<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Social Engineering Archives - International Finance</title>
	<atom:link href="https://internationalfinance.com/tag/social-engineering/feed/" rel="self" type="application/rss+xml" />
	<link>https://internationalfinance.com/tag/social-engineering/</link>
	<description>International Finance - Financial News, Magazine and Awards</description>
	<lastBuildDate>Wed, 20 Aug 2025 12:52:00 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.9</generator>

<image>
	<url>https://internationalfinance.com/wp-content/uploads/2020/08/favicon-1-75x75.png</url>
	<title>Social Engineering Archives - International Finance</title>
	<link>https://internationalfinance.com/tag/social-engineering/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Deepfake fallout: Welcome to the age of paranoia</title>
		<link>https://internationalfinance.com/magazine/technology-magazine/deepfake-fallout-welcome-to-the-age-of-paranoia/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=deepfake-fallout-welcome-to-the-age-of-paranoia</link>
					<comments>https://internationalfinance.com/magazine/technology-magazine/deepfake-fallout-welcome-to-the-age-of-paranoia/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Wed, 13 Aug 2025 07:47:15 +0000</pubDate>
				<category><![CDATA[Magazine]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Deepfake]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[GenAI]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Scammers]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=53207</guid>

					<description><![CDATA[<p>In Hong Kong, a financial worker was tricked into paying out $25 million when fraudsters used deepfake technology to impersonate the company’s CFO</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/deepfake-fallout-welcome-to-the-age-of-paranoia/">Deepfake fallout: Welcome to the age of paranoia</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="ai-optimize-54 ai-optimize-introduction"><span data-preserver-spaces="true">In 2025, reports emerged about cybercriminals using deepfake voice and video technology to impersonate senior US government officials and high-profile tech figures in sophisticated phishing campaigns designed to steal sensitive data.</span></p>
<p class="ai-optimize-55"><span data-preserver-spaces="true">According to the FBI, threat actors have been contacting current and former federal and state officials through fake voice and text messages claiming to be from trusted sources. These scammers then attempt to establish rapport before directing victims to malicious websites to extract passwords and other private information.</span></p>
<p class="ai-optimize-56"><span data-preserver-spaces="true">Apart from cautioning about the hackers&#8217; tendency to compromise one official’s account, the FBI believes these threat actors may use that access to impersonate the victims further and target others within their network. Verifying identities, avoiding unsolicited links, and enabling multifactor authentication to protect sensitive accounts will be even more crucial.</span></p>
<p class="ai-optimize-57"><span data-preserver-spaces="true">The FBI and cybersecurity experts </span><span data-preserver-spaces="true">are recommending</span><span data-preserver-spaces="true"> examining media for visual inconsistencies, avoiding software downloads during unverified calls, and never sharing credentials or wallet access unless certain of the source’s legitimacy.</span></p>
<p class="ai-optimize-58"><strong><span data-preserver-spaces="true">An evolving threat</span></strong></p>
<p class="ai-optimize-59"><span data-preserver-spaces="true">Essentially, we are talking about scams where sophisticated AI </span><span data-preserver-spaces="true">is used to create</span> <span data-preserver-spaces="true">highly convincing</span><span data-preserver-spaces="true"> audio, images, text, or videos that look, sound, and act like real people. The easy availability of this technology practically gives fraudsters access to Hollywood-style special effects, enabling bad actors to commit deepfake fraud at scale. The World Bank reports that deepfake fraud has surged by 900% in recent years. Losses fuelled by generative AI </span><span data-preserver-spaces="true">are on track to</span><span data-preserver-spaces="true"> reach $40 billion by 2027.</span></p>
<p class="ai-optimize-60"><span data-preserver-spaces="true">Deepfake fraud has become troubling because of its highly realistic nature, accessibility to fraudsters, and scalability. Generative artificial intelligence and deepfakes are making existing types of fraud, such as new account fraud, account takeover, phishing, impersonations, and social engineering, even more costly. While voice-cloning deepfakes have successfully targeted several global businesses, video-based deepfakes are empowering criminal groups like the Yahoo Boys with compelling romance scams.</span></p>
