Select your language

Cyberattacks caused high losses in 2018

International. Approximately two million cyberattacks in 2018 resulted in more than $45 billion in losses worldwide as local governments struggled to deal with ransomware and other malicious incidents.

The Internet Society's Online Trust Alliance (OTA), which identifies and promotes security and privacy best practices that foster consumer trust in the Internet, released its Cyber Incident and Cyberattack Trends Report, which found that the financial impact of ransomware increased by 60%, business email engagement (BEC) losses doubled, and cryptojacking incidents tripled, despite the fact that overall breaches and exposed records declined in 2018.

In the report, OTA observed a sharp increase in cyber incidents, such as supply chain attacks, business email compromise (BEC), and cryptojacking. Some types of attacks, such as ransomware, are not new but remain lucrative for criminals. Others, such as cryptojacking, show that criminals are shifting their focus towards new targets. Some of the report's main trends include:

Rise of cryptocurrencies breeds new cybercriminals
Along with the increase in the prevalence of cryptocurrency, comes the rise of cryptojacking, which tripled in 2018. This is a specific type of attack aimed at hijacking devices to harness the power of computers at scale to effectively exploit cryptocurrency. OTA believes these incidents are increasingly attractive to criminals as they represent a direct path from infiltration to entry and are difficult to detect.

- Publicidad -

Misleading email
Although known as an attack vector, Business Email Compromise (BEC) doubled in 2018, resulting in $1.3 billion in losses, as employees were tricked into sending funds or gift cards to attackers who use email to impersonate salespeople or executives. Many companies are reacting by clearly labeling all emails that originate outside the organization's network.

Attacks through third parties
Supply chain attacks, in which attackers infiltrate through third-party website content, vendor software, or third-party credentials, were not new in 2018 (similar attacks include Target in 2013, CCleaner, and Not Petya in 2017), but they continue to proliferate and transform. The most notable attack of 2018 was Magecart, which infected payment forms on more than 6,400 e-commerce sites worldwide. The OTA report compiled outside sources that estimated a 78% increase in these types of attacks in 2018, with two-thirds of organizations experiencing an attack at an average cost of $1.1 million and estimates that half of all cyberattacks involve the supply chain.

Governments under attack
While the total number of ransomware attacks decreased in 2018, the OTA report noted a troubling increase in reported ransomware attacks against state and local governments in 2018 and early 2019. The baltimore and atlanta city breaches led to the disruption of many government services and the rebuilding of entire network structures. Local governments are particularly vulnerable as they often rely on outdated technology and run older software and operating systems.

Cloud issues
Although it's also not new, 2018 brought a number of sensitive data that were left open to the internet due to misconfigured cloud services. Given the number of companies that rely on companies like Amazon, Google, and Microsoft for some or all of their cloud needs, it's increasingly important to ensure that cloud storage is secure. The report noted that a common problem with cloud computing is not even a true "attack," but a user error. The correct configuration of data storage is the responsibility of the data owner, not the cloud service and is often done incorrectly.

Increase credential stuffing
OTA found an increase in credential stuffing in 2018, a type of attack that recently gained prominence. Since there are now more than 2.2 billion breached credentials at stake and users often boast identical logins across services, attackers are leveraging ultra-fast computers and known username/password pairs or commonly used passwords to gain direct access to accounts across a wide range of industries. Several high-profile attacks occurred in 2018, and while many were initially believed to be breaches, they turned out to be brute-force credential attacks.

Most violations are avoidable
As in previous years, OTA found that most violations could have been easily avoided. He calculated that in 2018, 95 percent of all breaches could have been avoided through simple, common-sense approaches to improving security. The report provides a checklist.

Duván Chaverra Agudelo
Duván Chaverra AgudeloEmail: [email protected]
Editor Jefe
Jefe Editorial en Latin Press, Inc,. Comunicador Social y Periodista con experiencia de más de 13 años en medios de comunicación. Apasionado por la tecnología.

No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Security industry in Mexico and Latin America continues its expansion and professionalization

Security industry in Mexico and Latin America continues its expansion and professionalization

International. The security industry in Mexico and Latin America maintains a growth trend driven by digital transformation, the increase in physical and cyber risks, as well as the need to protect...

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

United States. Veeam Software today announced the launch of Agent Commander, a solution aimed at helping organizations detect risks associated with artificial intelligence, protect AI-based systems...

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

In industries where every minute counts, efficient asset and resource management has become a strategic factor to ensure operational continuity, safety, and productivity. By: Héctor Meléndez,...

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Puerto Rico. A centralized monitoring operation developed by Genesis Security was able to significantly reduce the volume of false alarms in its security systems, thanks to the integration of...

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Türkiye. An open-ocean fish farming farm in Turkey implemented a smart surveillance system based on Dahua solar cameras, thermal monitoring, and wireless data transmission to improve safety and...

 The Hidden Security Gap in Data Centers

The Hidden Security Gap in Data Centers

Imagine the journey of an authorized technician inside a data center. When he arrives, he presents his credential and enters the premises, and before entering the server corridor he needs a key to...

Digital fraud increased at Christmas

Digital fraud increased at Christmas

Colombia. During the holiday season, as e-commerce and digital transactions intensified, online fraud attempts also increased. Fake promotions, impersonation of businesses and messages that...

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Mexico. Milestone Systems, a leading provider of open platform video management software (VMS), hosted the Milestone XPerience Days Mexico 2025 event, a gathering that brought together industry...

Hikvision Mexico launches the third edition of

Hikvision Mexico launches the third edition of "Hikvision Women"

Mexico. Hikvision Mexico announced the launch of the third edition of its "Hikvision Women" program, an initiative aimed at strengthening the participation and professional development of women in...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter