Computer crime is going global. It is also becoming ever more sophisticated, adopting the same innovations that have been reshaping the technology landscape for businesses and other legitimate organizations. In the global era of cybercrime, attackers are becoming specialized. Some groups are concentrating on specific criminal exploits, while others offer support capabilities that have already been dubbed crime-as-a-service (CaaS), following in the footsteps of legitimate “as-a-service” offerings.

To combat the global cybercrime threat, organizations will need to think globally and act locally — that is, they need to be cognizant of the wide scope and sophistication of attackers while still taking specific actions to minimize the chance of a successful attack and ensure resilience in the face of breaches.

The Battleground of the Global Era of Cybercrime

As Steve Durbin reported at Infosec Island, cybercrime networks are rapidly growing in scope and sophistication. In particular, they “are beginning to develop complex hierarchies, partnerships and collaborations that mimic large private-sector organizations and are taking their activities worldwide.”

These criminal organizations are basing themselves in countries with weak or compromised legal systems and law enforcement, while taking full advantage of the Internet’s global connectivity to attack targets anywhere.

Although the press focuses primarily on high-profile American firms that have suffered cyberattacks, the victims are as global as the culprits. As reported by The Guardian, British Airways recently had to temporarily suspend its frequent flier rewards program after thousands of user accounts were hacked. In this case, prompt action by the hacked airline minimized the damage, but it’s only one example of a cyberattack.

As noted at Security Affairs, an effective response was also deployed by the European Central Bank (ECB) last year after criminals stole information and sought to use it for extortion. Most of the stolen data was protected by encryption (though contact information was not), underlining the value of encryption as a protective measure. The ECB also firmly refused to be intimidated by the attackers, turning back the extortion effort.

Building Layers of Protection

In the global era of cybercrime, organizations must protect against a widening range of threats. As the examples above show, a global perspective on threat intelligence is one key component of security protection. And concentrating on basics — such as encryption of data — continues to add a crucial layer of protection. But new technologies, and new ways of using that technology, have broadened the scope of threats.

Mobile devices have emerged as favorite targets. Their security protections are relatively weak and designed for easy use by oft-distracted users, which makes enabled protections even weaker. Moreover, as the continuing bring-your-own-device (BYOD) trend intermingles personal and corporate data on devices, this data becomes accessible via mobile networks that are often poorly secured. And penetrating a single device can give cybercriminals access to a user’s entire network.

Indeed, the human factor remains the most crucial element in security — and the most challenging. Spear phishing, or highly targeted emails or other messages that carry malware but are disguised to appear as if sent by a friend or colleague, has emerged as the cybercrime weapon of choice. The spread of social networks allows cybercriminals to trace links between individuals, leading to more effective targeting.

Attacks are inevitable, and some of them will succeed. Organizations’ protective measures must include an effective post-breach strategy to minimize the damage. A full spectrum of protective measures — from encryption of data and better incident response plans to actively encouraging better individual security behaviors — will give organizations the broadest possible protection in the global era of cybercrime.

More from Intelligence & Analytics

2022 Industry Threat Recap: Manufacturing

It seems like yesterday that industries were fumbling to understand the threats posed by post-pandemic economic and technological changes. While every disruption provides opportunities for positive change, it's hard to ignore the impact that global supply chains, rising labor costs, digital currency and environmental regulations have had on commerce worldwide. Many sectors are starting to see the light at the end of the tunnel. But 2022 has shown us that manufacturing still faces some dark clouds ahead when combatting persistent…

Cybersecurity in the Next-Generation Space Age, Pt. 3: Securing the New Space

View Part 1, Introduction to New Space, and Part 2, Cybersecurity Threats in New Space, in this series. As we see in the previous article of this series discussing the cybersecurity threats in the New Space, space technology is advancing at an unprecedented rate — with new technologies being launched into orbit at an increasingly rapid pace. The need to ensure the security and safety of these technologies has never been more pressing. So, let’s discover a range of measures…

Backdoor Deployment and Ransomware: Top Threats Identified in X-Force Threat Intelligence Index 2023

Deployment of backdoors was the number one action on objective taken by threat actors last year, according to the 2023 IBM Security X-Force Threat Intelligence Index — a comprehensive analysis of our research data collected throughout the year. Backdoor access is now among the hottest commodities on the dark web and can sell for thousands of dollars, compared to credit card data — which can go for as low as $10. On the dark web — a veritable eBay for…

The 13 Costliest Cyberattacks of 2022: Looking Back

2022 has shaped up to be a pricey year for victims of cyberattacks. Cyberattacks continue to target critical infrastructures such as health systems, small government agencies and educational institutions. Ransomware remains a popular attack method for large and small targets alike. While organizations may choose not to disclose the costs associated with a cyberattack, the loss of consumer trust will always be a risk after any significant attack. Let’s look at the 13 costliest cyberattacks of the past year and…