3.3 billion – that's how much personal information ended up on the black market over 12 months.
This is the result of attacks and data leaks at large internet companies such as Yahoo, LinkedIn and mySpace. In direct phishing breaches, 12 million records were stolen, and with the help of key-loggers, criminals managed to obtain 788,000 pieces of personal data.
The Scale of Cybercrime
The analysis carried out by the internet giant in cooperation with the University of California clearly shows the scale of cybercriminal activity. It was conducted using a system that automatically searches both public websites and those available only on the so-called Darknet, looking for stolen personal data.
230,000 logins and passwords per week
Between March 2016 and March 2017, cybercriminals obtained 15,000 personal records and 234,000 logins and passwords for internet services every week through phishing. These include, among others, email passwords stolen through key-logging, a technique that allows the interception of keyboard events on a device infected by a cracker.
– The results of the study make it clear that despite cybercriminals' unwavering interest in the data of individual users, their main target remains large companies and organizations that accumulate huge amounts of records containing personal data. This is hardly surprising – companies usually store a lot of data about employees or contractors, such as addresses, phone numbers, credit card or bank account numbers, and sometimes even medical data. This attracts crackers, because the more multi-element a record they manage to obtain, the greater its value on the black market. A payment card number alone is worth about $5, and together with its assigned email address its price increases fivefold. Each additional piece of information linked to a given record further raises its value – points out Adam Dzielnicki of Atman, the leader of the Polish data center market.
Mobile users also in the crosshairs
Attacks on Mobile Devices
Cybercriminals are also aware of the increasingly frequent use of private mobile devices for business purposes. Recognizing the growth of the BYOD trend, they try to infect not only laptops and desktops, but also mobile phones.
According to Google's analysis, 82% of phishing tools tried to obtain IP addresses and the current location of mobile devices. 18% of malicious software was aimed at obtaining phone numbers, as well as their brands and models.
An Impulse for Change
Google, as befits one of the largest representatives of the global internet economy, did not remain indifferent to the findings of the analysis, which strongly capture the imagination. The company admitted that thanks to them, it was able to improve its security measures and thereby protect 67 million email accounts from data theft in the near future. – Google's example shows that even the largest giants need systematic fixes and sealing of their infrastructure against the designs of cybercriminals. These actions take on particular importance today, when companies face the challenges related to GDPR, the new personal data protection regulations – points out Adam Dzielnicki of Atman.
According to him, a good practice that reduces the risk of data leaks in companies is combining systematic employee training with regular penetration tests and hardening of IT system vulnerabilities (so-called hardening).
– Training on the methods used by crackers is essential, because experience shows that humans are often the weakest link in the area of security. In turn, pentests make it possible to detect weak points in IT infrastructure and indicate critical elements that require sealing or updating – adds Adam Dzielnicki of Atman.