Site navigation

Biannual Report Reveals Huge Surge in Email Attacks

Graham Turner

,

email attack statistics
Acronis’ end-of-year Cyberthreats Report highlights the rise of generative AI systems to create malware and orchestrate attacks.

Cybersecurity firm Acronis’ Cyberthreats Report, H2 2023 documents alarming rises in cyberattacks, specifically with small-to-medium-businesses (SMBs) and managed service providers (MSPs) in the crosshairs, with data collected from over 1,000,000 unique endpoints across 15 key countries.

The report reveals a significant increase in AI-enhanced phishing, affecting over 90% of organisations and leading to a 222% surge in email attacks in 2023 compared to the second half of 2022. While ransomware variants and new groups decrease, the most infamous families of attack vectors still cause substantial data and financial losses worldwide.

The study emphasises the need for robust security solutions capable of detecting zero-day vulnerabilities exploitation. The report urges organisations to promptly patch vulnerable software to prevent threat actors from gaining domain administrative rights and infiltrating sensitive information.

Behavior-based detection and exploit prevention technology, combined with proper data backup following the 3-2-1 rule (keeping three copies of your data in two different types of media, and one off-site), are crucial for creating a last line of defense.

Candid Wüest, Acronis VP of product management, highlights a disturbing trend of cybercriminals leveraging genAI and LLMs, saying: “There’s a disturbing trend being recognised globally where bad actors continue to leverage ChatGPT and similar generative AI systems to increase cyber-attack efficiency, create malicious code, and automate attacks.”

“Now, more than ever, corporations need to prioritise comprehensive cyber protection solutions to ensure business continuity.”

The report predicts that advanced tactics like supply chain attacks, AI-driven attacks, and state-sponsored incursions are likely to intensify. MSPs are advised to prepare for threats unique to their operations, including “island hopping” and “credential stuffing.” Acronis offers training and certification programs through the MSP Academy to enhance cybersecurity skills.

Key findings from the report include Singapore, Spain, and Brazil being the most targeted countries for malware attacks in Q4 2023, with Acronis blocking nearly 28 million URLs, a 36% decrease compared to Q4 2022. Ransomware remains a major threat, with known gangs including LockBit, Cl0P, BlackCat/ALPHV, Play, and 8Base. Attacks on MSPs continue, and phishing and email attacks remain primary vectors of infection.


Recommended reading


The report underscores the rise of cyber-criminals leveraging AI tools such as WormGPT, FraudGPT, DarkBERT, DarkBART, and ChaosGPT. It emphasises the industry’s ongoing challenges, with bad actors continually profiting from cyber activities and exploiting AI-enhanced techniques for more convincing phishing schemes.

Curated by the advanced Acronis Cyber Protection Operation Center (CPOC), the report includes data on ransomware threats, phishing, malicious websites, software vulnerabilities, and a security forecast for 2024. Acronis releases biannual cyberthreat reports to set industry standards and keep users and partners informed about the global cyberthreat landscape.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data