News reports increasingly feature businesses that have been hacked*, had data stolen or had their operations brought to a standstill by ransomware. The existence of these risks is clear, but what are cybercriminals trying to achieve and how do they do it? More importantly, how can you use this knowledge to avoid becoming their next victim?
“All the software we use consists of tens of thousands of lines of code. These inevitably contain dozens, or perhaps hundreds, of errors. Hackers use automated scripts to find and exploit these vulnerabilities.”
Jan Jaarsma, founder of SBL Cyber Monitoring
The days when hackers attacked companies for ideological reasons, excitement or recognition of their hacking skills are largely over. Today, the ultimate objective is usually financial gain.
Hackers are no longer necessarily individuals working alone from an attic while wearing a hoodie. In some cases, we are dealing with organised groups that operate cybercrime as a business and are based in countries where prosecution is difficult.
Their business models involve different activities that often pursue the same objective:
Cybercriminals continuously attempt to gain access to corporate IT environments. They use automated scripts to scan internet-facing servers for known vulnerabilities. For example, if a vulnerability is discovered in Apache server software, attackers can use automated tools to search the internet for vulnerable systems.
Once access has been gained, attackers may download data stored on the server. This can include sensitive information such as payroll records or lists of email addresses.
Another method is to use stolen credentials to access systems such as Microsoft 365. Many people reuse the same password across different services. When credentials are stolen from one online platform, cybercriminals test them against other important systems. They then try to move as widely as possible through the IT network. When ransomware is eventually deployed, they may also attempt to block access to backups.
Phishing emails are among the best-known methods used to gain access to IT systems. The recipient is encouraged to open a malicious attachment or visit a fraudulent website, which may result in malware or ransomware being installed on the device.
Security solutions such as Microsoft Defender can detect and block many of these attacks. However, phishing techniques and malicious files continuously change, which means some attacks may evade existing security controls.
Smaller-scale scams are often similar to phishing attacks. Examples include fraudulent emails that appear to come from a CEO or supplier. The sender’s email address or the wording of the message may reveal that it is fraudulent, but recipients must remain alert. Attacks in which criminals impersonate senior executives are commonly referred to as CEO fraud or business email compromise.
Some criminals develop software that automatically scans servers for known vulnerabilities and missing security updates. They then sell these tools or services to other criminal organisations. Some ransomware groups operate so professionally that they even provide support to victims during cryptocurrency ransom payments.
The potential consequences include reputational damage, financial losses caused by production downtime and the theft of technologies or trade secrets.
It is impossible to protect an IT environment against every possible threat. Cybercriminals monitor newly discovered vulnerabilities and use automated tools to scan organisations from the outside.
Although you cannot eliminate every risk, you can make it considerably more difficult for attackers to gain access:
“The most common alerts we see at SBL Cyber Monitoring are related to systems that have not been updated on time. Many of these cyber risks can therefore be prevented.”
Jan Jaarsma, founder of SBL Cyber Monitoring
Cyber risks are a growing concern for businesses, while cybercriminals are using increasingly sophisticated methods to gain access to sensitive information. Although it is impossible to protect an IT or operational environment against every threat, organisations can take effective measures to reduce the likelihood and impact of a successful attack.
Simplifying the IT infrastructure, installing security updates promptly, implementing multi-factor authentication and improving employee awareness are essential steps towards strengthening an organisation’s protection against cyberattacks.
Would you like an external specialist to assess your organisation’s cyber resilience? Our experts can work with you and your team to conduct an assessment and discuss security measures tailored to your organisation.
* A hacker is someone with advanced computer skills who can manipulate systems. These skills can be used for legitimate purposes, as with ethical hackers, or for criminal activities. Although “cybercriminal” is the more precise term for someone carrying out illegal activities, this article occasionally uses both terms. This reflects common usage, in which hacking is often associated with cybercrime despite the broader meaning of the word.