By Ray Birch
CHICAGO—Not only are ransomware attacks continuing to increase, but so, too, is the use of social engineering, according to one company that says the tactic is allowing criminals to more effectively impersonate people in positions of authority, allowing them to fool employees into making critical mistakes.
That can include the longtime threat of clicking on a link and opening the door for ransomware into a system, but it can also include other forms of fraud, especially those that involve wiring money.
Matt Cullina, head of global cyber insurance business for CyberScout, a TransUnion brand, said what he called a “never-ending stream of data breaches,” combined with highly sophisticated and technical attacks, means all of the stolen personal information available on the Dark Web is “continuously replenished.”
“Cybercriminals use that information to impersonate people in positions of authority,”Cullina said. “Once in digital disguise, they can make all kinds of requests for access from unsuspecting people who are just trying to do their jobs or take care of their families.”
A Point of Emphasis
Cullina emphasized the importance of realizing social engineering attacks are not always levied against businesses. In 2023, for example, such attacks were increasingly levied against private individuals, most often by crooks disguised as financial institution employees or law enforcement officials.
“CyberScout observed an unprecedented increase in social engineering attacks in 2023. Cyber claims
stemming from social engineering attacks comprised 50% of all claims in 2023, a stat that barely topped
20% in 2021,” Cullina said.
CyberScout, Cullina said, is forecasting social engineering volume will only increase in 2024, for three reasons.
“Ransomware is becoming increasingly messy, forcing cybercriminals to reach for alternative
attack methods,” said Cullina. “The friction originates from several places: First, governments worldwide are stepping up pursuit and punishment of ransomware gangs while simultaneously outlawing payment of ransom demands.”
As CUToday.info reported, a study from cybersecurity firm Emsisoft recently concluded that banning payment of ransom will be the only way to stop the attacks.
No More Insurance
https://www.cutoday.info/site/THE-feature/A-Strategy-for-Addressing-Big-Risk-to-CUs
Two, while the rate of organizations—at least those acknowledging they were attacked by ransomware—is near 75%, according to Emsisoft—more insurance companies are choosing to not offer ransomware coverage, Cullina said.
And the third reason, according to Cullina, is, “Finally, victims are less inclined to pay a ransom.”
Given that backdrop, Cullina said, “social engineering works and it’s profitable. As just one example, in Q4 2023, CyberScout was contacted by a highly credentialed, intelligent executive who had been tricked into wiring $120,000 to a criminal in disguise as a contractor. Using a method known as pretexting, the criminal convinced the executive the money was past due and needed urgently before a high-stakes project could continue. The Internet Crime Complaint Center (IC3) data show attacks like this are costing victims $50,000 on average.”
‘Untraceable Acts’
There’s another factor at work, according to Cullina, and that is criminals are drawn to “untraceable acts.”
“Social engineering is much better at providing anonymity than ransomware,” Cullina said. “Furthermore, most law enforcement agencies do not have the resources to chase down perpetrators of one-off crimes. Similarly, financial institutions are increasingly unwilling to pursue wire transfer fraud when their customers willingly—albeit, foolishly—authorized the transaction.”
Cullina said that ransomware attacks had exceeded social engineering strikes until 2022.
“That’s when social engineering claims overtook ransomware,” he said. “Today, we are again seeing a pickup in ransomware cases, but not to the extreme levels it was at in 2020 and 2021. It has recovered a bit. But, at just about the same time, in Q1 of 2023, social engineering scams skyrocketed.”
A Broad Definition
Cullina acknowledged the term “social engineering” can be quite broad.
“It encompasses all of the issues—fishing, smishing all of the types of threat actor attempts to get access to your data and your funds,” he said. “But, overall, what the threat actor is doing is getting to know you and know your digital life and trying to understand who they're targeting so they can more easily target you. That could simply mean going on your social media sites and learning about you and your family, where you work, what have you. It could mean you're a prominent small business owner in your community, learning a little bit more about you…”
As Cullina noted, social engineering is often used to create a gateway for ransomware.
“They try to get your credentials by any means necessary by learning about you, getting some password hints and things, and then get access to your credentials to get into the system to commit ransomware,” he said.
Honor Among Thieves
Finally, while Cullina said he is not endorsing payment of the ransom, he said data show crooks largely keep their word.
“Normally the threat actor will lower their ransom demand in the back-and-forth negotiations. And when the electronic currency is delivered to them they send back the tokens or keys to unlock the data,” Cullina shared. “We have never seen a case where they haven't done that, where they haven't given the keys back after payment. These bad guys run a business themselves, these black market companies. They want to live to fight the next day and they have their own reputations to protect. So, giving their data back is one of those things that will make the next company pay.”
