share_log

Black Friday Triggers More Than 600% Rise in Attempted Retail Cyber Scams

Black Friday Triggers More Than 600% Rise in Attempted Retail Cyber Scams

黑色星期五引發零售行業網絡詐騙企圖激增超過600%
PR Newswire ·  2024/12/04 20:00

CAMBRIDGE, UK, Dec. 4, 2024 /PRNewswire/ -- Darktrace, a global leader in AI for cybersecurity, today revealed a surge in retail cyber attacks at the opening of the 2024 holiday shopping season.

英國劍橋,2024年12月4日/PRNewswire/ - 賽路特,一家領先的網絡安全概念公司,今日公佈了在2024年節日購物季開幕時零售網絡攻擊激增的消息。

Analysis from Darktrace's threat intelligence team using data from across the Darktrace customer fleet shows that during Black Friday week (25th to 29th November 2024) attempted Christmas-themed phishing attacks leapt 327%1 around the world, while Black Friday themed phishing attacks jumped 692% compared to the beginning of November (4th - 9th November)2, as bad actors seek to take advantage of consumers and holiday brands during the busy shopping period.

賽路特威脅情報團隊的分析顯示,利用賽路特客戶群體的數據,2024年11月25日至29日的黑色星期五週期間,全球試圖進行聖誕主題釣魚攻擊猛增327%1,而與11月初(11月4日至9日)相比,黑色星期五主題釣魚攻擊激增了692%2,壞人們試圖在繁忙的購物時期利用消費者和節日品牌。

The United States retail sector faced an especially aggressive wave of cyber threats, with phishing attacks mimicking major holiday brands3 including Walmart, Target, and Best Buy increasing by more than 2000% during peak shopping periods.

美國零售業在網絡威脅方面遭遇了特別激烈的一波攻擊,冒充沃爾瑪、Target和百思買等主要節日品牌的釣魚攻擊在購物高峰期增長了超過2000%3。

The analysis also highlighted the shifting attention of scammers as the festive season arrives from targeting business to consumer needs, with impersonation of major consumer brands4 growing 92% globally between the analyzed periods while mimicking of workplace focused brands5 declined by 9%.

分析還突出了騙子注意力轉向消費者需求的變化,隨着節日季節的到來,模仿主要消費品牌4在全球分析週期內增長了92%,而模仿以工作場所爲重點的品牌5則下降了9%。

Brands, particularly major retailers like those analyzed, invest significantly in protecting themselves and their customers from scams and cyber attacks and often step up those measures for the holiday period. However, brand impersonation in phishing occurs entirely outside retailers' legitimate infrastructure and security controls and happens at too great a volume for brands to catch and stop every instance. While new technologies, like AI, are helping security teams close the gap, brand impersonation remains a common challenge for brands.

品牌,特別是像那些受到分析的主要零售商一樣的品牌,投入了大量資金來保護自己和客戶免受詐騙和網絡攻擊。通常他們會加強這些措施以備節日之需。然而,在網絡釣魚中的品牌冒名頂替完全超出了零售商的合法基礎設施和安全控制範疇,且以一定數量發生,使得品牌難以攔截和阻止每一個攻擊實例。儘管新技術,如人工智能,正在幫助安全團隊彌合差距,品牌冒名頂替仍是品牌面臨的常見挑戰。

"The festive shopping season creates a perfect storm for cyber criminals," says Nathaniel Jones, VP of Threat Research, Darktrace. "Consumers are primed to expect floods of retail deals, while retailers are processing tremendous transaction volumes at speed. This combination makes spotting suspicious patterns more challenging than at any other part of the year. Bad actors taking advantage of that with brand impersonation is nothing new, but the rapidly growing volume of those attacks makes them a real worry. Both consumers and brands need to be increasingly alert to potential scams, but we can all take heart that big name retailers have some of the most sophisticated protections possible to help safeguard their customers, and technologies like AI cybersecurity, that spot spoofs and attacks that humans wouldn't, are catching and stopping more of these attacks than ever before."

「節日期間的購物旺季爲網絡犯罪分子創造了完美的環境,」賽路特威脅研究副總裁納撒尼爾·瓊斯表示。「消費者期待大量的零售交易,而零售商則以極快的速度處理巨大的交易量。這種組合使得發現可疑模式比全年的任何其他時候都更具挑戰性。利用品牌冒充來利用此情況並不新鮮,但是攻擊的數量迅速增加令人擔憂。消費者和品牌都需要更加警惕潛在的詐騙行爲,但我們可以放心,知名的零售商擁有可能幫助保護客戶的最先進的保護措施,而像人工智能網絡安全這樣的技術能夠發現人類無法覺察到的僞造和攻擊,正比以往更多地攔截和停止這些攻擊。」

Darktrace's findings demonstrate some of the most common brand spoofing strategies used by attackers during the holiday season. In one strategy, brand impersonation phishing, attackers send a phishing email designed to look like a favourite retailer, enticing their target to click a link for a discount, when in fact the link downloads malware to their device. The most effective attacks are multi-stage: brand impersonation emails lead unsuspecting shoppers directly to websites that look like the retailer but harvest login or payment details, creating a seamless deception that hands personal and financial data directly to attackers. This coordinated approach exploits the chaos of holiday sales, when shoppers are primed to expect high volumes of retail emails and website traffic promoting significant savings.

Darktrace的調查結果展示了攻擊者在假日季節期間使用的一些最常見的品牌冒充策略。在一種策略中,品牌冒充釣魚,攻擊者發送一封設計成像一個最愛零售商的釣魚郵件,誘使他們的目標點擊一個打折鏈接,當事實上該鏈接下載惡意軟件到他們的設備。最有效的攻擊是多階段的:品牌冒充郵件直接引導毫無戒心的購物者到類似零售商但收集登錄或付款細節的網站,造成無縫欺騙,直接將個人和財務數據交給攻擊者。這種協調的方式利用了假日銷售的混亂,當購物者預期會收到大量零售郵件和促銷重大節省的網站流量時。

Five essential security measures for retailers

零售商的五個必備安全措施

With the festive season in full swing, retailers must stay vigilant against rising cyber threats. Here are five tips to help businesses protect themselves and their customers.

隨着歡樂的季節全面展開,零售商必須保持警惕應對不斷增多的網絡威脅。以下是五個提示,可幫助企業保護自己和客戶。

  1. Make logins secure: Firstly, ensure all staff have strong passwords (12-16 characters). Set up multi-factor verification across all business systems. This extra layer of security means even if passwords are compromised, unauthorised users can't access your accounts during the busy retail period and use them to target your customers.
  2. Lock down email: Call your IT team and ask them if they have DMARC switched on. DMARC stops scammers from sending emails that look like they're from your company and helps you see who is illegitimately sending from your email domain to protect your brand.
  3. Prepare your team: Regular security training and business wide communications help staff identify and report seasonal scams. Focus on current threats and emerging patterns - when your team knows what to look for, they become your strongest defence against cyber attacks.
  4. Monitor brand impersonation: Set up Google Alerts to track mentions of your brand and warn you of counterfeit websites and fraudulent domains. Also lock down your brand name with official registrations. This makes it easier to spot and shut down fake accounts and copycat websites. Several brand protection tools out there can help catch imposters too. Quick detection helps you respond rapidly to brand exploitation and protect your customers from sophisticated scams.
  5. Strengthen payment processes: Implement tiered access policies with stricter controls for finance team members who handle transactions. Apply more rigorous authentication and monitoring requirements compared to non-financial roles, ensuring sensitive payment operations are limited to authorized personnel.
  1. 確保登錄安全:首先確保所有員工使用強密碼(12-16個字符)。在所有業務系統中設置多因素驗證。這種額外的安全層意味着即使密碼泄漏,未經授權的用戶在繁忙的零售期間無法訪問您的帳戶,並利用它們針對您的客戶。
  2. 鎖定電子郵件:聯繫您的IT團隊,問他們是否開啓了DMARC。DMARC可以阻止欺詐者發送看起來來自貴公司的電子郵件,並幫助您查看誰非法地從您的電子郵件域發送以保護您的品牌。
  3. 準備好你的團隊:定期的安全培訓和業務廣泛傳播有助於員工識別和報告季節性騙局。專注於當前的威脅和新興模式-當您的團隊知道該如何識別時,他們就成爲對抗網絡攻擊的最強大防禦。
  4. 監控品牌冒充:設置Google Alerts跟蹤您品牌的提及,並警告您有關假冒網站和欺詐域名。同時對您的品牌名稱進行正式註冊。這樣可以更容易地發現並關閉假帳戶和抄襲網站。還有一些品牌保護工具可以幫助發現冒名頂替者。快速檢測幫助您迅速應對品牌受到利用並保護您的客戶免受複雜的騙局。
  5. 加強支付流程:實施分級訪問策略,對處理交易的財務團隊成員加強控制。與非金融角色相比,應用更嚴格的身份驗證和監控要求,確保敏感的支付操作僅限於授權人員。

