SAN FRANCISCO – If there's a clear trend in the cybersecurity IT space in 2024, it's that the speed and agility of attackers has taken a major leap forward and that a shift in their attention to enterprises has moved from data extortion to services revenue streams. Ransomware is still a problem, but that's small potatoes compared to the big-time fraud and theft now happening in business circles.

Fortinet released its FortiGuard Labs Global Threat Landscape Report 2H 2023 at the RSAC 2024. One of the key takeaways was that attacks are being enacted faster and more tactically than in past years.

On average in the second half of 2023, attacks started 4.76 days after new exploits were publicly disclosed — 43% faster than the first half of the year report indicated. This is largely because the attacks are quickly becoming more corporate in nature, with more people being hired by hackers to do the dirty work.

“That's, unfortunately, the result of years of profiting by cybercriminals. They can afford to pay more people now. They have more sophisticated tools at hand,” Derek Manky, chief security strategist and global VP of threat intelligence at Fortinet, told SDxCentral.

“The vast majority of the attacks we're seeing are cyber-related and financially motivated. This is a criminal enterprise. It's not the teenage hacker in the basement. There's an average north of 50 people in one of these organizations; they're doing penetration of systems and money laundering, crypto departments, all of that. These people are distributed everywhere,” he said.

This is an enterprise-type effort, but most hackers work from home and collaborate on the dark web, Manky added.

Bad actors become much more selective

What stood out in the report is the attackers becoming much more selective on the target.

“So what that means is we actually saw a decline in volume, which you might think, 'Well, that's a good thing,' but it's not because they're actually just shifting the goalposts and becoming more targeted now into large enterprise operational technology,” Manky said.

That's the hot new target: operational technology. So what are the bad actors getting out of it?

“We've seen this in the past with ransomware as an example: from extortion, to double extortion, to triple extortion, and threatening to release things like intellectual property source code online unless they pay ransom,” Manky said. “It's shifted now from data [to IP]. And with this targeted nature, they're going after services in revenue streams.”

“Going back to the targets we're seeing in the report, 44% of all global ransomware now is OT-targeted. And if we look at OT specifically, manufacturing is No. 1,” he said.

In their playbooks, Manky said, hackers will perform a denial of service — either locking up systems or taking down a network — that's going to translate to X amount of dollars of lost revenue for the victim enterprise. They negotiate such a data stoppage as all part of their supply chain extortion.

“So that's what I mean about volumes dropping but that the risk is actually increasing,” he said.

Fortinet research finding highlights

Fortinet's Global Threat Landscape Report also provides insight into the ransomware targets, vulnerability exploitation, and discourse between threat actors on dark web forums, marketplaces, Telegram channels and other sources.

The findings include the following:

  • 44% of all ransomware and wiper samples targeted the industrial sectors: Across all of Fortinet’s sensors, ransomware detections dropped by 70% compared to the first half of 2023. The observed slowdown in ransomware over the last year can best be attributed to attackers shifting away from the traditional “spray and pray” strategy to more of a targeted approach, aimed largely at the energy, healthcare, manufacturing, transportation, logistics and automotive industries.
  • Fortinet telemetry found that 41% of organizations detected exploits from signatures less than one month old and nearly every organization (98%) detected N-day vulnerabilities that have existed for at least five years.
  • Dark Web Insights: Threat actors discussed targeting organizations within the finance industry most often, followed by the business services and education sectors. More than 3,000 data breaches were shared on prominent dark web forums. More than 850,000 payment cards were advertised for sale.