Sony Pixel Power calrec Sony

IBM Report: Cybercriminals Intensify Attacks on User Identities in the UK, Complicating Recovery Efforts for Enterprises

21/02/2024

LONDON, UK, Feb 21, 2024 IBM today released the 2024 X-Force Threat Intelligence Index highlighting an emerging global crisis as cybercriminals double down on exploiting user identities to compromise enterprises.

According to IBM X-Force, IBM Consulting's security services arm, cybercriminals last year generated more opportunities to log in to corporate networks through valid accounts, instead of hacking into them making this tactic a preferred weapon of choice for threat actors.

The X-Force Threat Intelligence Index is based on insights and observations from monitoring over 150 billion security events per day in more than 130 countries. In addition, data is gathered and analysed from multiple sources within IBM, including IBM X-Force Threat Intelligence, Incident Response, X-Force Red, IBM Managed Security Services, and data provided from Red Hat Insights and Intezer , which contributed to the 2024 report.

An emerging identity crisis

The report data revealed that exploiting valid accounts has become the path of least resistance for cybercriminals, with billions of compromised credentials accessible on the Dark Web.

According to the report, 50% of cyberattacks in the UK involved the exploitation of valid accounts as the initial access vector' and a further 25% of cases involved the exploitation of public-facing applications. Across Europe, X-Force observed a 66% year-on-year rise in attacks caused by the use of valid accounts contributing to Europe's prevalence as the most targeted region of 2023 and the record number of attacks that X-Force has ever reported regionally.

The criminal ecosystem was also quick to adapt to the use of valid accounts by attackers. In 2023, X-Force observed a 266% increase in infostealing malware, which is designed to steal personal and enterprise credentials, personally identifiable information, and banking and crypto wallet information.

This easy entry for attackers is harder to detect, eliciting a costly response from enterprises. According to X-Force, worldwide, major incidents caused by attackers using valid accounts were linked to nearly 200% more complex response measures by security teams than the average incident with defenders needing to distinguish between legitimate and malicious user activity on the network.

In fact, IBM's 2023 Cost of a Data Breach Report found that breaches caused by stolen or compromised credentials required roughly 11 months from detection to recovery the longest response lifecycle among all infection vectors.

Martin Borrett, Technical Director, IBM Security, UK, and Ireland (UKI) commented:

Our findings reveal that identity is increasingly being weaponised against enterprises, exploiting valid accounts and compromising credentials. It also shows us that the biggest security concern for enterprises stems not from novel or cryptic threats, but from well-known and existing ones.

Addressing cybersecurity challenges requires a strategic approach, emphasising the reinforcement of foundational security measures. Streamlining identity management through a unified Identity and Access Management (IAM) provider and strengthening legacy applications with modern security protocols are crucial steps in mitigating risks. Additionally, subjecting your system to rigorous stress tests by skilled offensive security teams proves invaluable in uncovering potential weaknesses. This insight is pivotal for crafting a robust incident response plan that engages all teams, from IT professionals to C-suite executives.

Julian David, CEO of techUK, added:

In an era marked by the growing sophistication of cybercriminals who exploit legitimate accounts to breach business defences, IBM's X-Force Threat Intelligence Index serves as a stark wake-up call.

The report underscores a troubling pattern where half of the cyberattacks in the UK rely on legitimate accounts for initial access, presenting significant challenges to businesses' recovery endeavours. To effectively combat this threat, businesses must adopt a strategic approach, integrating modern security protocols to mitigate risks and strengthen their defences against the ever-evolving landscape of cyber threats.

Further key UK findings include:

Malware made up 30% of security incidents observed in the UK.

Ransomware (30%) and cryptominers (20%) were the top malware types encountered in the country.

The impact of attacks was evenly distributed with extortion, digital currency mining and data leaks each making up 25% of total impacts in the UK.

