Site icon Back End News

Password stealers target small businesses in SEA

Cybersecurity solutions provider Kaspersky that cybercriminals have launched more than 11 million web attacks against small businesses (SMB) in Southeast Asia (SEA) during the first half of 2022. Most of the incidents are blocked from infecting Kaspersky users from Indonesia, Vietnam, and Thailand.

The highest number of incidents was foiled in Vietnam, Indonesia, and Malaysia during the first half of 2022.

Kaspersky’s telemetry on SMB covers enterprises with 50-250 employees and is based on detection verdicts of Kaspersky products received from SMB users who consented to provide statistical data.

PH ranks third in e-commerce phishing attacks in SEA — Kaspersky
Only half of SMBs are confident ex-employees can’t access corporate data — Kaspersky

Web-based threats, or online threats, are a category of cybersecurity risks that may cause an undesirable event or action via the internet. Web threats are made possible by end-user vulnerabilities, web service developers/operators, or web services themselves.

Password Stealing Ware

Aside from web threats, Kaspersky also has detected over 370,000 Trojan-PSW (Password Stealing Ware) trying to infect SMBs based in the region.

Trojan-PSW is a malware that steals passwords, along with other account information, which then allows attackers to gain access to the corporate network and steal sensitive information.

“Small business owners may think their companies are too insignificant to become a target for cybercriminals,” said Yeo Siang Tiong, general manager for Southeast Asia at Kaspersky. “There is a certain logic in that because attackers usually look for maximum profit from minimum effort. However, enterprises and government organizations should remember that SMBs are usually third-party suppliers to bigger companies and critical entities. This sector is part of a bigger chain and like dominoes, if a single password stealer can enter into a small enterprise’s systems, consider the entire chain compromised.”

To avoid falling victim to web attacks and Trojan password steals, Kaspersky suggests small and medium businesses to follow these tips:

Exit mobile version