Cybercriminals are using valid accounts more often as an entry point for attacks, accounting for 31.4% of cases in 2024, according to Kaspersky’s latest Incident Response analyst report. 

Public-facing applications (application or system that the public can access) remain the top attack vector at 39.2%, but the rise in valid account use signals a shift in hacking methods.

“Cyber threats continue to evolve relentlessly, with attackers adapting their methods to exploit the most vulnerable points in companies’ defenses,” said Konstantin Sapronov, head of the Global Emergency Response Team at Kaspersky.

The increase in valid account attacks is linked to initial access brokers (IABs), who sell stolen login credentials on the darknet. Cybercriminals buy these credentials to access systems without setting off security alarms. This method is often used in Ransomware-as-a-Service (RaaS) operations, where attackers pay for access before launching their attacks.

Selling of stolen credentials in the darknet

The report is based on investigations into security incidents at organizations that sought help from Kaspersky’s team. It highlights growing threats across industries and provides insights to help businesses strengthen their defenses.

Other attack methods have also increased. Cybercriminals exploiting trusted business relationships now account for 12.8% of cases, while phishing remains a common tactic in 9.8% of incidents.

As hackers refine their tactics, the report stresses the need for stronger security practices, continuous monitoring, and fast responses to reduce risks.

“This highlights the critical need for organizations to not only strengthen their immediate security measures but also to cultivate a proactive and adaptive incident response culture that can stay ahead of these emerging risks,” Sapronov said.

Discover more from Back End News

Subscribe now to keep reading and get access to the full archive.

Continue reading