{"id":49882,"date":"2022-06-23T16:39:42","date_gmt":"2022-06-23T08:39:42","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=49882"},"modified":"2022-06-23T16:39:45","modified_gmt":"2022-06-23T08:39:45","slug":"every-7-in-10-phishing-attempts-in-ph-are-finance-related","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2022\/06\/23\/every-7-in-10-phishing-attempts-in-ph-are-finance-related\/","title":{"rendered":"Every 7 in 10 phishing attempts in PH are finance-related"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Anonymized data voluntarily provided by Kaspersky customers showed that seven in 10 (68.95%) phishing attempts targeted finance-related transactions in the Philippines from February to April this year. This is the highest percentage of phishing attempts in Southeast Asia.\u00a0\u00a0<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The cybersecurity company detected and blocked phishing attacks against three financial categories namely, banks, e-commerce stores and payment systems.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Statistics from Kaspersky Security Network (KSN) revealed that phishing attempts in the Philippines is higher than in Indonesia (65.90%), Singapore (55.67%), Thailand (55.63%),&nbsp; Malaysia (50.58%), and Vietnam (36.12%).&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In all three finance categories during the same three-month period, Kaspersky data showed that there were one in two (58.50%) phishing attempts against payment systems in the country such as credit cards, debit cards, and mobile payment apps or e-wallets. This number is the highest among countries in SEA.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On the other hand, the same data also showed that phishing attempts in local banks was the lowest in the region at only 2.17%, while phishing attempts versus e-commerce shops in the country was the second lowest among SEA countries at 8.28%.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/ecp.yusercontent.com\/mail?url=https%3A%2F%2Flh6.googleusercontent.com%2FWKbHl1RIu4az9121UjmYApgbS1l5jV7FP6aylXHVu_EEtf4AenkJE3XfAP6-e0wGB_LxemYxJ1sILUuR27UuIKX54psN1Y_fmspnn1Kg9kmcqGF4DqqCqzEcqOU63cSqfbMpF8vDXWGUkMneGQ&amp;t=1655952823&amp;ymreqid=27f3344f-c727-c29c-1ca4-080006014200&amp;sig=U115ESEjOtgx5FCvjAbIyg--~D\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The percentages are from anonymized data based on the triggering of the deterministic component in Kaspersky\u2019s Anti-Phishing system on user computers. The component detects all pages with phishing content that the user has tried to open by following a link in an e-mail message or on the web, as long as links to these pages are present in the Kaspersky database.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cAlongside the increased adoption in digital transactions here in Southeast Asia, we also see the rise of \u2018Super Apps\u2019 in the region. These are the mobile applications that combine all popular monetary functions including e-banking, mobile wallets, online shopping, insurance, travel bookings, and even investments. Putting our data and digital money in one basket can trigger an aftermath snowball, with the impact of a phishing attack swelling at an unforeseeable rate,\u201d says Yeo Siang Tiong, General Manager for Southeast Asia at Kaspersky.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Super Apps are traditional banks and service providers\u2019 way of standing out in a rather crowded industry. As they try to work with third parties and incorporate their services into a single mobile app, the attack surface expands, opening up more doors to a malicious exploit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Phishing has remained to be the most effective trick on cybercriminals\u2019 sleeves. It is a known way to crack into a user\u2019s or even a company\u2019s network by playing on a user\u2019s emotions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A possible scenario is given that one app has all the financial details of a user, a simple phishing link asking for the user\u2019s credentials can compromise all the data available in the app. This magnifies the possible damaging effects of this threat.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIt is known that cybercriminals follow the money trail, so it is important for banks, app developers, and service providers to integrate cybersecurity from the beginning of application development. We expect hackers to target the rising Super Apps, both its infrastructure and its users through social engineering attacks. We urge all fintech companies to deploy a secure-by-design approach in their systems and to continuously provide proactive education for their users in this period where phishing attacks continue to thrive,\u201d adds Yeo.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While security systems are in place in most financial companies to protect customers from falling victim to suspicious activities, it is true that prevention is better than cure; much more can be proactively done at both the individual and bank level.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For enterprises, the most important method of protection is to keep in mind that cybersecurity should be a \u201cliving\u201d strategy, not a static platform. This will blend technology and effort, and is constantly upgraded, updated and improved.