• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

New cyber-threats that go bump in the night

Michal Lev-Ram
By
Michal Lev-Ram
Michal Lev-Ram
Special Correspondent
Down Arrow Button Icon
Michal Lev-Ram
By
Michal Lev-Ram
Michal Lev-Ram
Special Correspondent
Down Arrow Button Icon
April 22, 2014, 3:20 PM ET

FORTUNE — It’s that time of year again: Spring is in the air, Monarch butterflies are traveling north, and Verizon’s (VZ) data breach report is making the rounds, freaking out already freaked-out chief information security officers around the globe.

The annual report compiles and analyzes more than 63,000 security incidents (as well as 1,300 confirmed data breaches) from about 50 companies worldwide. This year’s 60-page document identified nine main patterns of attack, including point-of-sale intrusions, denial-of-service attacks and acts of cyberespionage. According to Verizon, 94% of all security incidents in 2013 can be traced to these nine basic categories.

(As for the other 6% of threats facing corporate America, well, ignorance is bliss, right?)

Here, our summary of the most pressing security threats for major companies:

1. Web app attacks

Hands down, this is the most common type of data breach. According to Verizon’s report, web applications remain the “proverbial punching bag of the Internet.” How do the bad guys do it? Phishing techniques, installing malware, and, yes, correctly guessing the name of your first stuffed animal, your oldest cousin’s eye color and your nickname in sixth grade. There are ways to better protect Internet-facing applications, Verizon insists, and it starts with two-factor authentication.

2. Cyberespionage

Incidents of unauthorized network or system access linked to state-affiliated actors have tripled — that’s right, tripled — over the last year. Espionage exhibits a wider variety of “threat actions” than any other attack pattern, Verizon says, which means that once intruders gain access, they’re making themselves comfortable and partaking in all sorts of activities, from scanning networks to exporting data. Verizon warns that we can’t keep blaming China, though — at least not just China. About 21% of reported incidents are now being instigated from Eastern Europe.

3. Point-of-sale intrusions

Given the recent high-profile Target (TGT) breach, in which hackers gained access to the credit card numbers of some 40 million customers, this may seem like the attack pattern du jour. But Verizon claims point-of-sale intrusions have actually been trending down over the last several years. “Recent highly publicized breaches of several large retailers have brought POS compromises to the forefront,” the report’s authors write. “But at the risk of getting all security-hipster on you — we’ve been talking about this for years.” Still, retailers and hotel companies in particular need to be concerned about this kind of attack. It only takes one massive point-of-sale intrusion to scare away customers and investors — just ask Target.

4. Payment card skimmers

Skimming mainly affects ATMs and gas pumps, and is a relatively crude form of attack that requires a skimming device to be physically added to a machine. It’s hardly a new tactic, but what’s different today is the way that the data from “skimmed” payment cards is collected. Before, a criminal had to retrieve the skimming device; now, a thief can remotely collect the data using Bluetooth or other wireless technologies. More modern ATMs are designed to be relatively tamper-free, but this is still a big problem in some parts of the world, such as Bulgaria and Armenia.

5. Insider misuse

Not sure what falls under this category? Imagine someone akin to the rebel NSA defense contractor Edward Snowden, or pretty much any unapproved or malicious use of organizational resources. The most common examples of this are employees using forbidden devices (e.g. USB drives) or services to send intellectual property to their personal accounts — or, more deliberately, posing as another user and sending messages aimed at getting a colleague fired. According to Verizon, many of the people committing these crimes are payment chain personnel and end users, but C-suite managers were more to blame in prior years. Bottom line: Trust no one.

6. Crimeware

This category includes any malware incident that doesn’t fit into the espionage or point-of-sale buckets. The goal is always some kind of illicit activity, such as stealing users’ online banking credentials. Most forms of crimeware start with web activity such as downloads or so-called drive-by infections, where a virus can be downloaded when a user unknowingly clicks on a deceptive pop-up window. What can corporations do to combat these types of attacks? Keep software such as browsers up to date.

