IBM Report: Cybercriminals Intensify Attacks on User Identities in the UK, Complicating Recovery Efforts for Enterprises
21/02/2024
According to IBM X-Force, IBM Consulting's security services arm, cybercriminals last year generated more opportunities to log in to corporate networks through valid accounts, instead of hacking into them making this tactic a preferred weapon of choice for threat actors.
The X-Force Threat Intelligence Index is based on insights and observations from monitoring over 150 billion security events per day in more than 130 countries. In addition, data is gathered and analysed from multiple sources within IBM, including IBM X-Force Threat Intelligence, Incident Response, X-Force Red, IBM Managed Security Services, and data provided from Red Hat Insights and Intezer , which contributed to the 2024 report.
An emerging identity crisis
The report data revealed that exploiting valid accounts has become the path of least resistance for cybercriminals, with billions of compromised credentials accessible on the Dark Web.
According to the report, 50% of cyberattacks in the UK involved the exploitation of valid accounts as the initial access vector' and a further 25% of cases involved the exploitation of public-facing applications. Across Europe, X-Force observed a 66% year-on-year rise in attacks caused by the use of valid accounts contributing to Europe's prevalence as the most targeted region of 2023 and the record number of attacks that X-Force has ever reported regionally.
The criminal ecosystem was also quick to adapt to the use of valid accounts by attackers. In 2023, X-Force observed a 266% increase in infostealing malware, which is designed to steal personal and enterprise credentials, personally identifiable information, and banking and crypto wallet information.
This easy entry for attackers is harder to detect, eliciting a costly response from enterprises. According to X-Force, worldwide, major incidents caused by attackers using valid accounts were linked to nearly 200% more complex response measures by security teams than the average incident with defenders needing to distinguish between legitimate and malicious user activity on the network.
In fact, IBM's 2023 Cost of a Data Breach Report found that breaches caused by stolen or compromised credentials required roughly 11 months from detection to recovery the longest response lifecycle among all infection vectors.
Martin Borrett, Technical Director, IBM Security, UK, and Ireland (UKI) commented:
Our findings reveal that identity is increasingly being weaponised against enterprises, exploiting valid accounts and compromising credentials. It also shows us that the biggest security concern for enterprises stems not from novel or cryptic threats, but from well-known and existing ones.
Addressing cybersecurity challenges requires a strategic approach, emphasising the reinforcement of foundational security measures. Streamlining identity management through a unified Identity and Access Management (IAM) provider and strengthening legacy applications with modern security protocols are crucial steps in mitigating risks. Additionally, subjecting your system to rigorous stress tests by skilled offensive security teams proves invaluable in uncovering potential weaknesses. This insight is pivotal for crafting a robust incident response plan that engages all teams, from IT professionals to C-suite executives.
Julian David, CEO of techUK, added:
In an era marked by the growing sophistication of cybercriminals who exploit legitimate accounts to breach business defences, IBM's X-Force Threat Intelligence Index serves as a stark wake-up call.
The report underscores a troubling pattern where half of the cyberattacks in the UK rely on legitimate accounts for initial access, presenting significant challenges to businesses' recovery endeavours. To effectively combat this threat, businesses must adopt a strategic approach, integrating modern security protocols to mitigate risks and strengthen their defences against the ever-evolving landscape of cyber threats.
Further key UK findings include:
Malware made up 30% of security incidents observed in the UK.
Ransomware (30%) and cryptominers (20%) were the top malware types encountered in the country.
The impact of attacks was evenly distributed with extortion, digital currency mining and data leaks each making up 25% of total impacts in the UK.
This marks a shift from 2022, when half the cases X-Force observed in the UK involved extortion (57%) twice the global average followed by data theft (29%).
The professional, business and consumer services industry was the most targeted sector in the UK, representing 39% of cases.
Energy (30%) and finance & insurance (17%) were the second and third most targeted industries in UK, respectively.
Manufacturing was the most targeted industry in Europe, accounting for 28% of cases.
