sb-au logo
Story image

Cyber-pandemic: The most notable cyber attacks of 2020

2020 and the COVID-19 pandemic saw employees move to remote working, keeping IT professionals on high alert for cyberattacks. 

Cynet has turned back the pages of 2020 to review the most noteworthy cyberattacks making up what it calls is the cyber-pandemic.

"2020 was the year that COVID-19 brought a major cyber-pandemic to the world," the company says.

An assessment by INTERPOL revealed that organisations and businesses rapidly deploying remote systems and networks to support staff working from home were being taken advantage of by cybercriminals. The report noted that in a four-month period, "some 907,000 spam messages, 737 incidents related to malware and 48,000 malicious URLs all related to COVID-19 were detected by INTERPOL and its private sector partners." 

Many of these never made the headlines, but six major attacks did ranked below by their overall impact, according to Cynet:

1. The SolarWinds Attack - This attack involved hackers compromising the infrastructure of SolarWinds, a company that produces a network and application monitoring platform called Orion, and then using that access to produce and distribute trojanised updates to the software's users. 

2. FireEye: The Stolen Red Team Tools - On August 12, 2020 FireEye announced that a sophisticated group of hackers, likely state-sponsored, broke into its network and stole tools that the company's experts developed to simulate real attackers and test the security of its customers. The attack was later found to be tied to SUNBURST malware which was also responsible for the SolarWinds attack. 

3. Software AG: Clop Ransomware Attack - The second-largest software vendor in Germany was reportedly hit by a ransomware attack in October 2020. News outlets reported that the German tech firm had been attacked by the Clop ransomware and that the cyber-criminal gang had demanded a $23 million ransom. 

4. Sopra Steria: Ryuk Ransomware Attack The 46,000 employee European information technology firm announced on October 21, 2020 that it had detected a cyber attack the previous evening. The virus was identified as a new version of the Ryuk ransomware, previously unknown to antivirus software providers and security agencies. The attack followed a previous infection with either TrickBot or BazarLoader. 

5. Telegram Hijack Hackers with access to the Signaling System 7 (SS7) used for connecting mobile networks across the world were able to gain access to Telegram messenger and email data of high-profile individuals in the cryptocurrency business. In what is believed to be a targeted attack, the hackers were after two-factor authentication (2FA) login codes delivered over the short messaging system of the victims mobile phone provider. 

6. BlackBaud: Ransomware Attack - Blackbaud, a cloud technology company, was hit by a data-stealing ransomware attack earlier this year. The attack was one of the biggest of the year in terms of the number of organisations affected, with nearly 200 organisations and millions of individuals potentially impacted. 

Lessons Learned 
According to Cynet, the most common causes of data breaches are weak or stolen credentials, back doors/vulnerabilities, malware, social engineering, excessive permissions, insider threats and improper configuration/user error, so businesses need to be diligent. 

"Cybersecurity needs to be top of mind and systems and setups need to be routinely assessed. Any organisation can become the victim of phishing schemes, ransomware, DDoS, malware, and other attacks leading to data breaches. Stress to customers that taking all necessary precautions is the best chance they have at staying secure," it says. 

"Along with detection and response tools, authentication protocols and ongoing employee security awareness training can make the biggest difference."

Eyal Gruner, CEO and founder of Cynet, says, "Because the reality is challenging and the future is not promising to be better in terms of cybersecurity threats and malicious attacks, cybersecurity professionals must be prepared in the defense of their organisation.

"Going deeper into 2021, Cynet stands ready to support organisations and address these challenges to improve overall security readiness with next-generation XDR (EPP, NGAV, EDR, NDR, UBA), SOAR and advanced MDR services in a single platform," he says. 

Story image
Microsoft Exchange breach a wake-up call to ditch the server
"There are owners who still have in-house exchange servers because they are suspicious of the cloud or have concerns about their data sovereignty or don't want to contemplate the capital expenditure. But the warning is clear. Get rid of them."More
Story image
AvePoint brings Salesforce Cloud Backup to channel partners
The product adds to the AvePoint suite of trusted Cloud Backup for Microsoft 365 and Dynamics 365 to provide managed service providers with backup and restore capabilities across multiple, popular SaaS providers.More
Story image
New wormable Android malware discovered through auto-replies in WhatsApp
Check Point Research has discovered new malware on Google’s Play Store that could spread through WhatsApp messages. More
Story image
IT leaders prioritising automation, Zero Trust and API-based security investments
"The study shows that a cocktail of multiplying threats, the proliferation of hybrid and cloud architectures, blended with a pandemic-fuelled explosion in distributed and remote work has created a perfect storm for network security teams."More
Story image
Enterprises underutilising security tools, causing teams to burn out
The report unveiled a lack of meaningful ROI metrics when reporting on security progress, as well as disparate opinions on objectives, tool effectiveness and security awareness amongst the organisation between executives and operations on security teams.More
Story image
2020 sees a global shift in financial malware threats
The financial threat landscape experienced a game-changing pandemic year, according to a new report from Kaspersky.More