Weekends and holidays: the days of hackers

Kaseya, Colonial Pipeline and JBS are just a few examples of companies that have been the target of a cyber attack over a long weekend.

• And who does not like weekends and holidays? Cybercriminals are no exception, but they actually prefer to "work" during this time.

hacker

Everyone loves a long weekend and holidays, but such dates can also be marked in cybercriminals' diaries. Once a cyberattack gains access to a corporate network during a holiday, it will have more time to spread, as offices are , making it easier for the perpetrators to go unnoticed.

And now that we have reached this point, Check Point Software Technologies Ltd. , a cyber security provider, has issued a stern warning about the dangers behind not paying attention to your office's cyber security during the holiday season.

The trend of attacks on weekends and holidays is not something new. The FBI and Cyber ​​Security and Infrastructure Security (CISA) have already warned of the dangers following the large-scale attacks in the United States this year.

On July 4, Independence Day, Kaseya, a computer management software company for msps, came under massive attack that hit 1.000 companies, with victims located in at least 17 countries.

The catastrophic cyber attack on the Colonial Pipeline - which supplies about 45% of the fuel throughout the East Coast of the United States - took place on Mother's Day weekend. As a result of this ransomware attack, it was forced to suspend its activities to deal with the threat.

The Friday before her weekend Day, the giant company JBS was forced to pay the equivalent of $11 million in Bitcoins as a ransom to restore a cyber attack.

During a vacation period or a weekend, companies often operate with a core team, consisting of a small number of staff on alert for any type of incident. This facilitates the operation of criminals in cyberspace in various ways.

On the one hand, it allows the full development of a ransomware before anyone notices it and on the other hand causes more panic during the response operations, especially if the victim's IT teams are not available to respond. This, in turn, could increase the chances of a ransom claim being paid.

"Long weekends create the perfect conditions for threatening factors to cause maximum damage. You have to take into account the fact that, at the moment, everything is "paralyzed", so once criminals gain access to the network, there is much more time to expand the attack and reach a large number of computers and their data. This is one of the reasons why it is necessary to have a good cyber security prevention strategy and not to wait until the damage is done before you face the problem ", explains Vassilis Nikolopoulos, head of the Security Engineering team of Check Point Software Technologies in Greece.

Tips for protecting a company from

• Prevention strategy: In this day and age, it is important to have a precautionary cyber security strategy to prevent data theft and cyber security issues. In contrast to a response strategy, these methods aim to monitor attack markers (IoAs) and deal with all processes, technology, systems, and people, with an emphasis on preparing for an attack without waiting for it to happen.

• Zero trust strategy: σύμφωνα με το Threat Intelligence Report της Check Point Software , το 98% των κακόβουλων αρχείων στην Ελλάδα στάλθηκαν μέσω ηλεκτρονικού υ. Αυτός είναι ο λόγος για τον οποίο, σε ολόκληρο τον κλάδο, οι επαγγελματίες ασφαλείας κινούνται σε μια νοοτροπία ασφάλειας μηδενικής εμπιστοσύνης: καμία συσκευή, χρήστης, ροή εργασίας ή σύστημα δεν πρέπει να θεωρείται αξιόπιστη από προεπιλογή, ανεξάρτητα από τη θέση από την οποία λειτουργεί, είτε εντός είτε εκτός της περιμέτρου ασφαλείας. Η εφαρμογή αυτών των αρχών επιτρέπει την υιοθέτηση μιας στάσης ασφαλείας “Άρνηση από προεπιλογή” όπου τα συστήματα γίνονται πιο δυσπρόσιτα και απομονώνονται μέχρι να καθιερωθεί ένα επίπεδο εμπιστοσύνης που θα φέρει το υψηλότερο επίπεδο προστασίας σε ένα σύστημα.

• Mobile device protection: Data mobility is one of the key points to consider when developing a cyber security strategy. In today's example, in which hybrid work has been adopted in most companies, there is a situation of multiple devices with many not having the appropriate security measures. These operations become the focus of many malicious cybercrime campaigns and, therefore, it is important to equip all devices with safeguards against any cyber attack.

• Cyber ​​training: very often one of the main entry points for a cyberattack is an employee's email or device, which is why this is one of the weakest links in any company: the lack of training for its members. It is of the utmost importance that company members are trained so that they are able to detect and avoid potential attacks. A social engineering message that encourages the user to click on a malicious link is enough. THE it is often considered one of the most important defenses that can be deployed.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.
hackers, hackers ελλαδα, hackers greece, iguru

Written by newsbot

Although the press releases will be from very select to rarely, I said to go ... because sometimes the authors are hiding.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).