Rejuvenate IT Logo

Phishing now starts more than half of all attacks – and multi-factor was got round in two thirds

Cisco Talos has published its summary of the incidents its response team handled between April and June. It is a useful document precisely because it is not a survey of opinions – it is a tally of what went wrong at businesses that had to ring for help.

Two figures stand out. Phishing was the way in for more than half of every case, up from about a third the previous quarter. And attackers got past multi-factor authentication in 65 per cent of cases, nearly double the 35 per cent Talos recorded three months earlier.

They did it in four main ways: fake sign-in pages that quietly pass your details to the real site as you type, so the attacker inherits your logged-in session; stealing that session outright; bombarding somebody with approval prompts until they tap yes to make it stop; and simply registering a new device of their own once inside.

Who this affects

Any business that has treated multi-factor as the finish line. It remains the single best thing you can switch on, and none of this is an argument against it – but “we have multi-factor” is now a statement about one obstacle rather than a guarantee.

Talos also found that 42 per cent of the businesses it helped could not see enough of what had happened to answer basic questions, and 31 per cent had something exposed to the internet that was out of date. Attackers made a point of using legitimate remote support software so their activity looked like ordinary IT work – the same pattern behind several incidents this summer.

Healthcare was the most targeted sector at 17 per cent, with public bodies and manufacturing next at 14 per cent each. Talos puts that down to a shared trait rather than a shared industry: these are places that cannot tolerate being stopped, so they are more likely to pay.

What to do with this

  • Move away from typed codes. Number matching, or a physical key, defeats both the fake sign-in page and the approval-prompt bombardment.
  • Make an unexpected prompt a reportable event. If somebody gets an approval request they did not trigger, that is an attacker holding their password. It should raise an alarm, not an eye-roll.
  • Check who can add a new sign-in device. Registering a device of their own was a favourite move. That should be a controlled action.
  • Keep enough records to answer questions. Four in ten businesses could not reconstruct what happened. Logs are dull until the week you need them.
  • Know which remote support tools belong on your machines. If you cannot name them, you cannot spot the one that should not be there.

Where we would start

If you do one thing after reading this, make it the sign-in method – that single change answers most of the 65 per cent. The rest is about being able to see what is happening on your own network, which is the gap Talos found in four out of ten cases.

That visibility is what our managed detection and response provides, with real people watching round the clock rather than a dashboard nobody opens, and our security awareness training covers the prompt-bombing trick directly.

Call us on 01202 237 273 or book a call.