IBM X-Force: Financial Services Most Targeted By Cybercriminals in 2016

IBM X-Force: Financial Services Most Targeted By Cybercriminals in 2016
27.04.2017 11:30 am

IBM X-Force: Financial Services Most Targeted By Cybercriminals in 2016

Security

 IBM Security today announced research from its IBM X-Force Research team which revealed the financial services industry was attacked more than any other industry in 2016 – 65 percent more than the average organization across all industries. 

As a result, the number of financial services records breached skyrocketed 937 percent in 2016 to more than 200 million. While the financial services industry was targeted the most by cyber-attacks in 2016, data from the IBM X-Force Threat Intelligence Index shows it ranked third by industry for the number of breached records - likely due to investments in security practices.

The financial gains associated with corporate and customer data available throughout the financial sector proved appetizing to cybercriminals in 2016. Financial institutions were forced to defend against a 29 percent increase in the number of attacks from 2015. Interestingly, in 2016, cybercriminals were able to steal significantly more records with a flat year-over-year number of publicly disclosed incidents tracked by IBM X-Force. 

"Cybercriminals have always gone where there is money to be made. While financial services has been a highly targeted industry by cybercriminals, in previous years, their main focus shifted to other more lucrative industries like healthcare or retail," said Nick Bradley, Practice Lead, IBM X-Force Threat Research. "However, in 2016 we saw a significant resurgence to financial services as criminals decided to go directly to the source money." 

Insiders Pose Largest Threat to Financial Services
In looking at ways the financial services sector was attacked in 2016, the report found that the industry was more affected by insider attacks (58 percent) than outsider attacks (42 percent). This shows the genesis of many of the breaches were a result of malicious activity.

Malicious activity inside an organization can be a result of an inadvertent act (53 percent) such as an employee accidentally being tricked to download a malware-laden document through a phishing email which then gives attackers access to information. Many of these attacks occur without the user being aware of it.

Financial Malware Continues to Thrive
IBM X-Force found that some countries experienced a marked increase in financial cybercrime in 2016. Cybercriminals sharpened their focus on business bank accounts by using malware such as Dridex, Neverquest, GozNym and TrickBot to target business banking services. Given the better defenses at large financial institutions, IBM X-Force researchers recently identified TrickBot malware campaigns targeting the less common brands in the industry, like private banks, wealth management,  and high value account types, indicating this ambitious malware gang plans on attacking in new territory.

Mitigating Risk
As cybercriminals continue to pivot and identify lucrative tactics to steal valuable information, IBM X-Force experts recommend the following tips to protect financial services organizations from attacks: 

  • Conduct Employee Awareness Training: Continuously train and test employees to teach them how to identify suspicious emails to avoid falling victim to phishing scams.
  • Reduce Exposure to Insider Threats: Combine data security and identity and access management solutions to protect sensitive data and govern the access of all legitimate users.
  • Apply a Cognitive Approach: Augment a security analyst's ability to identify and understand sophisticated threats by tapping into unlimited amounts of unstructured data from blogs, websites, research papers and the like, and correlating it with relevant security incidents.
  • Develop and Implement an Incident Response Plan: Identify the data necessary to respond to an attack, understand how to mitigate an attacker's access.

Related News

Experian Unveils Breakthrough Solution in the Fight Against Synthetic Identity Fraud

To combat a growing threat that’s expected to drive $48 billion in annual online payment fraud losses by 2023,1 Experian® today announced the launch of Sure Profile™. Experian... Read more »

Kompli-Global and Yoti team up to tackle fraudsters and money launderers with verified identities

Kompli-Global, the leading RegTech AML specialist, has formed a strategic partnership... Read more »

Koine signs international Joint Venture to deliver post-trade solutions to traditional exchanges and digital securities trading venues

Koine, the provider of segregated, institutional custody and settlement services for digital assets, has announced a joint... Read more »

Arcserve and Sophos Deepen Alliance to Unveil Fully Integrated Cyber and Data Protection for On-Premises, Cloud, and SaaS Workloads

Arcserve, LLC, the world’s most experienced data and ransomware protection provider, today... Read more »

Chargebacks911 launches Digital Chargeback University Educational Series

Chargebacks911, a dispute management specialist, announced dates for the first set of... Read more »

Paymentology introduces new card scoring model

Cloud based payment processor Paymentology has launched its new Instream Fraud Scoring model which aims to improve the identification and blocking of... Read more »

Magazine
ALL
Free Newsletter Sign-up
+44 (0) 208 819 32 53 +44 (0) 173 261 71 47
Download Our Mobile App
Financial It Youtube channel