{"id":3770,"date":"2021-09-03T10:39:28","date_gmt":"2021-09-03T08:39:28","guid":{"rendered":"https:\/\/10guards.com\/?p=3770"},"modified":"2021-09-13T09:43:38","modified_gmt":"2021-09-13T07:43:38","slug":"verizon-the-cyber-vector-for-companies-is-set","status":"publish","type":"post","link":"https:\/\/10guards.com\/it\/blog\/2021\/09\/03\/verizon-the-cyber-vector-for-companies-is-set\/","title":{"rendered":"Verizon: The Cyber Vector For Companies Is Set"},"content":{"rendered":"<p class=\"qtranxs-available-languages-message qtranxs-available-languages-message-it\">Ci spiace, ma questo articolo \u00e8 disponibile soltanto in <a href=\"https:\/\/10guards.com\/en\/wp-json\/wp\/v2\/posts\/3770\" class=\"qtranxs-available-language-link qtranxs-available-language-link-en\" title=\"en\">en<\/a>, <a href=\"https:\/\/10guards.com\/ru\/wp-json\/wp\/v2\/posts\/3770\" class=\"qtranxs-available-language-link qtranxs-available-language-link-ru\" title=\"ru\">ru<\/a> e <a href=\"https:\/\/10guards.com\/ua\/wp-json\/wp\/v2\/posts\/3770\" class=\"qtranxs-available-language-link qtranxs-available-language-link-ua\" title=\"ua\">ua<\/a>.<\/p><p>Throughout 2020 we often heard the word unprecedented, seemingly in excess. Yet, for cybersecurity, it is an apt description of the challenges companies faced as they shifted to a work-from-home culture. These challenges \u2014 with phishing, ransomware, and social engineering as the reigning champions of attack vectors \u2014 are outlined in the 2021 Verizon Data Breach and Investigations Report (DBIR 2021.)<\/p>\n<p>&nbsp;<\/p>\n<p>According to Verizon, \u201cbreaches are moving toward social and webapp vectors, and those are becoming more server based, such as gathering credentials and using them against cloud-based email systems\u201d. \u201cThe DBIR is not in the business of prediction, but it can go a long way to help you shape your response strategy in the face of an uncertain future\u201d, states the report.<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"color: #afcf60;\"><strong>What you need to know: <\/strong><\/span><\/p>\n<p>&nbsp;<\/p>\n<p>Report analyzed 29,207 quality incidents, of which 5,258 were confirmed breaches<\/p>\n<p>Phishing attacks increased by 11 percent, while attacks using ransomware rose by 6 percent<\/p>\n<p>85 percent of breaches involved a human element, while over 80 percent of breaches were discovered by external parties.<\/p>\n<p>&nbsp;<\/p>\n<p>Breach simulations found the median financial impact of a breach is $21,659, with 95 percent of incidents falling between $826 and $653,587.<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"color: #afcf60;\"><strong>Key points from Verizon\u2019s data breach report<\/strong><\/span><\/p>\n<p>&nbsp;<\/p>\n<ol>\n<li><strong>Phishing<\/strong><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>The incidence of phishing attacks in data breaches increased 11% more than in the previous year. It went from 25% to 36%.<\/p>\n<p>&nbsp;<\/p>\n<p>This high variation is related to the pandemic and scams that use COVID-19 to deceive and persuade people. An important point to note is the analysis of at least 150 templates of phishing emails.<\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cPhishing remains one of the top action varieties in breaches and has done so for the past two years\u201d, says the report.<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cThis increase correlates with our expectations given the initial rush in phishing and COVID-19-related phishing lures as the worldwide stay-at-home orders went into effect.\u201d<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<ol start=\"2\">\n<li><strong>Social engineering<\/strong><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>The report also points to an increase in social engineering attacks that result in data breaches: from 22% to almost 35%.<\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cWe\u2019ve definitely seen a jump in social engineering breaches as a pattern from last year with an overall upward trend since 2017. For the past couple of years, it appears to be correlated to an uptick in the compromise of cloud-based mail servers. What we cannot say is why email is so enticing to threat actors\u201d.<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<p>Verizon says that the most common forms of social engineering are phishing, BEC (Business Email Compromise), and spam. These scams are mostly propagated via malicious emails.<\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cBEC were the second most common form of social engineering. This attack scenario reflects the meteoric rise of misrepresentation, which was 15 times higher than last year in social incidents.\u201d<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<p>Verizon also claims that social engineering and phishing attacks are widely used to steal credentials and spread malware, such as C2, backdoor, trojan, and ransomware.<\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cThe majority of social engineering incidents were discovered externally. (\u2026) This means that when employees are falling for the bait, they don\u2019t realize they\u2019ve been hooked\u201d.<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<ol start=\"3\">\n<li><strong>Most common types of compromised data<\/strong><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>As in previous years, credentials remain at the top of the list as the type of data most compromised by cybercriminals. By hacking credentials, criminals have access to systems and sensitive information.<\/p>\n<p>&nbsp;<\/p>\n<p>In addition to credentials, personal data is another type of data that is highly targeted by cybercriminals. This kind of information is then sold on the dark web or even used in other types of fraud.<\/p>\n<p>&nbsp;<\/p>\n<p>Check the list with the most compromised data in breaches:<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>Credentials.<\/li>\n<li>Personal data.<\/li>\n<li>Medical data.<\/li>\n<li>Bank data.<\/li>\n<li>Internal data.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ol start=\"4\">\n<li><strong>System intrusion<\/strong><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>A chapter in the Verizon report is dedicated to system intrusion. According to the document, system intrusion is a pattern that consists of sophisticated and complex attacks that have several steps.