Select your language

Targets of cyberattacks on banks and financial services organizations

ciberataques bancosInternational. The 2021 Application Protection report, conducted by the F5 company at the beginning of this 2021, analyzed the main security incidents reported to the F5 SIRT for the years 2018 to 2020.

Financial services organizations including banks of different sizes, credit unions, insurance companies, stock exchanges, investment funds, payment processors, consumer finance lenders, brokers and companies serving the financial sector, experienced the highest proportion of incidents attributed to password login attacks (46.2%) compared to all other sectors. They were third in the percentage of denial-of-service (DoS) incidents (36.1%). The last largest category was web-related attacks, at 6.3%.

Incidents of cyberattacks on banks
Banks are the largest segment in financial services incident data 2018-2020, accounting for 40% of records. Outside of financial services organizations, banks saw more DoS attacks (41%), well above the 36% average. However, password login attacks decreased (41%), five points below the 46% average. One possible reason for this is that banks have better anti-bot controls that mitigate password login attacks and therefore see fewer attacks than the average financial organization. Web attacks account for 6% of reported bank security incidents.

Of the password login attacks, the majority of incidents were reported as brute force (77%), and the rest (23%) were reported as credential-stuffing botnet attacks. DoS attacks were primarily web application attacks (36%), followed by volumetric network attacks (24%) and DNS DoS attacks (14%), and the rest uncategorized.

- Publicidad -

Incidents of cyberattacks on banks large and small
Using a bank asset size of $100 billion to differentiate between large and small banks, we found that large banks reported more DoS attacks. Of all the incidents reported by the largest banks, 44% were DoS, while only 37% of the incidents at the smaller banks were flagged as DoS. This is reversed for password login attacks, with smaller banks finding a higher proportion (48%), while larger banks saw only 36%. The incidents of web attacks reported were almost the same: large banks 6% and small banks 7%.

Incidents of cyberattacks on credit unions
Credit unions are owned by their customers, so they are much more focused on individual consumers than the average bank. 88% of reported incidents were password login attacks. This is almost double the average and much higher than what banks see. In these institutions, DoS attacks are well below average and account for only 8% of reported incidents. It could be because they are perceived to have less money to pay the ransom. Credit unions also saw about half the average web attacks, at 3%.

Incidents of cyberattacks on insurance companies
Insurance companies handle large amounts of money and sensitive financial data, so they have experienced large cyber attacks. Insurance companies reported above-average DoS attacks (60%), but their password login attacks were below average, at 27%, and slightly more than the average web attack, at 7%.

Incidents of cyberattacks for stock exchanges
Incidents of DoS attacks reported on the stock exchange registered 80%, well above average and web attacks by 20%.

According to Banixco, in Mexico, during 2019 the number of security incidents reported by financial institutions intensified. From an average of 1 report per quarter in 2018, the statistic increased to an average of 4 reports per quarter in 2019. Likewise, in addition to registering a greater number of attacks, it was observed that the affected services were more diverse, from electronic transfers to ATMs and, in the same way, the means of computer attack were also varied, from software violation, fraudulent operations executed by third parties working within the institution, theft of passwords, abuse of deficiencies in the validation of balances, violation of telecommunications equipment, among others.

In the first half of 2021, a change in the target of attacks has been observed, now heading towards the ATMs of institutions, taking advantage of vulnerabilities in the programs that control the delivery of banknotes. Of the ten incidents reported by financial institutions during 2021, eight correspond to these types of attacks. Ransomware attacks continue to be an element of concern for financial institutions in Mexico as their impact can stop the operation of organizations for days representing a growing risk to financial stability.

"We can see from this data that attackers continue to move away from traditional software vulnerabilities toward softer targets like password logins and APIs. With the help of our colleagues at F5 SIRT, F5 Labs will continue to monitor these events, looking for patterns that suggest changes and changes in the tactics of cyber attackers," said Carlos Ortiz Bortoni, Country Manager of F5 Mexico.

- Publicidad -

* The full report can be viewed by clicking here.

Duván Chaverra Agudelo
Duván Chaverra AgudeloEmail: [email protected]
Editor Jefe
Jefe Editorial en Latin Press, Inc,. Comunicador Social y Periodista con experiencia de más de 13 años en medios de comunicación. Apasionado por la tecnología.

No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Security industry in Mexico and Latin America continues its expansion and professionalization

Security industry in Mexico and Latin America continues its expansion and professionalization

International. The security industry in Mexico and Latin America maintains a growth trend driven by digital transformation, the increase in physical and cyber risks, as well as the need to protect...

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

United States. Veeam Software today announced the launch of Agent Commander, a solution aimed at helping organizations detect risks associated with artificial intelligence, protect AI-based systems...

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

In industries where every minute counts, efficient asset and resource management has become a strategic factor to ensure operational continuity, safety, and productivity. By: Héctor Meléndez,...

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Puerto Rico. A centralized monitoring operation developed by Genesis Security was able to significantly reduce the volume of false alarms in its security systems, thanks to the integration of...

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Türkiye. An open-ocean fish farming farm in Turkey implemented a smart surveillance system based on Dahua solar cameras, thermal monitoring, and wireless data transmission to improve safety and...

 The Hidden Security Gap in Data Centers

The Hidden Security Gap in Data Centers

Imagine the journey of an authorized technician inside a data center. When he arrives, he presents his credential and enters the premises, and before entering the server corridor he needs a key to...

Digital fraud increased at Christmas

Digital fraud increased at Christmas

Colombia. During the holiday season, as e-commerce and digital transactions intensified, online fraud attempts also increased. Fake promotions, impersonation of businesses and messages that...

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Mexico. Milestone Systems, a leading provider of open platform video management software (VMS), hosted the Milestone XPerience Days Mexico 2025 event, a gathering that brought together industry...

Hikvision Mexico launches the third edition of

Hikvision Mexico launches the third edition of "Hikvision Women"

Mexico. Hikvision Mexico announced the launch of the third edition of its "Hikvision Women" program, an initiative aimed at strengthening the participation and professional development of women in...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter