• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
old hacks die hard: ransomware, social engineering top verizon dbir

Old Hacks Die Hard: Ransomware, Social Engineering Top Verizon DBIR Threats – Again

You are here: Home / Latest Cyber Security Vulnerabilities / Old Hacks Die Hard: Ransomware, Social Engineering Top Verizon DBIR Threats – Again
June 3, 2022

Deja-Vu details from this year’s DBIR report feels like we are stuck in the film ‘Groundhog Day.’

Ransomware and social engineering carry on to dominate troubles going through cybersecurity experts, according to Verizon’s 15th once-a-year Knowledge Breach Investigations Report (DBIR).

In typical, the outcomes of DBIR just affirm perfectly-set up developments, these types of as the growing threats of ransomware – up 13% this 12 months – and the inescapability of the “human element”, which was tied to 82% of all breaches.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


DBIR data is based mostly on 23,896 noted security incidents, like 5,212 verified breaches.

Ransomware is However Growing

The amount of ransomware incidents enhanced this 12 months by practically 13%, which the analysts noted is “an maximize as big as the final five decades mixed.” Ransomware now plays a function in 1 out of just about every four breaches.

While the prevalence of ransomware has been climbing, the mother nature of these attacks have remained amazingly regular. Verizon initially wrote about ransomware in their 2013 report, exactly where they described how:

When targeting companies, typically SMBs, the criminals access sufferer networks via Microsoft’s Distant Desktop Protocol (RDP) either via unpatched vulnerabilities or weak passwords. – DBIR 2013.

Nine yrs later on, the most prevalent vector for ransomware attackers is however desktop sharing software – employed in all-around 40% of attacks. The overpowering majority of all those occasions entail stolen qualifications.

“Had we recognised that what was real nine decades back would even now be real right now,” the scientists concluded, “we could have saved some time by just copying and pasting some text.”

Hackers are Concentrating on Us

There are all sorts of technical mechanisms by which attackers can attain initial access into a focus on organization. But they typically never want to try out all that. The considerably easier alternative, commonly, is to just trick persons.

According to Verizon, 82% of this year’s facts breaches included the “human element” – “the Use of stolen qualifications, Phishing, Misuse, or only an Mistake.”

Phishing, as predicted, is nevertheless the hackers’ go-to. Effectively more than 60% of this year’s breaches commenced that way. Phishers are nevertheless working with all the very same tricks, like pretexting – inventing a story to encourage targets to divulge delicate info – foremost to small business email compromise (27% of all attacks).

That does not essentially necessarily mean that targets are even now so unaware, so naive as to click on on any wayward link or easy-chatting email. “Only 2.9% of personnel might essentially click on phishing emails,” the researchers pointed out. It is just that 2.9% is “more than more than enough for criminals to continue to use it” as a technique for intrusion.

It’s the Very same Outdated Tale

When human error arises in cybersecurity discourse, someone’s bound to point out training. But, as the authors of DBIR mentioned, “Most schooling normally takes twice as prolonged to full than was predicted, with 10% getting 3 moments as prolonged.” On top of that, “while receiving schooling is uncomplicated, proving it is doing the job is a little bit tougher.”

It could just be that the cyber threat landscape is in a holding pattern, as it has been for some time now. Just about every 12 months, it seems, we’re struggling with the exact same sorts of attacks, and featuring variations of the exact methods that haven’t totally labored prior to. John Gunn, CEO of Token, summed it up greatest in an email to Threatpost:

“The most important investigate by and for the cybersecurity market is out, and it feels like the motion picture Groundhog Day. We are waking up to the very same outcomes yr soon after year considering the fact that the initially report in 2008,” Gunn wrote.


Some parts of this posting are sourced from:
threatpost.com

Previous Post: «the ultimate saas security posture management (sspm) checklist The Ultimate SaaS Security Posture Management (SSPM) Checklist
Next Post: Chinese LuoYu Hackers Using Man-on-the-Side Attacks to Deploy WinDealer Backdoor chinese luoyu hackers using man on the side attacks to deploy windealer backdoor»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]
  • GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections

Copyright © TheCyberSecurity.News, All Rights Reserved.