Manufacturing became the most attacked industry in 2021, making up 23.2% of all attacks, as stated in IBM’s Threat Intelligence Index 2022.
Manufacturing is also the most targeted of all operational technology (OT) industries, being victimized in 61% of all attacks.
OT systems are used to monitor events, processes and devices, and are traditionally associated with manufacturing and industrial environments, including industrial control systems such as supervisory control and data acquisition.
Ransomware accounts for 36% of all cyber attacks on OT industries.
Ransomware is a form of malicious software that enters a victim’s device through an attack vector (An attack vector is a method of gaining unauthorized access to a network or computer system). The software then copies and encrypts all data on the device, and threatens the victim with public exposure or the deletion of their data.
Phishing is the most prominent attack vector in 2021, overtaking vulnerability exploitation in 2020.
Vulnerability exploitations are flaws in software that cyber-criminals can exploit to gain unauthorized access to a network.
Phishing represented 41% of successful attack vectors, with vulnerability exploitation still being used in 34% of all attacks.
Phishing is often one of the leading attack vectors used by cyber-criminal groups, despite there being a mature level of service in the form of security training, which is both affordable and easily available.
In simulated campaigns, the average click rate for phishing links was 17.8%. However, when combined with fake phone calls that lend authenticity to the fake emails (known as vishing), this click rate increases to 53.2%.
June 2021 was a record month for phishing attacks, with 222,127 phishing emails being sent over 30 days.
A real-life example of phishing attacks are those launched by the REvil hacker group.
In 2021 multiple REvil ransomware incidents were observed to have started with a phishing email. These emails usually have very short messages, often refer to unpaid invoices, and would occasionally even hijack ongoing email conversations by initiating “reply all” with a ransomware attachment. The attachment, when opened, infects and effectively takes over the user’s device, encrypting all the data and sending copies that allow the criminal group to blackmail the victimized organization.
This is a real example of the phishing emails used by REvil – notable for its good spelling and presentation:
 

 
A further key reason manufacturing companies are being increasingly targeted is due to their vulnerability to blackmail. Manufacturers have a low tolerance for downtime due to the easily calculable losses they will suffer, which is exactly what massive data loss would cause, they therefore often pay the ransom to get back to work as quickly as possible.
If you are concerned about the threats posed to your business by phishing attacks, TecSec offer fake phishing campaigns that will inform your staff about the risks of phishing emails, and how to detect and report them. If you are interested in this service, please view our dedicated page here, or contact us at 01142238000.

SCADA Vulnerabilities

Over the past five years, the number of vulnerabilities discovered per year has also risen steadily.
Vulnerabilities related to industrial control systems increased at an even faster rate than overall vulnerabilities, with this category experiencing a 50% year-over-year increase respectively, compared to a 0.4% growth rate in the number of vulnerabilities overall.
There is now evidence that shows that cybercriminals are conducting massive research campaigns searching for exploitable communications in industrial networks.
Specifically, 2021 saw a considerable increase in reconnaissance activity targeting TCP Port 502.
Port 502 is commonly used by supervisory control and data acquisition (SCADA). Access to it could allow threat actors to control physical devices connected to the internet.
Port 502 is made even more vulnerable due to the lack of multi-factor authentication, and also due to most of the communications through the port being made in plain text files.
TecSec offers consultancy to help segregate and secure networks and we use vulnerability scans that can analyse your I.T. network and detect any vulnerabilities or weak points that may serve as attack vectors for cybercriminals. If you are interested in this service, please view our dedicated page here, or contact us at 01142238000.