2022년 8월 29일
보도자료

Acronis’ Mid-Year Cyberthreats Report Finds Ransomware is the Number-One Threat to Organizations, Projects Damages to exceed $30 Billion by 2023

다른 언어
English

Increasing complexity in IT continues to lead to breaches and compromises highlighting the need for more holistic approaches to Cyber Protection

SCHAFFHAUSEN, Switzerland, August 24, 2022 - Today, Acronis, a global leader in cyber protection, unveiled its mid-year cyberthreats report, conducted by Acronis' Cyber Protection Operation Centers, to provide an in-depth review of the cyberthreat trends the company's experts are tracking. The report details how ransomware continues to be the number one threat to large and medium-sized businesses, including government organizations, and underlines how over-complexity in IT and infrastructure leads to increased attacks. Nearly half of all reported breaches during the first half of 2022 involved stolen credentials, which enable phishing and ransomware campaigns. Findings underscore the need for more holistic approaches to cybersecurity.

To extract credentials and other sensitive information, cybercriminals use phishing and malicious emails as their preferred infection vectors. Nearly one percent of all emails contain malicious links or files, and more than one-quarter (26.5%) of all emails were delivered to the user's inbox (not blocked by Microsoft365) and then were removed by Acronis email security.

Moreover, the research reveals how cybercriminals also use malware and target unpatched software vulnerabilities to extract data and hold organizations hostage. Further complicating the cybersecurity threat landscape is the proliferation of attacks on non-traditional entry avenues. Attackers have made cryptocurrencies and decentralized finance systems a priority of late. Successful breaches using these various routes have resulted in the loss of billions of dollars and terabytes of exposed data.

These attacks are able to be launched due to overcomplexity in IT, a common problem throughout businesses as many tech leaders assume more vendors and programs lead to improved security when the inverse is actually true. Increased complexity exposes more surface area and gaps to potential attackers, keeping organizations vulnerable to potentially devastating damage.

"Today's cyberthreats are constantly evolving and evading traditional security measures," said Candid Wüest, Acronis VP of Cyber Protection Research. "Organizations of all sizes need a holistic approach to cybersecurity that integrates everything from anti-malware to email-security and vulnerability-assessment capabilities. Cybercriminals are becoming too sophisticated and the results of attacks too dire to leave it to single-layered approaches and point solutions."

Critical data points reveal complex threat landscape

As reliance on the cloud increases, attackers have homed in on different entryways to cloud-based networks. Cybercriminals increased their focus on Linux operating systems and managed service providers (MSPs) and their network of SMB customers. The threat landscape is shifting, and companies must keep pace.

Ransomware is worsening, even more so than we predicted.

  • Ransomware gangs, like Conti and Lapsus$, are inflicting serious damage.
  • The Conti gang demanded $10 million in ransom from the Costa Rican government and has published much of the 672 GB of data it stole.
  • Lapsus$ stole 1 TB of data and leaked credentials of over 70,000 NVIDIA users. The same gang also stole 30 GB worth of T-Mobile's source code.
  • The U.S. Department of State is concerned, offering up to $15 million for information about the leadership and co-conspirators of Conti.

The use of phishing, malicious emails and websites, and malware continues to grow.

  • Six hundred malicious email campaigns made their way across the internet in the first half of 2022.
  • 58% of the emails were phishing attempts.
  • Another 28% of those emails featured malware.
  • The business world is increasingly distributed, and in Q2 2022, an average of 8.3% of endpoints tried to access malicious URLs.

More cybercriminals are focusing on cryptocurrencies and decentralized finance (DeFi) platforms. By exploiting flaws in smart contracts or stealing recovery phrases and passwords with malware or phishing attempts, hackers have wormed their way into crypto wallets and exchanges alike.

  • Cyberattacks have contributed to a loss of more than $60 billion in DeFi currency since 2012.
  • $44 billion of that vanished during the last 12 months.

Unpatched vulnerabilities of exposed services is another common infection vector-just ask Kaseya. To that end, companies like Microsoft, Google, and Adobe have emphasized software patches and transparency around publicly submitted vulnerabilities. These patches likely helped stem the tide of 79 new exploits each month. Unpatched vulnerabilities also tie into how overcomplexity is hurting businesses more than helping, as all of these vulnerabilities serve as additional potential points of failure.

Breaches leave financial, SLA distress in their wake

Cybercriminals often demand ransoms or outright steal funds from their targets. But companies do not suffer challenges only to their bottom lines. Attacks often cause downtime and other service-level breaches, impacting a company's reputation and customer experience.

  • In 2021 alone, the FBI attributed a total loss of $2.4 billion to business email compromise (BEC).
  • Cyberattacks caused more than one-third (36%) of downtime in 2021.

The current cybersecurity threat landscape requires a multi-layered solution that combines anti-malware, EDR, DLP, email security, vulnerability assessment, patch management, RMM, and backup capabilities all in one place. The integration of these various components gives companies a better chance of avoiding cyberattacks, mitigating the damage of successful attacks, and retaining data that might have been altered or stolen in the process.

You can download a copy of the full Acronis Mid-Year Cyberthreats Report 2022 here.


아크로니스 소개:

아크로니스는 관리형 서비스 제공업체(MSP), 중소기업(SMB) 및 기업 IT 부서에게 기본적으로 통합된 사이버 보안, 데이터 보호 및 엔드포인트 관리 기능을 제공하는 글로벌 사이버 보안 회사입니다. 아크로니스 솔루션은 매우 효율적이며 최신 사이버 위협을 식별, 예방, 탐지, 대응, 해결 및 복구하여 다운타임을 최소화하도록 설계되어 데이터 무결성과 비즈니스 연속성을 보장합니다. 아크로니스는 다양하고 분산된 IT 환경의 요구 사항을 충족할 수 있는 고유한 기술을 바탕으로 MSP에 시장에서 가장 종합적인 보안 솔루션을 제공합니다.

2003년 싱가포르에서 설립된 스위스 회사인 아크로니스는 전 세계에 15개의 지사를 두고 있으며 50개 이상의 국가에 직원을 두고 있습니다. Acronis Cyber Protect는 150개국에서 26가지 언어로 제공되며 20,000개 이상의 서비스 제공업체가 750,000개 이상의 비즈니스를 보호하는 데 사용하고 있습니다. www.acronis.com에서 자세히 알아보세요.
홍보 연락처:
Katya Turtseva
커뮤니케이션 VP