Cloud misconfigurations continue to plague businesses, according to IBM Security’s "2020 X-Force Threat Intelligence Index." The company’s threat hunting team found that of the more than 8.5 billion records breached in 2019, 7 billion of those, or 86%, were due to misconfigured cloud servers and other improperly configured systems. For comparison, the 2018 report saw a 52% decrease from 2017 in records exposed because of misconfigurations.
In the annual report, IBM’s X-Force Incident Response and Intelligence Services (IRIS) compiles IBM Security software and security services analyses from the past year. It found that 2019 was a year of reemerging old threats being used in new ways.
It’s worth noting that the most recent index did see a slight year-over-year decrease (14%) in the number of misconfiguration incidents in 2019. What this means, according to X-Force, is that when a misconfiguration breach did occur, the number of records affected was significantly greater in 2019 compared to the year before.
Mistakes Lead to BreachesNearly three-quarters of the 2019 breaches where there were more than 100 million records breached were misconfiguration incidents. And in two of those misconfiguration incidents — both occurred in the professional services sector — the exposed record count was in the billions for each.
These misconfiguration statistics highlights a common theme across the report, said Nick Rossmann, research lead for IBM X-Force IRIS. “In many of the circumstances we’ve seen in 2019 that became public, it was inadvertent mistakes in your security environment that can lead to bigger errors,” he said.
In fact, 60% of initial entries into victims’ networks used either previously stolen credentials or known software vulnerabilities, allowing attackers to rely less on deception to gain access, according to the 2020 Index. As a consequence, phishing was a successful initial infection vector in less than one-third of incidents (31%), compared to half in 2018.
Attackers Invest in RansomwareHowever, one new-ish threat did emerge, Rossmann said. “Innovation with ransomware,” he said.
Ransomware attacks cost organizations more than $7.5 billion in 2019. Working in collaboration with security partner Intezer, X-Force observed new malware code in 45% of banking trojans code and 36% of ransomware code, Rossmann said. This suggest that by creating new code attackers are continuing to invest in efforts to avoid detection.
Additionally, ransomware attacks last year targeted both the public and private sectors, and IBM X-Force deployed its incident response team to ransomware incidents in 13 different industries worldwide, Rossmann added. In addition to the 100-plus U.S. government entities hit by ransomware attacks in 2019, IBM X-Force also saw significant attacks against retail, manufacturing, and transportation. These particular sectors are known to either hold a surplus of monetizable data or rely on outdated technology and, thus, be more vulnerable. The report noted that in 80% of observed ransomware attempts, attackers were exploiting Windows Server Message Block vulnerabilities — the same tactic used to spread WannaCry, which devastated businesses across 150 countries in 2017.
Spoofing Tech BrandsSuccessful phishing attacks were slightly down last year and accounted for 31% of incidents observed compared to half in 2018. But, as people become more cognizant of phishing emails, attackers are getting smarter. IBM worked with Quad9 on this piece of the report, and the vendors noted a trend were attackers impersonate consumer tech brands to trick users into clicking malicious links.
Alphabet domains topped the 10 most spoofed brands list. Google remained by far the most spoofed brand (39%) with YouTube (17%) in second. Meanwhile, Apple (15%), Amazon (12%), and Spotif (5%) rounded out the top five. “A big part of the modern consumer landscape are big tech companies, and it shows the value of them in phishing attempts — and how the bad guys are exploiting this,” Rossmann said.
Comments