They point directly to the world of finance, to cash. Last year hackers practically doubled the number of attacks, rising to 26% from 14% in 2016, to banks and other financial institutions. Almost one in five attacks, with an increase of 25%, have high tech corporations in their sights. There is also a new entry: it is the commercial activities and professional services that conquer the third place in the top five of the most targeted industries by hackers. Instead, they come out of the top five "governments, PA and public bodies": the intrusions from 14% in 2016 fall to 5%. So finance returns to the top step of the podium since 2014.
2017 is the annus horribilis of cyber security. 12 billion attempts were made in the world of attacks, 150 million were successful. This is revealed by the "Global threat intelligence report 2018" by Ntt Security, a multinational company headed by the Japanese telecommunications company NTT, analyzing around 40% of global internet traffic. 6.1 trillion logs (event logs) under observation, gathering data from the web, from the cloud, from client and partner security platforms, from Security Operations Centers and Ntt research centers.
"Criminals now aim directly at finance or create models of fraud by exploiting spear-phishing (scam targeted via email) as a simple but effective means of attack - explains Dolman Aradori, head of cyber secutity of Ntt Data Italy -. When they attack high tech companies, they are looking for information on the vulnerability of systems and products to be able to reuse them during user raids. Cyber security is increasingly becoming part of the cultural fabric of large companies. On the other hand, we note that in the SMEs there is still little sensitivity even if the imminent advent of the Gdpr is facilitating a slow conversion in behavior even in smaller realities ».
hacker-670x274.jpg
The report analyzes the most used tools: in one case out of four, malware such as spyware and keyloggers are used. The former record and transmit the user's online data and activity to third parties while a keylogger "captures" everything that is typed on the keyboard. In one out of four the "trojan horses" were used and the viruses are at 23% while the ransomware last year showed an exploit of 350%, rising to 7% from 1% of 2016. In the Emea area then they were very used: almost a third of the attacks were carried out with ransomware to hit industries, health, the betting business, commercial activities and professional services. From the point of view of hackers, these activities can be considered digital trojans, solutions to bypass the strengthened defenses of finance and large companies. "They are a bridgehead to the other companies they work for and end users because they often do not have the same levels of protection," Aradori emphasizes. You "enter" the studio, which, for example, processes payrolls and then passes into the network and into the systems of multinationals ".
The report identifies, through the IP address, also the countries of origin of the attacks: a game that is played between superpowers, especially the United States and China. The US, among other things, hosts a large number of hosting services with servers that criminals use as a trampoline. In China, the dreaded Unit 61398, a division of the popular army specialized in industrial espionage and intelligence, operates. An activity that, according to Ntt Security data, mainly targets the European production fabric. 67% of intrusions to the Old Continent industries come from Beijing. "The information war and cyber espionage have risen sharply compared to 2016 with + 24% and + 46%, confirming the fact that the" war between nations "is moving into cyberspace," remarks Dolman.