Sony Pixel Power calrec Sony

IBM Report: Cybercriminals Intensify Attacks on User Identities in the UK, Complicating Recovery Efforts for Enterprises

21/02/2024

LONDON, UK, Feb 21, 2024 IBM today released the 2024 X-Force Threat Intelligence Index highlighting an emerging global crisis as cybercriminals double down on exploiting user identities to compromise enterprises.

According to IBM X-Force, IBM Consulting's security services arm, cybercriminals last year generated more opportunities to log in to corporate networks through valid accounts, instead of hacking into them making this tactic a preferred weapon of choice for threat actors.

The X-Force Threat Intelligence Index is based on insights and observations from monitoring over 150 billion security events per day in more than 130 countries. In addition, data is gathered and analysed from multiple sources within IBM, including IBM X-Force Threat Intelligence, Incident Response, X-Force Red, IBM Managed Security Services, and data provided from Red Hat Insights and Intezer , which contributed to the 2024 report.

An emerging identity crisis

The report data revealed that exploiting valid accounts has become the path of least resistance for cybercriminals, with billions of compromised credentials accessible on the Dark Web.

According to the report, 50% of cyberattacks in the UK involved the exploitation of valid accounts as the initial access vector' and a further 25% of cases involved the exploitation of public-facing applications. Across Europe, X-Force observed a 66% year-on-year rise in attacks caused by the use of valid accounts contributing to Europe's prevalence as the most targeted region of 2023 and the record number of attacks that X-Force has ever reported regionally.

The criminal ecosystem was also quick to adapt to the use of valid accounts by attackers. In 2023, X-Force observed a 266% increase in infostealing malware, which is designed to steal personal and enterprise credentials, personally identifiable information, and banking and crypto wallet information.

This easy entry for attackers is harder to detect, eliciting a costly response from enterprises. According to X-Force, worldwide, major incidents caused by attackers using valid accounts were linked to nearly 200% more complex response measures by security teams than the average incident with defenders needing to distinguish between legitimate and malicious user activity on the network.

In fact, IBM's 2023 Cost of a Data Breach Report found that breaches caused by stolen or compromised credentials required roughly 11 months from detection to recovery the longest response lifecycle among all infection vectors.

Martin Borrett, Technical Director, IBM Security, UK, and Ireland (UKI) commented:

Our findings reveal that identity is increasingly being weaponised against enterprises, exploiting valid accounts and compromising credentials. It also shows us that the biggest security concern for enterprises stems not from novel or cryptic threats, but from well-known and existing ones.

Addressing cybersecurity challenges requires a strategic approach, emphasising the reinforcement of foundational security measures. Streamlining identity management through a unified Identity and Access Management (IAM) provider and strengthening legacy applications with modern security protocols are crucial steps in mitigating risks. Additionally, subjecting your system to rigorous stress tests by skilled offensive security teams proves invaluable in uncovering potential weaknesses. This insight is pivotal for crafting a robust incident response plan that engages all teams, from IT professionals to C-suite executives.

Julian David, CEO of techUK, added:

In an era marked by the growing sophistication of cybercriminals who exploit legitimate accounts to breach business defences, IBM's X-Force Threat Intelligence Index serves as a stark wake-up call.

The report underscores a troubling pattern where half of the cyberattacks in the UK rely on legitimate accounts for initial access, presenting significant challenges to businesses' recovery endeavours. To effectively combat this threat, businesses must adopt a strategic approach, integrating modern security protocols to mitigate risks and strengthen their defences against the ever-evolving landscape of cyber threats.

Further key UK findings include:

Malware made up 30% of security incidents observed in the UK.

Ransomware (30%) and cryptominers (20%) were the top malware types encountered in the country.

The impact of attacks was evenly distributed with extortion, digital currency mining and data leaks each making up 25% of total impacts in the UK.

This marks a shift from 2022, when half the cases X-Force observed in the UK involved extortion (57%) twice the global average followed by data theft (29%).

