Site navigation

UK Businesses Most at Risk From ERP System Hacking

Theo Priestley

,

ERP system hacking
A new US Homeland Security study finds ERP system hacking is becoming more prevalent, saying those using Oracle and SAP software are most at risk.

The study, backed by an official report issued by the United States Computer Emergency Readiness Team (US-CERT) describes an increase in the exploitation of vulnerabilities in Enterprise Resource Planning (ERP) applications.

ERP applications help organisations manage critical business processes, such as;

  • product lifecycle management
  • purchasing and invoicing
  • procurement
  • customer relationship management and,
  • supply chain management

Attackers are actively targeting these exploits and vulnerabilities within the ERP applications to obtain access to sensitive information, disrupt critical business operations and steal personal credentials.

Oracle and SAP Applications in the Firing Line

The research conducted focused exclusively on ERP system hacking that targeted Oracle and SAP applications, the two largest ERP vendors used by the vast majority of large businesses.

More than 200 SAP exploits and 2,500 Oracle exploits dating back over a decade are detailed in another highly critical ‘ERP Applications Under Fire‘ report by Digital Shadows, stating that there has been a dramatic increase in the interest in exploits for SAP applications, including SAP HANA, in dark web and cybercriminal forums.

In one example it was highlighted that the use of several botnets of the Dridex malware, set up over 2017 and 2018, allows cyber criminals to steal valid SAP user credentials and access companies’ internal IT environments.

In 2016 it was identified that at least 36 organisations worldwide were affected by an SAP vulnerability which resided on the SAP application layer, making it independent of the operating system and database applications that supported the SAP system.

A SAP spokesperson commenting on the report’s findings stated “Our recommendation to all of our customers is to implement SAP security patches as soon as they are available – typically on the second Tuesday of every month to protect SAP infrastructure from attacks.”

UK Businesses at Risk

Although US businesses are most vulnerable from ERP system hacking, according to the report the UK is the most exposed nation in Europe for internet-facing Oracle applications, while Germany has the most internet-facing SAP applications.

This is especially worrying as SAP in their own marketing literature claim “77% of the world’s transaction revenue touches an SAP system; 92% of the Forbes Global 2000 run SAP.”

In fact, the report goes on to detail that simply using a Google search can expose URLs for ERP systems used within corporations.

By simply using Google, it was possible to detect around 100 SAP ITS components that are internet-facing and indexed by the Google search engine.

The report recommends that all businesses take appropriate measures to mitigate the risk of being targeted, advising that “ERP applications are clearly a target for cyber attackers and it is no longer an option to rely solely on identity management and segregation of duties controls, as they are ineffective to prevent or detect these evolved risks.”

Theo Priestley

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data