{"id":50065,"date":"2022-05-26T08:36:30","date_gmt":"2022-05-26T15:36:30","guid":{"rendered":"http:\/\/www.enxmag.com\/twii\/?p=50065"},"modified":"2022-05-26T08:36:32","modified_gmt":"2022-05-26T15:36:32","slug":"phishing-attacks-increase-by-54-as-initial-attack-vector-for-access-and-extortion-attacks","status":"publish","type":"post","link":"https:\/\/www.enxmag.com\/twii\/the-week-in-imaging-twii\/editors-blog\/2022\/05\/phishing-attacks-increase-by-54-as-initial-attack-vector-for-access-and-extortion-attacks\/","title":{"rendered":"Phishing Attacks Increase by 54% as Initial Attack Vector for Access and Extortion Attacks"},"content":{"rendered":"\n<div class=\"wp-block-image\"><figure class=\"alignleft size-medium\"><img loading=\"lazy\" width=\"300\" height=\"149\" src=\"https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2022\/05\/KnowBe4-300x149.jpg\" alt=\"\" class=\"wp-image-50066\" srcset=\"https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2022\/05\/KnowBe4-300x149.jpg 300w, https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2022\/05\/KnowBe4.jpg 397w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/figure><\/div>\n\n\n\n<p>New analysis of threat activity for the first quarter of this year shows anyone with access to corporate email is now on the front lines of modern cyberattacks of all kinds.<\/p>\n\n\n\n<p>The key to a solid cyber defense is knowing your enemy. It\u2019s one of the reasons I spend so much of the time on this blog talking about industry reports \u2013 they provide insight into what threat actors are doing so you can know how to change up your cybersecurity strategy. In security vendor Kroll\u2019s Q1 2022 Threat Landscape report, it appears that the kinds of attacks are shifting around in importance, but phishing attacks are playing a primary role.<\/p>\n\n\n\n<p>According to the report, cybercriminals are changing their attack focus:<\/p>\n\n\n\n<ul><li>Ransomware attacks are down 30% from the previous quarter<\/li><li>Email Compromise is on the rise by 18%<\/li><li>Unauthorized access is down by 22%<\/li><\/ul>\n\n\n\n<p>It also appears that their initial attack vectors are also changing their stripes:<\/p>\n\n\n\n<ul><li>Vulnerabilities are down by two-thirds to just 3% of attacks<\/li><li>Zero-day exploits are down by half to 13% of attacks<\/li><li>Valid accounts are up 233% to represent 10% of attacks<\/li><li>Phishing is now used in 60% of attacks as the initial attack vector, rising 54% from last quarter<\/li><\/ul>\n\n\n\n<p>Those last two jumps are important \u2013 notice how phishing rose dramatically, and yet while vulnerabilities and zero-day attacks declined, valid accounts also rose. Where did those valid accounts (no doubt, purchased from the dark web) come from? In most cases, they, too, were obtained using a phishing campaign intent on harvesting credentials.<\/p>\n\n\n\n<p>So, as you look for the best way to shape your cybersecurity defenses to respond to shifts in attack methods, solutions that protect the user from malicious phishing attacks \u2013 as in the case of Security Awareness Training \u2013 are not only prudent but necessary. Until we are all able to stop receiving malicious emails, we\u2019re going to need to learn how to spot them to stop them.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>New analysis of threat activity for the first quarter of this year shows anyone with access to corporate email is now on the front lines of modern cyberattacks of all kinds. The key to a solid cyber defense is knowing your enemy. It\u2019s one of the reasons I spend so much of the time on this blog talking about industry reports \u2013 they provide insight into what threat actors are doing so you can know how to change up your cybersecurity strategy. In security vendor Kroll\u2019s Q1 2022 Threat Landscape report, it appears that the kinds of attacks are shifting around in importance, but phishing attacks are playing a primary role. According to the report, cybercriminals are changing their attack focus: Ransomware attacks are down 30% from the previous quarter Email Compromise is on the rise by 18% Unauthorized access is down by 22% It also appears that their initial attack vectors are also changing their stripes: Vulnerabilities are down by two-thirds to just 3% of attacks Zero-day exploits are down by half to 13% of attacks Valid accounts are up 233% to represent 10% of attacks Phishing is now used in 60% of attacks as the initial attack vector, rising 54% from last quarter Those last two jumps are important \u2013 notice how phishing rose dramatically, and yet while vulnerabilities and zero-day attacks declined, valid accounts also rose. Where did those valid accounts (no doubt, purchased from the dark web) come from? In most cases, they, too, were obtained using a phishing campaign intent on harvesting credentials. So, as you look for the best way to shape your cybersecurity defenses to respond to shifts in attack methods, solutions that protect the user from malicious phishing attacks \u2013 as in the case of Security Awareness Training \u2013 are not only prudent but necessary. Until we are all able to stop receiving malicious emails, we\u2019re going to need to learn how to spot them to stop them.<\/p>\n","protected":false},"author":178,"featured_media":50066,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[80,1650,82,1638],"tags":[4172],"_links":{"self":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/50065"}],"collection":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/users\/178"}],"replies":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/comments?post=50065"}],"version-history":[{"count":1,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/50065\/revisions"}],"predecessor-version":[{"id":50067,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/50065\/revisions\/50067"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/media\/50066"}],"wp:attachment":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/media?parent=50065"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/categories?post=50065"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/tags?post=50065"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}