Monday, March 20, 2023
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Cybersecurity

New cybersecurity data reveals persistent social engineering vulnerabilities

Researcher by Researcher
February 9, 2023
in Cybersecurity
0
New cybersecurity data reveals persistent social engineering vulnerabilities
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Ransomware was down last year, though LockBit led threat actors and employees opened a third of the toxic emails in the last six months of 2022.

A phishing attack via email.
Image: MASHKA/Adobe Stock

New research from NCC Group and Abnormal Security shows clouds and a bit of silver to line them: Ransomware attacks declined last year, but business email compromises increased — massively for smaller businesses — and a third of toxic emails got through their human gateways.

SEE: Mobile Device Security Policy (TechRepublic Premium)

Related articles

Sentra Raises $30 Million for DSPM Technology

Millions Stolen in Hack at Cryptocurrency ATM Manufacturer General Bytes

March 20, 2023
undetected since 2021 and resists firmware update

undetected since 2021 and resists firmware update

March 20, 2023

Jump to:

Ransomware attacks were down last year

According to risk management firm NCC Group, there was a 5% drop in ransomware attacks last year — from 2,667 attacks in 2021 to 2,531 attacks in 2022 — although between February and April there was an uptick due to LockBit activity during the Russia-Ukraine war.

In its just-released 2022 Annual H1 Threat Monitor, which follows incidents identified by its managed detection and response service and global cyber incident response team, the NCC Group reported:

  • The Industrials sector was the most targeted by criminal gangs for a second year running.
  • North America (44% of attacks) and Europe (35%) were the most targeted regions.
  • There were 230,519 DDoS events across 2022 with 45% targeted at the U.S., 27% of which occurred in January.
  • LockBit was responsible for 33% of the ransomware attacks (846) monitored by NCC.

The consultancy said an early 2022 surge in DDoS attacks and botnet-led breaches is due in part to greater turbulence within the wider cyberthreat landscape, thanks largely to the Russia-Ukraine war.

“DDoS continues to be weaponized by both criminal and hacktivist groups as part of the conflict, alongside disinformation campaigns and destructive malware, to cripple critical national infrastructure in Ukraine and beyond,” the report said.

LockBit leads the rogues gallery

Thanks partly to the war in Ukraine, LockBit and other players were more active than usual:

  1. LockBit was responsible for 33% of the ransomware attacks (846) monitored by NCC, a 94% increase compared to its 2021 activity, peaking in April with 103 attacks. The firm noted that this spike was ahead of the introduction of LockBit 3.0.
  2. BlackCat accounted for 8% of the total attacks last year, averaging 18 attacks each month with a peak of 30 incidents in December.
  3. Conti, a threat actor affiliated with Russia, was the busiest attacker in 2021, responsible for 21% of all attacks. It reduced its attack levels to 7% of all recorded attacks last year.

Industrials a consistent target

Must-read security coverage

According to NCC Group, the most targeted sectors in 2022 were: industrials, with 804 organizations hit, constituting 32% of attacks; consumer cyclicals, attacked 487 times for 20% of attacks; and the technology sector, targeted 263 times for 10% of all attacks.

Notably, hotels and entertainment enterprises, specialty retailers, homebuilding and construction supply retailers, and financial services dominated cyclicals targets. Meanwhile, software and IT services were the most targeted sector within technology.

In the report, Matt Hull, NCC Group’s global head of threat intelligence, said significant numbers of DDoS and malware attacks deployed by criminals, hacktivists and other nations were consequent to the conflict between Russia and Ukraine.

“Though perhaps not the ‘cybergeddon’ that some expected from the next big global conflict, we are seeing state-sponsored attacks ramp up with cyber warfare proving to be critical in this hybrid cyber-physical battlefield,” he said.

BEC attacks succeed by tricking a third of employees

Last year, social engineering attacks were big news after Cisco was compromised by phishing exploits and Microsoft, Samsung, NVIDIA and Uber were breached by Lapsu$. Already this year, Mailchimp and Riot Games have also been victims.

Business email compromises are making their way through human barriers: Nearly a third of employees are opening compromised emails, according to AI-based security platform Abnormal Security, whose new H1 2023 Email Threat Report looks at email threat landscape with a special interest in risks posed by employees.

The study, which looked at social engineering statistics and based on data aggregated between July and December last year, also found that those employees replied to 15% of BECs, on average. Some 36% of replies were initiated by employees who had previously engaged with an earlier attack.

Only 2.1% of known attacks were reported to security teams by employees. Crane Hassold, director of threat intelligence at Abnormal Security said several factors explain this phenomenon.

“One reason is the Bystander Effect, when employees assume that they aren’t the only target of an attack and therefore don’t need to report the email because surely a coworker already has” he said. “Some employees may believe that as long as they don’t engage with the attacker, they’ve done their duty, even though it eliminates the opportunity for the security team to warn other employees about the attack.”

