The era of large data may be coming to an end, as, according to the Identity Theft Resource Center (ITRC), cybercriminals have begun to focus on phishing, ransomware, and BEC scams.

The US-based non-profit organization helps victims of data breaches and provides regular updates on the scale of the challenge for businesses . In its 2021 predictions, it said cybercriminals are relying less on stolen personal information and more on “bad consumer behavior ,” such as password reuse, to carry out attacks.
“Cybercriminals are focusing on attacks that require logins and passwords to gain access to corporate networks and carry out ransomware attacks and Business Email Compromise (BEC) scams. These attacks require less effort, are largely automated, the risk of criminals getting caught is lower and the profits are much higher,” the ITRC said.
According to the organization, ransomware payments have increased significantly in recent years. In the third quarter of 2018, criminals earned an average of $10,000, and now this amount has reached at least $178,000. Large enterprises-victims give ransomware gangs more than $1 million. On the other hand, BEC scams were responsible for the loss of $1.8 billion in 2019.

The ITRC is already seeing a decline in data breaches. In October, the number of breaches reported (including all breaches up to the third quarter of 2020) was 30% lower than the number of breaches reported during the same period in 2019.
The organization claimed that 2020 may be the year with the lowest number of breaches in the US in the last five years.
However, this does not mean that there should be complacency. Phishing attacks and identity theft scams related to the pandemic will continue in 2021, as stolen identities are used to claim unemployment benefits, etc.
Source: Infosecurity Magazine