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Banks and service providers need to ensure a security team (or security experts) that will be able to ensure cyber defense infrastructure is updated, and will be able to provide support in the event of a cyber attack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To start, firms can invest in endpoint security solutions. Kaspersky currently offers its <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/go.kaspersky.com\/SEA_SMB_Promo_KERO.html?utm_campaign=SEA21Q2KERO\">Endpoint Detection and Response Optimum at a 35%<\/a> discount to help enterprises get started. Interested companies can visit this <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/go.kaspersky.com\/SEA_SMB_Promo_KERO.html?utm_campaign=SEA21Q2KERO\">link<\/a> to know more.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some more crucial steps to look into also include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Considering a <\/strong><a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/threat-intelligence\"><strong>threat intelligence platform<\/strong><\/a><strong>.<\/strong> Another key component to include would be to ensure access to the latest IT security trends\/threats \u2013 that is also known as threat intelligence. Threat intelligence will give the insight to act on, and paint a bigger, more accurate picture of the bank\u2019s digital presence, to educate senior stakeholders about the ongoing risks and vulnerabilities. This will empower them to be able to make informed decisions on what needs to be done to keep the potential harm at bay, refine existing security processes to better defend against known threats and to plug any gap in the IT infrastructure on an ongoing basis.&nbsp;<\/li><li><strong>Ensuring any third party vendors\u2019 cybersecurity systems are also updated.<\/strong> There have been increasing reports on how breaches to third-party security systems have implicated businesses. Whether you are the bank, the Government or a private enterprise, no one is immune from these security threats, and it is important that we heighten our vigilance when it comes to cybersecurity. It does not matter how secure your third-party vendor tells you their systems are, as the elevated prominence of supply chain attacks have shown us that it is important to take responsibility for your own cybersecurity posture rather than leaving it in your partners\u2019 hands.<\/li><li>As parties are impersonated by threat actors, <strong>the implementation of defense measures need to go beyond protecting their systems<\/strong>. Banks need to take proactive measures to remind their customers against falling prey to their impersonators and their phishing and scam attacks, even if they happen outside of their systems.&nbsp;<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Some things to keep in mind that can help individuals protect themselves against phishing attacks include:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Not responding. <\/strong>Even prompts to reply like texting \u201cUNSUBSCRIBE\u201d or \u201cSTOP\u201d can be a trick to identify active phone numbers. Attackers depend on your curiosity or anxiety over the situation at hand, but you can choose not to engage.&nbsp;<\/li><li><strong>Avoiding using any links or contact information in the email or message. <\/strong>Go directly to contact channels where possible. Remember that urgent notices can be verified directly on online accounts or via an official phone helpline.&nbsp;<\/li><li><strong>Looking out for mistakes, typos and strange characters in the text<\/strong>. Some threat actors really struggle with English, or some mistakes are intentionally made (such as using numbers to replace certain alphabets, eg \u201cBank L0an\u201d instead of \u201cBank Loan\u201d) in an attempt to bypass spam filters.<\/li><li><strong>Slowing down if a message is urgent.<\/strong> Emails and SMS are often read on the go, when one is distracted or in a hurry, leaving one\u2019s guard down. Approach offers as caution signs of possible phishing, remain calm and proceed carefully.&nbsp;<\/li><li><strong>Downloading an anti-malware app<\/strong>, which can protect against malicious apps such as <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/total-security\">Kaspersky Total Security<\/a> for a safety net.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Read Kaspersky\u2019s full 2021 Threat Landscape Report for Southeast Asia here <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/kasperskysea.co\/premium_report\">https:\/\/kasperskysea.co\/premium_report<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Statistics from Kaspersky Security Network (KSN) revealed that phishing attempts in the Philippines is higher than in Indonesia (65.90%), Singapore (55.67%), Thailand (55.63%),\u00a0 Malaysia (50.58%), and Vietnam (36.12%).\u00a0<\/p>\n","protected":false},"author":6,"featured_media":48973,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[6498,6151,286,101,54,96,2727,1656],"class_list":["post-49882","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-white-papers","tag-good-tech","tag-high-tech","tag-it-security","tag-kaspersky","tag-security","tag-technology","tag-technology-adaption","tag-technology-investment"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/49882","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=49882"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/49882\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/48973"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=49882"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=49882"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=49882"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}