Email Attacks Doubled In 2023

The leader cyber security  firm Acronis has released findings of its regular cyber threats report for the second half of 2023 called Acronis Cyberthreats Report H2 2023.  Notably, it uncovers the rise of Generative AI (Gen-AI) systems to create malware and orchestrate serious cyber attacks.

The report provides an in-depth analysis and prescriptive outlook on key security issues and prevalent cyber-threats worldwide.

By leveraging data collected from over 1,000,000 unique endpoints across 15 key countries, the findings conclude that AI-enhanced phishing affected over 90% of organisations and contributed to a 222% surge in email attacks in 2023 as compared to the second half of 2022.

Ransomware variants have decreased, yet the most effective attack vector are still causing companies across the globe to lose both their data and their money. In particular, Acronis identifies  the lack of strong security solutions which should be detecting the exploitation of zero-day vulnerabilities.

Organisations are falling victim to attacks due to the delay in patching vulnerable software which allows threat actors to gain domain administrative rights, uninstall security tools and infiltrate sensitive information. 

“There’s a disturbing trend being recognised globally where bad actors continue to leverage ChatGPT and similar generative AI systems to increase cyberattack efficiency, create malicious code, and automate attacks,” observed Candid Wüest, Acronis VP of Product Management. “Now, more than ever, corporations need to prioritise comprehensive cyber protection solutions to ensure business continuity.” he said.

These IT resources are allies to businesses who seek robust IT infrastructure and sound cyber security but because they centralise services to numerous businesses, from SMBs to large corporations; the scaling efficiencies that make them a business asset also make them a single point of failure where cyber criminals can exploit multiple entities through a single attack.

The report notes how more advanced tactics like supply chain attacks, AI-driven attacks and state-sponsored incursions are likely to intensify. MSPs should brace themselves for threats unique to their operations, including "island hopping," in which attackers use an MSP's infrastructure to attack clients, as well as "credential stuffing," which exploits an MSP's broad access to systems.

Key findings and themes from the report include:

Global Threat Landscape

  • Singapore, Spain, and Brazil emerged as the most targeted focus countries for malware attacks in Q4 2023.
  • Acronis blocked nearly 28 million URLs at the endpoint in Q4 2023, reflecting a 36% decrease compared to Q4 2022.
  • 33.4% of received emails were identified as spam, with 1.5% containing malware or phishing links.
  • The average lifespan of a malware sample in the wild is 2.1 days.
  • In Q4 2023, 1,353 ransomware cases were explicitly mentioned, with notable contributions from LockBit, Play, ALPHV and the active Toufan group.

Cyber Security Trends H2 2023

  • Ransomware remains a major threat to large and medium-sized businesses, impacting critical sectors such as government and health care.
  • Data stealers are the second most prevalent threat, contributing to most data breaches.
  • The use of generative AI systems, including ChatGPT, for launching cyberattacks and creating malicious content is on the rise.

Ransomware Trends

  • Known ransomware gangs in 2023 include LockBit, Cl0P, BlackCat / ALPHV, Play, and 8Base.
  • The ALPHV gang, whom the FBI targeted in December 2023, breached over 1,000 entities, demanded over $500 million, and received over $300 million in ransom payments.
  • Regardless of a decrease in ransomware variants, businesses continue to suffer data and financial losses.

Attacks on MSPs Are Increasing

  • Attacks on managed service providers (MSPs) continue, with a recent high-profile breach affecting multiple US (United States) government agencies.
  • Microsoft cloud email account vulnerabilities led to the compromise of 60,000 emails from 10 US State Department accounts.

Phishing & Amail Attacks Remain The Main Attack Vectors

  • The total number of email-based attacks detected in 2023 increased by 222%.
  • Organisations experienced a 54% increase in the number of attacks per organisation.
  • 91.1% of organisations faced AI-enhanced phishing attacks.

Cyber Criminals Embrace Malicious AI Tools 

  • Cyber criminals are leveraging malicious AI tools, including WormGPT, FraudGPT, DarkBERT, DarkBART and ChaosGPT.
  • The public release of ChatGPT has increased the use of generative AI for cyberattacks.

Bad actors continue to profit from these activities and are leveraging AI-enhanced techniques to create more convincing phishing schemes, guaranteeing that this problem will continue to plague businesses.

Acronis       Image: Unsplash

You Might Also Read: 

BEC Attacks: Trends & Predictions For 2024:

DIRECTORY OF SUPPLIERS - Email Security:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Cybercrime Hit 1.5m UK Businesses In 2023
Russian Military Botnet Dismantled »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall And Why Does It Matter

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall And Why Does It Matter

See how to use next-generation firewalls (NGFWs) and how they boost your security posture.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

A10 Networks

A10 Networks

A10 Networks is a leader in application networking, helping organizations of all sizes to accelerate, optimize and secure their applications.

Technology Association of Georgia (TAG)

Technology Association of Georgia (TAG)

TAG's mission is to educate, promote, influence and unite Georgia's technology community to stimulate and enhance Georgia's tech-based economy.

Commissum

Commissum

Commissum specialise in information assurance and security testing services.

Logsign

Logsign

Logsign is a Security Orchestration, Automation and Response (SOAR) platform with next-gen Security Information and Event Management (SIEM) solution.

Vuntie

Vuntie

Vuntie blend European craftsmanship, performance and open-source technology to deliver cybersecurity services including penetration testing, incident response, training and consultancy.

Sweepatic

Sweepatic

The Sweepatic reconnaissance platform discovers and analyses all internet facing assets and their exposure to risk.

Vector Informatik

Vector Informatik

Vector Informatik is a specialist in automotove electronics and provides services, embedded software and tools for securing embedded systems against cyber-attacks.

Cutting Edge Technologies (CE Tech)

Cutting Edge Technologies (CE Tech)

CE Tech is a Next Generation Technology Partner providing advanced technology infrastructure solutions through partnerships with leading technology providers.

Red Sky Alliance

Red Sky Alliance

Red Sky Alliance (Wapack Labs Corp) is a cyber threat intelligence firm that delivers proprietary intelligence data, analysis and in-depth strategic reporting.

Toothpic

Toothpic

ToothPic has invented, designed, developed and patented a solution to enable companies to turn every smartphone into a secure key for a user-friendly online authentication.

Inetum

Inetum

Inetum (formerly Gfi Informatique) is an agile IT services providing digital services and solutions, and a global group that helps companies and institutions to get the most out of digital flow.

Managed IT Services

Managed IT Services

Managed IT Services is a managed IT Services Company offering a diverse range of Cyber Security services and IT solutions.

PCS Security (PCSS)

PCS Security (PCSS)

PCS Security provides secure, reliable and state-of-the-art security solutions to help our customers address their security concerns.

PagerDuty

PagerDuty

PagerDuty is the central nervous system for a company’s digital operations. We identify issues in real-time and bring together the right people to respond to problems faster.

Pistachio

Pistachio

Pistachio is the new evolution of cybersecurity awareness training and attack simulations.

Cyphershield

Cyphershield

Cypershield is a Security and Smart Contract audit company providing professional smart contract auditing services for varied Crypto projects.