
According to a report on internet security conducted by Checkpoint Software Technologies Ltd, hacking is not what it used to be. In the past, hackers were motivated by using their knowledge of the internet to discover security holes in systems. However, today, many hackers only want to make money, resorting to fraudulent means. The hacker arrested by the US Department of Justice in September 2018 for spreading the WannaCry ransomware, for example, was part of a criminal organization called the Lazarus Group, which has links to the North Korean.
According to Checkpoint, more than 10,000 different malicious files are detected per day, while 700 malware families are used daily. Initially, most ransomware attacks such as WannaCry and Petya did not have a specific target. However, cybercriminals have changed tactics and now strike at the most vulnerable point of their target.
Cloud computing is an integral part of a business’s operations. It allows a company’s employees to access their data from any location or device. To make this process less complicated, the level of authentication and security is often not very strict. This makes services running in the Cloud more vulnerable to cyberattacks compared to on-premise services.
To penetrate a Cloud network, hackers need access to a single employee's email account or computer, which they obtain by sending an email (which may appear genuine) with a malicious link, hoping the target will click on it.
To facilitate operations, most organizations have relaxed device rules, allowing employees to access company-related data via their personal smartphones. This proliferation of personal devices in the workplace has increased risks for businesses. According to Checkpoint, cybercriminals can spy on users and record their credentials while they connect to corporate systems containing sensitive data via their smartphones. The Internet of Things (IoT) is another rapidly growing area with little focus on its security.
Checkpoint experts believe that in the future there will be more targeted attacks as cybercriminals achieve higher yields. Cloud infrastructure will face more Cryptojacking attacks. Attacks on mobile devices are also expected to increase, but instead of multiple forms of attack, it is likely that cybercriminals will use a comprehensive mobile malware, with multiple capabilities. Furthermore, with artificial intelligence (AI) becoming an integral part of many organizations’ operations, cybercriminals will try to manipulate AI systems. IoT devices, for their part, are predicted to remain the weakest link, as they are more difficult to secure.
Additionally, following the introduction of the General Data Protection Regulation in the European Union, more countries are set to enact their own data protection laws. This means that organizations will not be able to keep any breaches involving user data quiet and will have to disclose them publicly.
