Skip to content
Search AI Powered

Latest Stories

Median ransomware payment doubles to $26,000, Verizon says

Hackers launched more ransomware attacks on companies in the last two years than the previous 5 years combined, study finds.

verizon Screen Shot 2023-06-09 at 3.10.16 PM.png

Businesses are paying out soaring sums to retrieve their data after hackers encrypt their accounts, according to a report released this week by Verizon Business, the enterprise solutions division of the wireless data network provider.

The damage is caused by ransomware, which is malicious software (also known as malware) that encrypts an organization’s data and then extorts large sums of money to restore access, the Basking Ridge, New Jersey-based company said. That conclusion came from Verizon’s 16th annual Data Breach Investigations Report (2023 DBIR), which analyzed 16,312 security incidents and 5,199 breaches.


Ransomware remains one of the top cyberattack methods, representing almost a quarter of all breaches (24%). It has seen a dramatic rise in frequency over the past couple of years when the number of ransomware attacks was greater than the previous five years combined, Verizon said.

Part of the reason that ransomware is so popular with hackers is that it’s effective: The median cost per ransomware incident more than doubled over the past two years to $26,000.

In the overwhelming majority (74%) of incidents, hackers gain access to companies’ files through the human element, even as enterprises continue to safeguard critical infrastructure and increase training on cybersecurity protocols. One of the most common ways to exploit human nature is social engineering, which refers to manipulating an organization's sensitive information through tactics like phishing, in which a hacker convinces the user into clicking on a malicious link or attachment.

Executives are particularly vulnerable. “Senior leadership represents a growing cybersecurity threat for many organizations,” Chris Novak, managing director of Cybersecurity Consulting at Verizon Business, said in a release. “Not only do they possess an organization’s most sensitive information, they are often among the least protected, as many organizations make security protocol exceptions for them. With the growth and increasing sophistication of social engineering, organizations must enhance the protection of their senior leadership now to avoid expensive system intrusions.”

Another lucrative tactic for cybercriminals is social engineering, when attackers impersonate enterprise employees for financial gain, a method known as Business Email Compromise (BEC). The approach is especially effective when applied to businesses with distributed workforces, since they are challenged to create and strictly enforce human-centric security best practices for their remote employees. The median amount stolen in BECs has increased over the last couple of years to $50,000, based on Internet Crime Complaint Center (IC3) data.

And that trend might have contributed to a near doubling this past year of “pretexting,” an invented scenario that tricks someone into giving up information or committing an act that may result in a breach, Verizon said.

In other findings, the report found:

  • espionage garners substantial media attention, but only 3% of threat actors were motivated by espionage; the other 97% were motivated by financial gain. 
  • hackers tend to use new techniques soon after vulnerabilities are discovered. For example, 32% of yearly Log4j vulnerability scanning occurred in the first 30 days after its release, demonstrating threat actors’ velocity when escalating from a proof of concept to mass exploitation.
  • hackers use a variety of different techniques to gain entry to an organization, such as using stolen credentials (49%), phishing (12%), and exploiting vulnerabilities (5%).

 Finally, the report concluded that enterprises can help safeguard their critical infrastructure by adopting industry leading protocols and practices. For example, Verizon recently became the first nationwide telecom provider to become a participant of Mutually Agreed Norms for Routing Security (MANRS), a global initiative that provides crucial fixes to reduce the most common routing threats that can be exploited by attackers.

 

 

The Latest

More Stories

Image of earth made of sculpted paper, surrounded by trees and green

Creating a sustainability roadmap for the apparel industry: interview with Michael Sadowski

Michael Sadowski
Michael Sadowski

Most of the apparel sold in North America is manufactured in Asia, meaning the finished goods travel long distances to reach end markets, with all the associated greenhouse gas emissions. On top of that, apparel manufacturing itself requires a significant amount of energy, water, and raw materials like cotton. Overall, the production of apparel is responsible for about 2% of the world’s total greenhouse gas emissions, according to a report titled

Taking Stock of Progress Against the Roadmap to Net Zeroby the Apparel Impact Institute. Founded in 2017, the Apparel Impact Institute is an organization dedicated to identifying, funding, and then scaling solutions aimed at reducing the carbon emissions and other environmental impacts of the apparel and textile industries.

Keep ReadingShow less

Featured

xeneta air-freight.jpeg

Air cargo carriers enjoy 24% rise in average spot rates

The global air cargo market’s hot summer of double-digit demand growth continued in August with average spot rates showing their largest year-on-year jump with a 24% increase, according to the latest weekly analysis by Xeneta.

Xeneta cited two reasons to explain the increase. First, Global average air cargo spot rates reached $2.68 per kg in August due to continuing supply and demand imbalance. That came as August's global cargo supply grew at its slowest ratio in 2024 to-date at 2% year-on-year, while global cargo demand continued its double-digit growth, rising +11%.

Keep ReadingShow less
littler Screenshot 2024-09-04 at 2.59.02 PM.png

Congressional gridlock and election outcomes complicate search for labor

Worker shortages remain a persistent challenge for U.S. employers, even as labor force participation for prime-age workers continues to increase, according to an industry report from labor law firm Littler Mendelson P.C.

The report cites data showing that there are approximately 1.7 million workers missing from the post-pandemic workforce and that 38% of small firms are unable to fill open positions. At the same time, the “skills gap” in the workforce is accelerating as automation and AI create significant shifts in how work is performed.

Keep ReadingShow less
stax PR_13August2024-NEW.jpg

Toyota picks vendor to control smokestack emissions from its ro-ro ships

Stax Engineering, the venture-backed startup that provides smokestack emissions reduction services for maritime ships, will service all vessels from Toyota Motor North America Inc. visiting the Toyota Berth at the Port of Long Beach, according to a new five-year deal announced today.

Beginning in 2025 to coincide with new California Air Resources Board (CARB) standards, STAX will become the first and only emissions control provider to service roll-on/roll-off (ro-ros) vessels in the state of California, the company said.

Keep ReadingShow less
trucker premium_photo-1670650045209-54756fb80f7f.jpeg

ATA survey: Truckload drivers earn median salary of $76,420

Truckload drivers in the U.S. earned a median annual amount of $76,420 in 2023, posting an increase of 10% over the last survey, done two years ago, according to an industry survey from the fleet owners’ trade group American Trucking Associations (ATA).

That result showed that driver wages across the industry continue to increase post-pandemic, despite a challenging freight market for motor carriers. The data comes from ATA’s “Driver Compensation Study,” which asked 120 fleets, more than 150,000 employee drivers, and 14,000 independent contractors about their wage and benefit information.

Keep ReadingShow less