Cybercriminals concurrently targeting online, offline vulnerabilities – report

Cybercriminals concurrently targeting online, offline vulnerabilities – report
Cybercrime hacking and technology crime with laptop display show bitcoin icon in the server room /SHUTTERSTOCK

NAIROBI, Kenya, Oct 13 – Cybercriminals are simultaneously targeting online and offline vulnerabilities as in-person commerce returns to pre-pandemic levels, digital payment provider Visa has warned.

The firm cautions that physical points of vulnerability in stores are back to being targeted, while crooks continue to capitalize on e-commerce through malware, ransomware, and phishing attacks, among others.

“We are continuing to see high rates of skimming, growing over the already elevated levels of the winter of 2021, where fraudsters are jumping on the rise of in-person activity” said Paul D. Fabara, Chief Risk Officer at Visa.

The latest Visa Biannual Threats Report notes that while fraud early on during the Covid-19 pandemic was concentrated on online scams, in-person attacks are now trending higher as criminals widen their scope to once again capture physical targets.

It notes that in the past year there has been an increase in card-present threats such as physical skimming on ATM and point-of-sale terminals, a trend that will likely persist.

For instance, from June – November 2021, Visa saw a 176 per cent increase in physical skimming devices over the previous 12-month period.

Even so, the digital commerce environment, vastly accelerated by the pandemic, remains the richest target for cybercriminals.

Nearly three-fourths of fraud and data breach cases investigated by Visa’s Global Risk team involved e-commerce merchants, often social engineering and ransomware attacks.

These attacks shine a light on the need for stringent security controls on merchant websites and checkout pages, ensuring external code is not enabled in sensitive cardholder environments.

42 per cent of respondents in an MIT Technology Review Insights report say security measures are important for their customers, with 59 per cent acknowledging that cybersecurity threats are the biggest challenge to expanding digital payments.

Many are prioritizing advanced security capabilities like digital tokens (32 per cent), artificial intelligence and enhanced authorization (43 per cent).

Beyond attacks on traditional currency, threat actors are employing new tactics to defraud cryptocurrency users, including new malware focused on browser extension wallets for crypto users as well as innovation in phishing and social engineering schemes.

Crypto bridge services are also a target.  From January through February 2022, three sizeable thefts exploiting vulnerabilities in various bridge services netted cyber thieves over USD400 million.

While cybercrime persists, Visa has increased its efforts to mitigate fraud. Over the past five years, Visa has invested more than USD9 billion in network security.