Why Have Big Cybersecurity Hacks Surged in 2023?

Payments made to hackers who hold systems hostage for ransom increased by almost half through September, according to blockchain analytics firm Chainalysis Inc., totaling almost $500 million in payouts.
In just the past few months, hackers have paralyzed shipping at some of Australia's largest ports; wreaked havoc on Las Vegas casinos; brought about a shortage of disinfecting wipes and garbage bags at Clorox Co.; and disrupted clearance of some Treasury market trades.
The surge in activity is all the more striking after ransomware attacks slowed by some measures last year.
The lull corresponded to the timing of Russia's invasion in Ukraine in February 2022, and some experts link it to the fact that many hackers are believed to be based in Eastern Europe and redirected their efforts or were otherwise distracted.
Other theories posit that hacking groups were lying low after a series of high-profile attacks drew the attention of law enforcement.
The hackers' success in getting paid rises in step with the amount of disruption they cause in a victim's computer systems, experts say.
One reason is that many victims, desperate to recover their data or keep it off the dark web, or both, wind up paying the extortion, which fuels further attacks.
Another is the scale and global nature of the industry, as many of the hackers are based in Russia or other countries that provide them with safe haven.
Growing awareness has led many organizations to invest in backup infrastructure that can be activated in an emergency and cyber incident response training, giving them leverage with the hackers to negotiate a lower payment or to avoid paying altogether, said Bill Siegel, chief executive officer of ransomware incident response company Coveware.
Tracking trends in hacking is notoriously difficult.
Data maintained by cybersecurity firms often includes only the experiences of their own customers, and leak sites maintained by hackers usually don't name victims who pay up.
A spike in ransomware attacks in 2021, including one on Colonial Pipeline Co. that upended fuel supplies on the US East Coast, prompted the Biden administration to declare ransomware a national security priority.
The Ransomware Task Force, a cyber-focused nonprofit, set out a list of 48 actions the public and private sector could take to mitigate such attacks, and as of Dec. 18 companies will be required to disclose cybersecurity incidents to the Securities and Exchange Commission within four business days of determining they are material to investors.
Under the new rules, businesses will have to report on the impact of the hack, including what data was publicly disclosed and to the processes the company took to mitigate risk.
The top hacking groups are perfecting a kind of franchise model, selling technologies and data to new entrants which then share the profits from their attacks, he said.
Cl0p was behind the breach of MOVEit file transfer software over the summer, an attack that has affected more than 2,600 organizations, according to Brett Callow, a threat analyst at Emsisoft.
LockBit was behind an attack last month against the US arm of Industrial & Commercial Bank of China Ltd., which disrupted the $26 billion US Treasury market, and an attack the month before that took down a website that Boeing Co. uses to sell spare aircraft parts, software and services.
Those attacks, and others like them, highlight what cybersecurity experts say is the growing use by hacking groups of sophisticated analog forms of social engineering to gain initial entry into an organization.
The shift to work-from-home for many employers has also created new security vulnerabilities - and opportunities for hackers, according to Jim McMurry, founder and CEO of cybersecurity firm ThreatHunter.
Some of the biggest attacks from the past year have involved hackers getting faster at exploiting software flaws immediately after they're publicly disclosed and before victims have much time to apply the required fixes, including for technologies necessary for remote work, he said.


This Cyber News was published on www.bloomberg.com. Publication date: Mon, 18 Dec 2023 00:29:05 +0000


Cyber News related to Why Have Big Cybersecurity Hacks Surged in 2023?

