Cyberattacks targeting corporate cloud services have increased significantly in recent months as cybercriminals try to exploit the rise in remote working to gain access to corporate accounts.

The Covid – 19 pandemic and subsequent social distancing measures have forced organizations and employees to adapt to working from home with the help of cloud-based services.
However, the increase in the use of these services – which allow users to connect and access corporate resources remotely – has also led to an increase in hackers looking to take advantage of their growing popularity in order to steal login credentials, sensitive information and other data.
A new report from cybersecurity firm McAfee reveals that the number of remote attacks targeting cloud services increased by 630% between January and April of this year. The figures in the Cloud Adoption & Risk Report are based on data from 30 million McAfee users worldwide.
While some corporate login credentials could potentially be purchased from dark forums, in many cases, these attempts to breach cloud accounts will rely on brute-force, with cybercriminals trying common or simple passwords in an attempt to gain access.
Attacks fall into two broad categories. The first is brute force from an abnormal location, where login attempts come from a location that has not been used before and is not known to the organization. The nature of the cloud means that attackers can make login attempts from anywhere.
The second category is what researchers call 'suspicious superhuman', which involves multiple connection in a short period of time from geographically different locations, which it is impossible for a person to travel between in a short period of time.
For example, a user could be seen logging into one application from Asia, but then logging into another a few minutes later from a location in North America.
However, due to the increase in the use of cloud services, it may not always be obvious to security teams that something suspicious has happened, especially if they are responsible for monitoring thousands of accounts in a large organization.
“While we are seeing tremendous courage and global goodwill to overcome the COVID-19 pandemic, unfortunately we are also seeing an increase in hackers looking to exploit the sudden surge in cloud adoption created by the rise of working from home,” said Rajiv Gupta, senior vice president of cloud security at McAfee.
“The risk of threat actors targeting the cloud far outweighs the risk posed by changes in employee behavior,” he added.
While the rise of remote work and attackers looking to exploit it pose potential security concerns, organizations can manage the risk relatively simply. One way to achieve this is through the use of multi-factor, so if an attacker successfully enters the correct login credentials, there is an additional barrier preventing them from gaining access to an account.
