What Is Vishing?

Vishing: What It Is, How It Works, and How to Protect Yourself from Fraudulent Calls

The phone rings; you see a number that looks like your bank's, and you pick up without thinking twice. That's exactly what vishing is: a phone scam that uses social engineering and identity theft to steal your login credentials, verification codes, or money.

The term is a portmanteau of “voice” and “phishing,” and in recent years it has become one of the fastest-growing types of fraud in Spain.

What exactly is vishing?

Vishing is a phone scam in which the attacker impersonates a trusted entity (a bank, the tax authority, a telecommunications provider, or a company’s technical support) to trick the victim into revealing sensitive information or authorizing a transfer. No malware is involved, and there is no link to click; the entire attack happens during the conversation.

According to data from INCIBE, the public cybersecurity agency handled more than 120,000 cybersecurity incidents in 2025—a 26% increase from the previous year—and the industry itself reports that vishing was one of the fastest-growing types of cyberattacks during that period.

The Ministry of the Interior recorded 489,248 cybercrimes in 2025, of which 430,493 were computer scams. Far from being an outdated channel for fraud, the telephone has become one of scammers' preferred methods.

 

How Does Vishing Work? The Anatomy of a Fraudulent Call

A vishing attack usually follows a fairly recognizable script once you're familiar with it, even if it seems convincing at the time:

  1. Caller ID spoofing. The number you see on the screen looks real—it even matches your bank’s number—because the attacker has forged it.
  2. A sense of urgency. They alert you to a suspicious charge, an account freeze, or a held package. The goal is to make you act out of fear rather than calmly.
  3. Request for information or codes. They ask you to “confirm” your identity by providing an SMS code, your PIN, or saying “yes” out loud—information that can later be used to access your accounts, just like an infostealer that compromised your device.
  4. Quick hang-up. Before you can verify anything through another channel, the call ends and the damage is already done.

What has changed in recent years is the technical sophistication. Voice cloning using artificial intelligence now makes it possible to imitate the voice of a family member or an executive with just a few seconds of audio—something that sounded like science fiction a few years ago but is now a real threat to businesses and individuals alike.

You might be interested in:> SIM Swapping: What It Is, How It Works, and How to Avoid This Scam in 2026

 

 

 

Examples of vishing currently circulating

Here are some of the most common examples of vishing reported in Spain:

Call Type What they say What they're looking for
Fake Bank Security Department “We’ve detected suspicious activity in your account” SMS code or online banking password
Fake technical support “Your computer has a virus; we need remote access” Install remote control software
Fake Tax Agency “You have a pending tax refund—please confirm your information” Bank and personal information
Voice-Based CEO Fraud “I’m the CEO; I need an urgent wire transfer” Payment authorization from an employee
Fake telephone operator “We’re going to upgrade your plan—please confirm the code you receive” Fraudulent number porting

This last scenario is particularly dangerous because, if the scammer manages to port your number, they can intercept the verification codes from your banking apps.

 

How to Spot a Vishing Attack Before It’s Too Late

There are signs that are almost always present, although sometimes it's hard to see them in the heat of the moment:

  • They contact you unexpectedly and in a hurry, leaving you no time to think.
  • They ask for information that the real organization would never ask for over the phone, such as your full PIN or an SMS code.
  • They insist that you don’t hang up and call that number yourself to “verify” that it’s legitimate: that’s exactly the opposite of what you should do.
  • The caller ID matches your bank’s actual number—but that’s no longer a guarantee of anything, since caller ID spoofing is commonplace.

An important note: the classic advice to “hang up and call the number you have saved” is still valid, but only if you manually dial the number from your own phone—never call back or press any buttons the scammer suggests.

 

How to Avoid Vishing

Preventing vishing doesn't depend on having more technology, but on changing a few habits:

  • Never give out verification codes over the phone. No legitimate organization asks for them that way.
  • Hang up and verify through another channel. Contact your bank through the official app or the phone number listed on your documents—not the one that called you.
  • Be wary of any sense of urgency. Almost any real problem can wait ten minutes while you verify the information.
  • Install a call blocker that uses a database of numbers reported as fraudulent.
  • If you run a business, train your team. Voice-based CEO fraud has grown because many employees don't know it exists.

If you’ve already provided any sensitive information, act quickly: block your cards or access through your bank’s app, change your passwords, and file a report with the police or the Civil Guard. The sooner you act, the less time the scammer has to use that information.

 

Vishing in the Business World: Continuous Monitoring vs. Exposure

For a company, even one employee falling victim to vishing can open the door to a credential leak, CEO fraud, or unauthorized access to internal systems. One-time training is no longer enough; you must know at all times what data, credentials, or references about the organization are circulating externally, because many vishing campaigns are built using information from previous data breaches or exposed corporate profiles.

This is precisely what Continuous Threat Exposure Management (CTEM) is—a cyber-surveillance approach that continuously monitors what information about your company, your employees, or your suppliers is accessible to a potential attacker before they can use it.

Kartos, Enthec's cybersecurity monitoring solution, applies this CTEM model to businesses, detecting leaked credentials, data exposure, and attack surfaces that are later exploited in targeted vishing campaigns.

 

Frequently Asked Questions About Vishing

Is vishing the same as phishing?

No. Phishing occurs via email or a link, while vishing occurs via a phone call. Both aim to steal data or money, but they use different channels and different manipulation techniques.

Can the bank refund my money if I fall victim to a vishing scam?

It depends on the specific case. If someone accessed your account without your consent, PSD2 regulations require the bank to refund the amount. If you authorized the transaction under false pretenses, the process is more complicated, although Spanish courts are increasingly ruling in favor of victims.

How do I know if a call from my bank is real?

Hang up and call the official number listed on your card or in the app yourself. Never use the number that called you or the one the caller suggests.

Are small businesses also targets of vishing?

Yes, in fact, they are a common target precisely because they tend to have fewer verification protocols than large corporations, and a single transfer authorized by mistake can result in a significant loss.


Digital Supply Chain Risk

Digital Supply Chain Risk: Why Your Supplier's Security Breach Could Be Your Problem

Your company may have the best firewall on the market and still suffer a data breach without anyone ever having accessed your network. All it takes is for one of your vendors to have exposed credentials or a misconfigured server.

This is, in essence, the risk of the digital supply chain—that is, the exposure you inherit from every application, cloud service, or integration you connect to your business, even if you don’t manage it directly.

What exactly is digital supply chain risk?

When we talk about digital supply chain risk, we're referring to the vulnerabilities that enter your organization through third parties such as the invoicing software your finance department uses, the CRM where you upload customer data, or the logistics provider that has access to your ERP. Each of these points is a gateway that you don’t control, but for which you are held accountable.

This isn't a new problem, but in the past, a company typically had five or six critical suppliers. Today, with software as a service, APIs, and outsourcing, the list easily exceeds a hundred, and a large portion of it isn't even tracked.

 

Why a Supplier's Shortfall Becomes Your Problem

Here’s the nuance that many companies overlook: legally—and in the eyes of your customers—it almost never matters who made the mistake, but rather who is ultimately responsible for the data. And we’re not just talking about a financial penalty, but also the reputational damage that will follow the company.

According to an analysis by Cipher (Supply Chain Attacks: 2025 Analysis and 2026 Trends), by 2025, 22.5% of all reported security breaches involved a supplier or third party—twice as many as the previous year. And yet, most organizations continue to assess their cybersecurity solely from the inside.

 

The Most Common Blind Spots in Your Supply Chain

Most third-party security breaches result from oversights that build up over time and that no one stops to review:

  • Subdomains and Forgotten Assets: test environments or old websites that are still active and unpatched.
  • Leaked credentials: employee or vendor passwords circulating on the deep web following a third-party breach.
  • Unreviewed third-party access: integrations and permissions granted once and never audited.
  • Shadow IT: applications that a team procures without going through the IT department.
  • Mentions on underground forums: Information about your company circulating on the dark web without your knowledge.

Any of these points can become the source of an incident if no one monitors them constantly.

Digital Supply Chain

From the Annual Audit to the CTEM Approach

For years, the standard response to this risk was one-time on an ad hoc basis or vendor audit once a year. The problem is that months can pass between reviews, during which the attack surface can change completely.

 

Focus Frequency What it detects Main limitation
Annual Audit

 

On time, once a year Snapshot of the security status Outdated within weeks
Periodic Penetration Testing

 

Every 6–12 months Known technical vulnerabilities Does not cover third parties or new assets
CTEM (Continuous Threat Exposure Management)

 

Continuous Actual exposure, compromised credentials, forgotten assets, vendor risk Requires a specialized tool

 

CTEM (Continuous Threat Exposure Management) is based on a different concept: cybersecurity isn’t a test you pass once a year; it’s a process that must be monitored every day. Instead of waiting for the next audit, the goal is to have constant visibility into what is at risk, where, and how urgently action is needed.

This is where Enthec comes in, with its cyber-surveillance solutions designed specifically for this approach. Kartos, its enterprise platform, continuously monitors an organization’s exposed digital footprint and that of its critical suppliers. It detects leaked credentials, forgotten domains, and mentions on underground forums before they turn into an incident.

For those who manage their own exhibitions as professionals or freelancers, Enthec also offers Qondar, designed to monitor digital identity on an individual level.

What Your Company Can Do Starting Today

There's no need for a radical change overnight, but it's a good idea to start moving in this direction:

  1. Take a real inventory of your critical suppliers and what data or access each one has.
  2. Ask those vendors what security controls they implement and whether they are willing to share that information.
  3. Replace one-time reviews with continuous monitoring of your company’s and your value chain’s exposure.
  4. Prioritize based on impact, because not all suppliers require the same level of scrutiny.

 

Frequently Asked Questions

What is the difference between third-party risk and digital supply chain risk?

Third-party risk focuses on each individual supplier—their controls, certifications, track record, and so on. Digital supply chain risk is broader; it encompasses the entire network of technological dependencies through which an incident can spread.

How is the risk of a digital supplier measured?

It combines public information—such as exposed domains, leaked credentials, or reputation—with security questionnaires and, when possible, continuous monitoring of its exposure surface using cyber-surveillance tools.

Does CTEM replace penetration testing?

No, it complements it. Penetration testing remains useful for testing specific controls at a given time. The CTEM provides continuous monitoring between those one-off tests.

What size of company needs to monitor its digital supply chain?

Any company that relies on external suppliers to operate—which, these days, is practically any company with an online presence, regardless of its size.

If you want to know how much exposure your company and your critical suppliers have today, you can request a Kartos demo and see firsthand what it finds in your digital landscape.


robo de los datos de la tarjeta de crédito

How can your credit card data be stolen?

Spain is the third-most-affected European country for stolen credit cards sold on the dark web. According to a 2025 NordVPN study, Spanish users' banking data sells for an average of $11.68 per card, usually in bundles, suggesting the volume of compromised cards circulating in illegal markets. Meanwhile, in February 2026, Spanish banks and the OCU (Spanish Consumers' Organization) issued alerts after detecting a wave of fraudulent charges of just a few cents, designed to test whether a card is working before the final theft.

Knowing how your card details are stolen and what they do with them afterward is the first step to avoid becoming a victim.

 

Theft of credit card data in non-face-to-face transactions

In recent years, EMV systems have been implemented to prevent the physical cloning of credit cards. EMV is a payment method based on a technical standard for smart payment cards, payment terminals, and ATMs that can accept them. EMV stands for "Europay, Mastercard, and Visa," the three companies that created the standard.
That's why credit card vulnerabilities are more common during card-not-present (CNP) transactions.

 

How can they steal your credit card information? Most common forms

Cybercriminals use a variety of techniques to obtain your card details in both physical and digital environments. These are the most widespread methods currently used:

Phishing, smishing, and vishing

Phishing is the most common method. The attacker impersonates your bank, a courier company, or a payment platform (Amazon, PayPal, BBVA, CaixaBank, etc.) and sends you an email or SMS with a link to a fake website where you unknowingly enter your card details.

  • Smishing: The same technique is used via SMS. You often see messages like, "Your package is being held, please enter your details to release it."
  • Vishing: Phone call. The "fake bank technician" scam involves someone who detects a suspicious purchase and asks you to confirm details to cancel it.

In all cases, the objective is the same: for you to voluntarily enter the card number, expiry date, and CVV.

 

 

phishin to steal credit card data

Web skimming (formjacking)

Web skimming, also known as formjacking, involves injecting malicious JavaScript code into the payment page of a legitimate online store. The code is completely invisible to both the user and the merchant. It captures card details as soon as they are entered and sends them to the attacker's server.

Skimming and shimming on ATMs and data phones

Although EMV (chip) systems drastically reduced classic skimming, criminals have evolved:

  • Skimming: Installation of a physical device over the card reader of an ATM or point-of-sale terminal that copies the magnetic stripe. Modern models incorporate Bluetooth transmission to extract data remotely.
  • Shimming: The most recent and difficult-to-detect variant involves criminals inserting an ultra-thin electronic strip (shim) into the card reader slot. This shim intercepts communication between the card's EMV chip and the terminal, allowing them to read enough data to create fraudulent magnetic stripe cards.

Corporate data breaches

When criminals attack a company that stores payment data, they can obtain thousands or millions of card records in one fell swoop. These breaches are especially profitable for attackers and are the primary source of leaked credit card information sold on the dark web.

Data stolen in corporate security breaches can take months to appear on illegal markets. This prevents users from linking the leak to a specific incident.

Public WiFi networks and man-in-the-middle attacks

When you connect to an unencrypted public Wi-Fi network (airport, coffee shop, hotel) and make a purchase, an attacker on the same network can intercept the communication and capture your card details. This technique, known as a man-in-the-middle attack, is less common today thanks to HTTPS, but it remains an active vector in poorly configured networks.

Malware and spyware on devices

Malicious apps or infected downloads can install a keylogger or spyware that records everything you type, including your card details when making online purchases.

 

Technique Environment How it works Warning sign
Phishing / smishing Online / Mobile Email or SMS with a link to a fake bank website Suspicious URL, urgency in the message
Vishing Telephone A call from "your bank" asking for details No bank asks for the CVV over the phone.
Web skimming Online stores Malicious code in the payment form Difficult to detect as a user
Physical skimming ATMs and POS terminals Device superimposed on the reader Reader with loose or strange parts
Shimming ATMs and POS terminals Foil in the EMV chip slot Almost impossible to detect with the naked eye
Data leak Companies Database breach in a business Unknown charges weeks later
Public WiFi Open Networks Interception of the unencrypted connection Password-free Wi-Fi in public places
Malware / keylogger Own device Malicious app or download records keystrokes Strange device behavior

 

How are credit cards cloned?

Card cloning is the process by which criminals create a physical or virtual copy of your card using stolen data to make fraudulent purchases.

There are two main types:

  • Physical cloning: Using data obtained from the magnetic stripe via skimming, criminals encode a blank card with that information. This allows it to be used in stores that still accept magnetic stripe cards (increasingly less common in Europe, but still common in some Latin American countries or for in-person purchases with outdated terminals).
  • Virtual cloning (carding): Using the card's full details (number, expiration date, and CVV), criminals can make online purchases directly, without needing to manufacture any physical object. This has been the dominant method in Spain since the widespread adoption of the EMV chip.