7. Miscellaneous errors

Oops, I did it again — as in, I sent an email containing sensitive information to the wrong recipient. That’s the most common example of this kind of unintentional data disclosure. Others include accidentally posting non-public information to a company’s web server or even snail-mailing documents to the wrong physical address. There’s no cure for human error (other than replacing them with computers, of course), but Verizon says corporations can implement data loss prevention software to reduce instances of sensitive files sent by email and tighten processes around posting documents to internal and external websites.

8. Physical theft/loss 

Here’s a fun fact: It turns out that corporate assets like phones and laptops are stolen from corporate offices more often than from homes or vehicles. The primary cause of this type of incident? Carelessness. According to the Verizon report: “Accidents happen. People lose stuff. People steal stuff. And that’s never going to change.” The only thing you can change, advises the company, is to encrypt devices, back up data, and encourage employees to keep their gadgets close.

9. Distributed denial-of-service attacks

Last but not least, so-called DDoS threats include any attack aimed at compromising the availability of networks and systems. These are primarily directed at the financial, retail and public sectors. And while the motives behind shutting down corporate, consumer-facing websites remains the same — extortion, protest, or perverse fun — the tools at attackers’ disposal have become more sophisticated and more thoughtfully named, such as “Brobot” and “itsoknoproblembro.”

More on cybersecurity from Fortune:

  • Does signing up for Obamacare make you a cybercrime target?
  • 10 Questions: Nico Sell, co-founder and CEO, Wickr
  • The bug that rocked the foundations of the web
  • Trouble at Target: 3 questions for CEO Gregg Steinhafel
  • Kevin Mandia: Why selling Mandiant made sense
About the Author
Michal Lev-Ram
By Michal Lev-RamSpecial Correspondent
Twitter icon

Michal Lev-Ram is a special correspondent covering the technology and entertainment sectors for Fortune, writing analysis and longform reporting.

See full bioRight Arrow Button Icon

Latest in

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in

merz
CryptoEuropean Union
Move over, ‘Merkron.’ Europe’s new power couple is ‘Merzoni’
By Julia Khrebtan-Hörhager and The ConversationFebruary 11, 2026
3 hours ago
Personal Financemortgages
5 ways to access your home equity
By Joseph HostetlerFebruary 11, 2026
9 hours ago
Healthsleep
WinkBeds Mattress Review (2026): Rigorously Tested
By Christina SnyderFebruary 11, 2026
9 hours ago
van der beek
LawObituary
James Van Der Beek, child star and face of iconic GIF from ‘Dawson’s Creek,’ dies at 48 in ‘beyond devastating news’
By Mark Kennedy and The Associated PressFebruary 11, 2026
9 hours ago
President Donald Trump pictured in front of a waving American flag.
EconomyU.S. economy
Trump’s immigration curbs will help take 2.4 million people out of the workforce, but he’s betting AI can pick up the slack
By Tristan BoveFebruary 11, 2026
9 hours ago
desert
LawCrime
Search for Nancy Guthrie descends onto rugged desert terrain
By Ty O'Neil and The Associated PressFebruary 11, 2026
9 hours ago

Most Popular

placeholder alt text
Economy
America borrowed $43.5 billion a week in the first four months of the fiscal year, with debt interest on track to be over $1 trillion for 2026
By Eleanor PringleFebruary 10, 2026
2 days ago
placeholder alt text
Economy
It turns out that Joe Biden really did crush Americans' dreams for the future. Just look at how the vibe changed 5 years ago
By Jake AngeloFebruary 10, 2026
1 day ago
placeholder alt text
Commentary
Something big is happening in AI — and most people will be blindsided
By Matt ShumerFebruary 11, 2026
16 hours ago
placeholder alt text
Law
Law enforcement thought Nancy Guthrie's smart camera was disconnected, but Google Nest still had the tape
By Safiyah Riddle, Michael Liedtke and The Associated PressFebruary 11, 2026
19 hours ago
placeholder alt text
Crypto
Bitcoin reportedly sent to wallet associated with Nancy Guthrie’s ransom letter providing potential clue in investigation
By Carlos GarciaFebruary 11, 2026
12 hours ago
placeholder alt text
Economy
America’s national debt borrowing binge means interest payments will rocket to $2 trillion a year by 2036, CBO says
By Eleanor PringleFebruary 11, 2026
15 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.