Site navigation

ICO Hit With Huge Increase in Email Attacks

Graham Turner

,

ICO email attacks
2021 saw a 2,650% surge in email attacks as cyber-criminals targeted confidential data through the Information Commissioners Office (ICO).

ICO email attacks – by way of malware, phishing and spam emails – saw a huge surge last year, according to official figures.

The data, retrieved by the Freedom of Information Act (FOI) and analysed by the Parliament Street think tank, uncovered the volume of phishing emails detected, malware detected and blocked, and spam detected and blocked month by month in 2021.

The number of attacks rose significantly from 150,317 in January to a startling 4,135,075 in December, an increase of 2,650%.

“The pandemic continues to be a catalyst for opportunistic cyber-criminals to try and prey on unsuspecting, vulnerable people,” commented  Steven Peake, Manager for Barracuda Networks.

He added: “It is hardly surprising to see major organisations, such as the ICO, hit by such a high volume of threats as they represent lucrative targets. Phishing emails, malware and spam in particular account for a large proportion of the threats these organisations face so they need to implement measures to protect themselves. These cyberattackers aren’t going anywhere anytime soon.”

Detected and blocked spam accounted for the majority of the attacks on the ICO, with a 2,775% increase between January and December, with December in particular seeing a huge spike in attacks.

Phishing emails rose by 20% from January to December, whilst malware soared by 423%.

The bulk of the December attacks came from spam, with 4,125,992 attacks, whilst phishing emails made up 7,886 attacks and malware accounted for 1,197 attacks.

The giant leap in ICO email attacks through December coincides with the mass spread of the Omicron variant which came accompanied with a swarm of Covid test related attacks, as well as Christmas scams in the lead up to the holidays.


Recommended


Edward Blake, Area Vice President EMEA, Absolute Software, commented and offered some advice, saying: “Cyberattacks are targeting organisations across the globe at an alarming rate, once again reminding businesses of the need to re-evaluate and revamp their security protection if it is not up to scratch.

“Cybersecurity is not just about protecting endpoints via anti-malware or email cybersecurity solutions. Whilst these are important, there are now a variety of access points for cyber criminals to capitalise on that IT leaders need to be aware of. These include vulnerable unpatched applications and network vulnerabilities, stolen or illegally purchased log-in credentials, or even by hacking unprotected smart devices.

“In fact, it’s no longer even safe to assume that a cyber-criminal hasn’t already gained access to your organisation’s system, which is why it’s imperative that businesses adopt a Zero Trust approach to their cyber defences. This will ensure that malicious actors can not move laterally across a network once they have gained access, ensuring that a breach in the system does not necessarily equate to a breach in data.”


Scot-Secure 2022 – Scotland’s Largest Annual Cyber Security Summit

The 8th annual Scot-Secure Summit will take place on 23rd March at Dynamic Earth in Edinburgh, and streamed live through our virtual conference platform.

The programme will focus on promoting best-practice cyber security; looking at the current trends, key threats, and offering practical advice on improving resilience and implementing effective security measures.

For more information, visit www.scot-secure.com.

Graham Turner

Sub Editor

Latest News

Cybersecurity Editor's Picks

OpenAI Flags Potential ‘Critical’ Cyber Risk From Astra

Business Featured Funding

VC Access Expanded For Early-stage Companies in UK

Business Editor's Picks Technology

Comment | Managing Risk in Multi-Supplier SaaS Procurements

AI Recruitment Skills

Young Scots Seek Jobs That AI Can’t Replace