The professional, business and consumer services industry was the most targeted sector in the UK, representing 39% of cases.

Energy (30%) and finance & insurance (17%) were the second and third most targeted industries in UK, respectively.

Manufacturing was the most targeted industry in Europe, accounting for 28% of cases.

Europe overall experienced the highest percentage of incidents within the energy sector at 43%, as well as finance and insurance at 37%.

Major takeaways from the global report included:

Attacks on critical infrastructure reveal industry faux pas.

Worldwide, an alarming 69.6% of attacks that X-Force responded to were against critical infrastructure organisations, an alarming finding highlighting that cybercriminals are wagering on these high value targets' need for uptime to advance their objectives.

In 84% of attacks on critical sectors globally, compromise could have been mitigated with patching, multi-factor authentication, or least-privilege principals indicating that what the security industry historically described as basic security may be harder to achieve than portrayed.

Exploiting public-facing appl
LINK: https://uk.newsroom.ibm.com/IBM-Report-Cybercriminals-Intensify-Attack...
See more stories from ibm

Europe Stories

09/12/2024

Dalet Named an IDC Innovator in Media and Entertainment

Dalet, a leading technology and service provider for media-rich organizations, today announced that it has been named an IDC Innovator in the IDC Innovators: ...

09/11/2024

Dalet Expands Leadership Team to Fuel Next Stage of Growth

Dalet, a leading technology and service provider for media-rich organizations, today announced three new members of its executive team. Tara Bryant joins as Chi...

17/10/2024

It's Never Too Early To Spread Festive Cheer, Our Spotify Holiday Singles Are Here

The air is turning crisp, and it won't be long until everyone is walking aro...

17/10/2024

Coldplay Unites With Spotify and FC Barcelona To Release a Special El Clsico Shirt, Merch Collection, and Matchday Playlist

Spotify is once again collaborating with record-breaking legends from the worlds...

17/10/2024

Gold Medal Gymnast Rebeca Andrade Gives Us a Peek at Her Spotify

Rebeca Andrade knows her way around the gym floor . . . and vault, and uneven bars, and balance beam. The 25-year-old is the most decorated Latin American gymna...

17/10/2024

Your Exclusive Look Inside Our Charli xcx and Troye Sivan SWEAT Tour Afterparty

Since Charli xcx and Troye Sivan kicked off SWEAT, their joint tour of North America, in September, the live shows have become part of the cultural canon. Toget...

17/10/2024

Last Cut Media Increases EditShare Footprint to Streamline Production

Last Cut Media Increases EditShare Footprint to Streamline Production Adds capacity, AI indexing and sharing technologies Boston, MA, 17 October 2024 - EditS...

17/10/2024

BLAM vs BOLT: what's in a name?

Since its launch in 2020, Blue Lucy's flagship product, BLAM, has also been the company's only product. BLAM is a sophisticated workflow orchestration, ...

17/10/2024

Opinion: The transformative impact of remote production and cloud migration on the media industry

John Wastcoat, SVP business development and marketing at Zixi, highlights how me...

17/10/2024

How cinematographer Haris Zambarloukos captured the colour of Beetlejuice Beetlejuice

Zambarloukos details the cameras and lenses he used to capture Tim Burtons spook...

17/10/2024

EMG/Gravity Media names Eamonn Curtin as chief commercial officer

He takes up the role immediately, having spent the past 10 years as global client director at EMG/Gravity Media By Jenny Priestley Published: October 17, 202...

17/10/2024

Council pulls plug on Mo-Sys Plumstead Power Station deal

Mo-Sys planned to refurbish the Grade II listed site, opening eight studio stages By Matthew Corrigan Published: October 17, 2024 Mo-Sys planned to refurb...

17/10/2024

VEON Files its 2023 Form 20-F

17 Oct 2024 VEON Files its 2023 Form 20-F Amsterdam, 17 October 2024, 20:45: VEON Ltd. (Nasdaq: VEON, Euronext Amsterdam: VEON), a global digital operator ( VE...

