Are companies falling behind on cyber security awareness training?
New data from a Waterloo-based cyber security service suggests hackers have shifted their tactics and companies may not be keeping up.
Ryan Westman, senior manager of threat intelligence at eSentire, says spam emails and attachments have been the preferred route for sneaking malware into a target’s computer for many years.
“In 2020, email really dominated as the initial access factor at 66 per cent,” said Westman.
But it seems cyber criminals have found new attack methods.
“So in Q1, Q2 and Q3 in 2023, we’ve seen that browser-based initial access has really exploded to 47 per cent,” he said.
That accounts for nearly half of how all cyber attacks are making their way inside a computer. It comes as hackers have created millions of dangerous links that lead to fake websites.
“So what they’ll do is they’ll poison search engine results and it’ll basically result in someone searching for something like a legal document [being led to a fake site],” Westman said.
He adds that browser-based attacks can be trickier because they’re mimicking things like a Google ad, downloading a Zoom meeting or downloading a program like Adobe.
It seems companies are not keeping pace with these tactics as most continue to focus on identifying phishing emails.
“That’s actually one of the areas that I think the user awareness training needs to improve, is around the browser-based threats,” said Westman.
Some industries are more at risk of having sensitive information sold to other hackers on the dark web.
“Specifically in the case of what we’ve observed over the past year is a group referred to as the Gootloader malware group, they’ve specifically targeted the legal industry by poisoning search engine results for legal documents,” he said.
Just as companies begin learning of these new threats, another one is on the way. Westman said the rise of artificial intelligence could pose significant cyber security risks by 2025 – only adding to the constant game of digital cat and mouse.
HOW TO PROTECT YOURSELF
As simple as it sounds, Westman says an easy way someone can validate the information they’re seeing on a webpage is by reviewing the link they’ve visited.
“A really common thing would be to switch out an ‘E’ for a ‘3’ or a ‘1’ for an ‘L’ and it's very trivial, but it's very easy for a threat actor to stand up a page that looks and feels very similar to something like Adobe or a Zoom,” said Westman.
He also says a straightforward approach would be for companies to update their user awareness training to include browser-based threats.
It’s not the first time CTV News Kitchener has spoken with eSentire about cyber security.
They’ve offered tips for creating a strong password, maximizing cyber security, and even staying cyber safe during the Super Bowl.
CTVNews.ca Top Stories
LIVE UPDATES 'Terrifying' L.A. fires at 0% containment, 2 deaths reported
A series of wildfires are searing through the Los Angeles area, forcing many to evacuate their homes. Follow along here for the latest updates.
At least 60 University of Guelph students sick as 'cluster of illness' hits residence
The University of Guelph is dealing with what they are calling a ‘cluster of illness’ among students living in residence.
Mexico's president offers sarcastic retort to Trump's 'Gulf of America' comment
Mexico's President Claudia Sheinbaum responded sarcastically on Wednesday to U.S. president-elect Donald Trump's proposal to change the name of the Gulf of Mexico to the Gulf of America.
Regina murder suspect who appeared on national most wanted list arrested
The Regina Police Service (RPS) has arrested a suspect that appeared on Canada's Top 25 Most Wanted list – in relation to a homicide that occurred in May of 2024.
Ontario pitches energy partnership with U.S. amid Trump's tariff, Canada annexation threat
In the face of incoming U.S. president Donald Trump’s threat to acquire Canada and impose tariffs, Ontario Premier Doug Ford says he wants to expand its energy supply both sides of the border.
Ontario Premier Doug Ford uninjured in Highway 401 collision, says his office
Ontario Premier Doug Ford was unharmed after an OPP vehicle he was travelling in was involved in a collision on Highway 401.
Massive high-tech Canadian helicopter helps navy in hunt for submarines
Canadian warships on a mission to promote peace in the hotly-contested waters of the Indo-Pacific includes a highly-skilled specialized crew from the Royal Canadian Air Force.
Canada among 'top 5 losers' in new passport ranking
A new global ranking may raise doubts about Canada's reputation of being open to other countries.
JetBlue passenger suddenly opens exit door as flight is taxiing for takeoff at Boston airport
A person on board a plane at Boston Logan International Airport that was taxiing for takeoff suddenly opened an exit door and was quickly restrained by other passengers, authorities said.