CYBER SECURITY ENTHUSIAST

The cyber security industry is growing as you’re reading this. More specialists join the ranks, more malware is being launched every day than ever before. In 2015, 230,000 new malware sample were recorded daily. Naturally, more resources are being deployed to counter cyber attacks. That’s why I thought it would be helpful to sum up 10 cyber security facts that define the current information security landscape.

Don’t think that hackers are only targeting corporations, banks or wealthy celebrities. They go for individual users like you and me also.

Cost-of-Cyber-Crime-statistics 2017 ponemon accenture

Source: 2017 Cost of Cyber Crime Study: Global by Accenture and Ponemon

As long as you’re connected to the Internet, you can become a victim of cyber attacks.

So that’s why we wanted to walk you through some of the most shocking cyber security facts that you maybe wish you’d known until the present moment.

These will give you a much more accurate idea of how dangerous it really is to go online without proper protection.

 

1.The most wanted cyber criminals in the world

In 2016, there were 19 individuals on FBI’s Most Wanted List for cyber criminals you. Each of them was responsible responsible for consumer losses ranging from $350,000 to more than $100 million. In 2018, that same list has 41 cybercriminals from around the world.

most wanted cyber criminals in the world heimdal security

For example, on the list of FBI’s most wanted cyber criminals are the JABBERZEUS subjects, a group of individuals involved in a wide-ranging racketeering enterprise and scheme that installed, without authorization, malicious software known as Zeus on victims’ computers.

This type of financial malware was used to capture bank account numbers, passwords, personal identification numbers, and other confidential information necessary to log into online banking accounts.

Starting in September of 2011, the FBI began investigating a modified version of the Zeus Trojan, known as GameOver Zeus (GOZ), which we covered in depth. Thousands of corporations were infected with GameOver Zeus and as many as 1.2 million computers were infected prior to the take down of Zeus. It is believed GameOver Zeus is responsible for financial losses of more than $100 million.

How it affects you and what can you do to get protected:

  • Zero Day attacks can be powerful and very dangerous.
  • If you keep up to date with major news in the cyber security industry, it might help you identify attacks and know what to do about them.
  • Keep your software updated and take all necessary precautions to keep your financial and confidential information safe.

 

2. The most expensive computer virus of all times

 

Ever wondered how much damage a computer virus can do? Let us give you a compelling example through this next cyber security fact. MyDoom is considered to be the most expensive virus in the world and in cyber security history, having caused an estimated financial damage of $38.5 billion!

MyDoom was first spotted in January 2004 and it became the fastest-spreading email worm ever, exceeding all previous records. The virus’s origins are believed to be in Russia, but its author was never discovered.

Mydoom was mainly transmitted by email, disguised as spam email. A user might inadvertently open the attachment in the email and the worm would re-send itself to every address it could find. The original version contained a payload that did two things: it opened a backdoor into the user’s computer, allowing remote control of it, while also conducting a DDoS attack (Direct Denial Of Service) against SCO group’s website.

most expensive computer virus heimdal security


How it affects you and what can you do to get protected:

  • Viruses such as MyDoom can be extremely dangerous, because if a cyber criminal gains control over your computer, there’s no telling if and how you may regain control over your device.
  • Severe malware usually morphs and has a very low detection score, so antivirus solutions can’t detect it.
  • You need a proactive solution that can work as a supplement for your AV, scanning your Internet traffic and warning you when potential threats appear, while also blocking access to hacker controlled servers and keeping your data from leaking. We explained this in-depth here and, to put it in perspective, here is the volume of malware on a yearly basis.

malware-yearly statistic 2018

Source

3. Social media – a hackers’ favorite target

Currently, according to in depth statistics, there are more than 3 billion active social network users worldwide.

This is precisely why cyber attackers love social media as well!

Users that spend a lot of time on social networks are very likely to click links posted by trusted friends, which hackers use to their advantage. After the entire Facebook and Cambridge Analytica data breach, the threat of using social media to sway elections and the pervasiveness of political of bots should make you pause.

Here are some of the most popular types of cyber attacks directed at social media platforms:

  • Like-jacking: occurs when criminals post fake Facebook “like” buttons to webpages. Users who click the button don’t “like” the page, but instead download malware.
  • Link-jacking: this is a practice used to redirect one website’s links to another which hackers use to redirect users from trusted websites to malware infected websites that hide drive-by downloads or other types of infections.
  • Phishing: the attempt to acquire sensitive information such as usernames, passwords, and credit card details (and sometimes, indirectly, money) by disguising itself as a trustworthy entity in a Facebook message, Tweet or other social media message
  • Social spam: is unwanted spam content appearing on social networks and any website with user-generated content (comments, chat, etc.). It can appear in many forms, including bulk messages, profanity, insults, hate speech, malicious links, fraudulent reviews, fake friends, and personally identifiable information.

social media hacking heimdal security

Why are cyber attacks on social media so frequent?

