www.myconstructionexpert.com\/blog\/#organization"},"keywords":["Advise &amp; Consult","Construction Cybercrime","Cybercrime"],"articleSection":["Construction"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/","url":"https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/","name":"A Match Made in Cyber Hell - Advise &amp; Consult, Inc.","isPartOf":{"@id":"https:\/\/www.myconstructionexpert.com\/blog\/#website"},"datePublished":"2019-06-04T17:26:52+00:00","dateModified":"2019-06-04T17:27:01+00:00","description":"Construction cybercrime is on the rise. Cybercriminals find the construction world a rich phishing ground with fat prey and soft targets","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.myconstructionexpert.com\/blog\/construction-cybercrime-match-made-in-cyber-hell\/"]}]},{"@type":"WebSite","@id":"https:\/\/www.myconstructionexpert.com\/blog\/#website","url":"https:\/\/www.myconstructionexpert.com\/blog\/","name":"Advise &amp; Consult, Inc.","description":"Construction Expert Witnesses","publisher":{"@id":"https:\/\/www.myconstructionexpert.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.myconstructionexpert.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.myconstructionexpert.com\/blog\/#organization","name":"Advise & Consult","url":"https:\/\/www.myconstructionexpert.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.myconstructionexpert.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.myconstructionexpert.com\/blog\/wp-content\/uploads\/2015\/11\/AC-Red-Logo.png","contentUrl":"https:\/\/www.myconstructionexpert.com\/blog\/wp-content\/uploads\/2015\/11\/AC-Red-Logo.png","width":162,"height":75,"caption":"Advise & Consult"},"image":{"@id":"https:\/\/www.myconstructionexpert.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Advise-Consult-Inc-126949043996790\/","https:\/\/x.com\/adviseconsult","https:\/\/www.linkedin.com\/company-beta\/204526\/","https:\/\/www.youtube.com\/user\/MrConstructionExpert"]},{"@type":"Person","@id":"https:\/\/www.myconstructionexpert.com\/blog\/#\/schema\/person\/0a11abe008083d5fb19c2b0feefe7bd7","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.myconstructionexpert.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/b01e71b7acadd7657af782b7ad1a30cc?s=96&d=mm&r=pg","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b01e71b7acadd7657af782b7ad1a30cc?s=96&d=mm&r=pg","caption":"admin"},"sameAs":["http:\/\/www.expertwitnessinconstruction.com"]}]}},"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p2ztG6-3L4R","jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/www.myconstructionexpert.com\/blog\/wp-json\/wp\/v2\/posts\/895953","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.myconstructionexpert.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.myconstructionexpert.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.myconstructionexpert.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.myconstructionexpert.com\/blog\/wp-json\/wp\/v2\/comments?post=895953"}],"version-history":[{"count":1,"href":"https:\/\/www.myconstructionexpert.com\/blog\/wp-json\/wp\/v2\/posts\/895953\/revisions"}],"predecessor-version":[{"id":895954,"href":"https:\/\/www.myconstructionexpert.com\/blog\/wp-json\/wp\/v2\/posts\/895953\/revisions\/895954"}],"wp:attachment":[{"href":"https:\/\/www.myconstructionexpert.com\/blog\/wp-json\/wp\/v2\/media?parent=895953"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.myconstructionexpert.com\/blog\/wp-json\/wp\/v2\/categories?post=895953"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.myconstructionexpert.com\/blog\/wp-json\/wp\/v2\/tags?post=895953"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}