Connect with us

Hi, what are you looking for?

Headlines

2020 sees nearly 3M phishing attempts aimed at SMBs in SEA – Kaspersky

Despite this segment bearing the brunt of the still on-going pandemic, Kaspersky’s Anti-Phishing Technology has blocked a total of 2,890,825 attempts aimed at SMBs in the region last year, a 20% increase compared with 2,402,569 attempts to visit fraudulent urls detected in 2019.

Image by Megan Rexazin from Pixabay.com

Global cybersecurity company Kaspersky today unmasks the continued phishing campaigns against small and medium businesses (SMBs) in Southeast Asia (SEA). Despite this segment bearing the brunt of the still on-going pandemic, Kaspersky’s Anti-Phishing Technology has blocked a total of 2,890,825 attempts aimed at SMBs in the region last year, a 20% increase compared with 2,402,569 attempts to visit fraudulent urls detected in 2019.

Phishing is a form of cybercrime based on social engineering techniques that involves stealing confidential data from a person’s computer and subsequently using the data for other purposes – from stealing the target’s money to reselling their data. Phishing messages usually take the form of fake notifications from banks, providers, e-pay systems and other organizations, phishing also can take the form of an almost 100% perfect replica of a trusted website, to which the victim would be lured through phishing messages to later leave their personal data. 

In terms of per country cases of phishing targeting companies with 50-250 employees, Indonesia registered the most incidents in 2020, followed by Thailand, and Vietnam. Each of them logged over half a million attempts. Malaysian, Filipino, and Singaporean SMBs were not spared, with these nations charting a combined 795,052 attempts to visit phishing websites from January to December last year.

Phishing detections against SMBs in SEA with global ranking in 2020 based on Kaspersky Anti-Phishing Technology

SMBs in all six countries in the region have also witnessed an increased phishing attempts foiled by Kaspersky Year-on-Year (YOY), an expected aftermath of the segment’s urgent drive to digitalize amidst the pandemic.

Advertisement. Scroll to continue reading.

“While they serve as the bedrock of our regional economy, SMBs are low-hanging fruits for cybercriminals. These malicious actors are aware that owners are focused on keeping their cash flow more than their cybersecurity, at least for now. Social engineering attacks such as phishing is also the easiest way in. Combining our current stressed minds with the right buzzwords like COVID-19, and now the vaccines, we expect to see this threat being used more to steal money and data from this already battered segment,” says Yeo Siang Tiong, General Manager for Southeast Asia at Kaspersky.

Last year’s top 10 countries in terms of phishing attempts against SMBs are Brazil, Russia, USA, France, Italy, Mexico, Germany, Colombia, Spain, and India.

On a worldwide scale, online phishers exploited the COVID-19 theme, invited victims to non-existent video conferences and insisted that their targets register with “new corporate services”. Given that the fight against the pandemic is not over yet, Kaspersky predicts that the main trends of 2020 will stay relevant into the near future.

https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2021/02/09150908/2020_spam_report_10.png

An example of a fraudulent email inviting victims to attend a fake video conference

An important trend which businesses in SEA, a region famous for being highly active on social media, should note about is the phishing links and mails being shared via online networking platforms. Kaspersky experts have observed that scammers who were spreading their chain mail via social networks and instant messaging applications began to favor the latter in 2020. 

Message recipients were promised a discount or prize if they opened a link sent to them. The phishing web page contained a tempting message about a money prize, award or other, equally desirable, surprises.

Advertisement. Scroll to continue reading.

“It is true that governments and financial organizations are combining efforts to offer lifeboats for SMBs via grants and offers, but we have to accept that cybercriminals will spare no one. We at Kaspersky, for our part, offers holistic and budget-friendly solutions to help business owners achieve secured digitalization. Amidst the uncertainties, one thing I can say for sure is that building your IT security is always less costly than suffering a cyberattack,” adds Yeo.

Kaspersky experts also suggest the following tips for SMBs and employees to avoid being lured by cybercriminals through phishing: 

  • Teach employees about the basics of cybersecurity. For example, not opening or storing files from unknown emails or websites as they could be harmful to the whole company, or to not use any personal details in their passwords. In order to ensure passwords are strong, staff shouldn’t use their name, birthday, street address and other personal information.
  • Regularly remind staff of how to deal with sensitive data, for example, to only store it in trusted cloud services that need to be authenticated for access and that it should not be shared with untrusted third parties.
  • Enforce the use of legitimate software, downloaded from official sources.
  • Make backups of essential data and regularly update IT equipment and applications to avoid unpatched vulnerabilities that could cause a breach.
  • Configure Wi-Fi encryption. It is imperative to configure your network connection correctly and set your router’s log-in and password regularly.
  • Use a VPN if connecting to Wi-Fi networks that don’t belong to you. When you’re connected through a VPN, all of your data will be encrypted regardless of the network settings, and outsiders will not be able to read it.
  • Use corporate services for e-mail, messaging, and all other work. Stick to corporate resources when exchanging documents and other information. Those cloud drives, but configured for business, are generally far more reliable than the free user versions. 
  • Protect devices with an antivirus solution. It is vital that you install a reliable security solution on all devices that handle corporate data.

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

White Papers

When compared to 2023, Sophos saw a 51% increase in abusing “Living off the Land” binaries or LOLbins; since 2021, it’s increased by 83%.

HEADLINES

Someone illegally acquires or uses personal information such as bank account or credit card numbers of another person to obtain money, goods or services....

HEADLINES

To stay ahead of these challenges, organizations need to invest in AI-driven defenses, transition to quantum-safe encryption, and adopt a Zero Trust approach to...

HEADLINES

There was a 121% Year-on-Year (YoY) increase in identity fraud in 2024 across the region, with significant surges recorded in Singapore (207%), Thailand (206%)...

HEADLINES

As part of RCBC’s 2024 Cybersecurity literacy program, the webinar aims to help Filipinos level up their online banking safety by providing them with...

White Papers

The survey found that CXO’s feel less prepared than their global peers. Less than half or 48% in APAC said they felt completely prepared...

HEADLINES

On average, a single organization in the Philippines experiences 4,003 attacks per week, significantly higher than the APAC average of 2,870 attacks per week.

White Papers

Exploiting this vulnerability, cybercriminals craft deceptively authentic phishing emails that align with current trends, exploiting human emotions to invoke urgency and trick recipients into...

Advertisement