Because social media users usually trust their circles of online friends. The result: more than 600.000 Facebook accounts are compromised every single day! Also, 1 in 10 social media users said they’ve been a victim of a cyber attack and the numbers are on the rise. Now this is a cyber security statistic which we don’t want you to become part of.

How it affects you and what can you do to get protected:

 

4. 99% of computers are vulnerable to exploit kits

Cyber security fact: Oracle Java, Adobe Reader or Adobe Flash is present on 99% of computers. That means that 99% of computer users are vulnerable to exploit kits (software vulnerabilities).

Why? Because the vulnerabilities that these types of software often present are extremely critical: all it takes is one click on an infected advertising banner to give a hacker full access to your computer.

99 percent of computers are vulnerable heimdal security

Adobe Flash has a huge number of vulnerabilities, so cyber criminals target it in the majority of their attacks. By using these security holes in Flash, attackers can infect your computer with ransomware, such as various CryptoLocker variants or Teslacrypt and CTB-Locker.

The rise of exploit kits-as-a-service and the increasing use of automation has led to more sophisticated and aggressive attacks. Without adequately protecting your browsers and your entire system, you’ll leave yourself vulnerable to a huge range of cyber threats.

How it affects you and what can you do to get protected:

  • Keep your software updated at all times (the experts say so, not just us) or install a solution that does that automatically and silently.
  • Keep your operating system up to date.
  • Install an AV solution and a supplement that can do what AV fails to do: protect your system proactively from cyber threats by scanning incoming and outgoing Internet traffic.

 

5. Security warning: inside jobs

Maybe you’ll be surprised to find out that a shocking 59% of employees steal proprietary corporate data when they quit or are fired. But there are more types of insider threats to get protection against:

  • Malicious insiders are the least frequent, but have the potential to cause significant damage due to their level of access. Administrators with privileged identities are especially risky. According to the Ponemon Institute, “data breaches that result from malicious attacks are most costly.”
  • Exploited insiders may be “tricked” by external parties into providing data or passwords they shouldn’t.
  • Careless insiders
  • Careless insiders may simply press the wrong key and accidentally delete or modify critical information. A badly configured Amazon S3 leaked the data of over 150.000 Americans.

cyber security insider jobs heimdal security

These types of security risks is being acknowledged by companies everywhere, and strategies are put together to mitigate them:

“Almost half of European organizations believe that insider threats are now more difficult to detect, with senior IT managers being very worried about the things their own users can do with corporate data”

said Andrew Kellett, principal analyst at Ovum.

How it affects you and what can you do to get protected:

  • If a soon-to-be-ex-colleague decides to do some damage before he/she leaves the company, make sure your work goes unaffected.
  • Be careful how you manage your passwords: use a password management application, use strong passwords and change them regularly.
  • Protect your shared documents and keep updated backups of all the information you’re working on.

 

6. Social engineering – cyber criminals’ favorite way to manipulate victims

People are the weakest link when it comes to cyber security, which is why psychological manipulation of cyber attack victims is so common.

According to the definition, social engineering, in the context of information security, refers to psychological manipulation of people into performing actions or divulging confidential information. This is a type of confidence trick for the purpose of information gathering, fraud, or system access, and the first type of attack of this kind known in history is the Trojan horse itself (not the computer virus, but the Greek mythical event).

For example, in this attack, an international cyber crime ring based out of Eastern Europe managed to steal $1 billion in 2 years from 100 different banks in nearly 30 countries using spear phishing emails targeting bank employees. The spear phishing technique is, by far, the most successful on the internet today, accounting for 91% of attacks!

social engineering cyber hacking heimdal security

How it affects you and what can you do to get protected:

  • Always check the recipient of an email and the source of a message.
  • Don’t click any strange links and know what a phishing attack looks like.
  • Don’t install software from untrusted sources.
  • Don’t trust people blindly and don’t give away confidential information to strangers.

 

7. Your government is making you more vulnerable

Cyber security fact: governments around the world are creating malware and using it as digital weapons or in espionage programs. In the past 5 years, more than a handful of government malware have been discovered (such as Stuxnet), but their origins have yet to receive full attribution. The worst of those was the leaked NSA exploit EternalBlue which lead to the spread of WannaCry, the worst ransomware attack in history. If you also look at how North Korea forces programmers into indentured servitude and has them creating ransomware, things are looking pretty grim.

Besides civilians and private organizations becoming collateral damage, there are also other severe consequences.

