Cybersecurity Consciousness Month attracts to a detailed and Halloween is simply across the nook, so here’s a bunch of spine-tingling figures about some very actual tips and threats lurking on-line
30 Oct 2023
4 min. learn
October is Cybersecurity Consciousness Month (CSAM) within the US and Canada and European Cybersecurity Month (ECMS) on the opposite aspect of the pond. These campaigns symbolize a terrific alternative to share finest follow and enhance consciousness of all issues cybersecurity amongst companies and shoppers alike.
However October can be the scariest month of the yr. So with Halloween simply across the nook, it appeared like a good suggestion to mix the 2 occasions, and share 20 prime details and figures to scare the wits out of anybody who values their safety. Why 20? As a result of 2023 marks 20 years of CSAM.
This yr’s CSAM has a quite simple four-pronged message for bettering your safety:
- Use sturdy passwords and a password supervisor
- Activate multi-factor authentication (MFA)
- Acknowledge and report phishing
- Replace your software program
Our prime 20 spooky safety details that may hang-out you
With the above in thoughts, listed below are 20 terrifying safety details to maintain these suggestions prime of thoughts:
- Phishing was the most typical type of cybercrime in opposition to companies and shoppers final yr, in accordance with incidents reported to the FBI. There have been 300,000 in whole reported in 2022, though even this doubtless represents simply the tip of the iceberg.
- Phishing assaults use many lures. The commonest within the first half of 2023 was social media-themed lures, in accordance with ESET Risk Report H1 2023. These accounted for 37.5% of all phishing web sites.
- Username/password combos are in excessive demand, as a result of they will grant hackers entry to your on-line private and banking accounts. One 2022 report discovered greater than 24 billion such combos on the darkish internet, up from 15 billion in 2020.
- Software program updates are important to repair newly found vulnerabilities which cybercriminals can in any other case exploit. Final yr, a document quantity of those vulnerabilities have been found and printed: 25,096.
- Some 80% of vulnerabilities reported in 2022 have been both medium or excessive severity, with 16% deemed vital. Nevertheless, even non-critical vulnerabilities may be exploited by cybercriminals to damaging impact.
- Phishing continues to be an enormous money-maker for cybercriminals. In 2022 alone it value shoppers and companies over $52 million, in accordance with the FBI.
- MFA is an effective way to mitigate the specter of phishing and safe your on-line accounts. But 44% of People are solely “considerably acquainted” or haven’t heard of it in any respect, in accordance with one research.
- It’s not notably shocking then that solely 2.6% of X (previously Twitter) customers have MFA switched on to guard their account from phishing. Social media is a well-liked goal for cybercriminals, so you need to guard your accounts from unlawful takeover.
- Not all varieties of MFA are created equal, as a result of hackers can intercept codes despatched over textual content with relative ease. But SMS remains to be the most well-liked type of MFA. On Twitter (now X), it accounted for 74% of MFA in 2021, adopted by the safer choices of authentication apps (29%) and safety keys (1%).
- It’s necessary to make use of distinctive, hard-to-guess credentials for your whole accounts. A 2022 research by Digital Shadows discovered that 40 of the highest 50 most typical passwords may be cracked in below a second.
- In line with the identical research, almost one in each 200 passwords is “123456,” which may be simply guessed by cybercriminals.
- It’s essential to alter your passwords if they’ve been concerned in a knowledge breach. But in accordance with one 2021 research, lower than half (48%) of breach victims change the passwords on the breached account.
- Password reuse is harmful as it may well allow hackers to open lots of your accounts with a single stolen credential. But simply 15% of shoppers use a novel password on every account.
- Stolen credentials can have a vital affect in your digital life and funds. Over half (55%) of id crimes stemmed from compromised passwords final yr.
- Identification fraud stemming from stolen passwords may even trigger emotional and psychological issues. Almost a fifth (16%) of US victims reported ideas of suicide when interviewed this yr.
- When cybercriminals pay money for your passwords, they will hijack your social, banking and different accounts. Over a fifth (22%) of US adults have been a sufferer of account takeover (ATO), in accordance with one 2021 research.
- Account takeover can value victims expensive: the common monetary loss from monetary ATO assaults is almost $12,000.
- As consciousness grows, issues over cybersecurity are additionally growing. Almost half (46%) of People really feel assured concerning the safety of their on-line accounts and 56% are extra involved about their on-line security than ever earlier than, in accordance with Google.
- Password resets are necessary if you happen to’re involved your account could have been breached, or a corporation you do enterprise with notifies you of a breach. A fifth (21%) of People reset their passwords day by day or a number of occasions every week, which can suggest that they rely an excessive amount of on reminiscence.
- Password managers are an effective way to retailer lengthy, sturdy and distinctive passwords for each app and website. But, in accordance with the identical survey, solely 44% of People at the moment use one.
Keep in mind: good cybersecurity is for all yr spherical, not only for Halloween. So replace your software program when prompted, select sturdy and distinctive passwords or passphrases and retailer them in a password supervisor, change on MFA on all accounts that supply it, and get acquainted with tell-tale phishing techniques. Keep secure.
This video will even assist put you heading in the right direction to raised password safety: