Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operational Security

11/26/2018
09:35 AM
Jeffrey Burt
Jeffrey Burt
Jeffrey Burt
50%
50%

Carbon Black: Cyber Attacks Could Jump 60% During Holidays

Spear-phishing campaigns are the most common form of attack as shoppers go to the stores and online and employees hit the road, according to a survey from Carbon Black.

Companies can expect as much as a 60% percent increase in cyber attacks as this year's holiday shopping season gets underway, according to researchers with Carbon Black's Threat Analysis Unit.

In a report released on Cyber Monday, the "Carbon Black Holiday Threat Report," the researchers noted that the number of attacks jumped 57.5% from 2016 to 2017, and businesses can expect a similar jump this year, with many of attacks coming through spear-phishing campaigns that take advantage of commodity malware. Attacks in recent years targeting top-tier retailers -- and often through supply chain partners -- have led to the stealing of millions of customer records and credit card numbers, with companies having to pay the costs of major breaches.

"During the holiday season, there is often a ton of noise in the online world and attackers do everything they can to take advantage of that," Tom Kellermann, chief cybersecurity officer at Carbon Black, wrote in the report. "This applies not only to consumers who shop online, but also to businesses as well, many of which are understaffed and, in the case of retailers, approaching the busiest time of the year."

The holiday season, which essentially kicks off with Thanksgiving, is a focus of both cybersecurity vendors and the cybercriminals that are trying to take advantage of the huge increase of online and in-store shopping that occurs during the relatively short amount of time as well as the travel that happens both for Thanksgiving as well as Christmas. (See Employees Traveling This Holiday? Don't Forget Good Security Practices.)

In their report, the Carbon Black researchers said that after Thanksgiving, cybersecurity alerts last year jumped on both Black Friday -- the day after Thanksgiving -- and Cyber Monday, the first Monday after the holiday. That said, the highest spike in activity came in the days after Christmas, when consumers are out in the stores or online taking advantage of post-holiday shopping deals.

In an email to Security Now, Kellermann wrote there are multiple reasons for the sharp rise in cybercrime activity around the holiday season beyond the amount of money exchanging hands.

"Cybercriminals are always evolving," he said. "When it comes to increased cybercrime around the holidays, a number of factors are at play. For one, with attack kits readily and cheaply available on the dark web, the barrier to entry has never been lower. As a result, there are more criminals looking to make a quick buck. Second, criminals' attack arsenal is expanding. Yes, spear phishing attacks continue to be successful, but attackers are refining their craft by incorporating AI [artificial intelligence], using watering holes and targeting mobile applications."

As mentioned, spear-phishing campaigns remain the most common forms of attacks. That includes not only attacks on supply chain partners, but employees who travel for the holidays often take work with them, making them targets for spear-phishing efforts that promise such enticements as low airfares and deals on gift cards. Gift cards seem to be a particularly attractive avenue for cybercriminals even outside of the holiday season, as researchers at Kaspersky Lab noted in a report this summer. (See Kaspersky: There's No Such Thing as a Free Gift Card Code.)

Threat actors also will use fake package tracking emails as a way of getting users to expose their systems to malware, according to Carbon Black. Users who are excited about getting a holiday package may miss something simple in the email, such as having the email domain read "afedex.com" rather than "fedex.com."

The researchers also noted that many companies that aren't the size of an Amazon or Microsoft may be further hindered by being understaffed, particularly with people taking time off during the holidays. Given that, executives need to create a culture throughout their companies where employees are well aware of cybersecurity and Internet safety. In the case of spear-phishing emails, it means being diligent in examining emails for such tell-tale signs as poor grammar, misspelled words and unorthodox URLs as well as ensuring that the sender is someone they know and that the sender's email is legitimate.

It also means determining the motivation for the email, such as being skeptical of requests for personal or financial information, "especially in business settings where attackers are keen to use spoofed emails from executives to target lower-level employees," the Carbon Black analysts wrote. In addition, being cautious about attachments -- particularly from unknown individuals -- is key, they wrote.

"At Carbon Black, we like to say we have cybersecurity in our DNA," Kellermann told Security Now. "That's not always the case, though, for a mid-level accounting firm or, say, a hospital that's had limited exposure to cyber risk. If there is a silver lining to the slew of attacks we read about in the news, it's that awareness of cybersecurity issues has never been higher. For many organizations, this is seeping into their culture. Business leaders are seeing the profound effect a breach can have and they are driving awareness campaigns and mandatory education for employees. These programs are probably not as ubiquitous as we'd like but I think we're making good progress. A little education can go a long way."

Related posts:

— Jeffrey Burt is a long-time tech journalist whose work has appeared in such publications as eWEEK, The Next Platform and Channelnomics.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/6/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15505
PUBLISHED: 2020-07-07
MobileIron Core and Connector before 10.3.0.4, 10.4.x before 10.4.0.4, 10.5.x before 10.5.1.1, 10.5.2.x before 10.5.2.1, and 10.6.x before 10.6.0.1, and Sentry before 9.7.3 and 9.8.x before 9.8.1, allow remote attackers to execute arbitrary code via unspecified vectors.
CVE-2020-15506
PUBLISHED: 2020-07-07
MobileIron Core and Connector before 10.3.0.4, 10.4.x before 10.4.0.4, 10.5.x before 10.5.1.1, 10.5.2.x before 10.5.2.1, and 10.6.x before 10.6.0.1 allow remote attackers to bypass authentication mechanisms via unspecified vectors.
CVE-2020-15507
PUBLISHED: 2020-07-07
MobileIron Core and Connector before 10.3.0.4, 10.4.x before 10.4.0.4, 10.5.x before 10.5.1.1, 10.5.2.x before 10.5.2.1, and 10.6.x before 10.6.0.1 allow remote attackers to read files on the system via unspecified vectors.
CVE-2020-15096
PUBLISHED: 2020-07-07
In Electron before versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using "contextIsolation" are affecte...
CVE-2020-4075
PUBLISHED: 2020-07-07
In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, arbitrary local file read is possible by defining unsafe window options on a child window opened via window.open. As a workaround, ensure you are calling `event.preventDefault()` on all new-window events where the `url` or `options` is not ...