 

government malware heimdal security

In an article on Dark Reading, some key points are made as to how governments are making all of us more vulnerable to cyber attacks:

  • Government malware accelerates the evolution of criminal malware – cyber criminals do a lot of reverse engineering on government malware, and use its tactics and technical approach to create new, more advanced malware of their own.
  • Governments have fortified zero day vulnerability black markets – Zero Day vulnerabilities auctions have become common, but governments are buying the intelligence related to these vulnerabilities and weapon zing them, instead of disclosing them responsibly, as is the norm in the cyber security industry.
  • Governments try to restrict/backdoor/break encryption – in the name of transparency and protection against cyber criminals and terrorists, governments all over the world are trying to limit every individual’s right to encrypt confidential information. This is why “cyber policies” can do more damage than good.

changing attacker profiles

Source: McAfee Labs Threats Report, August 2015

How it affects you and what can you do to get protected:

 

8. There is a real-time map that shows cyber attacks in action

Ever wondered how cyber attacks look on a global scale? Check out this real-time map put together by Norse.

real time map of cyber attacks heimdal secuity

You might notice that the U.S. is one of the favorite targets for cyber criminals. For example, Chinese attackers alone caused more than $100 million worth of damage to U.S. Department of Defense networks according to leaked documents from Edward Snowden. Back in 2012, the same department used to suffer more than 10 million cyber attacks per day, and, given the evolution of cyber criminals, we can assume that these figures have climbed dramatically since then. For example, the U.S. Navy, which receives 110.000 cyber attacks every hour.

 

9. Hacktivism is the main motivation that drives cyber attacks

 

Hacktivism accounts for half of the cyber attacks launched in the world. The term represents a subversive use of computers and computer networks to promote a political agenda. With roots in hacker culture and hacker ethics, its ends are often related to the free speech, human rights, or freedom of information.

hacktivism statistic heimdal security

Although it may seems like the terms has a positive spin, it really depends on who is using the term. Hacktivism can be a politically motivated technology hack, a constructive form of anarchic civil disobedience, or an undefined anti-systemic gesture. It can signal anticapitalist or political protest; it can denote anti-spam activists, security experts, or open source advocate.

Hacktivists use code, website mirroring, geo-bombing and anonymous blogging to achieve their objectives, the oldest events of this type dating back to 1989. Anonymous may be the most widely known hacktivist group in the world, but there are many others that carry on cyber attacks of this kind.

How it affects you and what can you do to get protected:

  • Be careful about the websites you visit and always make sure they use the SSL security protocol.
  • Keep your passwords long, complicated, updated often and managed through dedicated app (NEVER store them in your browser).
  • Keep your system and software updated and also keep an eye out for trouble.

 

10. 68% of funds lost as a result of a cyber attack were declared unrecoverable

 

Cyber crime is not only costly, but poses other problems as well for organizations worldwide.

It’s becoming increasingly difficult to detect cyber attacks and resolve the security issues created by them: the average time to detect a malicious or criminal attack by a global study sample of organizations was 170 days (according to a research conducted by the Ponemon Institute). Moreover, no industry is safe: all business sectors are affected to a higher or lower degree.

financial losses cyber hacking heimdal security

The same research conducted by the Ponemon Institute found the average annualized cost of cyber crime incurred by a benchmark sample of U.S. organizations was $12.7 million, representing a 96% increase since the study was initiated 5 years ago.

As a result, organizations experienced a 176% increase in the number of cyber attacks, with an average of 138 successful attacks per week, compared to 50 attacks per week when the study was initially conducted in 2010.

And what’s more worrisome is that 68% of all these funds that were lost as a result of a cyber attack were never recovered and will probably never be.

How it affects you and what can you do to get protected:

  • Keep your financial information protected by using a password manager application to enter your passwords in your online banking website.
  • Be aware of phishing attempts and never give your confidential information over email or other means of electronic communication.
  • Get additional protection through software that can detect cyber threats and block them before they infect your system and leak financial data.

 

No threat is too small, no protection is too strong

 

However big or small, cyber security threats should be treated with caution. You may not be a millionaire (yet) or a C-level manager, but that doesn’t mean that you’re protected against a potential hacker attack. Don’t spare any precautions you can take and try to develop your own protection system with the tools and information you find online, such as this list of cyber security facts.

We recently published a guide to help you choose the best antivirus solution for you and there are plenty more security guides you can use to secure your social media accounts, your email, your operating system and more. Use them and navigate the web with a lot more peace of mind.

See the full infographic below:

Cyber Security Facts Infographic

Share This Infographic On Your Site

Spend time with your family, not updating their apps!
Let Heimdal FREE Silently and automatically update software Close security gaps Reinforce your antivirus of choice

INSTALL IT, FORGET IT AND BE PROTECTED

Download Heimdal FREE

*This article was initially published by Andra Zaharia in May 2016 and updated with current information in March 2018 by Ana Dascalescu.

The Hackable Human
2016.09.01 INTERMEDIATE READ

The Hackable Human – 6 Psychological Biases that Make Us Vulnerable

About the Time I Got Hacked
2016.02.10 INTERMEDIATE READ

True Story: About the Time I Got Hacked and Lost All My Work

Vulnerable Software Apps
2015.05.21 INTERMEDIATE READ

8 Vulnerable Software Apps Exposing Your Computer to Cyber Attacks [Infographic]

Comments

This type of article which is mandatory for the terms which are known as cybersecurity for that you need to know a lot more things about the facts which may affect you very harsh.

It was interesting to read and so many things to learn about cyber security hope to see you again with some classi post and learning article , great work done by you!!!

truly Amazing informative rich content article , despite some of the negative comments which I find baseless , I believe there was so much effort and research behind this article that took so much time and effort from the lady who prepared it and for that I raise my hat for the genuine desire to increase awareness among people like us who should be thankful to her .

all the best and keep up the good work 🙂

Number 11.. Fear-mongering like you also do…. to provide your product! With other words you do the same and think you are helping but it’s not. Fear is never the answer and also your product is not the answer and there are enough of free products out there that delete +80% of the problems and the other 20% are you and me. If you really want to help than you must lower the costs of Heimdal Pro. Go for quantity here if its so good I’m here for 15 years on Xp and I must see one malware problem but I have some knowledge to security tweak it and I’m staying on Xp for another two years minimum. And read your product here and I’m also of the view of:

Why do we have to spend our money to >= 2 security products? I think we should spend maximum 1 because paid products don’t garantee better protection, sometimes worse than free solutions and we spend money for something we don’t need or our paranoia

€34 for Heimdal Pro definitely not worth any penny, IMO. It should cost max $20 or $10-15
even HMPA isn’t worth $35 (but I know why it should be expensive)

Your problem is: WD doesn’t have a web filter (but can be enabled via tweaks). Malwarebytes has a relatively good web filter but everything else is weak

My recommendation:
– WD: enable web filter
– VS free
– Install a security chrome/firefox web filter: avira browser safety or norton safe web
– Use norton DNS and/or AdguardDNS (has google safe browsing API) because they have malware protection capability
(- OSArmor: default settings)

you can save a lot of money and system resources with this setup. Everything is free a you have so many layers of security

——-

carsten ibsen I think you wasted your money.
Heimdal doesn’t provide anything special!not worth it even for free:D Pls someone shows me a test that Heimdal blocked some targeted attacks. this is what they claim(a 2nd generation software to defend you against targeted attack haha)but what about the proof?it cants even block a simple phishing page! to me it’s only a DNS like Norton dns+avira browser extension. nothing more Or get a firewall like Eset which has IDS! I believe it works better than Heimdal.34$ is also high price!

So stop with this fear-mongering BS please and get a life…

Good read, and some people believe that common sense is the best defense against threat mitigation. Wake up smell the reality of IOT.
JOHAN
SSCP

Thank you for the feedback, Anthony, and for reading our blog!

Totally insane. I hope that they stop this BS internet because it’s out of control and this site is full of fear mongering a la EGO too. Get a life and is not beautiful to see a beautiful woman with this BS interest. Get a boy friend and live a little because we are almost there and then we have no need for safety anymore because the OS will be in the cloud and money has left the building how it is set up in this prehistoric old time. New time will safe us from this ego BS because this cannot go on much further. I browse and pay i the whole the world (China, US, Europe, UK) with the good and old Xp and no problems at all and you need a little trick and you need not to worry. When I surf with NoScript on every site thinks I’m surfing with Linux with Chrome browser but it is Xp with a very old Ff browser and there are o exploits for this and look also for Quarri MyPOQ. Good security! Good day from Belgium

Thank you very much Andra Zaharia for that very useful information

Thanks for your information,interesting to learn about cybersecurity

Helpful write up! Now people may have an idea what to do and what must not do. I still believe in the power of my AV (ESET Antivirus) for any cybersecurity threats like malware.

Long read, but worth it. Learned a lot of interesting things. Pretty concerning that 99% of systems are vulnerable. I’m curious to know which system isn’t.

It was a guesstimate. They named off several programs that almost all systems have where a malware could be distributed. Any system without this would be far less vulnerable. Any system hooked to the internet is susceptible to a virus, though. In order to not run the risk of a virus, you would need a home computer in a faraday cage that never is connected to the internet.

Cute Andra

We are getting to fall in a risk after a minute pass today. Virus and Malware always ready to capture our personal data. It is time to be serious in every minute. thanks for your help

There is a typo in this article. It says Game Over Zeus is responsible for for losses of over one hundred dollars US.

Thank you very much for your observation, Bob! That one missing word made all the difference.

Leave a Reply

Your email address will not be published. Required fields are marked *

GO TO TOP