Site navigation

600M Cyber-attacks Daily, Microsoft Report Reveals

Staff Writer

,

cyber-attacks microsoft
A rise in sophistication and global security tensions has lead to increased cyber-threats from nation-states and cyber-criminals, which often collaborate on intelligence operations. 

A new report from Microsoft has revealed that every day, over 600 million cyber-criminal and nation-state attacks are levied.

These attacks range from ransomware to identity theft and malware, and continue to blur the lines between nation-state threat actor activity and non-state-affiliated cyber-crime.

This is according to the Microsoft Digital Defense Report 2024, which found that nation-states are regularly collaborating with cyber-criminals to collect intelligence as threat actors serving Russia and Iran continue to lean on cyber and influence operations.

Nation-State Threats

Nation state actors appear to have a range of motivations, as revealed in the report, including espionage, election influence, cryptocurrency theft, cyber-crime services, data destruction and data theft for profit.

Nation-state influence operations tended to converge around the time of major elections for maximum effect. By the end of 2024, two billion people will have had the opportunity to vote in a nationwide election, with Russia, Iran, and China all engaging in election influence efforts during the year.

In 2024, the most targeted industries by nation-state actors included IT (24%) and education and research (21%). Education and research institutions often offer intelligence on policies for the government, and may be used as testing grounds by nation-states.

Countries being hit the most by nation-state cyber-threats, besides the US and the UK, include other countries with active military conflict or regional tensions, including Ukraine, Taiwan, the United Arab Emirates, and the state of Israel.

Microsoft also showed that North Korea is entering the ransomware playing field, with a newly identified North Korean ransomware variant, FakePenny, being aimed at aerospace and defence organisations.

Identity Attacks

The report also highlighted patterns in identity attacks, with more than 99% of them being password attacks, including phishing, breach replay, or password spray tactics.

These rely on predictable human behaviours, such as using easy-to-guess passwords, repeating passwords between sites, or perhaps more importantly, not using multifactor authentication.

In just over the past year, Microsoft said they blocked 7,000 password attacks per second.

Ransomware

Besides this, ransomware has remained a critical cyber concern, as Microsoft observed a 2.7b year-over-year increase in human-operated ransomware-linked encounters.

Despite a rise in the number of encounters, the percentage of organisations that have been ransomed, meaning their ransomed data has reached the encryption stage, decreased by more than threefold over the past two years. So, while ransomware groups may be making more attack attempts, these are not necessarily getting more successful.


Recommended reading


Fraud

Cyber-enabled financial fraud is on the rise globally, with new trends in the misuse of legitimate services.

One such type highlighted by Microsoft is called techscam, which uses fake tech support services and ads impersonating legitimate services to trick users into clicking malicious links or downloading malware.

The paper showed that techscam traffic surged 400% from 2021 to 2023, outpacing rises in malware (180% rise) and phishing (30% rise).

Distributed Denial of Service (DDoS)

DDoS attacks are evolving and growing more sophisticated as they transform to target the application layer.

Microsoft said they mitigated 1.25 million DDoS attacks in just the second half of the year, representing a 4x increase compared with last year.

Application-layer attacks tend to be stealthier, more sophisticated, and harder to mitigate than network-level attacks, making them a greater risk to businesses availability.

DIGIT Staff Writer Robot

Staff Writer

Staff Writer - DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data