Credentials and Personal Data Continue to be the Primary Targets of Social Engineering Scams

Stu Sjouwerman | Mar 14, 2019
SE-attacks

Targeted attacks are increasing, with cybercriminals focused on stealing information that can be used to impersonate a user and perpetuate their scams.

It’s one thing to have a user’s credentials – as they are temporary should a user go through a password reset process. So, cyber criminals need to focus their efforts on collecting data from victims that facilitates having enough details to properly impersonate users for the long run. According to security vendor Positive Technology’s latest Cybersecurity Threatscape Q4 2018 report, cybercriminals are doing just that:

  • 48% of attacks are focused on obtaining access to information
  • 28% of attacks focus on credentials as the target
  • 27% of attacks focus on personal data as the target

The collection of both credentials and personal data can facilitate the doxing of an individual, using the personal data (e.g., mother’s maiden name) to gain control over a user’s account on multiple sites (remember, a majority of users reuse passwords).

Organizations are at risk of successful cyberattack in the cloud and on-prem when a user’s credentials and personal data are successfully stolen. Educating users with Security Awareness Training will help them spot scams and fake websites seeking to harvest their credentials and personal data.


Find out how affordable new-school security awareness training is for your organization. Get a quote now.

 
Get A Quote
Request A Demo
 

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.