Freelancers working in any part of the world need to keep a close watch on their own privacy, since they don’t have the benefit of a large company with its own cybersecurity protocols and team to keep employees safe, but freelancers in Ukraine face a unique threat.
Alongside the everyday risks of working online, the risks of wartime threats to digital infrastructure and an unstable internet and power infrastructure mean that protecting your own data – not to mention your clients’ data – is particularly challenging.
JOIN US ON TELEGRAM
Follow our coverage of the war on the @Kyivpost_official.
Here are some practical ways to secure your data and prevent your livelihood from being disrupted.
Utilise a VPN for research
By now, most of us are aware of what a VPN is and (perhaps roughly) what it does. In a nutshell, it masks your real IP address from the websites you visit and encrypts traffic between your device and the VPN server, helping protect it from interception on the local network. However, a VPN does not prevent tracking through cookies, logged-in accounts, or other tracking technologies, and it does not protect against every online threat.
This is particularly important for Ukrainian freelancers to understand, since blackouts and power outages mean that many have to move their work to local cafes and unsecured hotspots. While they may seem legitimate, it is impossible for you to identify whether a bad actor is using the connection to hijack your private activity and data.
HTTPS already encrypts data exchanged with websites that use it. A trusted VPN can provide an additional layer of protection, particularly on unfamiliar networks, but it is not a substitute for other security measures. You can usually try a VPN free to get to know the tool before you sign up for a subscription – for instance, details on CyberGhost’s free trial are on their official page for those interested in trying the service.
Secure Your Accounts with 2FA and Regular Updates
Two-factor authentication is a strong line of defense against bad actors. Even if someone obtains your password, a second authentication factor adds another barrier to accessing your account. Depending on the service, this may involve a code generated by an authenticator app, a security key, or confirmation on a trusted device. The level of protection varies by method; no method should be described as impossible to bypass.
If you receive a prompt for 2FA on your phone that you don’t believe you have triggered via a normal login attempt, don’t click it or give approval. Instead, check the account’s security by opening its official app or typing its official website address into your browser yourself, rather than following a link in the unexpected notification.
Similarly, keep your devices up-to-date. Updates don’t just bring new emojis and UI features – they also keep software patched against vulnerabilities.
Use Freelancer-Friendly Payment Platforms
Unfortunately, invoicing scams are all too common these days. If you’re in a rush – or in a rush to be paid that week – you’re not always going to check things over as thoroughly as you should. Unfortunately, thanks to AI, it’s easier than ever for bad actors to put together a highly convincing invoice for payment and send it straight to your inbox.
Don’t send your banking details unless you are sure about the person on the other end.
Don’t Fall Victim to Social Engineering
This refers to tactics that involve bad actors using you as a point of entry, rather than, say, a vulnerability in the IT infrastructure. It’s the difference between someone trying to break in through a window, versus someone knocking on the door and convincing you to let them in – say, by pretending to be a police officer.
Common social engineering techniques include phishing emails, fake client queries, vishing (voice phishing, which may include using AI to imitate another person’s voice during a phone call) along with fake charities and, during wartime, fake relief programmes.
This article is published as part of Kyiv Post Spotlight and is not part of Kyiv Post’s editorial coverage.
