Manufacturing became the most attacked industry in 2021, making up 23.2% of all attacks, as stated in IBM’s Threat Intelligence Index 2022.
Manufacturing is also the most targeted of all operational technology (OT) industries, being victimized in 61% of all attacks.
OT systems are used to monitor events, processes and devices, and are traditionally associated with manufacturing and industrial environments, including industrial control systems such as supervisory control and data acquisition.
Ransomware accounts for 36% of all cyber attacks on OT industries.
Ransomware is a form of malicious software that enters a victim’s device through an attack vector (An attack vector is a method of gaining unauthorized access to a network or computer system). The software then copies and encrypts all data on the device, and threatens the victim with public exposure or the deletion of their data.
Phishing is the most prominent attack vector in 2021, overtaking vulnerability exploitation in 2020.
Vulnerability exploitations are flaws in software that cyber-criminals can exploit to gain unauthorized access to a network.
Phishing represented 41% of successful attack vectors, with vulnerability exploitation still being used in 34% of all attacks.
Phishing is often one of the leading attack vectors used by cyber-criminal groups, despite there being a mature level of service in the form of security training, which is both affordable and easily available.
In simulated campaigns, the average click rate for phishing links was 17.8%. However, when combined with fake phone calls that lend authenticity to the fake emails (known as vishing), this click rate increases to 53.2%.
June 2021 was a record month for phishing attacks, with 222,127 phishing emails being sent over 30 days.
A real-life example of phishing attacks are those launched by the REvil hacker group.
In 2021 multiple REvil ransomware incidents were observed to have started with a phishing email. These emails usually have very short messages, often refer to unpaid invoices, and would occasionally even hijack ongoing email conversations by initiating “reply all” with a ransomware attachment. The attachment, when opened, infects and effectively takes over the user’s device, encrypting all the data and sending copies that allow the criminal group to blackmail the victimized organization.
This is a real example of the phishing emails used by REvil – notable for its good spelling and presentation:








