The Register® — Biting the hand that feeds IT

Feeds

Hacktivists nicked more data than CYBER-CROOKS in 2011

Social crusaders account for 58% of data breaches

Cloud based data management

Hacktivism had a massive effect on the overall data breach scene last year.

More than half (58 per cent) of data stolen last year can be attributed to hacktivism – hacking to advance political and social objectives – according to the latest edition of the Data Breach Investigations report from Verizon.  The figures contrast sharply with findings from previous years, when the majority of attacks were carried out by cybercriminals, whose primary motivation was financial gain.

Seventy-nine per cent of attacks covered by Verizon's report were opportunistic. Only 4 per cent of the overall total were rated as particularly challenging for hackers to carry out. In addition, an estimated 97 per cent of breaches might have been avoidable without recourse to difficult or expensive countermeasures.

verizon_report_2

Image via Verizon

Wade Baker, director of risk intelligence at Verizon, told El Reg that 44 per cent of the attacks exploited default or easily guessable credentials. However he qualified this remark by saying that default passwords were a far greater problem in hacks involving smaller organisations.

Breaches originated from 36 countries around the globe, an increase from 22 countries during 2010. Nearly 70 per cent of breaches originated in Eastern Europe and less than 25 per cent originated in North America.

The report covers 855 data breaches that collectively spilled 174 million records, the second highest number since Verizon began collating this type of data back in 2004. External attacks were blamed for the vast majority (98 per cent) of data breaches. This external attacker group includes organised crime, activist groups, former employees, lone hackers and organisations sponsored by foreign governments.

Hacktivism by groups like Anonymous and LulzSec figured in many data breaches last year. Wade reckons recent arrests might reverse this trend, but he's far from sure on this point.

"Anonymous is a movement. It's hard to stop a movement by taking out individuals," he said.

verizon_report_1

Image via Verizon

Attacks were overwhelming led by outsiders of one type or another. Only 4 per cent of attacks relied on the involvement of internal employees. Business partners were a factor in than 1 per cent of data breaches.

Hacking appeared in 81 per cent of breaches (compared with 50 per cent in 2010) and malware featured in 69 per cent of breaches last year (also up from the 49 per cent recorded in 2010).

The increase is easily explained: hacking and malware offer outsiders an easy way to exploit security flaws and gain access to confidential data. The ready availability of easy-to-use hacking tools also contributes to this effect.

Social engineering (tricking end users into doing something stupid or handing over information to attackers) and SQL injection attacks against vulnerable webservers also figured as a factor in many attacks.

Another important factor in attacks is the slow speed at which organisations patch up vulnerable systems and the length of time between a successful compromise and its discovery, which is most often measured in months or even years. Third parties continue to detect the majority of breaches (92 per cent).

Industrial espionage revealed criminal interest in stealing trade secrets and gaining access to intellectual property. "This trend, while less frequent, has serious implications for the security of corporate data, especially if it gains steam," Verizon warns.

Wade said that attacks involving intellectual property theft were an "undercurrent in [the] data set". Industrial espionage was the prime motive in around 5 per cent of attacks, he said. In such cases insider involvement was more common.

While compliance programmes, such as the Payment Card Industry Data Security Standard, provide sound steps to increasing security, being PCI compliant does not make an organisation immune from attacks.

The US Secret Service and the Met Police's Central e-Crime Unit collaborated with Verizon in preparing the report, which this year also involved input from other police agencies in the Netherlands and Australia. Verizon's annual study, now in its fifth year, is considered among the best of its type in the infosec business.

Verizon's report, which includes separate recommendations for enterprises and small businesses on guarding against cyber attacks, can be found here. ®

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

CNN's headline was much more satisfyingly worded:

"Hactivists stole 58% of online data in 2011"

I'm thinking, man, I thought I'd have noticed if -that- much went missing...

Also, to the people bitching about Anonymous - it's not a group. I could say I'm "in" Anonymous and there I am. The more press it gets, the more likely idiots are to claim affiliation.

Some of the collective actions have been naïve to be sure, but the core of them generally seem genuine. I just wish they would stop giving ammunition to the bad guy.

1
0

umm

bit obvious but aren't hactivists a lot more likely to boast about what they got and criminals keep quiet then they can keep using it...

quite likely, criminals got a lot more thats not been detected yet...

1
0

Anonymous - it's not a group

Anonymous not being a group is the reason that I oppose their activities. Whilst there may indeed be a core of genuine nice people, they are likewise affiliated to a whole group of people who's activities range from unpleasant, vicious (see my note about the anonymous trolling videos) to positively dangerous.

The Register article 'ANONYMOUS: Behind the mask, inside the Hivemind' does indeed detail some of the 'Good' things that anonymous may have done. Personally following on from some of the responses I had to comments on that article I remain unconvinced on that score.

I don't think anybody would actually try and seriously argue that the 'Legion' of cannon fodder that also follow anonymous do anything good, at best they are a nuisance, and at worst dangerous.

I can accept that anonymous started out as a bunch of people with a penchant for Japanese porn, who may or may not at the time have had some sort of positive contribution to make. This may be why you delude yourself into thinking that there is a core of genuine people. Personally the actions of the majority far and away outweigh anything that may be positive in the 'legion'.

As of today my impression of anonymous is a cadre of semi intelligent provecteurs herding a bunch of cannon fodder sheep. Most, if not all, of anonymous' activities is counter productive and doesn't do anything 'good' for anybody (well apart from the laughs the 'shepherds' get when the sheep get arrested).

To 'stop giving ammunition to the bad guy' my advice to anybody in the core who is genuine would be to leave. If you must find a 'cause' that has clearly defined objectives.

0
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Internet fraud still stings suckers
Australians twice as gullible as Americans
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?