Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Security NewswireCybersecurity News

Internet Security Threat Report Reveals 81 Percent Increase in Malicious Attacks

May 2, 2012

The number of security vulnerabilities declined in 2011 but malicious attacks skyrocketed 81 percent from 2010, according a new Internet Security Threat Report by Symantec.

Advanced targeted attacks, in particular, were on the rise in 2011 and they are spreading to organizations of all sizes.

"Targeted attacks have changed," says Liam O Murchu, manager of security response operations for North America at Symantec. "The picture that we had before of targeted attacks was they went after CEOs or other top people in a company, and they went after very large companies and government agencies. Targeted attacks are now being spread out and used in far more scenarios."

O Murchu said the number of daily targeted attacks increased to an average of 94 per day by the end of November 2011. While targeted attacks have traditionally focused on the public sector and large organizations, more than 50 percent of targeted attacks in 2011 took aim at organizations with fewer than 2,500 employees. Nearly 18 percent of targeted attacks focused on companies with fewer than 250 employees.

O Murchu believes attackers may be targeting these smaller companies because they are in the supply chain or partner ecosystem of a larger company and are less well defended.

Attackers-who primarily use social engineering and malware to gain access to sensitive information-are also diversifying their targets within organizations. In the past, attackers largely focused their efforts on high-level executives, but 58 percent of attacks in 2011 targeted non-executives. O Murchu says many of the targets were in roles such as human resources, public relations and sales. While these workers may not have access to the data the attacker is ultimately after, they are often a convenient vector for penetrating an organization's defenses because they are easy to identify online and are used to being contacted and sent attachments (like resumes) from unknown sources.

Since many companies lack role-based access management that control what resources individual workers have access to depending on their role within the company, an attacker who successfully targets one of these workers often has access to a great deal of sensitive data.

"What companies need to realize right now is that once attackers get inside the perimeter of their network, they're going to spread out," O Murchu says. "Your defenses should not be focused primarily on the perimeter of the network. You should access controls set up correctly on all of your valuable data. And you should have applications in place that can watch for the loss of valuable data."

Symantec found more than 232.4 million identities were exposed overall in 2011, with an average of 1.1 million identities stolen per data breach. Attackers especially targeted the healthcare vertical. At 43 percent, Healthcare topped the list of sectors by number of data breaches. Government and education were numbers two and three, with 14 percent and 13 percent, respectively.

"We did see healthcare particularly targeted," O Murchu says. "It's likely that's because the attackers see healthcare providers as an easier target. They know they're going to have a large amount of information on their customers if they can get in."

But while the healthcare sector led the pack in number of data breaches, the picture is very different when measured by the number of identities exposed in breaches. There, healthcare was third, accounting for 8 percent of identities exposed in 2011. Instead, the Computer Software and Information Technology sectors were far and away the greatest culprits. The Computer Software sector accounted for 44 percent of the number of identities exposed, despite representing only 5 percent of the number of data breaches in 2011. The Information Technology sector accounted for 41 percent of the number of identities exposed, despite representing only 3 percent of the number of data breaches in 2011.

Hacking attacks were not the most frequent cause of data breaches, but they had the greatest effect. Hacking attacks exposed more than 187.2 million identities in 2011 according to the Norton Cybercrime Index. Lost or stolen devices-USB sticks, laptops, smartphones and tablets-accounted for 34.3 percent of breaches, making it the largest category. Theft or loss of these devices accounted for 18.5 million exposed identities.

Separately, Symantec said that spam levels dropped considerably in 2011, from 88.5 percent of all email in 2010 to 75.1 percent of all email in 2011. Symantec said that on average, 42 million spam messages were in global circulation per day in 2011, compared with 66.1 billion per day in 2010. Some of that may be the result of the takedown of the Rustock botnet. That botnet primarily pumped out pharmaceutical spam, and that category of spam was down 34 percent between 2010 and 2011. However, Symantec noted that the drop in spam may also be a result of attackers turning their attention to social networks as attack vectors. Recipients of such messages in social networks are often more apt to believe the links come from a trusted source.

KEYWORDS: cybercrime

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Half open laptop in blue

    There was an 81% year-over-year increase in ransomware attacks

    See More
  • Cisco Security Report Shows Unprecedented Growth of Advanced Attacks and Malicious Traffic

    See More
  • phishing

    Lookout Report: 37% Increase in Worldwide in Enterprise Mobile Phishing Attacks

    See More

Related Products

See More Products
  • 9780367221942.jpg

    From Visual Surveillance to Internet of Things: Technology and Applications

  • threat and detection.jpg

    Surveillance and Threat Detection

  • Hospitality Security: Managing Security in Today's Hotel, Lodging, Entertainment, and Tourism Environment

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing