The number of recorded business email compromise (BEC) attacks has doubled over the past year, and the threat accounts for nearly 60% of the social engineering incidents investigated by Verizon. 2023 Data Breach Investigation Report.
This year’s much-anticipated annual report is based on an analysis of 16,312 security incidents and 5,199 breaches over the past year.
The “pretexting” (BEC) category is now more common than phishing in social engineering incidents, but the latter remains more prevalent in breaches, the report notes. Currently, the median amount stolen in pretext attacks has reached $50,000.
Read more about BEC: BEC attacks to surge 81% in 2022
The success of these social engineering tactics is also a big reason why 74% of breaches now have a human element, according to the report.
Chris Novak, managing director of cybersecurity consulting at Verizon Business, argued that senior executives are particularly exposed to social engineering.
“These information not only possess the most sensitive information of an organization, but are often the least protected as many organizations make exceptions to their security protocols,” he said. added.
“As social engineering grows and becomes more sophisticated, organizations must better protect senior leaders to avoid costly system intrusions.”
Elsewhere, Verizon revealed that ransomware was responsible for a quarter (24%) of breaches, only a slight increase from last year’s report. However, the median cost per incident doubled from last year to this year, with 95% of costly ransomware incidents costing between $1 million and $2.25 million.
While email, desktop sharing software, and web applications remain the main vectors for ransomware attacks, credential theft (49%), phishing (12%), and vulnerability exploitation (5%) are the top threats. It has become the primary means by which actors infiltrate organizations.
Regarding the latter, Log4j bugs had an immediate and significant impact on the threat landscape, with the third (32%) of vulnerability scans for this utility occurring in the first 30 days after going public.
Verizon argued that this highlights how quickly threat actors can move from proof-of-concept to large-scale exploitation.
According to Verizon, the majority (97%) of attacks in the past year were motivated by financial gain rather than espionage.
Editorial image credit: JHVEPhoto / Shutterstock.com