Skip to content

近年來最大的網絡攻擊

We all know that cyber vulnerabilities are not a current issue. However, with the evolution of technology and virtualization growing in all areas of society, cybercrime becomes more and more frequent, creating a critical problem that deserves a lot of attention from the digital security industry.

One of the biggest challenges is to keep up with the evolution of these crimes, because as technology advances, crimes become increasingly strategic and sophisticated, requiring even more technological advances and security efforts, in addition to repeating a cycle that is difficult to prevent.

In recent years, especially during the coronavirus pandemic, in which most companies are adopting new work alternatives, migrating to digital environments, the role of criminals has been strengthened.

According to data from FortiGuard Labs, the year 2020 had 41 billion attempts of cyberattacks in Latin America. The good news is that while these attempts are taking place, the cybersecurity industry has also worked hard and strengthened itself to ensure as much security as possible for digital media and to weaken this cycle of attacks.

To get a sense of this problem’s scale and the lessons we can pass on to those who want to strengthen the security of their information, we have listed the 5 biggest cyberattacks in recent years. Check it out below.

 

Solar Winds: The Biggest and Most Sophisticated Attack in History

In 2020, Solar Winds, an information infrastructure company, suffered what can be considered, according to Microsoft’s President Brad Smith, as “the biggest and most sophisticated attack the world has ever seen”. This is because several tactics and techniques of cyber invasion and espionage were employed.

Hackers have inserted malicious software into Solar Winds’ monitoring software update that has been sent to up to 18,000 customers. These include Microsoft companies and the US Departments of Energy, Justice, and Nuclear Safety. But it was FireEye, one of Solar Winds’ client companies, the first victim to identify the attack.

In the Microsoft attack alone, according to its president, at least a thousand engineers took part. Ongoing investigations indicate that the operation is very complex and surprising even for specialists, as it combines very advanced and stealthy techniques, which have bypassed the radar of the most experienced security specialists. This made everyone apprehensive about a critical vulnerability in the technology infrastructure.

 

Colossal DDoS Attack Against Dyn

Dyn, an American company of DNS (Domain Name System) services, has suffered a DDoS attack, which, in general, is a type of attack that intensifies data traffic and overloads a certain server, making it unavailable to users.

This attack caused a system crash for all the company’s customers in 2016, who had virtual newspapers and magazines from the United States and other large companies among them: Amazon, Netflix, PayPal, Spotify, Tumblr, Twitter, GitHub, Xbox Live, and PlayStation Network.

It was an event known as “The American Internet Blackout”, one of the biggest DDoS attacks in recent times.

 

ASUS Automatic Updates

One of the largest laptop manufacturers in the world, ASUS, was the target of a hacker attack in 2018, with an automatic software update that infected nearly 1 million users worldwide.

The attack targeted 600 computers, but the malware spread and reached more users. As the attackers used the company’s legitimate security certificate during the action, it was almost impossible to raise suspicion.

This type of crime can increase users’ distrust and lead them to avoid machine upgrades, which can raise the level of vulnerabilities and cause even bigger problems.

 

STJ: Great Cyberattack in Brazil

Brazil is one of the countries with the highest number of users connected to the Internet, and according to the Internet Security Threat Report, released in 2019, the country occupies third place in the ranking of cyberattack attempts, fourth in bot attacks, and seventh in crypto-jacking.

As might be expected, government agencies are not left out of vulnerability for cybercrime. In Brazil, the biggest data attack involved the STJ (Supreme Court of Justice), a target of the ransomware actionwhich invaded more than 1,200 servers of the institution and destroyed the backups on the machines.

On the scale of this attack, Marta Schuh, Director of Cyber Insurance at the international broker Marsh, stated that: “It was like the STJ databases could be placed inside an incinerator.” As expected, the criminals offered to ransom the information in exchange for a sum of money.

 

A Leak of Sensitive Data from Over 100 million Americans

Paige A. Thompson, a former Amazon employee, was responsible for hacking the database of Capital One, a US financial institution, compromising the data of more than 100 million Americans and 6 million Canadians by obtaining access to personal data of credit card requests.

Although the affected information does not contain the users’ credit card numbers, as Capital One claimed, the damage will cost around $150 million to boost the institution’s digital security.

 

Other Relevant Data on Cybersecurity in 2020

 

  • 60% of users say they are poorly informed about cybersecurity. (ESET Survey).
  • Lack of backup is the main cause of loss of money for 3 out of 4 users (ESET Survey).
  • Of the top causes for data leaks, 16% are exploiting third-party software vulnerabilities, 19% are cloud-server misconfiguration procedures and login data breaches, and 14% involve phishing activities. (IBM)
  • 52% of data leaks were due to malicious attacks and 23% to human error. (IBM)
  • Only 61% of users believe that some of their passwords are secure. (ESET Survey)
  • The most used password in 2020 was “123456”, accounting for two and a half million users. (Nordpass)
  • 40% of consumers worldwide use between one and three financial applications, but only half have security software installed on their devices. (ESET Survey)
  • Reports of cyberattacks grew 400% during the pandemic. (FBI)
  • DDoS attacks increased 151% in the first half of 2020. (Neustar)

What Can We Expect from the Future?

The trend for the future is to have more devices and users connected to the Internet around the world, which could further increase the number of cyberattacks and attempts. On the other hand, it has been increasingly difficult and outdated to live in a non-digital world even to perform simple everyday tasks.

Therefore, more than ever, digital security must be a concern for companies and governments, which must continue to invest heavily in the prevention and control of threats, and for users, who must always keep up-to-date on the best ways to protect their data and what legal protection they can receive in cases of attack.

If you are interested in the subject, we also invite you to read the next article. After All, How to Act in Case of Data Invasion and Theft?