Fortinet Contributes to World Economic Forum's Strategic Cybersecurity Talent Framework - Shining a light on the cybersecurity workforce challenge, the World Economic Forum recently published its Strategic Cybersecurity Talent Framework, which is intended to serve as a reference for public and private decision-makers concerned by the ...
1 month ago Feeds.fortinet.com
Student Cybersecurity Clubs: Fostering Online Safety - Student cybersecurity clubs are playing a crucial role in promoting online safety among students. Student cybersecurity clubs play a vital role in this regard, as they provide a platform for students to learn about the latest threats, share best ...
6 months ago Securityzap.com
How to become a cybersecurity architect - Cybersecurity architects implement and maintain a comprehensive cybersecurity framework to protect their company's digital assets. The cybersecurity architect position is a fundamental role that all organizations need, said Lester Nichols, director ...
6 days ago Techtarget.com
Cybersecurity Training for Business Leaders - This article explores the significance of cybersecurity training for business leaders and its crucial role in establishing a secure and resilient business environment. By examining the key components of effective training programs and the ...
5 months ago Securityzap.com
Growing threats outpace cybersecurity workforce - The cybersecurity skills shortage threatens the well-being and even survival of numerous businesses as cybersecurity threats grow more numerous, sophisticated, and dangerous to the point that cybersecurity groups have vowed not to pay ransom demands. ...
5 months ago Legal.thomsonreuters.com
Understanding the New SEC Rules for Disclosing Cybersecurity Incidents - The U.S. Securities and Exchange Commission recently announced its new rules for public companies regarding cybersecurity risk management, strategy, governance, and incident exposure. "Currently, many public companies provide cybersecurity disclosure ...
7 months ago Feeds.dzone.com
Digital Learning Tools for Cybersecurity Education - In the field of cybersecurity education, digital learning tools have become indispensable. This article explores various digital learning tools tailored specifically to cybersecurity education. These digital learning tools play a crucial role in ...
6 months ago Securityzap.com
Cybersecurity Curriculum Development Tips for Schools - With the constant threat of cyber attacks, schools must prioritize the development of a robust cybersecurity curriculum to equip students with the necessary skills and knowledge. This article provides valuable insights and tips for schools aiming to ...
5 months ago Securityzap.com
The Importance of Cybersecurity Education in Schools - Cybersecurity education equips students with the knowledge and skills needed to protect themselves and others from cyber threats. Cybersecurity education can teach students about the impact of cyberbullying, how to prevent it, and how to respond ...
6 months ago Securityzap.com
What the cybersecurity workforce can expect in 2024 - For cybersecurity professionals, 2023 was a mixed bag of opportunities and concerns. The good news is that the number of people in cybersecurity jobs has reached its highest number ever: 5.5 million, according to the 2023 ISC2 Global Workforce Study. ...
5 months ago Securityintelligence.com
Cyber Employment 2024: Sky-High Expectations Fail Businesses & Job Seekers - Well-publicized estimates of a massive shortfall in cybersecurity workers have resulted in high expectations among job seekers in the field, but the reality often falls flat, because of a mismatch between companies' requirements and job seekers' ...
6 months ago Darkreading.com
Key cybersecurity skills gap statistics you should be aware of - As the sophistication and frequency of cyber threats continue to escalate, the demand for skilled cybersecurity professionals has never been bigger. The skills gap is not merely a statistical discrepancy; it represents a substantial vulnerability in ...
6 months ago Helpnetsecurity.com
Beyond Mere Compliance - Too often we continue to see executives whose approach to cybersecurity - compliance rather than protection - is strikingly similar to that of the ill-advised business owner whose minimal fire protection is designed only to meet the building code. ...
6 months ago Cyberdefensemagazine.com
Cybersecurity Training for Small Businesses - The importance of cybersecurity training for small businesses cannot be overstated in today's increasingly digital world. In conclusion, cybersecurity training is essential for small businesses to protect themselves against cyber threats. There are ...
4 months ago Securityzap.com
Gamification in Cybersecurity Education - Gamification has become increasingly prevalent in numerous domains, including cybersecurity education. Gamification presents a promising approach to meet this challenge, making cybersecurity education both effective and enjoyable. One way to ...
6 months ago Securityzap.com
How to Avoid Falling Below the Cybersecurity Poverty Line - The security poverty line broadly defines a divide between the organizations that have the means and resources to achieve and maintain mature security postures to protect data, and those that do not. It was first coined by cybersecurity expert Wendy ...
1 year ago Csoonline.com
The Endless Pursuit of the Ecosystem - The result was the biggest update I've made to Strategy of Security's cybersecurity ecosystem mapping since I first published it over two years ago. My goal is to define the most comprehensive and accurate taxonomy for the business of cybersecurity ...
6 months ago Securityboulevard.com
Cybersecurity Workforce Sustainability has a Problem. DEI Could be the Solution. - That's particularly true in cybersecurity, where it's increasingly difficult for organizations to fill critical roles during a worsening global talent shortage. There were more than four million unfilled cybersecurity jobs at the end of 2023. While ...
1 day ago Securityboulevard.com
Cybersecurity Workshops for Students - Cybersecurity workshops for students serve as an effective means to educate and empower the younger generation in protecting their digital assets. With proper planning and organization, cybersecurity workshops enable students to navigate the digital ...
6 months ago Securityzap.com
Cybersecurity Curriculum Development Tips - In this article, we will explore essential tips for developing a comprehensive and up-to-date cybersecurity curriculum. By staying abreast of the latest industry trends, educational program developers can ensure that their curriculum remains relevant ...
6 months ago Securityzap.com
Developing Cybersecurity Awareness Programs for Schools - Schools are increasingly becoming targets for cyberattacks, necessitating the development of robust cybersecurity awareness programs. Ultimately, a comprehensive cybersecurity awareness program is essential for schools to mitigate risks, enhance ...
6 months ago Securityzap.com
F5 Developing Fix for BIG-IP Vulnerability That Could Cause Denial of Service and Allow for Code Execution - F5 has warned of a serious format string vulnerability in BIG-IP that could allow an authenticated attacker to cause a denial-of-service and potentially execute malicious code. This security issue, tracked as CVE-2023-22374, affects iControl SOAP, an ...
1 year ago Securityweek.com
Cybersecurity Awareness Campaigns in Education - Cybersecurity awareness campaigns in education are essential to protect digital systems and information. The target audience for cybersecurity awareness campaigns in education includes students, teachers, administrators, and other staff members. ...
6 months ago Securityzap.com
What is the NIST Cybersecurity Framework? Definition from SearchSecurity - The NIST Cybersecurity Framework provides guidance on how to manage and reduce IT infrastructure security risk. NIST created the CSF to help private sector organizations in the United States develop a roadmap for critical infrastructure ...
5 months ago Techtarget.com
Essential Features of Cybersecurity Management Software for MSPs - Protect your clients' businesses from cyber threats with Cybersecurity Management Software. A vital tool that aids MSPs in enhancing their cybersecurity practices is Cybersecurity Management Software. In this article, we will delve into the features ...
1 month ago Hackread.com

Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)