TechBizWebTechBizWeb

    Subscribe to Updates

    Get the latest news about Technology and Business from all around the web..

    What's Hot

    Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

    November 7, 2022

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022
    Facebook Twitter Instagram
    • About Us
    • Privacy Policy
    • Guest Post
    • Terms
    • Contact
    Facebook Twitter Instagram
    TechBizWebTechBizWeb
    Subscribe
    • Home
    • Technology

      Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

      November 7, 2022

      Devialet brings its sci-fi design aesthetics to a $790 portable speaker

      November 7, 2022

      Elon Musk’s response to fake verified Elon Twitter accounts: a new permanent ban policy for impersonation

      November 7, 2022

      The iPhone 14 Pro and Pro Max will come with ‘longer wait times’ due to factory lockdown

      November 6, 2022

      Meta’s reportedly planning to lay off ‘thousands’ of workers this week

      November 6, 2022
    • Business
    • Cyber Security
      National Security News

      List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

      September 24, 2022

      Cybersecurity ranked most serious enterprise risk in 2022

      August 31, 2022

      Registration open for CISA virtual summit on K-12 school safety

      August 31, 2022

      What do the Trickbot leaks reveal about Russian cybercrime?

      August 31, 2022

      What cybersecurity measures do CISOs outsource?

      August 30, 2022
    • Blockchain
    • Vulnerabilities
    • Social Engineering
    • Malware
    • Cyber Security Alerts
    TechBizWebTechBizWeb
    Home»Cyber Security»Verizon Publishes 2019 Data Breach Investigations Report (DBIR)
    Cyber Security

    Verizon Publishes 2019 Data Breach Investigations Report (DBIR)

    May 8, 2019Updated:May 8, 2019No Comments7 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Verizon 2019 DBIR Shows Financially Motivated Attacks Increasing While Criminals Switch to Easiest Targets

    The Verizon 2019 Data Breach Investigations Report (DBIR) was published just after midnight today. This is the 12th edition since its launch in 2008, and the most extensive to date, with 73 contributors and an analysis of 41,686 security incidents including 2,013 confirmed breaches. A breach is defined as an incident that results in the confirmed disclosure or exposure of data.

    Purely from its detail and breadth of coverage, DBIR has become the breach bible for the security industry. Verizon does not speculate on the meaning of the data it provides, leaving that to independent security analysts. Like all surveys, it can only analyze and catalog the data it receives — it knows nothing about that which it knows nothing. As a result, DBIR provides evidence of security trends across the greater part of industry, but little in terms of specific causes for specific trends.

    An example of this can be seen in the relative trends for cyber espionage and financially motivated attacks (of which ransomware is probably the most visible and newsworthy example). The trend highlighted by the 2019 DBIR (PDF) is that financially motivated cyber-attacks are increasing across the board.

    In the manufacturing sector, the commonly held perception has long been that the majority of cyber-attacks are for cyber espionage. “Last year’s report showed financial as higher than espionage as motivation against the manufacturing sector for the first time,” Alex Pinto, head of Verizon security research, told SecurityWeek. “We quite honestly thought it was a fluke, and we described it as such.” But the distance between the two motivations has increased over the last year, with financially motivated attacks against manufacturing now standing at 68%. DBIR shows us this is happening, but doesn’t tell us why.

    “I won’t speculate,” said Pinto. “That’s not the function of DBIR.” It could simply be that financially motivated attacks have increased over the whole spectrum of industry — which it has — while cyber espionage has remained more static, “But we will be very careful about suggesting to manufacturing that the espionage attack is in decline.”

    On a personal basis, he continued, “there may be a bias in what is reported. Espionage is far more interesting than financially motivated attacks, so you may see more of those reported and in the news. It doesn’t mean that money-motivated attacks aren’t happening, but there is so much more of the run-of-the-mill financial stuff, it doesn’t necessarily get reported.”

    But bias in reporting could go further. In July 2018, Sophos reported that the true number of SamSam infections was probably much higher than commonly thought. Although there had been a handful of high-profile infections, Sophos and Neutrino followed the bitcoin wallet trail and concluded that around 233 victims had, mostly quietly, paid the ransom and not reported the incident.

    Here Pinto now pointed to the healthcare figures on ransomware, which is tracked by Verizon as the #2 malware type affecting all industries. “Healthcare is mandated to report any breach that occurs because of HIPAA regulations,” he said. “Ransomware has to be reported as a breach. So, all healthcare ransomware infections are reported. In our dataset as a whole, ransomware accounts for 24% — on healthcare it accounts for 70%.” Again, Pinto declined to speculate on causes behind the figures — but it is certainly possible that other industries are succumbing to ransomware attacks at a higher rate than they report simply because they don’t have to report; and that would certainly fit with the trend of increasing financially motivated attacks highlighted by the DBIR.

    It is possible, then, that the ransomware threat to industry is even greater than the DBIR figures suggest.

    Asked to highlight two particular trends exposed by the 2019 DBIR, Pinto suggested a ‘flight to ease’ by the attackers, and an increasing phishing focus on senior management (which may be two aspects of the same trend). For the former, he said it’s not a new phenomenon but one that has been widespread in 2018. “It’s the game of security,” said Pinto. “We make something harder, so the criminals switch to the next easiest thing that will keep their money flowing.”

    Bank fraud may be an example. The introduction of EMV bank cards (chip & pin) has made card-present fraud much harder. The criminals have responded by switching to card-not-present fraud. “From our aggregated data,” said Pinto, “it looks like web application-based payment card fraud is going to overtake non-web application fraud pretty soon. Those two lines are about to cross.” 

    Since 2015, point of sale breaches have decreased by a factor of ten, while web application breaches are now 13x more likely. Pinto added, “We have one partner, the National Cyber-Forensics and Training Alliance (NCFTA), based in the U.S., who is already suggesting, from its own data, that card-not-present is now more extensive than card-present fraud. We believe the reason for this shift — and it’s just speculation — is that chip and pin is simply moving the criminals towards something that is easier.”

    The phishing focus on senior management is another example of cybercriminals focusing on the easiest route to the maximum return. Talking about the business email compromise (BEC) threat, Pinto commented, “why bother hacking companies when we can just email the CFO and get him to send us money?”

    The BEC figures have come from a new DBIR partner this year — the FBI, which highlighted figures from its Internet Crime Complaint Center (FBI IC3); with a few new twists. One piece of good news, says Verizon, “is that the median loss for a business email compromise is approximately the same as the average cost of a used car. The bad news is that the dollar axis isn’t linear. There are about as many breaches resulting in the loss of between zero and the median as there are between the median and $100 million.”

    Of course, the FBI’s role isn’t simply to chart BEC losses, but to recover them where possible. In the last year, it introduced its Recovery Asset Team (RAT). “When the IC3 Recovery Asset Team acts upon BECs, and works with the destination bank,” says Verizon, “half of all US-based business email compromises had 99% of the money recovered or frozen; and only 9% had nothing recovered.”

    Pinto suggests that the real narrative of this year’s DBIR is that everything but nothing changes. “That’s my take on the narrative of the report,” he told SecurityWeek; “the more things change, the more they stay the same.” The hackers still hack servers and still deliver phishing emails; but they move to the easier targets with greater returns. “Even though we see specific targets and attack locations change,” adds Bryan Sartin, Verizon’s executive director of security professional services, “ultimately the tactics used by the criminals remain the same.”

    Related: Business-Critical Systems Increasingly Hit by Ransomware: Verizon 2018 DBIR 

    Related: State-Affiliated Hackers Responsible for Nearly 1 in 5 External Data Breaches: Verizon 2017 DBIR 

    Related: Verizon 2016 DBIR: What You Need to Know 

    Related: Don’t Sweat Mobile and IoT: Verizon 2015 DBIR

    view counter

    Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

    Previous Columns by Kevin Townsend:
    Tags:



    Source link

    Digitpol
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    National Security News

    List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

    September 24, 2022 Cyber Security

    Cybersecurity ranked most serious enterprise risk in 2022

    August 31, 2022 Cyber Security

    Registration open for CISA virtual summit on K-12 school safety

    August 31, 2022 Cyber Security

    What do the Trickbot leaks reveal about Russian cybercrime?

    August 31, 2022 Cyber Security

    What cybersecurity measures do CISOs outsource?

    August 30, 2022 Cyber Security

    SIA announces Women in Security Forum scholarship recipients

    August 30, 2022 Cyber Security
    Editors Picks

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022

    Google Cloud Says Running Validator on Solana Blockchain

    November 7, 2022

    European stocks rise as investors boosted by China speculation

    November 7, 2022
    Trending Now

    Evergrande creditors sell ‘Versailles mansion’ plot in Hong Kong

    By techbizweb

    OpenSea Creates Tool for NFT Creators to Enforce Royalties On-Chain

    By techbizweb

    FTSE chairs warn of declining relations with institutional investors

    By techbizweb

    https://www.nationalsportsacademy.com

    slot gacor hari ini

    http://www.inadesfo.org/

    http://www.eueomgbissau.org/

    http://www.congo-mai-mai.net/

    http://www.angelesdelafrontera.org/

    http://fifaworldcup2018schedule.com/

    http://tony4gtrmcr.co.uk/

    http://www.standrewsagreement.org/

    http://www.bob-russell.co.uk/

    http://davidmulholland.co.uk/

    http://railwayhotelenniskillen.com/

    http://www.fantasysportstrades.com/

    http://www.rainleaf-flooring.com

    http://mothersagainstguns.org/

    http://ma-coc.org/

    slot online

    http://www.paradoxmag.com/situs-judi-slot-online-gampang-menang-2021/

    http://www.paradoxmag.com/situs-judi-slot-online-terbaru-2021/

    http://slot-terbaru.net/

    Slot Gacor

    Slot Online

    Situs Slot Gacor

    http://www.appdexterity.com/

    https://cars4kids-deutschland.de/

    https://www.stretchingculture.com/

    https://www.b-123-hp.com/slot-gacor/

    https://denzstaffing.nl/

    https://ezbbqcooking.com/slot-gacor/

    https://www.mbahelp24.com/slot-gacor

    https://minhtanstore.com/slot-jackpot-terbesar/

    https://njbpusupplierdiversity.com/slot-gacor-gampang-menang/

    https://www.floridaspecialtycropfoundation.org/slot-gampang-menang/

    https://childrenscornerpreschool.org/slot-gacor-gampang-menang/

    https://cryptoquoter.com/slot-online-terbaik/

    https://alorkantho24.com/slot-gacor/

    https://ellas.xyz/slot-gacor/

    https://it.dougamatome.xyz/slot-online/

    https://www.daltercume.com/slot-gacor/

    https://josi-ana.dougamatome.xyz/slot88/

    https://josi-ana.dougamatome.xyz/slot-gacor/

    https://fastobserver.com/slot-jackpot-terbesar/

    https://www.planetexperts.com/slot-gacor/

    https://bfsolution.group/slot-bet-kecil/

    https://rustleva.co/slot/

    https://bfsolution.group/slot-bet-kecil/

    https://www.hotelcalimareal.com/togel-online/

    https://anime-game.dougamatome.xyz/slot-gacor-gampang-menang/

    https://anime-game.dougamatome.xyz/togel-online/

    https://bourbonbarrelfoods.com/slot/

    http://suneo39.wp.xdomain.jp/slot/

    https://techbizweb.com/slot-gacor/

    https://www.generalcatalyst.com/18-daftar-slot-gacor-terbaik-gampang-menang-jackpot-hari-ini/

    https://www.hotelcalimareal.com/slot-online/

    https://www.blockgates.io/slot-gacor/

    https://l12.com.br/slot-gacor/

    slot paling gacor

    https://www.donalds-hobby.com/slot-online/

    https://thecryptodirt.com/slot-gacor-hari-ini/

    http://iseta.edu.ar/aulavirtual/app/upload/users/1/1205/my_files/sbobet.html

    http://escuelavirtual.mincit.gov.co/app/upload/users/1/194/my_files/slot.html

    https://www.dev.medecinesfax.org/courses/JUDICASINO/document/slot.html

    http://www.e-archivos.org/cursos/courses/JUDICASINO/document/slot-gacor.html

    http://iesma.com.br/ead/main/upload/users/4/447/my_files/slot.html

    https://www.fundacoop.org/chamilo/app/upload/users/1/1185/my_files/slot.html

    https://fata-aatf.org/eskola/main/upload/users/3/31/my_files/slot.html

    https://uancv.edu.pe/ofinvestigacion/app/upload/users/3/328/my_files/slot-terlengkap.html

    https://micost.edu.my/EL/app/upload/users/2/209/my_files/slot-gacor.html

    https://www.academiacoderdojo.ro/elearningdev/app/upload/users/2/2442/my_files/slot-online.html

    http://campus-cidci.ulg.ac.be/courses/JUDICASINO/document/slot-termurah.html

    https://www.escueladerobotica.misiones.gob.ar/aula-ste/courses/LIVECASINO/document/slot-tergacor.html

    http://ccdipeepccqqfar.usac.edu.gt/chamilo/app/upload/users/3/358/my_files/slot-online.html

    https://cunori.edu.gt/campus/app/upload/users/7/7334/my_files/slot-online.html

    http://u-rus.com.ar/aula/app/upload/users/1/1322/my_files/slot.html

    http://icrodarisoveria.edu.it/chamilo/app/upload/users/1/1855/my_files/slot.html

    https://iestpliliagutierrez.edu.pe/clarolgm/courses/CASINO/document/slot.html

    http://pva.cobach.edu.mx/app/upload/users/7/7379/my_files/slot.html

    http://www.imb-pc-online.edu.gt/PL/app/upload/users/3/373/my_files/slot.html

    http://avcs.upeu.edu.pe/main/upload/users/3333/my_files/slot.html

    https://chamilo.fca.uas.edu.mx/app/upload/users/1/11186/my_files/slot-online/

    TechBizWeb
    Facebook Twitter Instagram Pinterest Vimeo YouTube
    • Home
    • Guest Post
    • About Us
    • Privacy Policy
    • Our Authors
    • Terms and Conditions
    • Contact
    © 2023 Tech Biz Web. Developed by Sawah Dev.

    Type above and press Enter to search. Press Esc to cancel.