 

____________________

 

References to mentioned research.

 

https://noticias.r7.com/distrito-federal/jornal-de-brasilia/mp-no-df-abre-inquerito-para-apurar-vazamento-de-dados-de-clientes-do-banco-pan-04092019

https://olhardigital.com.br/2021/02/15/noticias/solarwinds-ataque-foi-o-maior-e-mais-sofisticado-que-o-mundo-ja-viu/

https://veja.abril.com.br/blog/radar-economico/brasil-sofre-seu-maior-ataque-hacker-da-historia/

https://olhardigital.com.br/2019/07/31/seguranca/hacker-vazou-dados-sensiveis-de-mais-de-100-milhoes-de-americanos/

https://canaltech.com.br/video/top-tech/7-ataques-hacker-que-entraram-para-a-historia-top-tech-10404/

https://olhardigital.com.br/2020/12/31/retrospectiva-2020/retrospectiva-2020-relembre-os-piores-ataques-ciberneticos/

按一下以存取 ESET_Security_Report_2020_BR-1.pdf

About Version 2 Limited
Version 2 Limited is one of the most dynamic IT companies in Asia. The company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Senhasegura
Senhasegura strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

為什麼數據是新石油?

Performing any task today is much easier than it was a few years ago. With the evolution of technology, the consumer can make purchases faster and more practical, receive optimized ads – which help a lot when purchasing something -, social networks with features that follow the biggest trends, ease of payments and banking transactions, among others.

On the other hand, in exchange for all this comfort, the customer provides their data, which will be used as a resource/raw material by the companies. In this “win-win” relationship, the company makes life easier for customers through the use of data, but also exponentially increases its profits. 

Thus, there is much debate among specialists about the reciprocity of this relationship, considering the power and value of data today. Far from being just good things, just like at the time of the industrial revolution, the information and data age also brings some problems, which are constantly debated in search of the best solution within the current scenario. 

Such problems revolve around ethical and security issues in the use of data, since not all consumers are fully aware of how their data is used by companies and the great effort to protect this data from hackers, since the Internet is a place “where everyone treads”. 

This concern around data integrity is yet another aspect that emphasizes how valuable this resource is to society as a whole. In this article, we will explain the value of data in the information world and the main reasons why it is an essential part of a business strategy. We invite you to keep reading the article and find out why data is the new oil.

The Value of Data

Saying that data is the new oil is a smart and simple way to get a sense of where we are standing. However, the author of the statement himself, Ajay Banga, Mastercard’s CEO, added that data is even more valuable than oil, considering that oil is a scarce and finite resource, while data is inexhaustible and only increases. 

Furthermore, they can be continuously reused, even after being transformed, to generate new information, while oil is discarded after its transformation. That is, the more data, the more information is generated and the more valuable it becomes. 

Most people are aware of the contribution of their data to the economy, but not everyone knows or can measure this value, which leads many people to lose interest in the value of their personal data. Also, the benefits offered “free of charge” by companies work as a form of payment to the user for providing their data, who perceives the exchange as fair.

Nevertheless, this “bargaining” relationship is not always voluntary, since, with the new privacy policies, some companies “force” users to grant permission on their personal data if they want to continue using their tool. 

This only increases the users’ lack of control over their data, because between making them available and losing access to the tools’ benefits, the first option seems more sensible. In short, concerning data in the relationship between company and users, everyone wins, but disproportionately.

With the new data protection laws in the countries, a company that fails to comply with regulations or puts customer and user data at risk is punished with huge fines. 

This is because personal data such as name, age and date of birth, IP address, or sensitive information such as religious and ideological beliefs, health information, genetic and biometric data, for example, can be used for various purposes, from optimizing/customizing the use of a tool by the customer to increasing the company’s sales or as a criminal weapon. 

Therefore, privacy policies are full of strict requirements imposed on companies that work with data collection and storage.

Data in Business Strategies

It is important to understand that, from an organization’s point of view, for example, having the raw material is not enough, that is, it is not enough just to obtain the data, but to know how to handle and manage them properly in order to obtain information that generates value. 

The consequence of this is valuable returns for companies, both financially and in areas that have an impact on the world. The company that manages to get this increases competitiveness, productivity, and stands out from the crowd. 

So, it is not the data itself that makes it so important to companies, but the information and value that can be generated from it. 

In this sense, having a good data management policy today is essential for organizations, since, unlike a few years ago, when companies were working with hypotheses to analyze the competition and achieve customer preference, nowadays, data provides us with concrete, accurate information that, when handled correctly, helps drive the business forward. 

Therefore, good data management favors:

  • Making the best decisions based on data.
  • More precision in identifying problems.
  • More strategic and precise approaches.
  • Optimization of resources (time, money, and labor).
  • In-depth understanding of customer tastes and behaviors.
  • A greater understanding of the market and the competition.
  • Increase in sales.
  • Closer relationships with customers.

Data is The Future

Data is changing the world, as everything that can be done from exploiting it and the fact it is inexhaustible and reusable makes this resource even more valuable than oil. 

With the data revolution, not only do companies change the way they work, but the population also changes the way they think and act in society. The trend is for this to increase in the near future.

However, before appropriating this comparison of data with oil and trying to be part of this revolution, it is necessary to bear in mind that not all countries get rich from the sale of oil, and one of the reasons is the poor management of the resource. 

With data, it is no different. In this race towards evolution, as Yuval Noah Harari says in the book 21 Lessons For The 21st Century, “those who have the data own the future”, and those who are aware of it and make the best use of them lead the way.

About Version 2 Limited
Version 2 Limited is one of the most dynamic IT companies in Asia. The company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Senhasegura
Senhasegura strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.