Ransomware attacks are on a steep rise and it’s also popular these days as a service in the form of RaaS. But the latest report by Microsoft says that over 80 per cent of ransomware attacks can be traced to common configuration errors in software and devices.
According to the latest edition of Cyber Signals (Microsoft’s cyberthreat intelligence brief), a vast majority of ransomware attacks can be (over 80 per cent) traced to common configuration errors in software and devices, which would mean that end point device security management needs to be looked at.
Amongst other findings, Cyber Signals revealed that the median time for an attacker to access a person’s private data if they fall victim to a phishing email is one hour, 12 minutes. For endpoint threats, the median time for an attacker to begin moving laterally within a corporate network if a device is compromised is one hour, 42 minutes.
With the increasing number of cybercrimes around the world, the Cyber Signals brief reported that Microsoft’s Digital Crimes Unit has directed the removal of more than 5,31,000 unique phishing URLs and 5,400 phish kits between July 2021 and June 2022. This has led to the identification and closure of over 1,400 malicious email accounts used to collect stolen customer credentials.
Focusing on the evolving factors that are affecting the extortion segment of cybercrime economy and the rise of RaaS, the second edition of Cyber Signals has shared some deep insights. The insights by Microsoft were obtained from Microsoft’s 43 trillion security signals and 8,500 security experts, which included threat hunters, forensics investigators, malware engineers, and researchers.
“It takes new levels of collaboration to meet the ransomware challenge. The best defenses begin with clarity and prioritisation, that means more sharing of information across and between the public and private sectors and a collective resolve to help each other make the world safer for all. At Microsoft, we take that responsibility to heart because we believe security is a team sport,” said Vasu Jakkal, Corporate Vice President, Security, Compliance, Identity, and Management at Microsoft.
In US alone, the cost of cybercrime in totaled more than USD 6.9 billion (according to Federal Bureau of Investigation’s 2021 Internet Crime Report). Further, EU’s ENISA has also reported about 10 terabytes of data were stolen each month by ransomware threat actors, with 58.2 percent of stolen files including employees’ personal data in between May 2021 and June 2022. This puts the spotlight on ransomware and increasing concerns around it.