This marks a shift from 2022, when half the cases X-Force observed in the UK involved extortion (57%) twice the global average followed by data theft (29%).

The professional, business and consumer services industry was the most targeted sector in the UK, representing 39% of cases.

Energy (30%) and finance & insurance (17%) were the second and third most targeted industries in UK, respectively.

Manufacturing was the most targeted industry in Europe, accounting for 28% of cases.

Europe overall experienced the highest percentage of incidents within the energy sector at 43%, as well as finance and insurance at 37%.

Major takeaways from the global report included:

Attacks on critical infrastructure reveal industry faux pas.

Worldwide, an alarming 69.6% of attacks that X-Force responded to were against critical infrastructure organisations, an alarming finding highlighting that cybercriminals are wagering on these high value targets' need for uptime to advance their objectives.

In 84% of attacks on critical sectors globally, compromise could have been mitigated with patching, multi-factor authentication, or least-privilege principals indicating that what the security industry historically described as basic security may be harder to achieve than portrayed.

Exploiting public-facing appl
LINK: https://uk.newsroom.ibm.com/IBM-Report-Cybercriminals-Intensify-Attack...
See more stories from ibm

More from IBM

25/04/2024

IBM Transforms the Storage Ownership Experience with IBM Storage Assurance

LONDON, UK, April 25, 2024 IBM (NYSE: IBM) today announced new storage capabilities that give clients choice and control in the data center to maximise perfor...

05/04/2024

IBM and The Government of Spain Collaborate to Advance National AI strategy and Build the World's Leading Spanish Language AI Models

Madrid, Spain April 5, 2024 The President of the Government, Pedro S nchez, ...

26/03/2024

IBM Announces EMEA Geography Winners of the 2024 IBM Partner Plus Awards

London, UK, March 26, 2024 Today, IBM (NYSE: IBM) announced the EMEA geography winners of the 2024 IBM Partner Plus Awards, which celebrate IBM partners who a...

21/02/2024

IBM Report: Cybercriminals Intensify Attacks on User Identities in the UK, Complicating Recovery Efforts for Enterprises

LONDON, UK, Feb 21, 2024 IBM today released the 2024 X-Force Threat Intelligen...

06/02/2024

New IBM LinuxONE 4 Express to Offer Cost Savings and Client Value through a Cyber Resilient Hybrid Cloud and AI Platform

LONDON, U.K., February 6, 2024 IBM (NYSE: IBM) today announced IBM LinuxONE 4 ...

18/01/2024

IBM to Acquire Application Modernization Capabilities from Advanced

Today, IBM is announcing that it has signed a definitive agreement to acquire application modernization capabilities from Advanced, bringing a combination of ta...

10/01/2024

UK Lags Leading Asian Economies on Enterprise AI Adoption - New IBM Study

LONDON and ARMONK, N.Y., January 10, 2024 New research commissioned by IBM (NYSE: IBM) found that more than a third of UK organisations with over 1,000 employ...

13/12/2023

NATO Selects IBM to Further Enhance Alliance's Cybersecurity Resilience

LONDON, UK, December 13, 2023 - Today, IBM (NYSE: IBM) signed a contract with the NATO Communications and Information Agency (NCI Agency) to help strengthen the...

05/12/2023

AWS Announces IBM Winner of the 2023 Global Systems Integrator Partner of the Year Award

LONDON, UK, 5 December, 2023 Amazon Web Services, Inc. (AWS), an Amazon.com co...

30/11/2023

IBM Advances Geospatial AI to Address Climate Challenges

LONDON, UK, Nov 30, 2023 IBM (NYSE: IBM) today announced new efforts that apply its geospatial AI technologies, including IBM's geospatial foundation mode...

22/11/2023

IBM Commits to Train 2 Million in Artificial Intelligence in Three Years, with a Focus on Underrepresented Communities

DUBLIN, 22 November, 2023 - To help close the global artificial intelligence (AI...

08/11/2023

New IBM Study Explores the Changing Role of Leadership as UK Businesses Embrace Generative AI

Wednesday 8 November, London: Today, IBM launched its new report Leadership in ...

27/10/2023

The Sunday Times: Why Big Blue is betting on an AI reboot

Arvind Krishna, Chairman and CEO of IBM, met recently with one of the UK's leading business editors in New York for a major profile interview. The Sunday T...

18/10/2023

IBM Expands Relationship with AWS to Bring Generative AI Solutions and Dedicated Expertise to Clients

LONDON, UK, October 18, 2023: IBM (NYSE: IBM) today announced an expansion of it...

13/09/2023

IBM Announced as Sponsor of 2023 U.N. Climate Change Conference (COP28)

LONDON, UK, September 13, 2023 IBM (NYSE: IBM) today announced its role as an Associate Pathway Partner of the 2023 United Nations Climate Change Conference (...

17/08/2023

IBM Consulting Collaborates with Microsoft to Help Companies Accelerate Adoption of Generative AI

LONDON, UK, August 17, 2023 - Today, IBM (NYSE: IBM) is expanding its collaborat...

14/08/2023

IBM Study: AI Drives Massive Shifts in Jobs and Skills as Employees Prioritise Meaningful Work

LONDON, UK, August 14, 2023 - Executives in the UK estimate that 41% of their wo...

24/07/2023

IBM Security Report: Cost of a Data Breach for UK Businesses Averages 3.4m

LONDON, UK. 24 July 2023 IBM Security today released its annual Cost of a Data Breach Report,1 which revealed that UK organisations pay an average of £3.4m fo...

20/07/2023

Crown Commercial Service and IBM Sign 3-Year Memorandum of Understanding to Boost Public Sector Services

The Crown Commercial Service (CCS) has announced a new 3-year Memorandum of Unde...

18/07/2023

Digital Realty Selects IBM Sustainability Software to Transform Data into Insights Across its Global Data Centers and Offices

LONDON, UK; July 18, 2023London, UK; July 18, 2023 - IBM (NYSE:IBM) today announ...

27/06/2023

IBM Study: CEOs Embrace Generative AI as Productivity Jumps to the Top of their Agendas

LONDON, UK, June 27, 2023 A new study by the IBM (NYSE: IBM) Institute for Bus...

21/06/2023

IBM Brings Generative AI Commentary and AI Draw Analysis to the Wimbledon Digital Experience

LONDON, U.K. and ARMONK N.Y., June 21, 2023 IBM (NYSE: IBM) and The All Englan...

19/05/2023

Diageo partners with IBM Consulting and SAP to drive its digital transformation initiative

IBM Consulting has been selected to revolutionise Diageo's IT environment by...

23/04/2023

IBM statement on the Confederation of British Industry

You may have seen recent media coverage relating to the Confederation of British Industry (CBI), the largest business association in the UK. IBM agrees with th...

17/04/2023

New IBM Study Reveals Inadequate Data Hinders Progress Against Environmental, Social and Governance Goals

LONDON, UK, April 17, 2023 - A new global IBM (NYSE: IBM) Institute for Business...

03/04/2023

IBM Statement on UK Government's AI Regulation White Paper

IBM is pleased to see the UK government making progress on its plans to develop a pro-innovation approach to AI regulation. Like similar approaches in Singapore...

14/03/2023

IBM launches RFP to help accelerate global water management solutions for vulnerable populations

LONDON, UK, March 1, 2023 - IBM (NYSE: IBM) announced today that it is accepting...

01/03/2023

IBM and Chief Study Finds Women in Leadership Pipeline has Hollowed Out in the Middle

LONDON, UK, March 1, 2023 - The leadership pipeline for women has hollowed out i...

22/02/2023

IBM Report: Vulnerable UK energy system among top targets for cybercriminals as businesses face growing extortion threat

ARMONK, N.Y. and LONDON, UK, FEBRUARY 22, 2023 IBM Security (NYSE: IBM) today ...

