HomeSecurityC-suite executives are the first target of hackers

C-suite executives are the first target of hackers

State-sponsored attacks, cloud storage misconfiguration, ransomware and social threats targeting C-suite executives pose the most significant risks to global organizations, according to Verizon.

C-suite

The recently released 2019 Data Breach Investigations Report includes analysis of over 40,000 security incidents and more than 2,000 reported data breaches across 180 countries, including new FBI data to this year’s study. It found that the vast majority (71%) of breaches continue to be financially motivated, although espionage was the next most common motive (25%). 

Senior executives were highlighted as a particular security risk in this year's report, as they are 12 times more likely to be victims of a "social incident" and nine times more likely to be the target of a social breach than in previous years.

Executives are at risk because they often have less time to review emails for signs of fraud or simply delegate their communications to their assistants. However, to an attacker, they represent a valuable target, given their privileged access and approval for, for example, corporate money transfers.

The latter is linked to BEC attacks, which often involve the destruction of a C-level exec's account before sending a member of the finance team to request a large transfer of funds. According to the report, BEC fraud was responsible for 370 incidents, or 248 confirmed breaches.

“A BEC scam can be a significant incident, since it compromises the integrity of the people making decisions about transferring money, but also a breach [if] it compromises the identity and password of an organizational email account,” Verizon senior information security data scientist Gabe Bassett told Infosecurity.

These aren’t just social threats: attackers are increasingly using stolen credentials to hijack cloud email accounts. In fact, 29% of breaches involved stolen log-ins, reflecting the rise in
authentication activity.

The report also revealed that ransomware continues to pose a serious threat to organizations – accounting for a quarter (24%) of all malware incidents analyzed and ranking second in terms of most widely used malware.

However, the cryptojacking threat has decreased significantly, accounting for only 2% of incidents and no longer ranking in the top 10 malware used.

Organizations are still lagging far behind in discovering attacks. to do. In more than half (56%) of breach incidents, it took “months or more” before IT teams identified suspicious activity.

Cloud-based file breaches exposed at least 60 million files analyzed, representing 21% of breaches caused by bugs, according to the report.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS