The pandemic years showed us in an unprecedented way how quickly we can develop new technologies and use them to navigate a changing everyday reality. The internet tools that enabled remote work and entertainment also became a gateway for cybercriminals. The same could happen with the rapidly developing AI technology. Where will hackers look for opportunities for their malicious activities in 2023?
2023 will certainly bring further changes to how we function online, both professionally and in our personal lives. The boundaries between the physical and virtual worlds will continue to blur. Cybersecurity experts will have to deal with the consequences of these changes across the entire IT ecosystem, especially within cloud-based applications, to which we are increasingly entrusting our entertainment, professional, and private lives.
Cloud-based environments have enormous potential and will continue to help millions of users create, store, and share vast amounts of personal data and intellectual property. However, this goldmine of information attracts not only ordinary users and companies but also cybercriminals.
So what will 2023 look like online? This question is answered by ESET experts, who predict three trends within which hackers may seek new attack opportunities:
TREND 1 – Entertainment: Gamers as a New Target
Alongside the growing popularity of social apps, there has been significant growth in gaming platforms. This new branch of the economy – digital entertainment – is expanding worldwide. For Generation Z, gaming and spending time together in a virtual world has become a new way to connect with peers. Online games also draw in older generations. Millions of players are part of this brave new world of digital possibilities and risks every day.
Gamers Under Fire
A new trend that will be observed in 2023 is an increase in attacks on users of gaming services. As a given service, game, or other digital platform grows in popularity, new types of attacks emerge. It is increasingly common for players who want to rank among the best to use cheating programs. Game developers deploy protections against such practices, known as "anti-cheat" software. Penalties for cheaters are severe – from temporary account bans to permanent removal from the game. Cybercriminals often exploit players' desire to cheat by creating malware bundled with cheating programs, thereby gaining access to users' computers. If more than one person uses a given computer, all users are exposed to data theft.
TREND 2 – The Blurring Line Between Business and Pleasure
Work and Personal Life Combined
In recent years, as hybrid work became the norm, platforms created for business purposes began taking on a social role. The reverse process also occurred. Social media opened up to business, driving the growing popularity of e.g. social selling. Professional networking, finding new clients, hiring, and job hunting are now sometimes done even via dating apps.
Cyber World Trends and Challenges in 2023 – Expert Summary
Using apps in such diverse ways may seem like a creative solution, but it carries very real and serious risks. Using work devices and services for personal purposes can expose us to significant problems. Falling for phishing on any messaging platform can result in downloading malware that steals both personal and work messages.
In this situation, if employers expect employees to be constantly available, they must introduce clear rules separating private and professional spheres. This means providing employees with devices dedicated to work – not just laptops, but also smartphones – and clearly defining the rules for using company resources, for example when working remotely via home infrastructure.
TREND 3 – AI in the Service of Cybercriminals
AI as a Criminal Tool
Artificial intelligence is a tool that will certainly develop dynamically in the near future. Solutions based on it offer many benefits, such as more accessible and faster customer service, easier searching for product information, or faster problem-solving. The goal of AI solution designers is to make interaction with artificial intelligence as indistinguishable as possible from a conversation with a real person.
Of course, AI also brings a range of threats we will need to prepare for. Already, new technologies can generate images of people who don't exist or write texts that sound exactly like statements from real people. Cybercriminals can be expected to exploit this before long.
Creating a fake person who looks real and chats with a user – for example, on a dating site – could become one of the most effective ways to extract data that enables impersonating the victim.
– The acceleration of new technology development has also led to a leap in cybercrime. As we know from US FinCEN data, in 2021 the costs resulting from ransomware attacks amounted to $1.2 billion. It is projected that by 2031, approximately $265 billion will be spent globally on the effects of ransomware. Fortunately, cybersecurity systems are also developing systematically. However, much depends on users themselves, who should always remember basic security principles, such as limited trust online – says Beniamin Szczepankiewicz, senior cybersecurity specialist at ESET.
Combining real life with the virtual can contribute to our development, but it's worth setting limits. In life in cyberspace, just as in the real one, we must above all take care of our privacy and security.
Summary
ESET experts predict that in 2023 cybercriminals will focus on three areas: gamers, the blurring of boundaries between work and private life, and the use of artificial intelligence to create fake identities. The growth in popularity of gaming platforms goes hand in hand with new attacks, while hybrid work increases the risk of phishing on messaging platforms. AI, though developing dynamically, can be used for data extortion – an example being fake profiles on dating sites. Beniamin Szczepankiewicz from ESET cites FinCEN data: in 2021, ransomware losses amounted to $1.2 billion, and by 2031 they could reach $265 billion. User caution remains key.