<p class="ai-optimize-61"><span data-preserver-spaces="true">Consider this: Generative AI rapidly creates images that appear &#8216;realistic&#8217; with almost zero imperfections, eliminating telltale signs of deepfakes such as strange-looking fingers, distorted faces, or stretched-out arms. To make matters worse, using cloud computing, criminals can launch multiple attacks simultaneously or create a large volume of synthetic content for a targeted campaign, such as spear-phishing fraud.</span></p>
<p class="ai-optimize-62"><span data-preserver-spaces="true">Generative AI and deepfakes are already being incorporated into several common frauds. This includes &#8220;New Account Opening Fraud,&#8221; where criminals use deepfake technology with synthetic videos, audio, or images that appear to be a legitimate person opening a new bank account. From there, they can bypass facial recognition or liveness detection measures. By mimicking an account holder’s appearance, voice, and mannerisms, fraudsters can convince a customer service representative to grant them access to someone else’s account.</span></p>
<p class="ai-optimize-63"><span data-preserver-spaces="true">Spelling and grammar mistakes were once obvious red flags of phishing scams. However, thanks to GenAI, criminals are less likely to make these errors. Fraudsters can now craft persuasive phishing messages that are grammatically correct, contextually relevant, and have perfect spelling.</span></p>
<p class="ai-optimize-64"><span data-preserver-spaces="true">Fraudsters can also convincingly imitate individuals in professional settings, such as meetings or legal proceedings, to commit fraud. In personal settings, they can pretend to be a loved one </span><span data-preserver-spaces="true">in need of</span><span data-preserver-spaces="true"> financial or medical help, as in a romance or grandparent scam. Synthetic identities (fake identities created by combining real and fictitious information) are now appearing to look like real people. These synthetic identities are defrauding businesses and other individuals.</span></p>
<p class="ai-optimize-65"><span data-preserver-spaces="true">In Hong Kong, a financial worker was tricked into paying </span><span data-preserver-spaces="true">out</span><span data-preserver-spaces="true"> $25 million when fraudsters used deepfake technology to impersonate the company’s CFO. In Italy, a group of entrepreneurs was targeted by scammers earlier in 2025, who copied the Defence Minister Guido Crosetto’s voice and requested money to help pay the ransom of journalists kidnapped overseas.</span></p>
<p class="ai-optimize-66"><span data-preserver-spaces="true">At least one victim paid €1 million to an overseas account. WPP Digital CEO Mark Read said United Kingdom-based scammers unsuccessfully used a combination of a voice clone and YouTube footage to schedule a meeting with themselves and ad company executives in 2024.</span></p>
<p class="ai-optimize-67"><span data-preserver-spaces="true">Video-based deepfake frauds make impersonation-based fraud, like romance scams, even more difficult to catch. In 2024, American consumers lost an estimated $1.14 billion to romance scams. With deepfake technology, scammers can create a large library of fake online suitors. Aided by advanced large language models (LLMs) like LoveGPT, romance scammers can target multiple victims at the same time.</span></p>
<p class="ai-optimize-68"><span data-preserver-spaces="true">Manipulating publicly available images to commit romance scams has proven effective. In 2024, a scammer used simpler technology to deceive a French woman into believing she was in a relationship with Brad Pitt. Organised romance scam groups like the Yahoo Boys are creating more personalised communication for their targets in real time, making romance scams even more convincing and likely to succeed.</span></p>
<p class="ai-optimize-69"><span data-preserver-spaces="true">Even tech boss Elon Musk couldn&#8217;t save himself from being deepfaked. In 2024, there were reports of AI-powered videos posing as genuine footage of the Tesla and X (formerly Twitter) boss going viral. The New York Times dubbed deepfake “Musk, the Internet’s biggest scammer.”</span></p>
<p class="ai-optimize-70"><span data-preserver-spaces="true">Steve Beauchamp, an 82-year-old retiree, told the New York Times that he drained his retirement fund and invested $690,000 in such a scam over several weeks, convinced that a video he had seen of Musk was real. His money soon vanished without a trace.</span></p>
<p class="ai-optimize-71"><span data-preserver-spaces="true">“Now, whether it was AI making him say </span><span data-preserver-spaces="true">the things that</span><span data-preserver-spaces="true"> he was saying, I </span><span data-preserver-spaces="true">really</span><span data-preserver-spaces="true"> don’t know. But as far as the picture, if somebody had said, Pick him out of a lineup, that’s him. Looked just like Elon Musk, sounded just like Elon Musk, and I thought it was him,” Beauchamp told the NYT.</span></p>
<p class="ai-optimize-72"><span data-preserver-spaces="true">Deepfake-powered videos can fuel other impersonation tactics </span><span data-preserver-spaces="true">like</span><span data-preserver-spaces="true"> &#8220;CEO fraud&#8221; or grandparent scams. If the target believes they are interacting with </span><span data-preserver-spaces="true">the</span><span data-preserver-spaces="true"> real person, they are more inclined to follow their instructions to help their company or a family member.</span></p>
<p class="ai-optimize-73"><span data-preserver-spaces="true">While audio and visual manipulation have emerged as critical components behind the deepfakes&#8217; success, the rest depends on trust. Here, psychological manipulation from social engineering is working wonders for cybercriminals.</span></p>
<p class="ai-optimize-74"><span data-preserver-spaces="true">By scouring information like social media profiles, compromised data, or other sensitive information, fraudsters create specific scenarios that emotionally trigger their targets and quickly gain their attention and trust. </span><span data-preserver-spaces="true">The more detailed </span><span data-preserver-spaces="true">a story the scammer presents</span><span data-preserver-spaces="true">, the more believable it is.</span></p>
<p class="ai-optimize-75"><span data-preserver-spaces="true">Businesses and banks may see a rise in highly personalised “scams as a service” tactics. </span><span data-preserver-spaces="true">Criminals can purchase pre-configured deepfake materials for a specific target (a bank manager or executive)</span><span data-preserver-spaces="true">, in addition to accessing</span><span data-preserver-spaces="true"> information like email lists to gain intel on any financial organisation’s internal hierarchy.</span></p>
<p class="ai-optimize-76"><strong><span data-preserver-spaces="true">Money and trust </span><span data-preserver-spaces="true">getting</span><span data-preserver-spaces="true"> eroded</span></strong></p>
<p class="ai-optimize-77"><span data-preserver-spaces="true">In a 2024 Deloitte poll, 25.9% of executives revealed that their organisations had experienced one or more deepfake incidents targeting financial and accounting data in the 12 months prior, while 50% of all respondents said they expected a rise in attacks over the following 12 months.</span></p>
<p class="ai-optimize-78"><span data-preserver-spaces="true">The United States Financial Crimes Enforcement Network (FinCEN) issued an alert in 2024 to help financial institutions identify fraud schemes that use deepfake media created with GenAI tools.</span></p>
<p class="ai-optimize-79"><span data-preserver-spaces="true">The network observed </span><span data-preserver-spaces="true">an increase in</span><span data-preserver-spaces="true"> suspicious activity reports from financial institutions describing the suspected use of deepfake media in fraud schemes targeting their institutions and customers, beginning in 2023 and continuing into 2024.</span></p>
<p class="ai-optimize-80"><span data-preserver-spaces="true">Deloitte’s Centre for Financial Services predicts that GenAI could enable fraud losses to reach $40 billion in the United States by 2027. To make matters worse, digital trust is “crumbling” under an avalanche of synthetic media, misinformation, and deepfake fraud, according to a new report from Jumio.</span></p>
<p class="ai-optimize-81"><span data-preserver-spaces="true">The firm’s fourth annual &#8220;Jumio Online Identity Study&#8221; surveyed 8,001 adult consumers split equally between the United States, Mexico, the United Kingdom, and Singapore. </span><span data-preserver-spaces="true">They have much in common: </span><span data-preserver-spaces="true">namely,</span><span data-preserver-spaces="true"> a growing fear that AI-powered fraud now poses a greater threat to personal security than traditional forms of identity theft, and a corresponding rise in </span><span data-preserver-spaces="true">skepticism</span><span data-preserver-spaces="true"> about anything and everything online.</span></p>
<p class="ai-optimize-82"><span data-preserver-spaces="true">&#8220;Fraud-as-a-service (FaaS) ecosystems have erupted like a bad rash, enabling even amateur fraudsters to leverage synthetic identities, deepfake videos, and botnet-driven account takeovers. Consumers must navigate scam emails, manipulated social media content, and digitally altered identity documents. Seven out of ten global consumers (69%) indicated they are more </span><span data-preserver-spaces="true">skeptical</span><span data-preserver-spaces="true"> of the content they see online due to AI-generated fraud than they were last year,&#8221; the report noted.</span></p>
<p class="ai-optimize-83"><span data-preserver-spaces="true">When asked who they trust most to protect their </span><span data-preserver-spaces="true">personal</span><span data-preserver-spaces="true"> data, 93% of respondents said they trust themselves over the government or Big Tech.</span></p>
<p class="ai-optimize-84"><span data-preserver-spaces="true">However, Jumio said, “Self-reliance does not mean consumers want to go it alone. </span><span data-preserver-spaces="true">In fact,</span><span data-preserver-spaces="true"> when asked who should be most responsible for stopping AI-powered fraud, 43% pointed to Big Tech, compared to just 18% who chose themselves.”</span></p>
<p class="ai-optimize-85"><span data-preserver-spaces="true">The research further showed that consumers are open to modernised fraud protection, even if it means additional steps. Most respondents globally said they would be willing to spend more time completing comprehensive identity verification processes, especially in sectors where the stakes are high, like banking or healthcare.&#8221;</span></p>
<p class="ai-optimize-86"><span data-preserver-spaces="true">But it also recognises that technology alone is not the answer. Jumio CEO Robert Prigge said, “Building a trustworthy digital world depends on strong consumer education and transparency. </span><span data-preserver-spaces="true">With </span><span data-preserver-spaces="true">day-to-day</span><span data-preserver-spaces="true"> worries about generative algorithmic technologies on the rise, the trust gap </span><span data-preserver-spaces="true">also</span><span data-preserver-spaces="true"> continues to grow proportionally.</span><span data-preserver-spaces="true"> As such, businesses must also earn consumer trust in these protections.”</span></p>
<p class="ai-optimize-87"><strong><span data-preserver-spaces="true">The age of paranoia kicks in</span></strong></p>
<p class="ai-optimize-88"><span data-preserver-spaces="true">Nicole Yelland, who works in public relations for a Detroit-based nonprofit, now conducts a multi-step background check whenever she receives a meeting request from someone she doesn’t know. Yelland runs the person’s information through Spokeo, a personal data aggregator. If the contact claims to speak Spanish, Yelland says, she will casually test their ability to understand and translate trickier phrases. If something doesn’t </span><span data-preserver-spaces="true">quite</span><span data-preserver-spaces="true"> seem right, she’ll ask the person to join a Microsoft Teams call— with their camera on.</span></p>
<p class="ai-optimize-89"><span data-preserver-spaces="true">If Yelland sounds paranoid, that’s because she is. </span><span data-preserver-spaces="true">In January, </span><span data-preserver-spaces="true">before she started her current nonprofit role,</span><span data-preserver-spaces="true"> Yelland says</span><span data-preserver-spaces="true">, </span><span data-preserver-spaces="true">she got roped into an elaborate scam targeting job seekers.</span><span data-preserver-spaces="true"> &#8220;Now, I do the whole verification rigmarole any time someone reaches out to me,” she said to WIRED.</span></p>
<p class="ai-optimize-90"><span data-preserver-spaces="true">In a time when remote work and distributed teams have become commonplace, professional communication channels are no longer safe, thanks to the GenAI-powered scams. The same AI tools that tech companies use to boost worker productivity </span><span data-preserver-spaces="true">are also making</span><span data-preserver-spaces="true"> it easier for criminals and fraudsters to construct fake personas in seconds.</span></p>
<p class="ai-optimize-91"><span data-preserver-spaces="true">Big Tech journalist Lauren Goode said, &#8220;On LinkedIn, it can be hard to distinguish a slightly touched-up headshot of a real person from a too-polished, AI-generated facsimile. Deepfake videos are getting so good that longtime email scammers are pivoting to impersonating people on live video calls. According to the US Federal Trade Commission, reports of job and employment-related scams nearly tripled from 2020 to 2024, and actual losses from those scams have increased from $90 million to $500 million.&#8221;</span></p>
<p class="ai-optimize-92"><span data-preserver-spaces="true">Yelland says the scammers who approached her in January 2025 were impersonating a real company</span><span data-preserver-spaces="true">, one</span><span data-preserver-spaces="true"> with a legitimate product.</span><span data-preserver-spaces="true"> The “hiring manager” she corresponded with over email also seemed legit, even sharing a slide deck outlining the responsibilities of the role they were advertising.</span></p>
<p class="ai-optimize-93"><span data-preserver-spaces="true">However, during the first video interview, Yelland says, the scammers refused to turn their cameras on during a Microsoft Teams meeting </span><span data-preserver-spaces="true">and made</span><span data-preserver-spaces="true"> unusual requests for detailed personal information, including her driver’s license number. Realising she’d been duped, Yelland slammed her laptop shut.</span></p>
<p class="ai-optimize-94"><span data-preserver-spaces="true">These schemes have forced AI players to work on technologies to detect other AI-enabled deepfakes, including GetReal Labs and Reality Defender. OpenAI CEO Sam Altman also runs an identity-verification startup called &#8220;Tools for Humanity,&#8221; which makes eye-scanning devices that capture a person’s biometric data, create a unique identifier for their identity, and store that information on the blockchain. The whole idea behind it is proving “personhood,” or that someone is a real human.</span></p>
<p class="ai-optimize-95"><span data-preserver-spaces="true">&#8220;A section of corporate professionals is also turning to old-fashioned social engineering techniques to verify every fishy-seeming interaction they have. Welcome to the age of paranoia, when someone might ask you to send them an email while you’re mid-conversation on the phone, slide into your Instagram DMs to ensure the LinkedIn message you sent was really from you, or request you text a selfie with a time stamp, proving you are who you claim to be. Some colleagues say they even share code words </span><span data-preserver-spaces="true">with each other</span><span data-preserver-spaces="true">, so they </span><span data-preserver-spaces="true">have a way to</span><span data-preserver-spaces="true"> ensure they’re not being misled if an encounter feels off,&#8221; Goode stated.</span></p>
<p class="ai-optimize-96"><span data-preserver-spaces="true">Daniel Goldman, a blockchain software engineer and former startup founder, said, &#8220;What’s funny is, the lo-fi approach works.&#8221;</span></p>
<p class="ai-optimize-97"><span data-preserver-spaces="true">Goldman began changing his </span><span data-preserver-spaces="true">own</span><span data-preserver-spaces="true"> professional behaviour after he heard</span><span data-preserver-spaces="true"> a prominent figure in the crypto world had been convincingly deepfaked on a video call.</span></p>
<p class="ai-optimize-98"><span data-preserver-spaces="true">He </span><span data-preserver-spaces="true">ended up warning</span><span data-preserver-spaces="true"> his close ones that even if they hear &#8220;his voice&#8221; or &#8220;see him&#8221; on a video call asking for money or an internet password, they should hang up and email him </span><span data-preserver-spaces="true">first</span><span data-preserver-spaces="true"> before doing anything.</span></p>
<p class="ai-optimize-99"><span data-preserver-spaces="true">Ken Schumacher, founder of the recruitment verification service Ropes, has worked with hiring managers who ask job candidates rapid-fire questions about the city where they claim to live on their </span><span data-preserver-spaces="true">resume</span><span data-preserver-spaces="true">, such as their favourite coffee shops and places to hang out. Another verification tactic </span><span data-preserver-spaces="true">being used by people</span><span data-preserver-spaces="true"> is what Schumacher calls the “phone camera trick.”</span></p>
<p class="ai-optimize-100"><span data-preserver-spaces="true">Here, if someone suspects the person they’re talking to over video chat is being deceitful, they can ask them to hold up their phone camera to show their laptop. The idea is to verify whether the individual may be running deepfake technology on their computer, obscuring their true identity or surroundings.</span></p>
<p class="ai-optimize-101"><span data-preserver-spaces="true">However, it’s safe to say this approach can also be off-putting: Honest job candidates may be hesitant to show off the inside of their homes or offices, or worry a hiring manager is trying to learn details about their personal lives.</span></p>
<p class="ai-optimize-102"><span data-preserver-spaces="true">“Everyone is on edge and wary of each other now,” Schumacher says, and it perfectly sums up the mood change people are undergoing in the age of GenAI-powered scams.</span></p>
<p class="ai-optimize-103"><span data-preserver-spaces="true">As deepfakes </span><span data-preserver-spaces="true">grow</span><span data-preserver-spaces="true"> more advanced and accessible, AI-driven scams are reshaping cybercrime. Traditional security is no longer enough; vigilance, identity checks, and robust cybersecurity frameworks are the need of the hour </span><span data-preserver-spaces="true">to counter this rising threat</span><span data-preserver-spaces="true">.</span></p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/deepfake-fallout-welcome-to-the-age-of-paranoia/">Deepfake fallout: Welcome to the age of paranoia</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/magazine/technology-magazine/deepfake-fallout-welcome-to-the-age-of-paranoia/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Data breach nightmare: Are you prepared?</title>
		<link>https://internationalfinance.com/magazine/technology-magazine/data-breach-nightmare-are-you-prepared/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=data-breach-nightmare-are-you-prepared</link>
					<comments>https://internationalfinance.com/magazine/technology-magazine/data-breach-nightmare-are-you-prepared/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Mon, 17 Jun 2024 18:25:48 +0000</pubDate>
				<category><![CDATA[Magazine]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Password]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[Surfshark]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=50196</guid>

					<description><![CDATA[<p>Data breaches in Europe fell four times in Q3 2023, from 48.1 million in Q2 of 2023 to 10.9 million in Q3 of 2023</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/data-breach-nightmare-are-you-prepared/">Data breach nightmare: Are you prepared?</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>World Backup Day 2024 has passed, but the frightening probability of data loss is still very much there. According to Statista, during the fourth quarter of 2023, over eight million records were compromised due to data breaches globally. It shouldn&#8217;t be unclear to any organisation—the question isn&#8217;t if, but when.</p>
<p>Verizon&#8217;s 2024 Data Breach Investigations Report states that the &#8220;Human Element&#8221; is responsible for an astounding 74% of breaches. These security lapses result from a variety of human errors, including devious social engineering schemes, unintentional mistakes, and improper use of confidential data.</p>
<p>And the above percentage has remained consistent with the 2023 data, suggesting that the human element remains a steady risk concern. However, reporting practices have improved this year, with 20% of the surveyed individuals recognising phishing in simulated exercises. Some 11% of individuals who clicked a malicious email reported it.</p>
<p>A dire picture is painted by IBM&#8217;s 2023 Cost of a Data Breach Report, which shows that data breach costs have reached an all-time high of $4.45 million on average in 2023. The ramifications are complex. Data breaches cause irreversible harm to a company&#8217;s reputation, undermining customer trust and drawing regulatory attention, in addition to complicated legal issues and large fines. This is a nightmare situation for any business.</p>
<p>Most likely, we&#8217;ve made mistakes that lead to data loss: losing or erasing files, sending the wrong person an email, leaving computers open while getting coffee, inadvertently providing information to unsolicited enquiries, and so on.</p>
<p>This article will explore the top five data management mistakes made by people that lead to data loss and what businesses can do to prevent them.</p>
<p><strong>Ignoring updates and patches</strong></p>
<p>The convenience of technology can lead people to become complacent about keeping their software up to date. This lackadaisical approach can have serious consequences, as failing to install updates leaves systems vulnerable to security breaches. Neglecting software maintenance can give hackers an easy opportunity to exploit weaknesses. Without proper backups, recovering lost data can be extremely difficult.</p>
<p>Organisations can strengthen their defences and vaccinate themselves against potential threats by maintaining software at all times and taking a proactive approach to maintenance.</p>
<p><strong>Poorly managed high-privileged accounts</strong></p>
<p>According to the Netwrix 2018 IT Risks Report, only 38% of organisations update admin passwords quarterly, with the rest doing so annually or less frequently. This lack of regular updates leaves accounts with high privileges vulnerable to attacks, as malicious actors can exploit compromised credentials to gain access to sensitive company data.</p>
<p>Implementing the least-privilege principle for all accounts and systems can help prevent unauthorised access and minimise the impact of security breaches such as accidental deletions or ransomware attacks. Monitoring temporary privileges in real-time, using separate administrative and employee accounts, upgrading email security, and implementing two-factor authentication are additional measures organisations can take to enhance cybersecurity.</p>
<p><strong>Inadequate password practices</strong></p>
<p>According to LastPass&#8217;s Psychology of Passwords Report, 59% of users use the same password for all of their accounts, increasing the possibility of credential compromise. Certain users continue to use passwords that are simple to decipher, like &#8220;password&#8221; or &#8220;123456.&#8221; Even strong passwords can be compromised, particularly if they are shared with colleagues or kept on unprotected devices or documents.</p>
<p>IT professionals are not immune to human error either. According to The 2020 State of Password and Authentication Security Behaviours Report by The Ponemon Institute, 42% of organisations use sticky notes for password management, and 53% of respondents use email to share passwords with coworkers in Bitwarden&#8217;s 2022 Password Decisions Survey. Even more concerning: according to Keeper Security&#8217;s Workplace Password Malpractice Report 2021, 44% of employees claim to use the same login information for both personal and professional accounts.</p>
<p>In addition to employing a password manager and changing passwords on a regular basis, staff members ought to receive training so they can be aware of the repercussions of weak password security. Reminders about security should be incorporated into login procedures by organisations.</p>
<p><strong>Allowing unauthorised access to company-issued devices</strong></p>
