Cyberthreats facing SMBs

April 2024 Editor's Choice

Sophos released its annual 2024 Sophos Threat Report, with this year’s report detailing Cybercrime on Main Street and the biggest threats facing small- and medium-sized businesses (SMBs, organisations with 500 employees or less).

According to the report, in 2023, nearly 50% of malware detections for SMBs were keyloggers, spyware and stealers, malware that attackers use to steal data and credentials. Attackers use this stolen information to gain unauthorised remote access, extort victims, deploy ransomware, and more.

The Sophos report also analyses initial access brokers (IABs) — criminals who specialise in breaking into computer networks. As seen in the report, IABs are using the dark web to advertise their ability and services to break specifically into SMB networks or sell ready-to-go-access to SMBs they have already cracked.

“The value of ‘data’ as currency has increased exponentially among cybercriminals, and this is particularly true for SMBs, which tend to use one service or software application per function for their entire operation. For example, let us say attackers deploy an infostealer on their target’s network to steal credentials and then get hold of the password for the company’s accounting software. Attackers could then access the targeted company’s financials and funnel funds into their is a reason that more than 90% of all cyberattacks reported to Sophos in 2023 involved data or credential theft, whether through ransomware attacks, data extortion, unauthorised remote access, or simply data theft.”

Ransomware remains the biggest cyber threat to SMBs

While the number of ransomware attacks against SMBs has stabilised, it continues to be the biggest cyber threat to SMBs. Out of the SMB cases handled by Sophos Incident Response (IR), which helps organisations under active attack, LockBit was the top ransomware gang wreaking havoc. Akira and BlackCat were second and third, respectively. SMBs studied in the report also faced attacks by lingering older and lesser-known ransomware, such as BitLocker and Crytox.

Ransomware operators continue to change ransomware tactics, according to the report. This includes leveraging remote encryption and targeting managed service providers (MSPs). Between 2022 and 2023, the number of ransomware attacks that involved remote encryption — when attackers use an unmanaged device on organisations’ networks to encrypt files on other systems in the network — increased by 62%.

While the number of ransomware attacks against SMBs has stabilised, it continues to be the biggest cyber threat to SMBs. Out of the SMB cases handled by Sophos Incident Response (IR), which helps organisations under active attack, LockBit was the top ransomware gang wreaking havoc. Akira and BlackCat were second and third, respectively. SMBs studied in the report also faced attacks by lingering older and lesser-known ransomware, such as BitLocker and Crytox.

Ransomware operators continue to change ransomware tactics, according to the report. This includes leveraging remote encryption and targeting managed service providers (MSPs). Between 2022 and 2023, the number of ransomware attacks that involved remote encryption — when attackers use an unmanaged device on organisations’ networks to encrypt files on other systems in the network — increased by 62%.

In addition, this past year, Sophos’s Managed Detection and Response (MDR) team responded to five cases involving small businesses that were attacked through an exploit in their MSPs’ remote monitoring and management (RMM) software.

Social engineering and business email compromise (BEC) attacks

According to the Sophos report, business email compromise (BEC) attacks were the second-highest type of attack that Sophos IR handled in 2023, following ransomware.

These BEC attacks and other social engineering campaigns contain an increasing level of sophistication. Rather than simply sending an email with a malicious attachment, attackers are now more likely to engage with their targets by sending a series of conversational emails back and forth or even calling them.

In an attempt to evade detection by traditional spam prevention tools, attackers are now experimenting with new formats for their malicious content, embedding images containing malicious code or sending malicious attachments in OneNote or archive formats. In one case Sophos investigated, the attackers sent a PDF document with a blurry, unreadable thumbnail of an 'invoice’. The download button contained a link to a malicious website.

For in-depth details about these cybercrimes and more targeting SMBs, please read the 2024 Sophos Threat Report: Cybercrime on Main Street.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Here’s to a SMART 2025
SMART Security Solutions Editor's Choice News & Events
This is the final news brief from SMART Security Solutions for 2024, and the teams would like to take this opportunity to thank our readers, advertisers and partners and wish everyone a safe and secure festive season.

Read more...
SA company develops world-first safe K9 training for drug detection
Editor's Choice News & Events Security Services & Risk Management Government and Parastatal (Industry)
The Braveheart Bio-Dog Academy recently announced the results of its scientific research into training dogs to accurately detect drugs and explosives without harming either the dogs or their handlers.

Read more...
AI-powered automation for an operational efficiency edge
Editor's Choice AI & Data Analytics IoT & Automation
In the fast-moving world of digital transformation, businesses are under immense pressure to accelerate their operations and adapt quickly to stay competitive in an era dominated by AI and technological advancements.

Read more...
Elvey to distribute Tiandy
Elvey Security Technologies Editor's Choice Surveillance News & Events
Tiandy’s presence in South Africa was boosted in November with the announcement that Elvey Security Technologies will distribute a broad range of Tiandy equipment through its channel partners and provide project assistance.

Read more...
Standards for fire detection
SAQCC (Fire) Editor's Choice Fire & Safety Associations
With the increased number of devastating fires reported throughout South Africa, adequate and suitable fire detection cannot be overstated. SAQCC Fire will publish a series of articles in SMART Security Solutions to provide insight into fire detection requirements and importance.

Read more...
Taking fire safety seriously
G2 Fire Editor's Choice Fire & Safety Security Services & Risk Management
To gain insights into how fire systems must be designed, installed and maintained, SMART Security Solutions asked Nichola Allan, MD of G2 Fire, for some insights into the local fire market.

Read more...
The best of local and international
Technoswitch Fire Detection & Suppression Editor's Choice
SMART Security Solutions speaks to Technoswitch’s Managing Director, Brett Birch, to learn more about the company and how it serves the fire safety market in South and sub-Saharan Africa.

Read more...
Creating safer schools across southern Africa
Technews Publishing Editor's Choice
The My Safe Space initiative, conceptualised and steered by James Dalton and a number of partners, aims to addresses bullying in schools and help keep people safe when dropping off or collecting children from school.

Read more...
Understanding operational technology and its critical role in cybersecurity
Editor's Choice
By understanding the role of operational technology and prioritising its security, businesses can ensure the uninterrupted operation of the systems that power our modern world — and protect the consumers who rely on them.

Read more...
Talent and tech: Critical elements for AI success
Editor's Choice
The business value of AI will only be fully realised when enterprises evolve beyond simply consuming the technology to wielding it for competitive advantage, because this is where the magic happens.

Read more...