17/10/2024

DUNE: PROPHECY coming exclusively to Sky and NOW on November 18, as official trailer released

DUNE: PROPHECY coming exclusively to Sky and NOW on November 18, as official tra...

17/10/2024

Rohde & Schwarz achieves full coverage of Skylos test plan for NB-NTN devices, enabling SMS services

Rohde & Schwarz achieves full coverage of Skylos test plan for NB-NTN devices, e...

17/10/2024

RNZ Selects Dalet for New Editorial System

Dalet, a leading technology and service provider for media-rich organizations, today announced that RNZ has partnered with Dalet to transform its editorial syst...

17/10/2024

Blancco Launches Free ROI Calculator to Help Enterprises Quantify Financial and ESG Benefits of Data Erasure

Home News & Press Press Release Blancco Launches Free ROI Calculator to He...

17/10/2024

2024-10-16

For the first time, businesses of all sizes around the world - even those without a brick-and-mortar presence - can manage the way they appear to over 1 billion...

17/10/2024

Thales makes first shipment of 300 night vision goggles for French Army under Bi-NYX contract

Facebook Twitter LinkedIn French forces have received the first 300 Thales...

17/10/2024

Genelec opens new Seoul Experience Centre

Genelec opens new Seoul Experience Centre posted: 17/10/2024 Seoul, South Korea, October 2024....Genelec has added Seoul to its growing global network of ...

17/10/2024

Joe Duffy returns with the 18th season of The Meaning of Life'

Guests include Sin ad Burke, Bryan Dobson, Sonia O'Sullivan, Ricky Tomlinson, David Norris, Catherine Joyce Collins, Ronan Tynan, Olwen Fou r , Fintan O'...

17/10/2024

Hollywood actors Colin Farrell, Rupert Everett and Aidan Quinn among guests on this Friday's Late Late Show

Hollywood actors Colin Farrell, Rupert Everett and Aidan Quinn among guests on t...

16/10/2024

New role at Thomson for Federica Varalda

We are pleased to announce that Federica Varalda has been appointed as Managing Director - Development for the Thomson Group. She will be leading project develo...

16/10/2024

It's Never Too Early To Spread Festive Cheer-Our Spotify Holiday Singles Are Here

The air is turning crisp, and it won't be long until everyone is walking aro...

16/10/2024

Setting Dynamic DNS (DDNS) On A Siretta Router

Applicable Products Part number Description QUARTZ-22-LTE (EU) Dual Port Dual SIM LTE Router (EU) QUARTZ-22-UMTS (EU) Dual Port Dual SIM UMTS Rout...

16/10/2024

Chayse Irvin, ASC, CSC on Travis Scott's Mo City Flexologist

Director Kahlil Joseph's name is just as likely to appear in world-renowned art exhibitions as it is atop the credits for lauded music videos. In the latter...

16/10/2024

Kunstmin Theater in Dordrecht Chooses Clear-Com Arcadia for Communication Revolution

eds3_5_jq(document).ready(function($) { $(#eds_sliderM519).chameleonSlider_2_1({...

16/10/2024

ARRI launches 14-strong Ens Prime lens range

Ens lenses feature a magnification ratio of 1:4 on most focal lengths, equivalent to 10 close focus on the 32mm, which, said the company, is only 3.7 from the ...

16/10/2024

Thales demonstrates its capacity to deploy drone swarms with unparalleled levels of autonomy using AI

Facebook Twitter LinkedIn On 16 October 2024, in the first flight tests of...

16/10/2024

Riedel Communications Appoints Jason Barden as Regional Sales Director for CALA/LATAM Market

Wuppertal October 16, 2024 Riedel Communications Appoints Jason Barden as Regi...

