The ThreatMetrix Cybercrime Report 2017 is out, and is a troubling read for anyone who has anything to do with data security. As a fraud prevention company protecting nearly a billion and a half users around the world, they’re uniquely positioned to know, and their insights on the threat landscape is invaluable.
Their main finding is that hackers, scammers and fraudsters are moving away from using stolen debit and credit cards, given that these things have such a short shelf life. On the face of it, that sounds like it might be a good thing, until you understand what they’re doing instead.
They’re making use of stolen identity data to create bogus accounts, then applying for lines of credit on their own. Even worse, they’re taking full advantage of automation to speed the process along. According to the report, the volume of global fraud attacks is up a mind blowing 100 percent in just two years, with 700 million incidents reported in 2017 alone.
Bots are coming to play an increasingly important role in the activity of the fraudsters, too. Once a new, fraudulent account has been created, it’s handed off to a bot to test it and make sure it’s valid, which increases its value on the Dark Web.
How big of a problem are bots on the web these days?
According to the report, ThreatMetrix blocked 1.5 billion bot attacks last year, with some retailers reporting that more than 90% of their daily traffic is comprised of bots.
At the root, what’s driving this behavior are the increasingly common, large-scale data breaches that put up to hundreds of millions of data records into the hands of fraudsters. Until and unless the flow of data can be stopped, we can expect this type of activity to continue to increase.
No matter how you slice it, 2018 is going to be a very interesting and very busy year.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
Intel’s year isn’t getting off to a very good start. Just after the discovery of a pair of critical vulnerabilities that have been in their chipsets for more than a decade comes the discovery of yet another serious flaw that could impact millions of laptops around the world.
Normally, Google’s robust series of checks and audits are pretty good at catching malicious code and preventing it from making its way to the Play Store. Sometimes, however, something slips through anyway despite the company’s best efforts. This latest one is particularly bad.
Do you use any of the following Chrome browser extensions?
Does your company utilize either RackSwitch or BladeCenter networking switches? Are those switches running ENOS (the Enterprise Network Operating System)? If so, there’s a backdoor in your network you weren’t aware of. Even worse, it’s been there since 2004.
A duo of researchers stumbled across a series of vulnerabilities in literally hundreds of GPS services that leave sensitive GPS tracking data open to hackers. Dubbed “Trackmageddon” by the researchers, the vulnerabilities span a range of weaknesses that include default or easy-to-guess passwords, IDOR (Insecure Direct Object Reference) issues, insecure API endpoints, and data collection folders that are entirely unsecured.
There’s a constant tug of war playing out on the national stage. On one side, privacy advocates are pushing for greater autonomy for end users, and hard limits to the types of searches that law enforcement agencies are allowed to conduct.
Remember the KRACK WiFi (WPA2) vulnerability, discovered by Mathy Vanhoef? It turns out that his discovery was a catalyst for action. Recently, the WiFi Alliance, which is the industry’s standards organization, released details about its new WPA3 protocol.
What’s an HDD manufacturer to do when faced with competition by faster, more efficient SSD drives?
Recently, a group of investors wrote an open letter to Apple, urging the company to do more in regards to offering better and more robust parental controls on the devices the company makes. Although the group of investors control some $2 billion in Apple stock, this is a drop in the proverbial bucket, given the company’s $900 billion market cap. Nonetheless, the letter seems to have gotten Apple’s attention.