Europe overall experienced the highest percentage of incidents within the energy sector at 43%, as well as finance and insurance at 37%.
Major takeaways from the global report included:
Attacks on critical infrastructure reveal industry faux pas.
Worldwide, an alarming 69.6% of attacks that X-Force responded to were against critical infrastructure organisations, an alarming finding highlighting that cybercriminals are wagering on these high value targets' need for uptime to advance their objectives.
In 84% of attacks on critical sectors globally, compromise could have been mitigated with patching, multi-factor authentication, or least-privilege principals indicating that what the security industry historically described as basic security may be harder to achieve than portrayed.
Exploiting public-facing appl
LINK: | https://uk.newsroom.ibm.com/IBM-Report-Cybercriminals-Intensify-Attack... |
See more stories from ibm |
Most recent headlines
09/12/2024
Dalet Named an IDC Innovator in Media and Entertainment
Dalet, a leading technology and service provider for media-rich organizations, today announced that it has been named an IDC Innovator in the IDC Innovators: ...
23/11/2024
Heartwarming Out of My Mind Highlights the Importance of Disability Advocacy
PARK CITY, UTAH - JANUARY 19: (L-R) Judith Light, Rosemarie Dewitt, Luke Kirby, Michael Chernus, Phoebe-Rae Taylor, Sharon M. Draper, Amber Sealey, and Courtney...
23/11/2024
TCLtv+ Adds 23 CBS Fast Channels
LOS ANGELES/NEW YORK TCL's streaming service TCLtv+ has struck a content deal with Paramount Streaming that will add 23 CBS FAST channels to its lineup....
23/11/2024
Viamedia Signs Ad Rep Deals with 7 More Service Providers
LEXINGTON, Ky. The independent advertising rep firm Viamedia has further expanded its sales network with news that it has agreements to manage advertising sale...
23/11/2024
The Trade Desk Jumps Into Streaming TV With Ventura OS
VENTURA, Calif. Programmatic ad giant The Trade Desk is pushing into the streaming technology business with a new operating system called Ventura....
23/11/2024
Writers Guild, 3 PBS Stations Reach Tentative Agreement for New Contract
BOSTON, LOS ANGELES AND NEW YORK The Writers Guild of America has announced that it has reached a tentative agreement with management at PBS member stations WGB...
23/11/2024
Supreme Court to Consider Legality of FCC's Universal Service Fund
WASHINGTON, D.C. The U.S. Supreme Court has agreed to hear an appeal in a case that alleges the FCC does not have the authority to decide how funds from the Uni...
22/11/2024
Michelle Satter to Be Honored at 2025 Sundance Film Festival Gala Celebrating Sundance Institute Presented by Google TV
Sean Wang, Julian Brave NoiseCat, and Emily Kassie to Receive Annual Vanguard Aw...
22/11/2024
Spotify Inks a New Partnership With Bloomsbury To Offer A Greater Assortment of Audiobooks
Our library continues to grow. In 2022, we announced the addition of audiobooks ...
22/11/2024
SBS wins Australian Podcast Publisher of the Year for third year running
SBS wins Australian Podcast Publisher of the Year for third year running 22 November, 2024 Media releases An outstanding slate of multilingual, multicultur...
22/11/2024
Film Lighting: a Cinematic Guide w/ Free Lighting Plots
Home Applications Film Lighting: a Cinematic Guide w/ Free Lighting Plots Your Guide to Film Lighting In this guide, we'll explore the history of fil...
22/11/2024
Fox, Hulu Renew Content Deal
Fox Entertainment and Hulu have renewed a multi-year content distribution agreement that will keep in-season streaming rights for Fox's programming slate on...
22/11/2024
Academy Award-Winning Film Studio Caviar Signs Director Duo MAMA
Academy Award-Winning Film Studio Caviar Signs Director Duo MAMA Brie Clayton November 22, 2024 0 Comments Academy Award-winning independent film stud...
22/11/2024
A Creative Alliance for Black Friday: Independent Software Makers Unite for Photographers
A Creative Alliance for Black Friday: Independent Software Makers Unite for Phot...
22/11/2024
Partial Bold Text using After Effects expressions UPDATED
Partial Bold Text using After Effects expressions UPDATED Graham Quince November 22, 2024 0 Comments Now with an improved expression for Per Word Se...
22/11/2024
John Lawson Steps Down as AWARN Executive Director
WASHINGTON John Lawson, longtime broadcast alerting advocate and founder of the AWARN Alliance, said he is stepping down as its executive director to work full-...
22/11/2024
Red, white and Blue Lucy UK media tech provider reaches across the Pond
Entering the American market follows a period of significant growth for the company By Matthew Corrigan Published: November 22, 2024 Entering the American...
22/11/2024
Warner Bros. Discovery Introduces Shop With Max and Moments
NEW YORK Warner Bros. Discovery Advertising Sales has incorporated Kerv's AI-enhanced technology into its ad-tech platform and launched two new ad offerings...
22/11/2024
EDO, Vizio Ink New Multiyear Smart-TV Data Licensing Pact
NEW YORK Vizio's Inscape, a smart-TV data provider, and EDO said they have extended their longstanding data partnership....
22/11/2024
New Pixotope Reveal Enables AR, Virtual Production Without Green Screens
OSLO, Norway Live augmented reality and virtual production specialist Pixotope Technologies has launched Pixotope Reveal, an AI-powered background segmentation ...
22/11/2024
Nominations Open for 2025 NAB Technology Awards
The National Association of Broadcasters has opened nominations for the 2025 NAB Technology Awards, recognizing excellence in broadcast engineering, digital lea...
22/11/2024
Thanksgiving TV Sports Ad-Spend Binge To Hit $624 Million
In between helpings of turkey and other Thanksgiving Day fare, viewers will see companies dishing up hefty portions of ads on sports programming, with the natio...
22/11/2024
8 Channels Added to MyFree DirecTV Streaming Lineup
Following the recent launch of the MyFree DirecTV free-ad supported package of 70-plus streaming channels, DirecTV has launched eight new channels catering to s...
22/11/2024
Viant, Disney Advertising Expand CTV Ad Collaboration
IRVINE, Calif. Viant Technology said it has expanded its agreement with Disney Advertising that's focused on making premium connected TV, video and display ...
22/11/2024
Xumo To Make Ad Inventory Available Programmatically With PubMatic
PHILADELPHIA and REDWOOD CITY, Calif. Xumo, the streaming platform joint venture of Comcast and Charter Communications, has reached an agreement to make its pre...
22/11/2024
Mediaocean To Acquire Innovid, Will Merge It With Flashtalking
NEW YORK Privately-held ad tech giant Mediaocean has inked a definitive agreement to acquire Innovid, an independent software platform for advertising creation,...
22/11/2024
Viz University introduces new Viz Artist certifications aimed at upskilling designers of all levels
Viz University introduces new Viz Artist certifications aimed at upskilling desi...
22/11/2024
NBC Sports President Rick Cordella on How Comcast's NBCU Cable-Net Spinoff Will Impact Sports Ops
NBC Sports President Rick Cordella on How Comcast's NBCU Cable-Net Spinoff W...
22/11/2024
NWSL Championship 2024: CBS Sports Caps Off First Year of In-House Broadcasts With Saturday's Final in Kansas City
NWSL Championship 2024: CBS Sports Caps Off First Year of In-House Broadcasts Wi...
22/11/2024
Premier League To Establish In-House Media-Operations Business for 2026-27 Season
Premier League To Establish In-House Media-Operations Business for 2026-27 Seaso...
22/11/2024
SailGP Season 5 Set to Be Most Expansive Yet'
SailGP Season 5 set to be most expansive yet' By George Bevir Friday, November 22, 2024 - 10:34 Print This Story SailGP: The New Zealand Sail Grand P...
22/11/2024
SailGP Season 5: New Broadcasters, New Requirements
SailGP Season 5: New broadcasters, new requirements By George Bevir Friday, November 22, 2024 - 10:34 Print This Story The Germany SailGP team in action a...
