https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

MSSP Insider


Shutterstock

Cybersecurity Roundup

Twitter Cyberattack Could Prompt Surge in Similar Hacks

  • Written by Edward Gately
  • July 24, 2020
Companies need a strong, layered defense to thwart such attacks every time.

… the perpetrator behaves differently. If stolen credentials aren’t useful, there is much less incentive for an attacker to send phishing attacks, spread credential stealing malware, and attempt to socially engineer access to user credentials, reducing the number of effective attacks you need to guard against.

Barracuda: Specialized Economy Around ATO

A specialized economy has emerged around email account takeover (ATO), according to a new report by Barracuda.

Over the past year, Barracuda researchers teamed up with researchers at UC Berkeley. They studied the end-to-end life cycle of a compromised account. They examined 159 compromised accounts that span 111 organizations.

Highlights from the report include:

  • More than one-third of the hijacked accounts had attackers dwelling in the account for more than one week.
  • One in five (20%) compromised accounts appear in at least one online password data breach. This suggests cybercriminals are exploiting credential reuse across employees’ personal and organization accounts.
  • In 31% of these compromises, one set of attackers focuses on compromising accounts. The attackers then sell account access to another set of cybercriminals who focus on monetizing the hijacked accounts.
  • Almost four in five (78%) attackers did not access any applications outside of email.

Neil Shah is a cybersecurity software technologist at Barracuda Networks. He said the report includes two “quite surprising” findings.

Barracuda's Neil Shah

Barracuda’s Neil Shah

“We see evidence of some accounts being compromised and exploited by a single attacker, while on the other side we see accounts being compromised by one attacker and likely sold to another attacker that uses and extracts value from the accounts,” he said. “Therefore, a more mature economy seems to be growing where attackers are specializing in their roles of compromising accounts and extracting value from accounts. Secondly, with each of these enterprise accounts having access to many Office 365 cloud applications, such as SharePoint and Microsoft Teams, we still see that 78% of attackers still only access email. That was a slight shock to me, but it comes to show that email contains sufficient information/value for attackers, such as contact lists and potentially sensitive communication among employees.”

Preventing ATO is a complex task, Shah said.

“All an attacker really needs to do is gain access to one employee account within an enterprise, and they now have access to a wealth of business information, functionality and sensitive enterprise emails,” he said. “In addition, they would potentially be able to launch additional attacks against other users using the trusted identity of the compromised account.”

Real-time detectors can be useful in defending against ATOs, Shah said. In addition, non-real-time detection can still be fairly valuable, he said.

“Namely, a detector that monitors continuous activity after the initial compromise can still mitigate significant damage,” he said. “We also found that 20% of enterprise accounts within our study were compromised via an external data breach, which further illustrates the value in a non-real time detector in the need of monitoring continuous activity in an account. Another thing is that organizations should train their employees on the importance of password management and the dangers of password reuse between any accounts, especially personal and enterprise accounts.”

Once attackers penetrate the enterprise border and gain access to enterprise accounts, the damages can be …

  • Page 1
  • Page 2
  • Page 3
  • Page 4
Tags: MSPs Cloud and Edge Endpoint MSSP Insider Network Security

Most Recent


  • Dark Web, hacker
    Kaspersky Study: Dark Web Ads Offer Jobs, Careers in Cyber Crime
    Some dark web job ads included bonuses and commissions for successful projects.
  • Man's silhouette behind a transparent cell graphic and the letters RMM
    Hackers Use Legitimate RMM Software to Steal from Federal Employees
    Attacks on RMMs have caused "insurmountable" losses for SMBs.
  • INtelisys AMP'd Newport Beach 2023
    Intelisys AMP'd Images: Partners Explore B2B Purchasing Trends, CX, Security Solutions
    Customers "literally don't know" how their own buying journey works, and that's an opportunity for partners.
  • Slow investment
    The Gately Report: Cybersecurity M&A, Investment Likely to Cool Somewhat in 2023
    Meantime, the FBI prevented more than $130 million in ransom payments to the Hive ransomware group.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Security Vulnerability
    Older Fortinet Vulnerabilities Lead to Attack on Local Government Office
  • Threats
    Cybersecurity and Threat Protection: MSSPs, Get Your Advice Here
  • DevSecOps
    ServiceNow, Microsoft Set to Deliver Broad SecOps Integration
  • Dunce Cap Businessman
    Tired of MSSPs ‘Failing,’ Nuspire Debuts Platform to Combat Cyberattacks

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Kaspersky Study: Dark Web Ads Offer Jobs, Careers in Cyber Crime

January 30, 2023

7 Channel People Making Waves This Week at 8×8, Intel, Google Cloud, RingCentral, More

January 27, 2023

Intelisys AMP’d Images: Partners Explore B2B Purchasing Trends, CX, Security Solutions

January 27, 2023

Industry Perspectives

View all

The Benefits of Hiring an Investment Bank

January 30, 2023

Make the Most of the Gift of Time in 2023

January 25, 2023

Strong Partnerships Ease Challenging UPS Upgrade

January 24, 2023

Webinars

View all

Next-Generation MSP Platform: The Building Blocks for Your Business

February 15, 2023

Security Secrets of the MSP 501: How to Be a Cyber Leader in 2023

December 15, 2022
  • 1

Cybersecurity Certifications: Their Evolving Role in the Fight Against Increasing Attacks

December 13, 2022

White Papers

View all

Overcoming Your Endpoint Security Limitations with a Skeleton Crew

October 25, 2022

Embracing the Zero Trust Mindset For Endpoints

October 24, 2022

Endpoints are the Destination

October 24, 2022

Channel Futures TV

View all

Coffee with Craig and James Episode 117: Cato Networks, Video Killed the Podcast Stars

Retired Astronaut Capt. Scott Kelly Previews His CP Expo Keynote

December 21, 2022

Fusion Connect Eyes Future with Intrado UC, Managed Network Customers

September 23, 2022

RingCentral Focused on Hybrid Work, Microsoft Teams, Other Integrations

September 23, 2022

Twitter

ChannelFutures

.@Avant_CCC offers tips on #CPaaS sales, ideal customers and tech benefits on #ChannelFuturesTV.… twitter.com/i/web/status/1…

January 30, 2023
ChannelFutures

.@kaspersky study examines thousands of employment ads on the #DarkWeb. dlvr.it/ShhH2m https://t.co/zli195hsBz

January 30, 2023
ChannelFutures

.@IngramCloud makes important @Microsoft-related changes to its #cloudmarketplace. dlvr.it/ShhCpR https://t.co/0zwCkUOH5z

January 30, 2023
ChannelFutures

A @NICELtd - @Cognizant partnership promises to accelerate customer adoption of advance #CX solutions.… twitter.com/i/web/status/1…

January 30, 2023
ChannelFutures

Cybersecurity advisory warns of hackers' malicious use of #RMM. @CISACyber dlvr.it/ShYRwg https://t.co/zsBvQWqOYY

January 27, 2023
ChannelFutures

Reaction to #Intel earnings coming in fast and furious. Find out what investors are saying, and how CEO Pat Gelsing… twitter.com/i/web/status/1…

January 27, 2023
ChannelFutures

Our latest #GatelyReport looks at #cybersecurity M&A, investment with @progresspartner, @cyber_advisory, @FBI Hive… twitter.com/i/web/status/1…

January 27, 2023
ChannelFutures

.@channelsmart says plan and boost client #retention efforts to reduce #churn. dlvr.it/ShXvhj https://t.co/4jyHPCjTBn

January 27, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X