Hackers look to target big tech firms through IT professionals

Cybercriminals are turning their attention towards employees of IT companies, using them as entry points into the company’s own infrastructure.

IT staffers receive an average of 40 targeted phishing attacks every year, according to a July 2021 report by cybersecurity firm Barracuda Networks. The company analyzed more than 12 million phishing and social engineering attacks impacting more than 3 million mailboxes at 17,000 organizations, between May 2020 and June 2021.

Phishing attacks are cybercrimes where an attacker tries to coerce the victim to visit malicious links, which can then be used to install malware on their devices. They are usually carried out using emails, text messages, or even phone calls. Social engineering, on the other hand, involves the psychological manipulation of a victim to trick them into giving away sensitive information.

The report said that old methodologies of email protection that relied on rules, policies, allow or block lists, signatures, and other attributes of traditional email security are no longer effective against the growing threat of socially-engineered attacks.

The average organization is hit by 700 social engineering attacks every year and one out of every 10 such attempts is aimed at compromising business emails, according to Barracuda’s report.

Attackers can target employees outside of the finance and executive teams to find the “weak links” in an organization, said Don MacLennan, senior vice president, engineering and product management, email protection at Barracuda. “Targeting lower-level employees offers them (cybercriminals) a way to get in the door and then work their way up to higher value targets. That’s why it’s important to make sure you have protection and training for all employees, not just focus on the ones you think are the most likely to be attacked,” he said.

“The rapid shift to remote work witnessed a tremendous disruption of security programs,” according to Prashant Bhatkal, security software sales leader, IBM technology sales.

Organizations were focused on bringing their business online, making security an “afterthought”, which led to a “record high” in data breaches in India during the pandemic, Bhatkal said.

To their credit, organizations are taking the matter of security seriously. “Securing identities has become a core tenet of security, as identities can create walled gardens in the face of fading organizational perimeters and increasing workforce mobility. So, it helps in establishing a digital trust with your employees, your customers, partners, and vendors,” said Gurpal Singh, associate research manager at International Data Corporation (IDC), a market research firm.

Subscribe to Mint Newsletters

* Enter a valid email

* Thank you for subscribing to our newsletter.

Never miss a story! Stay connected and informed with Mint.
Download
our App Now!!

Stay connected with us on social media platform for instant update click here to join our  Twitter, & Facebook

We are now on Telegram. Click here to join our channel (@TechiUpdate) and stay updated with the latest Technology headlines.

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! TechiLive.in is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – [email protected]. The content will be deleted within 24 hours.