The FTC advisory tracks crypto scams up to May 2022, but the losses from 2021 alone represent a 60x increase from those recorded in 2018, and over 5x the 2020 numbers.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Cyber insurance providers wants policyholders to increase their cyber resilience. A thorough incident response strategy that leverages digital forensics can help enterprises ensure they have the means to protect themselves even after an attack has occurred.
Advisory warns that state-backed Chinese hackers have deep penetration into "major" US telcos, and are getting in by compromising an assortment of networking equipment and routers.
Healthcare provider Shields Health Care Group suffered a data breach that exposed sensitive personal health information for at least 2 million patients.
The cyberattack on Colonial Pipeline was a big lesson. It is imperative that critical infrastructure companies uplevel their protection against modern security risks by using modern techniques and automation to comply with new cybersecurity regulations.
LockBit may have wanted to the hit the headlines following a Mandiant report linking them to Evil Corp, which would mean lost revenue due to US government sanctions.
EEA’s PSD2 regulation aims to protect consumers against fraud by securing the digital payments for Card Not Present (CNP) transactions. Study shows that merchants have seen some higher loss from failed and abandoned transactions than that from fraudsters.
According to Moody’s report, organizations tend to have upped their cybersecurity investments across the board, but with a strong preference for basic measures and cyber insurance.
Over the next 10 years, we will see companies continue to replace their on-premise network and security appliances with a secured corporate network over the internet. Remote access solutions like zero trust network access (ZTNA) and secure access server edge (SASE) are here to stay.
Analysis of leaked chats shows that the Russian Conti ransomware gang had developed proof-of-concept code for stealthy firmware attacks targeting Intel's Management Engine.










