26 Jul 2011
Sophisticated marketing and social engineering tactics are helping to change the face of cyber crime, according to the latest quarterly report from security firm IID.
Practices such as targeted phishing attacks and spam campaigns are benefiting from improved marketing techniques and tricks, the firm said.
IID president and chief technology officer Rod Rasmussen told V3 that criminals increasingly rely on compromised accounts to spread attacks to additional targets within an organisation.
He explained that in many cases, an attacker will target staff in strategic roles, such as a human resources manager, and then use the reputation of that stolen account to increase the likelihood of successful attacks on other employees.
"Because this is going on, you are getting communications from an account that you know and trust," he said. "It is always good to ask. Pick up the phone and make a call if something weird is going on."
Underworld interest in accessing that information has also increased lately. Rasmussen explained that online crime forums which previously dealt only in stolen credit card numbers have begun to trade in online account credentials.
The IID executive said that, along with making targeted attacks more effective, a compromised account can be used to break into other accounts owned by the same user.
"It is a cascading effect in a way. One compromise leads to another compromise which leads to even more compromises," Rasmussen said. "A lot of the people doing this are not that sophisticated, but they have access to information."
Criminals can likewise use the stolen credentials from one site to take over additional accounts on other sites because many people reuse their account names and passwords.
"It is not just your password that is important to protect, it is your username as well," Rasmussen said. "That is being driven home as a hard lesson these days."
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
A Multi-national data analytic's and cloud computing...
A multi-national software solutions organisation are...
A multi-national software solution provider are looking...
Service Delivery Manager, Customer Service, PCT, Primary...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?