The entire carding process operates like an industrial chain: some criminals steal the data, others validate it by making micropayments of cents to verify that the card is active, and a third group exploits it until the available credit is exhausted.

 

What can they do with your card details?

Once your card details are in the hands of attackers, the most common uses are:

Fraudulent use Description
Direct online purchases They place orders in online stores on behalf of third parties or with an anonymous shipping address
Selling on the dark web They sell the data in packages to other criminals at an average price of €10 per card in Spain
Carding (test micropayments) They make minimal charges (€0.50–€1) to verify that the card works before operating.
Creation of cloned physical cards Using magnetic stripe data, they manufacture cards for use in chip-free POS terminals
Identity fraud They combine your card details with other personal information to impersonate you.
Fraudulent transfers or tricks In some cases, they can access online banking if they also have the login credentials.

 

 

My credit card was hacked: signs to detect it and what to do

If you suspect your credit card has been hacked, or that your data is part of a credit card leak, the signs often appear sooner than you think, although almost no one associates them with fraud until the damage is already visible.

These are the most frequent signs that indicate your card details may have been compromised:

  • Unknown charges on your statement, especially micropayments of cents (a classic sign of carding).
  • Notifications from your bank for purchases you did not make, even if you had the card at all times.
  • Failed attempts to access your online banking from unknown devices or locations.
  • You receive purchase confirmations for orders you didn't place. Sometimes on platforms you don't even know exist.
  • Your card is declined for a routine purchase for no apparent reason (this may indicate the bank blocked it due to suspicious activity detected before you).
  • Your bank details appear in a data breach alert, such as those issued by Qondar when it detects your credentials on the dark web.

Practical rule: Review your card transactions at least once a week. The sooner you identify a fraudulent charge, the easier it is to recover your money and the less damage it can do.

 

What to do if your card details have been stolen?

If you detect unauthorized charges or suspect that your data has been compromised, act in this order:

  1. Call your bank immediately to block or cancel the card. Most have a 24-hour helpline. Do it even if you're not sure; it's free and reversible.
  2. Document fraudulent charges with screenshots of the statement before the bank removes them from the visible history.
  3. File a complaint with the National Police or the Civil Guard. This is necessary for the bank to process the refund and for the police investigation to move forward.
  4. Request a chargeback from your bank. In cases of card fraud, European regulations (PSD2) require banks to return the amount immediately in most cases, except in cases of serious cardholder negligence.
  5. Check if your data is circulating on other platforms using monitoring tools like Qondar. Credit card data breaches often expose other personal data as well.
  6. Change the passwords on the platforms where you saved that card. (Amazon, PayPal, plataformas de streaming...).

 

How to protect your credit card data: a practical guide 2026

Online shopping

  • Only buy from websites with HTTPS and recognized trust seals.
  • Use single-use virtual cards for purchases at stores you don't know.
  • Activate real-time notifications from your bank for every charge.
  • Avoid saving your card details on platforms if you don't use them regularly.
  • Never make purchases while connected to a public WiFi network without a VPN.

At ATMs and card payment terminals

  • Visually inspect the reader before inserting the card. If it has loose parts, play, or anything stuck to it, do not use it.
  • Prefer contactless (NFC) payment to push notifications whenever possible: it eliminates the risk of shimming.
  • Cover the keypad with your hand when entering the PIN, even if you don't see any cameras.
  • Preferably use ATMs located in bank offices or large establishments.

On your device and email

  • Do not click on links in SMS messages or emails that ask you to confirm bank details, even if the sender appears to be your bank. Always access your account through the official app or by typing the URL directly.
  • Keep your operating system and applications updated to close malware vulnerabilities.
  • Activate two-factor authentication (2FA) on your online banking.

Continuous monitoring

Reactive protection has its limits; you act only after you know something has happened. Continuous monitoring of your data on the dark web, like that offered by Qondar, allows you to detect a breach before it can be exploited.

Learn more about personal privacy and how to protect it.

 

Qondar: Continuous monitoring of your banking data on the web and the dark web

Most credit card fraud goes undetected until the damage is already done. The problem is that weeks or months can pass between when your data is leaked and when a criminal uses it.

Qondar, Enthec's personal cyber-surveillance platform, solves exactly this problem. It automatically and continuously monitors whether your card details, such as the number, expiration date, and combinations with your email or phone number, appear in leaked databases, carding forums, dark web marketplaces, or any other source of exposure.

When it detects that your data is being transmitted, it alerts you in real time. So you can cancel the card, notify the bank, and block any use before the impact becomes greater.

You don't need technical knowledge. Qondar works in the background, like a permanent alarm system for your identity and digital assets.

 

Frequently Asked Questions

How can they steal my card details without taking the card from me?

Through digital techniques such as phishing (fake websites that impersonate your bank), web skimming (malicious code in online stores), or malware on your device. They can also use physical devices installed on ATMs (skimming and shimming) that capture data when you insert your card.

What is a leaked credit card?

A leaked credit card is one whose data criminals have illegally obtained and sold or distributed on dark web marketplaces or carding forums. In 2025, Spain was the third European country with the most leaked credit cards circulating on these markets.

How are credit cards cloned?

Through skimming (devices on ATMs that read the magnetic stripe) or shimming (sheets that intercept the EMV chip), criminals obtain data to manufacture counterfeit physical cards. In online environments, virtual cloning uses the card number, expiration date, and CVV to make purchases without needing a physical card.

How can I tell if my debit or credit card has been hacked?

The clearest signs are unfamiliar charges on your statement, purchase confirmations you didn't make, or your card being declined for no apparent reason. You may also receive alerts from your bank or tools like Qondar if your data appears in a data breach.

What can they do with my card details?

They primarily use them to make fraudulent online purchases, sell them on the dark web to other criminals, or create cloned physical cards. In some cases, they also combine them with other personal data to impersonate you with your bank.

Will the bank refund my money if my card has been hacked?

In most cases, yes, as long as you report it promptly and you were not grossly negligent. European regulations such as PSD2 require banks to refund the amount immediately in cases of card fraud.

Is it the same if my physical card is stolen as if my data is stolen?

No. If your physical card is stolen, the bank blocks it and issues a new one. If someone steals your data (number, expiration date, CVV) without you losing the card, you may keep using it without knowing it's compromised, while criminals use it online. That's why early detection is crucial.

How can I prevent my card details from being leaked?

Use single-use virtual cards for online purchases, activate real-time notifications, avoid entering data on websites without HTTPS, physically inspect ATMs before using them, and use continuous monitoring tools like Qondar to see whether your data has appeared in any data breaches.

 


What is doxing: Definition, risks, and how to protect yourself

The Internet is a space where we share information daily. Social networks, forms, online purchases… Each action leaves a slight digital trace. Most of the time, we are unaware of how much we reveal about ourselves. This is where an increasingly well-known and feared concept comes into play: doxing.

 

What is doxing, and why should you care?

Doxing (short for dropping dox or "dropping documents") is the practice of collecting and publishing a person's personal information without their consentwith the aim of exposing, intimidating, or harming them. This may include her full name, address, phone number, email address, place of work, private photos, family information, and even financial data.

What distinguishes doxing from a simple Google search is the intention: the doxer gathers scattered information from multiple sources such as social networks, leaked databases, public records, the dark web… to build a detailed profile of a person and use it against them.

These types of attacks, which initially emerged in very specific online communities, have spread in recent years and can have serious consequences: from harassment, threats, and identity theft… up to and including job loss or legal problems.

Doxing on the internet is not just a simple hacking game. It is a form of digital violence classified in Spain and many other countries with penalties that can reach up to four years in prison.

 

Qondar: Personal cyber-surveillance to know when you're being doxed before it's too late

Before continuing, it is worth stopping at our featured tool: Qondar, a solution for personal cyber surveillance.

Qondar has been developed for anyone who wants to maintain control over their information on the network without needing advanced technical knowledge. It works like a Continuous Threat Exposure Management (CTEM) platform. It lets you detect if your data is being shared without permission in forums, leaked databases, social networks, or even the dark web.

Even if you don't know what doxing on the internet is, you may still suffer an attack. If so, Qondar will tell you before it's too late.

 

Why does someone decide to dox another person?

There is no single attacker profile or motivation. Doxing, as this phenomenon is also known, can have many faces:

  • Personal revenge: Ex-partners, ex-friends, or work conflicts can lead to malicious leaks.
  • Extreme ideology or activism: Some users publish data about opponents to intimidate or silence them in political or social debates.
  • Practical jokes or viral challenges: especially among teenagers or in toxic online communities.
  • Extortion and blackmail: Once they have your data, some attackers try to obtain money or favors in exchange for not disclosing it.
  • Coordinated harassment. Organized groups (sometimes called hate brigades) simultaneously attack the same person, especially journalists, activists, or public figures.
  • Professional cybercrime. Personal information such as DOB, address, and phone number is sold on specialized forums to facilitate identity fraud.

Whatever the reason, the result is the same: your privacy and security are compromised.

 

what is doxing

 

What type of data is typically exposed when doxing?

Although the degree of exposure varies, the most common data that is published or sold in doxing cases are:

  • Full name and physical address
  • Phone number
  • Email
  • Profiles on social networks (including anonymous accounts linked to the person)
  • Personal photos
  • Information about the family environment
  • Employment or academic data
  • Purchases, searches, donations, or affiliations

A simple cross-referencing of leaked databases, like those circulating on the dark web, can be enough to build a complete profile in minutes. That's why prevention is more effective than reaction.

Bonus: Where is doxed data published? Primarily on platforms like Doxbin (accessible from the open web, with nearly 200,000 registrations), dark web forums, Telegram channels, and, in cases of coordinated harassment, directly on social networks like X or Reddit.

 

How to avoid being doxed: good practices to protect your privacy

To know how to protect yourself from doxing involves changing certain digital habits.. Here are some practical tips that you can start applying today, now that you understand what doxing is:

  • Audit your digital footprint regularly

Enter your first and last name into search engines and see what comes up. Also search for combinations with your email address, phone number, and most-used username. If you find data that shouldn't be public, request its removal by exercising your right to be forgotten through your national Data Protection Agency.

Tools like Qondar automate this process by monitoring any new occurrences in your data in real time and notifying you immediately.

  • Review the privacy settings of your social media accounts

  • Activate private profiles on Instagram, TikTok, and Facebook.
  • Check what information is public on LinkedIn (date of birth, phone number, location).
  • Delete or limit your Facebook posting history.
  • Do not post documents, plane tickets, or photos that show your address or car registration.

You might be interested in→ 5 social media security strategies.

  • Use strong, unique passwords and enable 2FA

  • Do not reuse passwords across multiple services.
  • Enable two-step authentication (2FA) whenever possible.

Learn how to manage passwords properly.

  • Beware of online forms and contests

  • Do you really need to give your phone number to enter that raffle?
  • Use secondary or temporary email addresses whenever possible.
  • Protect your anonymity in public debates and forums

Many doxing victims are targeted precisely because of their opinions expressed online. If you participate in polarized debates, avoid using the same username on multiple platforms and don't post unnecessary personal details.

  • Protect your immediate surroundings

Doxing often involves information about family members. Talk to people in your life about what information they post that could locate you (mentions of your workplace, photos taken at your home, geolocation of joint posts).

  • Continuously monitor with specialized tools

Manual protection has its limits. Continuous monitoring solutions like Qondar allow you to detect exposures in real time, including the appearance of your data on the dark web or in leaked databases, before the damage becomes irreversible.

 

How to avoid doxing

 

What do you do if you have been doxed?

If you're already a victim of doxing, act quickly. Every hour counts.

  1. Document everything before requesting withdrawals. Take screenshots of all published content, including URLs.
  2. Contact the platforms where the information has been published. Use the content removal forms from Google, Meta, X, and any other involved platforms.
  3. Report it to the National Security Authorities, especially if there are threats, blackmail, or sexual content. Doxing can be classified as discovery and disclosure of secrets, harassment, or threats.
  4. Contact your national Data Protection Agency if your data protection rights have been violated. In 2025, the Spanish AEPD imposed a record 40 million euros in sanctions, reflecting its growing activity in defense of citizens.
  5. Inform those around you so that they are alert to possible attempts at social engineering using your information.
  6. Seek psychological support if the emotional impact is intense. Cyberbullying can cause anxiety, post-traumatic stress, and social isolation.

 

Is there any definitive protection against doxing?

There is no 100% foolproof barrier. But you can drastically minimize your exposure and be prepared to act before the damage becomes serious.

The key lies in early detection. On the internet, published data is indexed, copied, and distributed within minutes. What takes hours to publish can take years to disappear. That's why continuous and proactive monitoring of your digital identity is the most effective measure available today.

This is precisely what Qondar does: to continuously and automatically monitor whether your information appears where it shouldn't, and alert you in real time so you can take action. No technical knowledge required. No interruptions to your daily routine.

Now that you know what doxing is, it's clear that it's not a problem exclusive to celebrities or public figures. In a world where identity theft on social media is growing year after year, protecting your personal information is crucial.

Your privacy is part of your security. Start protecting it today.

 

Frequently Asked Questions

What does it mean to dox someone?

Doxing someone means collecting and publishing that person's personal information (name, address, phone number, workplace, etc.) without their consent, with the aim of exposing, intimidating, or harming them.

Is it a crime to dox someone?

Yes. Although most penal codes around the world do not use the term "doxing," the practice can be classified as disclosure of secrets, harassment, or threats, with penalties of up to four years in prison. It can also lead to sanctions for violations of the Data Protection Acts and the Data Protection Regulations.

How do I know if I'm being doxed?

The most common signs are receiving threatening messages from strangers, noticing that people you don't know know details of your private life, or finding posts with your personal information on forums or social networks.

Tools like Qondar allow you to detect it proactively, before the effects are visible.

How to avoid being doxed?

The most effective measures are to audit your digital footprint regularly, properly configure privacy settings on social networks, use unique passwords with 2FA, be cautious with the data you provide in forms, and use continuous monitoring solutions like Qondar.

What do I do if someone has published my personal data without my permission?

Document everything with screenshots, request the removal of the content from the platform and Google through the right to be forgotten, report it to the Security Authorities, and go to the Data Protection Agency if your data protection rights have been violated.

 


Infostealer, the malware that silently steals your credentials before anyone detects it

An infostealer is a type of malware designed to steal passwords, session cookies, and banking information from a device without the victim noticing. It doesn’t encrypt files, display a ransom note, or slow the computer down. It simply copies whatever it finds and sends it to an external server.

That’s why, by the time someone discovers they’ve been infected, it’s usually too late—their credentials have been circulating on dark web forums for weeks or months.

 

Infostealer: What It Is and Why It’s Hard to Notice It’s There

The question of what an infostealer is has a more unsettling answer than usual: it is software designed to go unnoticed. Unlike ransomware, which requires the victim to know they’ve been attacked in order to demand a ransom, the infostealer relies on the opposite. The longer it goes undetected, the more new passwords it can capture each time the user logs in to a different service.

It is usually installed through pirated software cracks, a fake browser extension, or a legitimate-looking email attachment. Once inside, it runs just once, steals whatever it can, and in many cases self-destructs.

 

How InfoStealer Malware Works, Step by Step

The infostealer malware follows a fairly consistent pattern, although each family (Lumma, RedLine, Vidar, and Raccoon are the most active) has its own technical variants:

  • It accesses the database where the browser stores passwords and decrypts them locally.
  • It copies active session cookies, allowing it to impersonate the user even if two-step verification is enabled, because that cookie already proves that the MFA has been completed.
  • It extracts credentials from email clients, corporate VPNs, and cryptocurrency wallets.
  • It packages everything into a file called "stealer log" and uploads it to a Telegram channel or a dark web marketplace.

That last step is crucial. Stealer logs are collected, organized by domain, and resold to other cybercriminals for months on end. A stealer log collected today may still be useful to an attacker a year from now.

 

infostealer

Statistics that explain why infostealers have become the biggest silent threat

The figures from the latest industry reports leave little room for doubt. According to Flashpoint, infostealers stole more than 1.8 billion credentials in 2025 from 5.8 million infected devices, an 800% increase compared to the previous four months.

FACT

FIGURE

SOURCE

Credentials stolen in 2025

+1.8 billion

Flashpoint

Bank accounts compromised in 2025

+1 million

Kaspersky

Stolen cards still valid as of March 2026

74%

Kaspersky

These figures paint a consistent picture. When an infostealer enters the picture, there’s almost always a larger attack behind it—whether it’s ransomware, banking fraud, or unauthorized access to corporate systems. The infostealer is rarely the final attack. It’s the gateway.

Why Passwords Are No Longer the Barrier You Think They Are

Here, it’s worth challenging a piece of advice that’s often repeated without nuance: “Change your password every three months, and you’ll be protected.” With an active infostealer, that’s not enough. If the malware steals the session cookie during the attack, the attacker doesn’t need to know the password or bypass two-factor authentication. They log in directly using the already-established session, as if they were the user themselves.

This changes the defense strategy. It’s not enough to simply react when a suspicious login alert comes in. You need to know, in advance, whether your credentials are already circulating in a log stealer, before anyone uses them. That leap separates reactive cybersecurity from continuous monitoring.

How to Protect Yourself from an Infostealer Virus, Both at Work and at Home

Some measures significantly reduce the risk, although none is foolproof on its own:

  • Avoid installing pirated software, cracks, or browser extensions from dubious sources—the most common entry point.
  • Use a dedicated password manager instead of saving your credentials in your browser.
  • Log out of sensitive services when you’re done, rather than leaving them open indefinitely.
  • Check periodically to see if your email address or passwords have appeared in any known data breaches.

For a company, however, manually checking the dark web for leaked corporate credentials is not feasible at scale. This is where Continuous Threat Exposure Management comes into play—a framework that involves constantly monitoring an organization’s actual exposure surface, rather than conducting one-off audits once a year.

Enthec operates on this approach, offering two complementary cybersecurity solutions. Kartos, designed for businesses, continuously monitors whether corporate credentials, domains, or digital assets are exposed on dark web forums and marketplaces before an attacker can use them.

Qondaraimed at individuals, does the same at an individual level, checking whether your personal information has appeared in any keylogger logs or data breaches so you can act before falling victim to fraud.

If you manage security for an organization, or simply want to know if your data is already circulating without your knowledge, it’s worth checking what information about you or your company is currently exposed. Contact us.

 

Frequently Asked Questions About the Infostealer

How do I know if I have an infostealer on my computer?

It's difficult to detect based on visible symptoms, because it doesn't slow down the system or display any warnings. The most reliable way is to check whether your credentials have appeared in any known data breach databases or to use a monitoring service that continuously monitors the dark web.

Does a standard antivirus program detect an infostealer virus?

It can detect known variants, but many families are updated every few weeks precisely to evade the signatures of traditional antivirus software. That is why the subscription model (“malware as a service”) used by the operators of these campaigns is so effective.

Is changing my password enough if my computer has been compromised by an infostealer?

Not always. If the malware also stole the active session cookie, the attacker can continue to gain access until that session is manually closed on all devices—not just until you change your password.

What is the difference between an infostealer and ransomware?

Ransomware alerts the victim because it needs to negotiate a ransom. An infostealer, on the other hand, aims to do the opposite: go unnoticed for as long as possible so it can keep collecting data without arousing suspicion.


Reactive vs. Proactive Cybersecurity

Reactive vs. Proactive Cybersecurity: What's the Real Difference, and Why Does It Matter to Business?

A company detects unauthorized access to its network on a Tuesday morning. The IT team spends the next 48 hours putting out fires, isolating servers, reviewing logs, and explaining to management what happened. That is reactive cybersecurity in its purest form: responding after the damage has already been done.

Proactive cybersecurity raises a different question. Instead of asking, “How do we fix this?”, ask, “How did we know this could happen, and why didn’t we act sooner?” The difference may seem semantic, but it completely changes the cost, impact, and reputation associated with an incident.

 

What Exactly Is Reactive Cybersecurity?

Reactive security is based on detection and response after the fact. An antivirus program that blocks malware after it has already been executed, a SOC that analyzes an alert after the attack, a recovery plan that is triggered once the ransomware has already encrypted files. It’s not useless—far from it—and without these layers, any incident would be much worse.

The problem is that this model assumes the attack will occur first and the defense will react afterward. And it is during that window of time—between when the attacker gains access and when the company becomes aware of it—that almost all of the actual damage occurs: data theft, lateral movement across the network, and extortion.

The IBM study (Cost of a Data Breach Report 2026) estimated the average time to identify and contain a breach at 247 days. That’s more than eight months during which an attacker can move freely within a company’s systems, while the company remains unaware that it has been compromised.

 

What Changes with a Proactive Approach

Proactive cybersecurity doesn't wait for an alert. It looks for the conditions that make an attack possible before anyone can exploit them—such as credentials leaked on forums, unpatched vulnerabilities, fraudulent domains impersonating the brand, and exposed digital assets that no one even remembers exist.

This requires something that many companies still lack: continuous visibility into their own exposure, not just a one-time snapshot once a year. A penetration testing The annual report describes the security status on the day the test was conducted. Three months later, that photo is no longer useful, because the infrastructure, vendors, and exposed credentials change every week.

This is where the concept of continuous threat exposure management. It is, quite simply, a shift in approach: it involves moving away from hunting down vulnerabilities one by one and instead continuously managing everything an attacker could see and exploit from the outside.

Reactive Cybersecurity Proactive Cybersecurity
When it takes effect After the incident Before it happens
What it detects Alerts and damage that has already occurred Exposures, leaks, and potential attack vectors
Frequency On-demand Continuous, 24/7
Cost of Failure High: rescue, recovery, reputation Low: Risk is addressed before damage occurs
Real-life example SOC analyzes a post-attack alert Kartos detects leaked credentials before they are used
Main limitation By the time it takes effect, the damage has already been done Requires investment in continuous monitoring

 

Reactive vs. Proactive Cybersecurity

 

Why the Difference Matters to the Business, Not Just to IT

Let's be straightforward here: the debate between reactive and proactive approaches is not just a technical discussion confined to the IT department. It is a business decision with a direct impact on the income statement.

A security incident doesn't just cost the amount of the ransom or the cost of technical repairs. It costs in downtime, customers switching to competitors, fines if personal data is involved, and trust which takes years to rebuild. Being proactive does not eliminate the risk, but it does drastically reduce the window of time during which an attacker can operate undetected.

Furthermore, there is an economic argument that many executives overlook: prevention is cheaper than remediation, and in cybersecurity, the difference is enormous. Hiring continuous cyber monitoring costs a fraction of what it costs to manage a data breach that has already occurred—including lawyers, crisis communications, and upset customers.

 

How Continuous Exposure Management Is Applied in Practice

The theory behind CTEM is all well and good, but what really matters to a company is how it translates into day-to-day operations. At Enthec, that’s exactly what we focus on, with Kartos, our continuous cyber monitoring platform for businesses.

Kartos constantly monitors what an attacker would see if they decided to investigate an organization. Among the vectors it continuously monitors are:

  • Credentials leaked on the dark web: employee usernames and passwords exposed on illegal forums or marketplaces before anyone can use them.
  • Fraudulent domains: domain registrations similar to the company’s, intended to impersonate the corporate identity or deceive customers.
  • Vulnerabilities in public services: open ports, outdated services, or insecure configurations visible from outside the perimeter.
  • Sensitive information exposed: internal code, documents, or data that have ended up in public repositories or third-party forums without anyone noticing.

For personal use, Enthec offers Qondar, designed for executives, at-risk professionals, or anyone who wants to know if their digital identity, credentials, or personal data have ever been compromised. The logic is the same as in Kartos, adapted for an individual rather than an entire organization.

The two approaches are complementary

It would be a mistake to frame this as an either/or choice. No serious company would eliminate its ability to respond to incidents. What changes with a proactive system is the starting point: rather than the attack itself being the first warning sign, the company already knows where it is vulnerable and has been able to close those doors in advance.

The ideal combination is clear. Maintain a capacity to respond when something slips through the cracks (because it always happens) and combine that with continuous monitoring to keep the list of "somethings" as short as possible.

Organizations that invest only in reactive measures spend their time putting out fires without asking themselves why they keep happening. Those who invest only in prevention without a response plan are in for some unpleasant surprises when something they didn't see coming goes wrong.

The Real Cost of Waiting

Let's go back to the example from the beginning. That company that discovered the unauthorized access on a Tuesday morning had likely been exposed for weeks or months without realizing it.

If your company still manages cybersecurity solely on a reactive basis, it’s worth asking yourself how much of your actual exposure you’re unaware of right now. An initial assessment of your exposure surface using Kartos is usually enough to answer that question with concrete data, not assumptions.

 

Frequently Asked Questions

Does proactive cybersecurity replace antivirus software or firewalls?

No. They are complementary layers. Antivirus software and firewalls are still necessary as internal barriers; proactive monitoring provides visibility into what is happening outside the perimeter, before that risk reaches those barriers.

Is CTEM the same as a penetration test or a security audit?

Not exactly. A penetration test assesses security at a specific point in time. CTEM involves continuous monitoring, with constant updates to the attack surface—not a snapshot that becomes outdated within weeks.

What size of company needs continuous cyber monitoring?

Any organization with a significant digital presence, employees with corporate credentials, or customer data to manage. The risk depends not only on the organization’s size, but also on its surface area and how attractive that information is to an attacker.

How much does it cost to implement proactive cybersecurity versus reactive cybersecurity?

The cost of continuous monitoring is significantly lower than that of managing a breach that has already occurred. According to the IBM Cost of a Data Breach Report 2026, the average cost of an incident exceeds $4.99 million globally. Investment in preventive monitoring typically represents a fraction of that figure.


relevancia en la seguridad de las telecomunicaciones

The relevance of cybersecurity in telecommunications

Sending an email, holding a video meeting, or saving files to the cloud are actions we take for granted in our businesses. But behind this apparent simplicity lies a complex network that sustains telecommunications: networks, devices, providers, data…

And in that sea of ​constant information, cybersecurity has become an absolutely essential element for business continuity.

We're no longer just talking about protecting computers or servers, but the telecommunications infrastructure that shapes our lives. From data centers to employees' smartphones, cybersecurity in telecommunications is a key component of ensuring digital, economic, and social stability.

In an environment such as telecommunications, where the exhibition area is vast and dynamic, a solution such as Kartos is advisable and essential to ensure business continuity and protect reputation and user trust.

Unlike other more reactive approaches, our Kartos solution uses a continuous Threat Exposure Management (CTEM) model.. This means it helps organizations maintain a constant and up-to-date view of all their exposed assets, detect vulnerabilities, and anticipate possible attacks.

 

Why is cybersecurity so critical in telecommunications?

Telecommunications are the nervous system of our digital society. and cybersecurity in telecommunications is a structural priority for all sectors.

According to the Kaspersky Security Bulletin 2025 report, 20.7% of users in the telecom sector suffered device threats during the past year, and almost 10% of organizations experienced ransomware incidents. According to Check Point data gathered from analyses of the Spanish market, telecommunications ranks among the three most attacked sectors in the country.

A highly exposed sector

Telecommunications is one of the world's sectors that is attacked the most. It's no coincidence: Operators manage massive volumes of data, critical network infrastructure, and connections with millions of users. Any security breach can have devastating consequences: service interruptions, theft of sensitive data, espionage, or even attacks on national infrastructure.

Threats are constantly evolving

Cybercriminals never rest. New techniques, exploits, and ways to break into systems are developed daily. From ransomware attacks targeting service providers to signal interception or large-scale identity theft, having an antivirus or firewall is no longer enough.

It is necessary to have tools that proactively analyze and identify weaknesses before they are exploited, and maintain constant surveillance of the digital ecosystem. As we propose with Kartos, continuous threat management makes a substantial difference.

 

The most relevant threats to the telecom sector in 2026

The threats facing telecom operators in 2026 are all the more dangerous because they intersect and amplify each other:

  • APT (Advanced Persistent Threats) Groups: actors with state resources seeking stealthy and prolonged access to critical infrastructure for espionage or sabotage.
  • Supply chain attacks: The reliance on multiple suppliers and integrated platforms makes each external supplier a potential entry point.
  • Targeted ransomware: Specific campaigns against operators with a high impact on service continuity and high blackmail power.
  • SIM swapping and SIM-enabled fraud: Telephone line impersonation to access bank accounts, emails, and corporate systems.
  • High-intensity DDoS: Denial-of-service attacks that seek to disrupt critical services and extort operators.
  • AI-powered attacks: The use of artificial intelligence by attackers to create more credible phishing campaigns, automate vulnerability scanning, and generate corporate deepfakes.

As Leonid Bezvershenko, senior researcher at Kaspersky GReAT, points out, these threats "do not disappear, but rather intersect with operational risks stemming from automation, quantum cryptography, and satellite integration."

You may be interested in→ 6 online threats that can affect your business.

 

Towards a more preventive and strategic approach

The traditional security model, based on reacting once an incident occurs, is no longer enough.. In an environment as changing as the digital one, prevention and anticipation are essential.

 

cybersecurity in telecommunications

 

The regulatory framework in 2026: NIS2 and its impact on telecommunications

Regulatory pressure on cybersecurity in telecommunications has intensified significantly in 2026. The NIS2 Directive (EU Directive 2022/2555) is the main legal framework that obliges telecommunications operators to strengthen their security measures.

Explore this topic further in the following post-> NIS 2: How does it affect businesses and what measures should be taken to comply with the regulations?

 

What does NIS2 require of telecommunications operators?

Telecommunications are classified as essential entities underNIS2, which implies the strictest requirements of the directive:

  • Mandatory notification of serious incidents within a maximum of 24 hours.
  • Implementation of verifiable and auditable risk management measures.
  • Direct responsibility of the governing bodies, with the possibility of disqualification for managers.
  • Penalties of up to 10 million euros or 2% of global annual turnover.
  • Extension of security requirements to the entire supply chain of ICT providers.

In Spain, although the transposition of NIS2 is still going through parliamentary procedures with estimates of entry into force throughout 2026, the competent authorities have already initiated supervisory procedures.

To delve deeper into the regulatory requirements that affect organizations in the sector, we recommend you check out our article on GRC in cybersecurity: Governance, risk and regulatory compliance.

 

CTEM: continuous management against threats

The traditional IT security model involved periodically reviewing systems, searching for flaws, and applying patches. However, in today's context, this methodology is insufficient. The key is constant vigilance.

Continuous Threat Exposure Management (CTEM) is a more dynamic and adaptive approach. It allows companies to:

  • Know what assets are exposed on the Internet (servers, domains, applications, etc.).
  • Detect misconfigurations or vulnerabilities before they are exploited.
  • Prioritize what to fix first based on the actual level of risk.

Our tool, Kartos, is explicitly designed to implement this model. Its noninvasive approach allows monitoring without the need to install agents and offers a clear view of any organization's external security posture.

 

Artificial intelligence as a defensive ally

By 2026, AI has become a central element in both attacks and defense. The WEF Global Cybersecurity Outlook 2026 states that 94% of cybersecurity industry leaders identify AI as the main driver of change for this year.

In telecommunications, offensive AI has a particularly significant impact, enabling the automation of network endpoint scanning, the generation of customized phishing campaigns at scale, and the cloning of executive identities for B2B fraud. The defensive response requires applying that same processing capacity to detect traffic anomalies, correlate signals distributed across complex infrastructures, and reduce incident response time.

 

What your company can do now

If you work in a company that relies on digital infrastructure (which is practically all of them), there are some steps you can start considering today:

1. Perform an exposure diagnosis

The first step is knowing which assets of your organization are visible from outside the perimeter and what condition they are in. Do you have domains similar to yours registered by third parties? Are employee credentials circulating on specialized forums? Do any of your providers have expired certificates with active access to your network?

Kartos lets you get this picture of the external exposure without affecting your internal systems, in a matter of hours. You can find more information about how to detect CVE vulnerabilities on your digital surface without touching your internal network.

2. Implement a CTEM strategy

Monitoring must be continuous and automated. Threats don't wait for you to schedule an audit. The CTEM model ensures that any change to your attack surface—a new lookalike domain, a compromised credential, a misconfiguration—is detected and prioritized in real time.

Also discover how the perimeter cybersecurity approach complements your existing infrastructure to strengthen access.

3. Protect key people

The executives and security officers of the operators are deliberate targets. Their digital identity, credentials, and online reputation are attack vectors that remain outside the corporate perimeter.

Qondar, our personal digital protection platform, extends the logic of CTEM to the individual digital assets of key people in your organization.

4. Teach your team

No tool can replace the human factor. Make sure your team understands the risks and knows how to respond.

 

Cybersecurity in telecommunications as a guarantee of continuity

In a world where everything is digital, ensuring cybersecurity in telecommunications is not an add-on or a discretionary expense; it is the core of any business continuity strategy. Exposure to threats is constant, regulatory penalties are increasing, and the consequences of an incident can be irreversible for an organization's reputation and operations.

The question is no longer whether your organization will be targeted. The question is whether you will have enough visibility to detect it before it causes harm.

Kartos helps companies in the telecommunications sector regain control of their external digital security. No installations, no intrusion, no human operation to introduce delays. Just your domain, and a complete, continuous view of everything an attacker could see and exploit.

Do you want to know what's exposed in your organization right now?

Request a Kartos demo and get a clear, actionable view of your external security posture→ Contact Enthec


Account Hijacking

Account Hijacking: What It Is, How It Happens, and What to Do If Your Accounts Have Been Compromised

If one day you try to log in to your email and your password no longer works, or you receive a login notification from a country you've never been to, you may have been the victim of an account takeover—in other words, someone has taken control of something that belongs to you without your permission.

This is no minor issue. Fraud related to account theft and takeover results in combined losses of more than billions of euros each year for individuals and businesses. And the trend, far from improving, continues to worsen.

 

What exactly is account hijacking?

Account hijacking, also known as account takeover, is the process by which an unauthorized third party gains access to and control over someone else's digital account. This could be an email account, a social media account, a banking platform, a subscription service, or any other platform where you have saved login credentials.

Once inside, the attacker can do virtually anything, such as read your private messages, carry out financial transactions, impersonate you to your contacts, sell access to the account on the black market, or use it as a point of entry to compromise other related systems.

What makes this type of attack particularly dangerous is that, in many cases, the victim doesn't realize it right away. The intrusion may go unnoticed for days or weeks before the damage becomes apparent.

 

How Account Hijacking Occurs

There are several ways attackers can gain control of someone else's account. Knowing what they are is the first step to avoiding them.

Data Breaches and Exposed Credentials

One of the most common causes. When a company experiences a security breach, your users' credentials (email addresses and passwords) may end up being posted on forums or sold on the dark web. If you reuse the same password across multiple services, a single data breach can compromise several of your accounts at once.

Credential stuffing attacks

This method takes advantage of precisely that. Attackers use lists of leaked credentials and automatically test them on hundreds of different platforms. If the username and password match on any of them, they gain access without having to hack anything.

Phishing and Direct Deception

Fake emails, messages, or websites that impersonate legitimate services remain a highly effective entry point. The goal is simple: to get you to enter your information into a form that is actually sending that information directly to the attacker.

To learn more, check out our post:> Phishing: What It Is and How Many Types There Are.

Malware and Spyware

Some malicious programs install themselves on the victim's device and capture keystrokes, passwords saved in the browser, or session cookies—all without the user noticing anything unusual.

Social engineering.

Sometimes no technical sophistication is needed to carry out a social engineering attack. A call from someone posing as technical support, an urgent “account verification” message, or a seemingly harmless conversation can be enough to trick someone into voluntarily handing over their credentials.

 

Signs That Your Account May Have Been Compromised

There isn't always a clear warning. However, there are Signs You Shouldn't Ignore:

  • Login notifications from unknown locations or devices.
  • Changes to your profile information that you didn't make.
  • Messages sent from your account that you don't remember writing.
  • Unable to log in because the password or recovery email address has been changed.
  • Transactions you don't recognize.
  • Contacts who tell you they've received strange messages from you.

If you notice any of these symptoms, take action immediately.

 

What to Do If Someone Has Taken Control of Your Account

1. Try to regain access as soon as possible

Most platforms have an account recovery process that uses a backup email address, phone number, or security questions. Use it right away.

2. Change the related passwords

If you've reused that same password on other services, change them all immediately. Start with your email account, which is usually the master key to all your other accounts.

You might be interested in:> How to manage business passwords and credentials easily and securely to avoid online threats

3. Enable two-step verification

If you hadn't enabled it before, do so now. And if you already had it enabled, check to make sure that your verification methods are still the same and haven't been changed.

4. Check the devices with active access

Many apps and websites let you view active devices and sessions. Close any that you don't recognize.

5. Let the people around you know

If the attacker has been able to send messages or emails from your account, notify your contacts so they don't click on any links they've received from you in the last few days.

6. Report the incident

In Spain, you can report it to the National Cybersecurity Institute (INCIBE) via its cybersecurity helpline (017) or file a report with the National Police or the Civil Guard.

 

Steps to Take in the Event of Account Hijacking

 

How to Prevent Account Hijacking

Prevention remains the best strategy. Some basic measures are very effective:

  • Use unique and strong passwords for each service. A password manager can help you manage them.
  • Enable multi-factor authentication for all services that support it.
  • Keep your devices up to date and protected with anti-malware solutions.
  • Be wary of emails or messages that ask you to verify your credentials immediately.
  • Check periodically to see if your data has appeared in any known data breaches.

This last point is more important than it seems. Knowing that your credentials are exposed before the attacker uses them it gives you time to act.

 

Continuous monitoring as an additional layer of protection

For both individuals and businesses, having a solution that continuously monitors the exposure of credentials on the web, the dark web, and other intelligence sources provides a real advantage against account hijacking.

We have been working in this field since Enthec, using two tools for Continuous Threat Exposure Management. Kartos, designed to protect organizations, and Qondar, designed for individuals. Both tools allow you to detect in real time whether a person’s or a company’s data has been exposed, so you can take action before any damage occurs.

Because one of the problems with account takeover is precisely that: by the time you realize what has happened, the attacker has already been in for hours or days.

Do you want to know if your credentials—or your organization's—are currently exposed? Find out how Enthec can help you stay in control of your digital footprint before others do it for you.


evaluación del riesgo de los proveedores

Keys to Supplier Evaluation: How to Manage Third Parties in Your Company

Supplier evaluation is one of the most critical processes in modern business management. It's not enough to simply choose the best partners at the start of a business relationship; you must continuously review their performance, security practices, and alignment with your organization's standards.

Each vendor represents a potential entry point for external threats. Therefore, a rigorous assessment process must, in addition to classic operational criteria, include a thorough analysis of third-party cybersecurity risks.

With Kartos Third Parties, Enthec's platform for third-party risk management, you can obtain an automated, real-time risk assessment of your suppliers without requiring intrusion or human intervention.

Kartos Third Parties

 

What is supplier evaluation, and why is it important?

Supplier evaluation is the process by which a company analyzes and rates the performance of the third parties with which it works.

It's not just about choosing suppliers but also about regularly reviewing their performance to ensure they meet the quality, cost, and deadline standards you need, among other things. However, we must not forget that effective supplier management is incomplete without a cybersecurity analysis, since each supplier is a potential entry point for external threats.

If a supplier doesn't meet expectations, it can lead to delays, increase costs, or even affect your company's reputation. Therefore, a good evaluation system helps to:

  • Choose the most suitable suppliers from the start.
  • Reduce risks in the supply chain.
  • Ensure the quality of products or services.
  • Avoid unnecessary costs.
  • Comply with standards and regulations.

Now that we know why it's important, let's examine how you can implement this process in your company.

 

Supplier evaluation criteria: What should you measure?

Not all suppliers are the same or equally important to your business. Therefore, defining supplier evaluation criteria that adapt to your needs is essential. Here are some of the most commonly used:

1. Quality of the product or service

The first criterion to evaluate is quality. Whether a technology service provider or a parts manufacturer, their quality should match your expectations. To measure it, you can review aspects such as:

  • Materials used.
  • Quality certifications.
  • Results of audits or inspections.
  • Defect or failure rate.

2. Compliance with deadlines

A supplier that delivers late can cause problems in production or in the provision of your services. To evaluate this criterion, you can measure, for example, their percentage of on-time deliveries or their ability to respond to emergencies.

3. Price and payment terms

Cost is a key factor in any business, but the cheapest provider is not always the best option. Evaluate:

  • Value.
  • Flexibility in payments and financing.
  • Transparency in additional costs.

4. Responsiveness and after-sales service

A good supplier not only meets deadlines but also responds when problems arise. To assess this, clear aspects such as customer service should be considered.

5. Sustainability and social responsibility

More and more companies value suppliers that are responsible for the environment and society, taking into account the use of sustainable materials, compliance with environmental regulations, and good labor and inclusion practices.

6. Cybersecurity

Before starting a business relationship, companies should consider key cybersecurity criteria, including the maturity of their cybersecurity strategy, threat protection, and cybersecurity solutions for handling security breaches.

For a complete assessment, Kartos provides a real-time platform that automates the detection of third-party and umpteenth risks, ensuring effective risk management throughout the business relationship.

 

Supplier evaluation procedure

You already have clear criteria, but how can you implement a supplier evaluation procedure effectively? Here is a step-by-step guide:

1. Define the evaluation criteria

Not all suppliers must meet the exact requirements. For example, a software vendor will have different criteria than a raw material vendor. Therefore, it is essential to determine which aspects are a priority in each case before starting the evaluation.

2. Gather objective information

To properly evaluate suppliers, you need objective data. Some ways to get information are:

  • Audits or inspections.
  • Satisfaction surveys.
  • Internal records of incidents.
  • Supplier documentation (certifications, licenses, etc.).

3. Assign a score

A simple way to evaluate suppliers is to assign a score to each criterion, for example, from 1 to 5. You can create an evaluation chart and calculate a weighted average based on the importance of each criterion.

If a provider scores low, you may need to look for alternatives or renegotiate terms.

4. Make decisions and follow up

Once you've earned your scores, decide which providers will continue to work with you and which ones need improvement. It's a good idea to do regular reviews, such as every six months or a year, to ensure the supplier still meets the standards.

 

Supplier Evaluation

 

 

Supplier evaluation: a practical example with weighted criteria

To illustrate how this process works in practice, let's look at an example of an assessment applied to a technology service provider with access to sensitive corporate data.

In this case, the most heavily weighted criteria would be cybersecurity (30%), service quality (25%), and meeting deadlines (20%), compared to criteria such as price (15%) or sustainability (10%).

If a supplier scores 4/5 for quality, 5/5 for on-time delivery, but only 2/5 for cybersecurity, the weighted average may place them below the minimum acceptable threshold, despite their good operational performance. This is precisely the type of situation that the third-party risk analysis with Kartos allows you to detect before it becomes an incident.

 

Best Practices for Managing Suppliers

For effective supplier management, here are some key tips:

  • Negotiate clear agreements. Set up well-defined contracts to avoid misunderstandings.
  • Foster long-term relationships. It is not just about evaluating but about building relationships of trust.
  • Digitize the process. Use management software to keep better control of information.
  • Continuously monitor the security of your suppliers. Make sure they meet data protection standards.
  • Don't rely on a single supplier. Diversify to reduce risk in the event of failures or unforeseen events.

Evaluating service and product providers is not a simple process but a key tool for optimizing your company's performance. An inefficient supplier can generate risks to your business, while a reliable and well-managed one can become a great ally.

Implementing a supplier evaluation procedure with well-defined criteria and continuous monitoring will improve quality, reduce risks, and ensure your company's sustainable growth.

With Kartos, you can simplify and improve this process, ensuring regulatory compliance, mitigating security risks, and protecting information in your supply chain.

 

Frequently asked questions about supplier evaluation

How often should I evaluate my suppliers?

The minimum recommended frequency is semiannual or annual. Depending on the supplier's criticality level, suppliers with access to sensitive data or a critical role in the supply chain should be monitored continuously, not just during periodic reviews.

What criteria are prioritized in the evaluation of technology service providers?

For technology providers, cybersecurity and regulatory compliance should have the greatest weight in the evaluation, followed by the quality of service and response times to incidents.

How can I assess a provider's cybersecurity without accessing their systems?

There are specialized platforms, such as Kartos, for monitoring third-party external attack surfaces that allow you to assess a supplier's cybersecurity posture non-intrusively by analyzing their public digital exposure outside their infrastructure.

What regulations require a formal supplier evaluation process?

The NIS2 Directive, the DORA Regulations and the GDPR establish explicit obligations regarding the management of third-party risks. Having a documented evaluation procedure is a key requirement for regulatory compliance.

Can I use a supplier evaluation template or example as a starting point?

Yeah. An evaluation template with weighted criteria and a scoring scale is a good starting point, but it must be adapted to the specific characteristics of each sector and supplier type. Most importantly, the process must be systematic, documented, and reviewed regularly.