<\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cThe majority of these attacks involve malware (70%), usually of the Ransomware variety, but also of the magecart attack type used to target payment card data in web applications. Hacking (40%) also appears in many attacks and most often consists of the use of stolen credentials or brute force attacks.\u201d<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<ol start=\"5\">\n<li><strong>Malware<\/strong><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>Making a comparative analysis, the use of malware in breaches has not changed much compared to the previous year. The percentage remains in about 20% of cases. The most used types of malware are:<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>Ransomware.<\/li>\n<li>C2.<\/li>\n<li>Trojan.<\/li>\n<li>Downloaders.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cWe found 30% of the malware was directly installed by the actor, 23% was sent there by email and 20% was dropped from a web application. While this probably doesn\u2019t surprise many people, it does highlight the importance of having a robust defense to cover these three major entry paths for malware\u201d.<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<ol start=\"6\">\n<li><strong>Ransomware<\/strong><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>Ransomware is responsible for the vast majority of data breaches involving malware. About 10% of all breaches analyzed by Verizon involve ransomware.<\/p>\n<p>&nbsp;<\/p>\n<p>This percentage represents more than twice the frequency of the previous year, which confirms an upward trend since 2016.<\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cThis is because actors have adopted the new tactic of stealing the data and publishing it instead of just encrypting it. These attacks have some variety in terms of how the ransomware gets on the system, with actors having strong preferences that can be broken into several vectors\u201d.<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<p>The most common forms of ransomware infections involve stolen credentials, brute force attacks, and malicious emails.<\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cAttackers are less likely to purely target payment data and are more likely to broadly target any data that will impact the victim organization\u2019s operations. This will increase the likelihood that the organization will pay up in a Ransomware incident\u201d.<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<ol start=\"7\">\n<li><strong>Human error and misuse<\/strong><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>Verizon continues to rate human errors and misuse as significant actions in cases of breaches. Despite this, the numbers dropped this year.<\/p>\n<p>&nbsp;<\/p>\n<p>The error is present in 17% of breaches (from 22%). The main varieties of error are misconfiguration and misdelivery.<\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cSadly, misdelivery remains alive and well in our dataset, and while a number of these breaches are electronic data only (e.g., email to the wrong distribution list), there remains a significant number that involve paper documents.\u201d<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<p>The misuse corresponds to about 5% of cases (from 8%). In these cases, the most common variety is privilege abuse. The second place went to data mishandling.<\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cWe would have expected an appreciable increase in people performing misuse from home, given the increase of those who are working remotely due to the pandemic. However, we did not see an increase from remote access as a vector.\u201d<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<p>However, Verizon reports that companies\u2019 difficulty identifying and reporting this access vector may influence the data.<\/p>\n<p>&nbsp;<\/p>\n<ol start=\"8\">\n<li><strong>Actors and motivation<\/strong><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>Compared to last year, the participation of external actors in breaches rose to 80% (from 70%). Internal actors and partners now account for 20% of cases.<\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cIt seems clear that our external actors are not giving up their close-ups, as they continue year after year to dominate the actor types in breaches.\u201d<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<blockquote><p>\u201cAs in past years, financially motivated attacks continue to be the most common (90%), likewise, actors categorized as organized crime continue to be number one (80%),\u201d<\/p><\/blockquote>\n<p>Source: <a href=\"https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/\" target=\"_blank\" rel=\"noopener\">Verizon<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Ci spiace, ma questo articolo \u00e8 disponibile soltanto in en, ru e ua.Throughout 2020 we often heard the word unprecedented, seemingly in excess. Yet, for cybersecurity, it is an apt description of the challenges companies faced as they shifted to a work-from-home culture. These challenges \u2014 with phishing, ransomware, and social engineering as the reigning [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":3771,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-3770","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"aioseo_notices":[],"jetpack_featured_media_url":"https:\/\/10guards.com\/wp-content\/uploads\/phishing-and-human-factor.jpg","_links":{"self":[{"href":"https:\/\/10guards.com\/it\/wp-json\/wp\/v2\/posts\/3770","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/10guards.com\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/10guards.com\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/10guards.com\/it\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/10guards.com\/it\/wp-json\/wp\/v2\/comments?post=3770"}],"version-history":[{"count":6,"href":"https:\/\/10guards.com\/it\/wp-json\/wp\/v2\/posts\/3770\/revisions"}],"predecessor-version":[{"id":3779,"href":"https:\/\/10guards.com\/it\/wp-json\/wp\/v2\/posts\/3770\/revisions\/3779"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/10guards.com\/it\/wp-json\/wp\/v2\/media\/3771"}],"wp:attachment":[{"href":"https:\/\/10guards.com\/it\/wp-json\/wp\/v2\/media?parent=3770"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/10guards.com\/it\/wp-json\/wp\/v2\/categories?post=3770"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/10guards.com\/it\/wp-json\/wp\/v2\/tags?post=3770"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}