16/10/2024

MP visits unique Northern Ireland transmitter site

Sorcha Eastwood MP visits transmitting station, highlighting personal and national importance of broadcast infrastructure October 15, 2024: Sorcha Eastwood, MP...

16/10/2024

IFABC Elects New President and Secretary at 31st General Assembly

This biennial event brings together IFABC members from around the world to meet and share ideas, news and developments in media auditing and digital advertising...

16/10/2024

ESA orders 6 additional radar-based satellites to Thales Alenia Space for IRIDE Earth observation constellation

Facebook Twitter LinkedIn This new batch of radar satellites will also be ...

16/10/2024

RT's exciting slate of homegrown content for children

Over 110 hours of new video and podcast content commissioned in 2024 for Ireland's youngest citizens and their families -RT jr podcast turned TV series Mad...

16/10/2024

RT is looking for a new member of the RT Audience Council

RT is looking for a new member to join the RT Audience Council which helps us understand the views of our diverse audiences. RT is required to appoint an Au...

16/10/2024

German Armed Forces receive final Ground Alerter 10 sense and warn camp protection system

Facebook Twitter LinkedIn On 16 October 2024, Thales officially handed ove...

15/10/2024

Music Videos in Beta Brings an Improved Viewing Experience to New Markets

Earlier this year, Spotify introduced music videos in beta, giving Premium subscribers in 12 markets another way to connect with the songs and artists they love...

15/10/2024

Revisit Some of Music's Most Iconic Hits With Our Spotify Anniversaries' Video Series

Music serves as a powerful memory booster, and Spotify recently introduced a new...

15/10/2024

Viasat Selects ST Engineering iDirect's Next-Generation Ground Technology to Accelerate Customers' Digital Transformation

Long-term partnership expands with new technology, paving the way for further ef...

15/10/2024

Making the dragons fly

Martin Pelletier, visual effects supervisor at Rodeo FX, explains how House of the Dragon's fantastic flying beasts are able to take to the air By Matthew ...

15/10/2024

Adobe adds Gen AI video extension capabilities to Premiere Pro

The company has also unveiled updates to Frame.io and plans to help 30 million people develop AI literacy and content creation skills by 2030 By Jenny Priestle...

15/10/2024

Watch: What caught our AI at IBC

Watch a panel featuring TVBEuropes content director Jenny Priestley discuss some of the biggest talking points from IBC2024 By TVBEurope Staff Published: Oct...

15/10/2024

Ofcom extends Channel 4's licence for a further decade

The new licence is designed to support Channel 4's digital content and distribution strategy, while safeguarding its investment in UK content, said Ofcom B...

15/10/2024

Mid-Month Drop: AEAF Awards, Dark Matter, NHL 25, Saudi Film Confex, and more.

We're halfway through a thrilling October, so it's time to take a beat and celebrate our wicked achievements so far. Caroline Parot, CEO Technicolor G...

15/10/2024

Rohde & Schwarz drives AirFuel Alliance RF standardization efforts with first RF wireless power tester prototype

Rohde & Schwarz drives AirFuel Alliance RF standardization efforts with first RF...

15/10/2024

HMS Networks changes organization to strengthen customer focus and cross-selling

HMS Networks changes organization to strengthen customer focus and cross-selling 15 Oct 2024 at 07:30 GMT+2 Regulatory press release HMS Networks AB (publ)...

15/10/2024

2024-10-15

CUPERTINO, CALIFORNIA Apple today introduced the new iPad mini, supercharged by the A17 Pro chip and Apple Intelligence, the easy-to-use personal intelligence s...

15/10/2024

Thales radios successfully tested by the German Armed Forces to be deployed within the NATO enhanced Forward Presence

Facebook Twitter LinkedIn The German Armed Forces conducted operational te...

15/10/2024

KNDS selects Thales Power Systems Solution for the Leopard 2 A8

Facebook Twitter LinkedIn KNDS awarded Thales a contract to deliver compact, programable and scalable High-Power Solid-State Power Distribution Boards (SS...