2018-黑色星期五威胁报告(英文版)-1mb
报告摘要
Kaspersky Lab - Beyond Black Friday Threat Report, 2017 Summary
Introduction
The holiday shopping season, including Thanksgiving, Black Friday, Cyber Monday, and Christmas, represents a significant portion of annual sales for retailers in the U.S., Europe, and APAC. This period is marked by increased consumer activity, with a notable rise in online shopping and financial transactions. The heightened competition and consumer interest in deals and convenience have led to more aggressive marketing campaigns, which can be exploited by cybercriminals.
Methodology and Key Findings
Kaspersky Lab's report is based on data from its heuristic anti-phishing system, which detects phishing links before they are added to its database. The findings cover the fourth quarter of 2016 up to October 18, 2017. Key observations include:
- Financial phishing has grown significantly, now accounting for 49.77% of all phishing attacks in 2017, up from 34.33% in 2015.
- The use of smartphones for online banking, shopping, and payment has doubled in a year, with up to 75% of emails opened on mobile devices during Black Friday and Cyber Monday.
- Attack levels are now more evenly distributed throughout the year, with a notable 33% decrease in attacks detected on Black Friday 2016 compared to the previous day.
- Cybercriminals are leveraging the Black Friday name and consumer security concerns to disguise their phishing attacks as legitimate security alerts or urgent messages.
Phishing – A Universal Threat
Phishing remains one of the most common methods used to steal personal and financial information. It is not limited to emails but extends to website banners, pop-ups, SMS, and social media. Kaspersky Lab's data shows that China, Australia, and Brazil were particularly vulnerable in 2017, with up to 28% of users targeted. The trend indicates that phishing is a global threat, and no brand is immune.
A New Pool for Phishers
The rise of mobile-first behavior has created new opportunities for cybercriminals. During the holiday season, consumers are more susceptible to phishing due to:
- Distracted shopping on mobile devices.
- Increased marketing noise, which can lead to users missing warning signs.
- Spoofed web interfaces that mimic legitimate brands and services.
Financial Phishing on the Rise
The proportion of phishing attacks targeting financial data has steadily increased over the years. In 2017, financial phishing accounted for half of all phishing attacks, with a 3.6 to 4.0% increase in U.S. holiday sales compared to 2016. The trend shows that financial phishing is not limited to the holiday period, but it remains a significant risk during this time due to localized attack peaks and increased consumer vulnerability.
Types of Financial Phishing
Financial phishing is categorized into three types based on the target:
- Online Shopping
- Online Banking
- Online Payments
The data shows that the share of attacks targeting online shopping has decreased over the years, while attacks on online banking and payments have remained relatively stable. In 2017, online payments saw the highest growth in phishing attacks.
Attackers Follow Consumer Adoption Trends
Cybercriminals are adapting to consumer trends, such as the increased use of PayPal and other payment systems. The attacks are now more evenly distributed across different brand names, indicating that attackers are no longer focusing on a few major brands.
Multi-Brand Retailers Remain a Top Choice for Financial Phishing
Attackers are increasingly targeting multi-brand retailers such as Amazon, Taobao, and Alibaba, as they are more likely to be used by a wide range of consumers. These platforms are popular for their variety and convenience, making them attractive targets for phishing.
Black Friday Attacks
Black Friday is a peak time for financial phishing attacks, with a noticeable decline after the holiday. In 2016, attacks dropped by 33% within a day, likely due to the high volume of traffic and consumer activity. The use of phishing pages that mimic legitimate brands is a common tactic.
Examples of Financial Phishing Attacks in 2017
- Black Friday-themed phishing pages were used to lure users with attractive discounts.
- Phishing emails often mimic legitimate brands like Amazon and PayPal, using security warnings or false login pages.
- Attackers may create the illusion that the user has already been hacked or compromised, prompting immediate action.
What Happens to Your Data?
In some cases, attackers use fake login pages that look like legitimate ones to steal personal and financial data. The stolen information includes:
- Login credentials
- Personal details
- Payment card information
- Bank account details
These data are then sent to cybercriminals for fraudulent activities, such as unauthorized transactions or identity theft.
Conclusion and Advice
The report highlights the growing threat of financial phishing during the holiday season and offers advice to consumers, retailers, and financial organizations:
For Consumers
- Avoid clicking on suspicious links or emails from unknown sources.
- Never enter personal or financial information on unfamiliar or suspicious websites.
- Use secure Wi-Fi networks and HTTPS connections for online transactions.
- Double-check URLs and secure connections before entering sensitive data.
- Do not share passwords or PINs with anyone.
- Install security solutions with built-in anti-fraud technologies.
For Retailers
- Keep online platforms updated with critical security patches.
- Monitor personal information used for registration and flag unusual or suspicious data.
- Implement two-factor authentication to prevent unauthorized access.
- Use CAPTCHA and restrict transaction attempts to reduce fraud.
- Educate customers on recognizing phishing attempts and securing their data.
For Financial Organizations
- Develop an enterprise-wide fraud prevention strategy.
- Use a multi-layered approach to detect and prevent fraud.
- Educate customers on how to identify legitimate messages and contact the organization in case of suspicious activity.
- Ensure that anti-fraud teams are well-staffed during the holiday period.
Summary
The holiday shopping season is a prime time for cybercriminals to exploit consumers through phishing attacks. With the rise of mobile usage and aggressive marketing campaigns, the risk of falling victim to financial phishing has increased. Kaspersky Lab's report emphasizes the need for vigilance and the implementation of robust security measures to protect both individuals and organizations.
试读结束,高清完整版pdf/doc/ppt,请点下载