About Darktrace

關於Darktrace

Darktrace is a global leader in AI for cybersecurity that keeps organizations ahead of the changing threat landscape every day. Founded in 2013, Darktrace provides the essential cybersecurity platform protecting organizations from unknown threats using its proprietary AI that learns from the unique patterns of life for each customer in real-time. The Darktrace ActiveAI Security Platform delivers a proactive approach to cyber resilience with pre-emptive visibility into security posture, real-time threat detection, and autonomous response – securing the business across cloud, email, identities, operational technology, endpoints, and network. Breakthrough innovations from our R&D teams in Cambridge, UK, and The Hague, Netherlands have resulted in over 200 patent applications filed. Darktrace's platform and services are supported by over 2,400 employees around the world who protect nearly 10,000 customers across all major industries globally. To learn more, visit .

Darktrace是全球領先的網絡安全人工智能領域的企業,在每天保持組織處於不斷變化的威脅格局之前。Darktrace成立於2013年,通過其獨有的人工智能平台,以實時從每位客戶獨特生活模式中學習的方法,保護組織免受未知威脅。Darktrace ActiveAI安全平台以主動的方式提供對網絡安全的彈性,預先查看安全姿勢,實時威脅檢測和自主響應-確保業務在雲端、電子郵件、身份、運營技術、終端和網絡中得到保障。我們在英國劍橋、荷蘭海牙的研發團隊帶來的突破性創新已經產生了200多項專利申請。Darktrace的平台和服務得到全球2400名員工的支持,他們在全球範圍內保護着近一萬家各行各業的客戶。要了解更多,請訪問網站。

1Based on analysis of 626 customer deployments and attempted phishing emails mentioning Christmas that were detected by Darktrace / EMAIL.
2Emails in the analysis mentioning 'Black Friday' or 'Cyber Monday'.
3Walmart, Target, Best Buy, Macy's, Old Navy, 1800-Flowers
4 Amazon, eBay, Netflix, Alibaba, Paypal, Apple
5Oracle, Zoom, Adobe, Microsoft Exchange, Microsoft Outlook, Microsoft Teams, Slack, WeTransfer, Docusign, Sharepoint, Linkedin, Dropbox

基於對626個客戶部署的分析及由Darktrace檢測到提到聖誕節的釣魚電子郵件。
分析中提到「黑色星期五」或「網絡星期一」的電子郵件。
沃爾瑪、Target、百思買、梅西百貨、Old Navy、1800-Flowers
亞馬遜、ebay、奈飛、阿里巴巴、paypal、蘋果
Oracle、Zoom、adobe、微軟Exchange、微軟Outlook、微軟Teams、Slack、WeTransfer、docusign、Sharepoint、Linkedin、dropbox

SOURCE Darktrace

消息來源:Darktrace

WANT YOUR COMPANY'S NEWS FEATURED ON PRNEWSWIRE.COM?

想要您公司的新聞在PRNEWSWIRE.COM上特色呈現嗎?

440k+
440k+

Newsrooms &
新聞發佈室&

Influencers
影響力人士
9k+
9k+

Digital Media
數字媒體

Outlets
Outlets
270k+
270k+

Journalists
記者

Opted In
Opted In
GET STARTED
開始使用

譯文內容由第三人軟體翻譯。


以上內容僅用作資訊或教育之目的,不構成與富途相關的任何投資建議。富途竭力但無法保證上述全部內容的真實性、準確性和原創性。
    搶先評論