<p>There are many new security risks brought about by the blending of personal and professional domains. According to Statista, up to 20% of UK workers permitted friends and family to use company-issued devices in 2021. Although it might seem harmless to let someone quickly check their email, doing so puts sensitive data at risk of malware incursions. Friends and family are unlikely to purposefully snoop for private information, but they could unintentionally download malware that gives access to cloud storage, business data, and applications.</p>
<p>Companies need to set up explicit guidelines for using devices. For employees who work remotely or are on the go and need access to confidential company information, Kingston Technology&#8217;s encrypted USB drives and SSDs are an excellent option. The essential security features for every device should be installed, such as screen locks, two-factor authentication, application blacklisting, and remote wiping programmes.<br />
Succumbing to phishing/social engineering attacks<br />
Studies show that 98% of cyberattacks use social engineering and phishing techniques. These attacks are widespread. Hackers frequently use false emails to trick people into clicking on malicious links or opening infected attachments, which can lead to the disclosure of private information or the download of malware.<br />
For instance, a notification to view a file shared by a colleague or reset a password. These attacks have the potential to permanently destroy data if they are used to spread ransomware or other forms of malware. Many people continue to fall prey to these threats despite increased awareness of them because they lack cybersecurity training and caution.</p>
<p>It&#8217;s critical to give staff members regular, continuing education. While there is no way to completely prevent unintentional data loss, the risk can be significantly reduced by creating and routinely testing an extensive business continuity plan.</p>
<p><strong>India: The epicentre for data breach?</strong></p>
<p>As per a cybersecurity report by Surfshark, India ranked 10th globally in Q3 2023 with 369,000 compromised accounts. It remained among the most compromised nations globally, even though the quantity of compromised accounts declined, for the third consecutive quarter in 2023.</p>
<p>After China and Malaysia, India ranked third in Asia for the number of accounts that were compromised during the third quarter. According to the report, 31.5% of all accounts worldwide had their security compromised; the United States ranked highest, accounting for 26% of all breaches that occurred between July and September. China, Mexico, and France are in order of precedence, with Russia in second place.</p>
<p>According to the most recent Surfshark data, India ranked higher in Q3 of 2023 than in Q2 of 2023 for data breaches. India&#8217;s breach rate decreased by 74%, propelling the country from seventh to 10th place in the world rankings. This corresponds to a decrease in compromised accounts from 11.4 million in Q2 to 369,000 in Q3.</p>
<p>During an interaction with Business Today, Agneska Sablovskaja, Lead Researcher at Surfshark, said, &#8220;The third quarter of 2023 shows a general decrease in data breach count. Yet every minute, over 240 online accounts were compromised globally, exposing sensitive information to malicious actors. We recommend a vigilant approach by maintaining accounts only on actively used platforms and implementing two-factor authentication for enhanced security.&#8221;</p>
<p>Data breaches in Europe fell four times in Q3 2023, from 48.1 million in Q2 of 2023 to 10.9 million in Q3 of 2023. To put this into perspective, one in 2.9 accounts compromised in Q3 2023 came from Europe, with Russia accounting for 65% of these breaches.</p>
<p>The study found that an additional 12% of the accounts came from Asia (3.8 million). Less than 8% of the total for the quarter came from any other region, and nearly 15% is still unidentified. Oceania saw the biggest quarter-over-quarter decline of any region, down 91%, from 3.3 million compromised accounts in Q2 2023 to 289.6000 in Q3 2023.</p>
<p>All in all, in today&#8217;s digital world, data loss is not just a technical issue, but a very human one. Mistakes happen, and businesses need to be ready for the unfortunate reality of data loss caused by human error. With the increase in ransomware attacks, regular backups are crucial in preventing permanent data loss. Employee training and stricter access controls also play a key role in protecting data.</p>
<p>Hardware-encrypted solutions provide stronger data protection compared to software-based options, ensuring essential files are safeguarded. By acknowledging the impact of human behaviour on vulnerabilities and implementing proactive security measures, organisations can better prepare for potential data loss incidents.</p>
<p>The post <a href="https://internationalfinance.com/magazine/technology-magazine/data-breach-nightmare-are-you-prepared/">Data breach nightmare: Are you prepared?</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/magazine/technology-magazine/data-breach-nightmare-are-you-prepared/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