14/02/2023

New IBM survey reveals the greatest perceived barrier to professional or technical skill development is that programs are too expensive

London, 14th February 2023 Job seekers, students, and career changers around t...

09/01/2023

Nicola Hodson named Chief Executive, IBM in the UK and Ireland

London, 9 January 2023 IBM today announced that Nicola Hodson has been named Chief Executive, IBM in the UK and Ireland. Dr Hodson succeeds Sreeram Visvanatha...

25/10/2022

IBM Grants $500,000 in-kind to City of Dublin Education Training Board To Boost Cybersecurity Preparedness

October 25, 2022 - As schools become more dependent on technology, ransomware at...

28/09/2022

UK Business Leaders Say Hybrid Cloud is Critical to Modernisation, Yet Security, Skills and Compliance Concerns Impede Success

ARMONK, N.Y., September 28, 2022 New market research from IBM (NYSE: IBM) reve...

31/08/2022

REPROCELL, IBM and STFC harness the power of AI in drug discovery and precision medicine

Glasgow, UK and Daresbury, UK: REPROCELL Europe Ltd, IBM Research and STFC today...

27/07/2022

IBM Report: Consumers Pay the Price as Data Breach Costs Reach All-Time High

CAMBRIDGE, Mass., July 27, 2022 IBM Security today released the annual Cost of a Data Breach Report,[1] revealing costlier and higher-impact data breaches tha...

21/06/2022

IBM Reveals New AI and Cloud Powered Fan Experiences for Wimbledon 2022

London, 21st June, 2022 IBM (NYSE: IBM) and the All England Lawn Tennis Club today unveil new ways for Wimbledon fans around the world to experience The Champ...

18/05/2022

IBM Study: Skills Shortage Stalls UK's AI Adoption as Europe Accelerates

London, 18th May 2022 A global study from IBM (NYSE: IBM) has revealed UK businesses are not progressing their use of artificial intelligence (AI) at the same...

10/05/2022

IBM Study: Sustainability Ranks Among Highest Priorities on CEO Agendas, Yet Lack of Data Insights Hinders Progress

IBM Study: Sustainability Ranks Among Highest Priorities on CEO Agendas, Yet Lac...

13/07/2020

From Studio to Screen: How IBM Developed a Digital Showcase for Final-Year Students at University of the Arts London

From Studio to Screen: How IBM Developed a Digital Showcase for Final-Year Stude...

25/09/2019

CICS 50th Anniversary

CICS 50th Anniversary 19 September, 2019 | Written by: Nick Garrod...

18/09/2019

Rugby Football Union, IBM delivering a refreshed digital experience

Rugby Football Union, IBM delivering a refreshed digital experience 16 August, 2019 | Written by: John Kaduthodil Staying relevant, maintaining and exceedin...

18/09/2019

IBM's Internship program is helping Marwell Zoo improve its recycling with smart technology

IBM's Internship program is helping Marwell Zoo improve its recycling with s...

09/07/2019

IBM Closes Landmark Acquisition of Red Hat for $34 Billion; Defines Open, Hybrid Cloud Future

London - 09 Jul 2019: - Acquisition positions IBM as the leading hybrid cloud p...

03/07/2019

Moorfields Eye Hospital launches first virtual assistant to connect with patients

London - 02 Jul 2019: Moorfields Eye Hospital NHS Foundation Trust (Moorfields)...

13/06/2019

Wimbledon & IBM Herald The Role of AI to Maintain a Competitive Advantage in Sports Landscape

London, UK - 13 Jun 2019: The All England Lawn Tennis Club (AELTC) and IBM toda...

14/02/2019

SPF Private Clients introduces its First AI Mortgage Advisor Built on IBM Watson and IBM Cloud

London, UK - 14 Feb 2019: Ava was created to handle the significant increase in...