Challenges of securing access to corporate networks have never been more critical – increasing sophistication coupled with expensive consequences have made cyber attacks a catastrophic global issue.
In order to better understand the nature of these attacks, IS Decisions looked into eight years of open source data to build awareness of the methods and motives behind these attacks.
CountriesÂ
While the UK did not have the most cyber attacks over the past eight years, they came in second place.
The UK suffered from 605 cyber attacks, experiencing 6% of attacks overall. The US took the top spot, with a whopping 4,870 cyber attacks over the past eight years, equalling just over 49% of overall attacks.
Based on the data, the UK’s year-to-year cyber attacks decreased by 32% from 2021 to 2022. Russia saw the largest increase in cyber attacks between 2021 to 2022, increasing by 950%.
The data also reveals that even though crime has dropped, the UK experienced the highest number of cybercrime victims per million internet users of 2022, at 4,783.
François Amigorena, CEO at IS Decisions commented: “Our research has shown that the prevalence of specific motives and the type of attack methods can change year on year. Most notably over the past year, we can see the largest increases in the number of attacks on Russia and Ukraine, which are up by 950% and 400% respectively. The analysis also highlights spikes in attacks with a financial motive during years of economic uncertainty, such as the Covid-19 pandemic.”
Motives
Financially motivated cyber attacks have increased by 686% over the past eight years, and are the only motive in the study which saw year on year growth. Those attacks peaked in 2022 at 1,155.
Unsurprisingly, the biggest increase in financially motivated attacks were in 2019, an increase of 76% in just a year, as many organisations have to adapt to remote working overnight, exposing many vulnerabilities.
A recent study by Deloitte, which revealed that during the pandemic 35% of cyber attacks used previously unseen malware or methods. These new methods included phishing attacks using SMS and vishing, ransomware attacks which combined data leakage to persuade victims to pay ransoms, and phishing campaigns which used news about vaccine developments.
These unseen methods could therefore be a key factor behind the significant increase in successful cyber attacks from 2019 to 2020.
Protest motivated attacks peaked in 2022 at 193, likely impacted by the Russian invasion of Ukraine, as cyber attacks against each country grew by 950% and 400% respectively. Protest was the most common motive in Russia.
Interestingly, political espionage fell year by year from 2019 to 2022 despite growing concerns from governments about the use of cyber attacks during global conflicts – this pattern counters the increase in protest cyber attacks.
Amigorena explained: “Financial gain is a major motive for criminals and data breaches can be devastating for organizations, especially for SMBs who may have smaller financial safety nets. Another consideration is that for many organizations cyber attacks can create a loss of trust in their customer or client base which can lead to further financial losses.”
Recommended
- What does Digital Transformation Mean to Incremental CEO, Mark Skelton?
- Scotland to Benefit from Faster Radiology Reporting
- Understanding Cyber Insurance: How Far Can It Go?
MethodÂ
The exploitation of application servers was the most common method across the different motives.
69% of industrial-espionage attacks used this methods, as well as 42% of financial attacks, 41% of political espionage attacks, and 46% of personal attacks.
Data attacks, such as manipulating, destroying or encrypting a victim’s data through various attack types, are also one of the most common methods that threat actors use. This method was used in 34% of attacks with a sabotage motive and 35% of attacks with a financial motive.
External denial of service attacks, such as DDoS, were most commonly used to create disruption to support a military operation (33%), protest (27%), and sabotage (20%). In February of 2022, the Ukrainian defense ministry was hit by a DDoS attack and two Ukrainian banks lost access to their online banking services.