22/11/2024
SailGP Season 5: AI Cameras to Get Viewers Closer to the Action
SailGP Season 5: AI cameras to get viewers closer to the action By George Bevir Friday, November 22, 2024 - 10:33 Print This Story Getting viewers closer ...
22/11/2024
SailGP Season 5: Getting Umpires Onscreen and More Studio-Based Content
SailGP Season 5: Getting umpires onscreen and more studio-based content By George Bevir Friday, November 22, 2024 - 10:33 Print This Story Australia SailG...
22/11/2024
SailGP Season 5: Enhanced LiveLine Graphics Bring Augmented Reality to Chase Boats
SailGP Season 5: Enhanced LiveLine graphics bring augmented reality to chase boa...
22/11/2024
Full House: Inside Production of the European Curling Championships
Full house: Inside production of the European Curling Championships By Kevin Hilton Thursday, November 21, 2024 - 12:40 Print This Story Curling star Anna...
22/11/2024
NBC Sports President Rick Cordella on How Comcast's NBCU Cable Net Spinoff Will Impact Sports Ops
NBC Sports President Rick Cordella on How Comcast's NBCU Cable Net Spinoff W...
22/11/2024
Sky and Peacock's Original hit drama series The Day of the Jackal scores a second season renewal
Sky and Peacock's Original hit drama series The Day of the Jackal scores a s...
22/11/2024
Rugged Rugby: Conquer or Die' Premieres December 10: A Battle for Supremacy Begins
Back to All News Rugged Rugby: Conquer or Die' Premieres December 10: A Ba...
22/11/2024
Standards Pavilion elevates the role of standards in advancing climate action at COP29
Friday 22 November, Baku, Azerbaijan: As COP29 wraps up in Azerbaijan, the Stand...
22/11/2024
Let's Make Toy Show Day Official
Let's Make Toy Show Day Official The Late Late Toy Show | Friday December 6th | 9:35PM Watch Below The Late Late Toy Show is fast approaching and kids al...
22/11/2024
COOPANS, the Alliance Managing Europe's Largest Air Traffic Volume, Upgrades its Air Traffic Control (ATC) System with Thales
Facebook Twitter LinkedIn COOPANS is a leading international cooperation b...
22/11/2024
Press release
Facebook Twitter LinkedIn Thales confirms that the Parquet National Financier (PNF) in France and the Serious Fraud Office (SFO) in the United Kingdom hav...
22/11/2024
RT General Election 2024: Critical Election Period
The broadcasting regulator, Coimisi n na Me n has removed the traditional broadcast Moratorium for television and radio. In the past, this applied from 14:00 ...
21/11/2024
Neneh Cherry Takes Us on a Musical Journey Inspired by Her Memoir, A Thousand Threads'
Neneh Cherry, a musical trailblazer for more than three decades, is full of stor...
21/11/2024
6 Spotify Audiobook Features That Level Up Your Listening Experience
Since launching our audiobooks offering, we've continuously upped our game on designing a user experience that provides seamless and engaging listening. You...
21/11/2024
SEP 2024 / PAG launches new MPL150 Battery at IBC24
1ST SEPTEMBER 2024 PAG Ltd. UK, the creator of innovative, high-end portable power systems for the film and television industry, has announced the introduction...
21/11/2024
SEP 2024 / PAG Introduces new Cinergy Battery
1ST SEPTEMBER 2024 PAG Ltd. UK, the creator of innovative, high-end, portable power systems for the film and television industry, has announced the introductio...
21/11/2024
Celebrating The Best Of The Best
The HPA Awards exist to honor and recognize the accomplishments of the talented HPA community and to support their efforts with increased awareness and celebrat...
21/11/2024
L3Harris Co-Founder, Chair and CEO Chris Kubasik: Arsenal of Democracy 2.0 Will Require New Ways of Doing Business
He writes in POLITICO: When it comes to protecting our country, innovation and s...