BradEgeland.com
  • Welcome
  • Blog
  • Expertise
  • Resume
  • Software / Service Reviews
  • Contact
  • Videos
  • Books / White Papers
  • Mentoring Contact Form
  • Awards/Recognition
  • Templates & Downloads
  • Clients
  • Professional Services
  • Past Survey Results

Attackers Target Vulnerable Financial Customers This Holiday Season

12/3/2022

0 Comments

 
Picture
Cybercriminals are changing how they target financial institutions this holiday season: some 80% of them are going after vulnerable customers rather than the institutions themselves.


A new report from Akamai also found a massive 257% increase in the number of web applications and API attacks against the financial services sector in the past year.


Other important findings include:


  • Customer account takeover attempts represent more than 40% of attack types, with another 40% focusing on website scraping used to create more convincing phishing scams.
  • Within a 24-hour span, exploitation of newly discovered zero-day vulnerabilities against financial services reaches multiple thousands of attacks per hour and peaks quickly — affording little time to patch and react.
  • Phishing campaigns against financial services customers are introducing techniques that bypass two-factor authentication solutions and increase risk for everyday customers.





Steve Winterfeld, advisory CISO at Akamai, said the shift to attacking APIs means that security teams must focus on testing and close monitoring, adding that in some cases that may require new capabilities or skill sets.


“During high traffic times often driven by holidays we will see increases in attacks trying to hide in the increased volume, Winterfeld said. “The insights on customer-focused attacks also provides companies with critical information on where they need to reevaluate how they are categorizing attacks and tracking fraud trends. Fraud prevention is moving into cybersecurity where it can be prevented at the edge."


Teresa Walsh, global head of intelligence for the Financial Services Information Sharing and Analysis Center added that the data in Akamai’s report underscores the harsh realities security professionals in the financial services industry face every day.


“With next-generation technology amplifying attack volume and sophistication for financial services organizations, sharing threat intelligence and security best practices is especially critical to protecting the sector and its customers,” Walsh said.


Scott Gerlach, co-founder and chief security officer at StackHawk, said threat actors will go after anything that can gain them assets, such as money, information, or fame — subsequently, banking customers and their personal assets fall under that category. Gerlach said many organizations are still taking API security into consideration too late after the API has been shipped to production or they are using legacy security tooling that isn't built to test APIs thoroughly.


“Both methods leave vulnerabilities undiscovered and create gaps in protection— and that's exactly what threat actors are looking for,” said Gerlach. “Organizations have to scale API security practices along with the increase in API usage. That means security and engineering teams partnering early in the software development lifecycle to understand what APIs are being developed, what data they handle, and how to best test the APIs for potential security issues early and often.”


David Maynor, senior director of threat intelligence at Cybrary, said Akamai’s findings align with what he has seen in the wild. Maynor said the surge in attacks shows that the threat actors targeting FinServ know the huge windfall they will have if they are successful.
​

“This also says to me personally that the attackers have selected their victims and are trying to find tools and attacks to penetrate the victim,” Maynor said. “This targeting pattern is rare and the reverse of what’s generally observed: lazy attackers using a tool or exploit they have to compromise victims opportunistically.”

0 Comments



Leave a Reply.

    Author:

    Picture

    Brad Egeland


    Named the "#1 Provider of Project Management Content in the World," Brad Egeland has over 25 years of professional IT experience as a developer, manager, project manager, cybersecurity enthusiast, consultant and author.  He has written more than 8,000 expert online articles, eBooks, white papers and video articles for clients worldwide.  If you want Brad to write for your site, contact him. Want your content on this blog and promoted? Contact him. Looking for advice/menoring? Contact him.

    Picture
    Picture
    Picture
    Picture
    Picture
    Picture

    RSS Feed

    Archives

    December 2022
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    August 2021
    July 2021
    June 2021
    May 2021
    April 2021
    March 2021
    February 2021
    January 2021
    December 2020
    November 2020
    October 2020
    September 2020
    August 2020
    July 2020
    June 2020
    May 2020
    April 2020
    March 2020
    February 2020
    January 2020
    December 2019
    November 2019
    October 2019
    September 2019
    August 2019
    July 2019
    June 2019
    May 2019
    April 2019
    March 2019
    February 2019
    January 2019
    December 2018
    November 2018
    October 2018
    September 2018
    August 2018
    July 2018
    June 2018
    May 2018
    April 2018
    March 2018
    February 2018
    January 2018
    December 2017
    November 2017
    October 2017
    September 2017
    August 2017
    July 2017
    June 2017
    May 2017
    April 2017
    March 2017
    February 2017
    January 2017
    December 2016
    November 2016
    October 2016
    September 2016
    August 2016
    July 2016
    June 2016
    May 2016
    April 2016
    March 2016
    February 2016
    January 2016
    December 2015
    November 2015
    October 2015
    September 2015
    August 2015
    July 2015
    June 2015
    May 2015
    April 2015
    March 2015
    February 2015
    January 2015
    December 2014
    November 2014
    October 2014
    September 2014
    August 2014
    July 2014
    June 2014
    May 2014
    April 2014
    March 2014
    February 2014
    January 2014
    December 2013
    November 2013
    October 2013
    September 2013
    August 2013
    July 2013
    June 2013
    May 2013
    April 2013
    March 2013
    February 2013
    January 2013
    December 2012
    November 2012
    October 2012
    September 2012
    August 2012
    July 2012
    June 2012
    May 2012
    April 2012
    March 2012
    February 2012
    January 2012
    December 2011
    November 2011
    October 2011
    September 2011
    August 2011
    July 2011
    June 2011
    May 2011
    March 2011
    January 2011
    December 2010
    November 2010
    October 2010
    September 2010
    August 2010
    June 2010
    May 2010
    April 2010
    March 2010
    November 2009

    RSS Feed

Powered by Create your own unique website with customizable templates.