Attacks/Breaches

9/6/2016
10:00 AM
Nick Hayes
Nick Hayes
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
100%
0%

Why Social Media Sites Are The New Cyber Weapons Of Choice

Facebook, LinkedIn, and Twitter can't secure their own environments, let alone yours. It's time to sharpen your security acumen.

Cyber criminals run rampant across every social network today. We often see headlines about social marketing fails and celebrity account hacks, but they’re just the tip of the iceberg. Far more nefarious activity takes place across these social channels, while most organizations remain oblivious and exposed. Companies’ poor social media security practices put their brands, customers, executives, and entire organizations at serious risk.

Let’s look at the numbers. According to Cisco, Facebook scams were the most common form of malware distributed in 2015; the FBI said that social media-related events had quadrupled over the past five years; and PricewaterhouseCoopers found that more than one in eight enterprises suffered a security breach due to a social media-related cyber attack.

The first thing you must come to terms with is that social networks can’t secure their own environments, let alone yours. As much as they aim to mitigate security threats and terrorist propaganda on their platforms, they aren’t close to 100% effective. For example, Facebook reported that for 2015 up to 2% of its monthly average users—31 million accounts—are false, Twitter estimates 5%, and LinkedIn openly admitted, “We don’t have a reliable system for identifying and counting duplicate or fraudulent accounts.”

Despite this, social networks remain some of the most trusted channels online. Data shows that consumers implicitly trust people’s activity on social media more so than on any other communications channel. This is why social media sites are now a treasure trove for cyber criminals: The attackers now have incredibly broad reach and can easily manipulate users and execute a variety of widespread cyber attacks and scams, including everything from social engineering to exploit distribution to counterfeit sales to brand impersonations, account takeovers, customer fraud, and much more.

The point is that cyber criminals now weaponize social media sites and their data, leading to some of the biggest data breaches over the last few years. For example, LinkedIn was a key tool for reconnaissance (the scraping of public social data and social engineering tactics) for the cyber criminals who executed Anthem Health’s 2015 breach and its 80 million stolen records, while Twitter was an integral component of an innovative malware exploit dubbed “Hammertoss.” This technique has even been rumored to be connected to the Pentagon’s data breach last summer that took down the security agency’s 4,200-employee email server for two weeks while undetermined amounts of data were stolen.

Sinister Threats
While social media sites may not create completely new cyber threats, they do substantially amplify the risk of existing ones. From reconnaissance to brand hijacking and threat coordination, cyber criminals have been using social media to boost the effectiveness of their attacks for years. It’s clear that social media risk isn’t solely about brand and reputation damage but is a sinister cybersecurity threat that can lead to major data breaches, numerous compliance issues, and large amounts of lost revenue due to fraud and counterfeit sales, along with a slew of other risks.

So what does this all mean for your brand? Both security professionals and marketers alike should start treating social channels like the dangerous security threat they truly are, and align strategies to effectively fend against the range of cyber techniques currently in use. A first step in the right direction is to develop a framework and assess your social risk plan. Identify your most valuable social assets and customer touch points, and develop technical capabilities to continuously monitor them for signs of compromise and behavioral abnormalities.

But don’t stop there. To truly build an effective social media security plan, you need to understand your external risk environment and scour social channels for cyber threats outside of your direct control—be they doxing attempts, brand impersonations, or physical security threats to your employees or top executives. This should be done while also seeking feedback company-wide and coordinating with a range of stakeholders across legal, compliance, operations, and finance to ensure that all bases are covered.

Remember, social media is still in its infancy. Bolster your social media security acumen today so you’re better prepared for new social media exploits and innovative techniques that cyber criminals are sure to develop in the months and years to come.

Related Content:

 

 

Nick Hayes is an analyst at Forrester. His research is dedicated to helping risk professionals and other business leaders understand and manage customer-facing risks in order to build more resilient brands. He has extensive knowledge of the security, privacy, archiving, and ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 3   >   >>
DesertsafariDubai
50%
50%
DesertsafariDubai,
User Rank: Apprentice
12/11/2017 | 12:38:02 AM
Desert Safari Dubai
Hi Thanks for sharing this post. its realy Help full :)
TimTonne
50%
50%
TimTonne,
User Rank: Apprentice
11/4/2017 | 12:09:08 PM
Re: The tip here is to keep educating your self.
Your blog provided us valuable information to work on. You have done a outstanding job! Thx dd3sat.
desertlifetour1
50%
50%
desertlifetour1,
User Rank: Apprentice
10/7/2017 | 1:08:40 AM
Desert Life Tourism
Totally agree with your sharing information 

 
desertlifetour1
50%
50%
desertlifetour1,
User Rank: Apprentice
9/29/2017 | 8:17:13 AM
Re: Cyber security
Great article  thanks for sharing
Sammy324
50%
50%
Sammy324,
User Rank: Strategist
9/1/2017 | 10:37:03 AM
Re: From here we got the news!
I think you've made a really good point here and I support it. And while we're at it, maybe you'd like to try these CBD gummies at https://www.cannabisoilforsale.org/cbd-gummies/?
kv24ob
100%
0%
kv24ob,
User Rank: Apprentice
6/27/2017 | 6:19:14 AM
Re: From here we got the news!
Let me get this straight: Microsoft new about both tools and exploits but didn't patch them until now?
bradprat
100%
0%
bradprat,
User Rank: Apprentice
5/29/2017 | 6:49:36 PM
Re: From here we got the news! Re:
It is no secret that no information is safe that we share on social media. Good informative article
FranckD064
50%
50%
FranckD064,
User Rank: Apprentice
4/22/2017 | 9:54:07 PM
Social hoverboard
Totally agree with your opinion
juliazz
50%
50%
juliazz,
User Rank: Apprentice
3/26/2017 | 7:04:55 AM
Social media
Totally agree with your post, social media is dangerous thing.
Dubai Desert Safari
50%
50%
Dubai Desert Safari,
User Rank: Apprentice
11/13/2016 | 4:08:00 AM
Thanks
<a href="https://www.dubaieveningsafari.com/">Thanks to share informations, from Desert Safari Dubai</a>
Page 1 / 3   >   >>
More Than Half of Users Reuse Passwords
Curtis Franklin Jr., Senior Editor at Dark Reading,  5/24/2018
Is Threat Intelligence Garbage?
Chris McDaniels, Chief Information Security Officer of Mosaic451,  5/23/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-11505
PUBLISHED: 2018-05-26
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.
CVE-2018-6409
PUBLISHED: 2018-05-26
An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter.
CVE-2018-6410
PUBLISHED: 2018-05-26
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
CVE-2018-6411
PUBLISHED: 2018-05-26
An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection.
CVE-2018-11500
PUBLISHED: 2018-05-26
An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in &quot;admin/sysUser/save.do?callbackType=closeCurrent&amp;navTabId=sysUser/list&quot; that can add an admin account.