Additional findings from the report include:

  • 84% of employee reports to phishing mailboxes are either safe emails or graymail.
  • Employees in entry-level sales roles with titles like Sales Associate and Sales Specialist read and reply to text-based BEC attacks 78% of the time.
  • Nearly two-thirds of large enterprises experienced a supply chain compromise attack in the second half of 2022.
  • From the first to the second half of 2022, BEC attacks targeting SMB organizations grew by 147%.

Hassold said the “graymail” phenomenon constitutes what is essentially a side effect of security awareness training, which has caused a significant amount of questionable or unwanted mail to get reported to an organization’s SOC team.

“While we’ve tried to condition employees to report malicious messages to a security team, the unintended consequence is the teams that are triaging these reports are now frequently overloaded reviewing non-malicious emails,” he said.

He added that the vast increase in SMB attacks reflects an overall rise.

“We’re looking at the ratio of BEC attacks per 1,000 mailboxes,” Hassold said, “Even though SMBs do make up a vast majority of businesses, the reasoning for this datapoint likely has to do with the overall increase in BEC attacks in the second half of the year and SMBs being more susceptible to these attacks, since they aren’t able to invest as much into defenses that would stop them.”

Looking ahead to 2023

NCC’s Hull said bad actors will focus their attention on compromising supply chains in 2023, bypassing multi-factor authentication and taking advantage of misconfigured APIs.

“The threat will persist,” he said. “Organizations must remain vigilant, understand how they could be exposed and take steps to mitigate any risk.”



Source link

Tags: CybersecurityDataengineeringpersistentrevealssocialvulnerabilities
Share76Tweet47

Related Posts

Sentra Raises $30 Million for DSPM Technology

Millions Stolen in Hack at Cryptocurrency ATM Manufacturer General Bytes

March 20, 2023
0

Cryptocurrency ATM manufacturer General Bytes over the weekend disclosed a security incident that resulted in the theft of millions of...

undetected since 2021 and resists firmware update

undetected since 2021 and resists firmware update

March 20, 2023
0

A possible Chinese attack campaign on compromised unpatched SonicWall SMA edge devices stayed undetected since 2021 and could persist even...

Sentra Raises $30 Million for DSPM Technology

New ‘Trigona’ Ransomware Targets US, Europe, Australia

March 20, 2023
0

A new ransomware family has proven highly active over the past several months, cybersecurity firm Palo Alto Networks warns. Dubbed...

Biden administration sees dangers in cloud, but users must protect perimeters

Biden administration sees dangers in cloud, but users must protect perimeters

March 19, 2023
0

Image: Maksym Yemelyanov/Adobe Stock President Joe Biden’s administration, as part of its recently released National Cybersecurity Strategy, said critical sectors...

Huawei Has Replaced Thousands of US-Banned Parts With Chinese Versions: Founder

Huawei Has Replaced Thousands of US-Banned Parts With Chinese Versions: Founder

March 19, 2023
0

Chinese technology giant Huawei has replaced thousands of product components banned by the United States with homegrown versions, its founder...

Load More
  • Trending
  • Comments
  • Latest
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
Supply chain efficiency starts with securing port operations

Supply chain efficiency starts with securing port operations

March 15, 2022
A first look at threat intelligence and threat hunting tools

A first look at threat intelligence and threat hunting tools

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
First Dero Cryptojacking Targets Unprotected Kubernetes Instances

First Dero Cryptojacking Targets Unprotected Kubernetes Instances

March 20, 2023
Running WordPress on Microsoft Azure

Running WordPress on Microsoft Azure

March 20, 2023
Sentra Raises $30 Million for DSPM Technology

Millions Stolen in Hack at Cryptocurrency ATM Manufacturer General Bytes

March 20, 2023
Why You Should Opt Out of Sharing Data With Your Mobile Provider – Krebs on Security

Why You Should Opt Out of Sharing Data With Your Mobile Provider – Krebs on Security

March 20, 2023

Recent Posts

First Dero Cryptojacking Targets Unprotected Kubernetes Instances

First Dero Cryptojacking Targets Unprotected Kubernetes Instances

March 20, 2023
Running WordPress on Microsoft Azure

Running WordPress on Microsoft Azure

March 20, 2023
Sentra Raises $30 Million for DSPM Technology

Millions Stolen in Hack at Cryptocurrency ATM Manufacturer General Bytes

March 20, 2023

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • LetsAskBinuBlogs
  • Malware
  • Networking
  • Protection

Tags

Access attack Attacks banking BiWeekly bug Cisco cloud code critical Cybersecurity Data Digital exploited financial Fintech Flaw flaws Google Group Hackers Krebs Latest launches malware Microsoft million Network News open patches Payments platform Ransomware RoundUp security Software Stories TFT Threat Top vulnerabilities vulnerability warns Week

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved