HomeinetSymantec New Era Mega Breach Signals Benefits and Behavior Change for...

Symantec New Era Mega Breach Signals Benefits and Behavior Change for Cybercriminals

symantec
Symantec

Symantec Report Reveals Number of Mega Data Breaches from One in 2012 to 8 in 2013; 552 Million Identities Exposed in 2013

Athens, April 14, 2014 – After lurking in the shadows for the first 10 months of 2013, cybercriminals have unleashed the most damaging series of cyberattacks in history. The 19th annual Symantec Internet Security Threat Report (ISTR)highlights a significant shift in cybercriminal behavior, revealing that the bad guys were plotting for months before organizing a massive theft operation – rather than small executive strikes with smaller rewards.

“A Mega Breach can be worth as much as 50 smaller attacks,” said Christos Ventouris, Information Security Specialist for Southeast Europe for Symantec. “While the level of attack sophistication continues to improve, what has been surprising over the past year has been the fact that attackers are now more patient – ​​waiting to strike when the payoff is bigger and better.”

In 2013, there was a 62% increase in the number of data breaches compared to the previous year, resulting in the exposure of more than 552 million identities – clearly demonstrating that cybercrime remains a real and damaging threat to consumers and businesses.

“Security incidents that are handled well can improve customer perceptions of a company, but if handled poorly, they can be disastrous,” said Ed Ferrara, vice president and principal analyst at Forrester Research. “If customers lose trust in a company because of how it handles personal information and privacy, they are likely to look elsewhere.”[1]

Defense is the Best Offense

The size and scope of breaches have skyrocketed, jeopardizing the trust and reputation of businesses and increasingly compromising users’ personal information – from credit card numbers and medical records to passwords and bank account details. Each of the top data breaches in 2013 resulted in the loss of tens of millions of data records, compared to 2012, when there was only one data breach of this magnitude.

“Success breeds success – especially when it comes to cybercriminals,” said Mr. Ventouris. “The potential for bigger rewards means that large-scale attacks will remain at the forefront. Businesses of all sizes need to re-examine and possibly redesign their security strategy.”

Targeted attacks increased by 91% and lasted on average three times longer than in 2012. Administrative secretaries and those working in public relations were the two professions that cybercriminals focused on and used as a stepping stone to their higher-level targets, such as business executives and celebrities.

Data for the Greek Market

In 2013, Greece had a downward trend in the overall picture of the Internet Security Threat Profile of the world, reaching 43rd place in the Global Ranking, while in 2012 it was in 42nd place. More specifically, Greece is in 30th place in global spam levels (0.7%), while in 2012 Greece was in 29th place. Malicious code activity in 2013 is ranked 58th in the global ranking (0.2% of the total) while in 2014 it was in 54th place. Phishing hosts also had a decline, where Greece is now in 63rd place worldwide (with the 2012 ranking being in 60th place), while malware via email was 1 in 718.8 emails.

How to Build Your Resilience in Cyberspace

While the increasing flow of data from smart devices, apps and other online services is tempting cybercriminals, there are a number of steps businesses and consumers can take to protect themselves – whether it’s a major breach, a targeted attack or common spam. Symantec recommends the following best practices:

For Businesses:

  • Know your data: Protection should focus on the information – not the device or data center. Understand where your data lives and where it moves, so you can determine best practices and processes for protecting it. 
  • Educate your executives: Provide guidance on information protection, including corporate practices and procedures for protecting sensitive data on personal and corporate devices.
  • Implement a strong security strategy: Strengthen your security infrastructure with measures that include data loss prevention, network security, endpoint protection, encryption, strong authentication, as well as defensive measures such as reputation-based technologies.

For Consumers:

  • Practice understanding technology: Passwords are the key to your kingdom. Use password management software to create strong, unique passwords for every website you visit, and keep your devices – including smartphones – updated with the latest security software.
  • Be vigilant: Monitor bank and credit card accounts for any irregularities, be cautious when handling unexpected emails, and beware of online offers that seem too good to be true – they usually are.
  • Know who you're dealing with: Familiarize yourself with the policies of your partners and online services that may ask for banking or personal information. As a best practice, visit the official website directly (rather than clicking on an email link) if you need to share sensitive information.

[1] New Research: CISOs Need To Add Customer Obsession To Their Job Description, Ed Ferrara Forrester Research, Inc. Blog Post, March 2014

Symantec Press Release

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS