Home Tech News Mobile devices are one of the most popular “entry points” for hackers

Mobile devices are one of the most popular “entry points” for hackers

23

Mobile devices are compact assistants with great functionality, right up to binding bank cards, contactless data transfer and doing business. You can use social networks, instant messengers, mail, personal accounts, negotiate and work without looking up from your cell phone. Pretty comfortable!

More and more functionality is being developed for smartphones, which allows the user to solve many problems using only one small device. But such growth provokes activity among attackers. Today, 90% of people worldwide use mobile devices, more than 25% use active Internet access.

In this regard, threats to mobile security tend to grow rapidly in 2020. After all, a hacker now needs to access your phone to use your data and even a credit card. And believe me, this is extremely simple.

Mobile threats for companies

The scandal with Facebook in 2018 due to data leakage shows that not a single company, large or small, is safe from hackers. Even cybersecurity research and development companies may be vulnerable.

Verizon Mobile Security Index 2019 report showed that too many organizations were not prepared to repel attacks, which led to data theft or downtime.

Smartphones, tablets, laptops and other connected devices are gaining popularity in the work environment despite the fact that they are not subjected to thorough analysis. The VMSI report examined mobile device vulnerabilities in detail. The share of organizations that confirm that mobile devices pose an unnecessary risk or are involved in data leakage is growing every year.

The failure of companies to correctly repel attacks shows that their current protection is not enough. About 86% are worried about the rise of mobile threats last year, and 93% of financial services companies are worried that they need to deploy a more reliable security system.

Violations are often caused by phishing and social engineering schemes that force employees to click on infected links. The most frequently mentioned motives for employees are personal gain (46%), unintentional (36%), anger (32%), convenience (32%), ideology (27%), espionage (24%), fun / curiosity (24% ) or coercion / managerial pressure (21%).

Mobile devices for business

Smartphones are increasingly being used for work, which includes the transfer of any business data through insecure communication channels. More and more employees are viewing several mailboxes, work and personal, from one weakly protected mobile device. In this regard, more and more cybercriminals are switching to online fraud, including extortion.

Having obtained even remote (and not direct, through theft) access to a mobile device, an attacker will be able to recognize not only personal but also a bank or corporate accesses. And crank it up so that you remain in the dark.

In addition, there are other threats to mobile devices that can open hackers access to a smartphone. Below are the most popular tools for cybercriminals:

Top 5 threats for mobile devices:

1. Social engineering with bad passwords,

2. Mobile advertising fraud,

3. Damaged device and outdated software,

4. Using insecure Wi-Fi connections,

5. Data leakage on a mobile device and cyber attacks.

Read this also:  Folding smartphone Oppo Find N3 Flip looks very unusual

Consider each of the threats in more detail.

Social engineering

According to a FireEye report, 91% of cybercrimes start with email. This type of attack is aimed at deceiving people so that victims click on a dangerous link and give attackers access to their device.

Smartphone users are at the greatest risk since many senders only display the names of senders. This makes it easy to fake messages and tricks people into believing that the letter came from someone they know. Users are more likely to respond to a phishing attack on a mobile device than on a computer. The small screen, the limited display of information and the ability to open a link or response with one click (even by accident) increase the likelihood of phishing success.

In addition to mail, messengers, social networks and games remain vulnerable. According to a Wandera report, 83% of phishing attacks in the last year came from text messages on Facebook Messenger and WhatsApp. Moreover, those who have already clicked on a phishing link are very likely to repeat their action in the future.

Social engineering also includes “poor password hygiene”, which makes it very easy for an attacker to gain access to a telephone. According to LastPass analysis, half of the professionals use the same passwords for work and personal accounts. And stolen passwords become the reason for breaking corporate data.

Mobile Advertising Fraud

According to the IAB (Interactive Advertising Bureau) report, mobile advertising generates revenue of $ 57.9 billion, and this is only in the first half of 2019. Of course, attackers have found a way to “infiltrate” the revenue stream from mobile advertising, which is why many companies suffer losses.

Advertising fraud can take several forms, but the most common is the use of malware to create clicks on ads that supposedly come from a real user using a website or application.

For example, a user has downloaded a game or an unverified messenger that in the background will generate fraudulent clicks on legitimate ads appearing in the application. Thus, scammers rob the company. Not only advertisers but also mobile users become victims. As in the case of crypto-hacking, advertising fraud malware runs in the background and can slow down the smartphone, drain its battery, increase the level of data charging or cause overheating.

The most popular mobile advertising fraud platform is Android. Therefore, it is extremely important to download only official applications from trusted sources.

Damage to the device and outdated software

A lost mobile device can pose a serious security risk. Most people still do not use pin codes or biometric protection, even more – do not use encryption. In case of damage or loss of the device, it becomes an easy target for the attacker.

A Wandera report also indicated that 43% of companies have at least one smartphone on their list without any lock screen protection. And passwords preferred to use four-character, that is, the simplest.

Another problem for users is the untimely updating of software (software). Smartphones pose a particular risk to corporate security because they have no guarantee of regular software updates. Most mobile device manufacturers do not support the product effectively and rarely release system updates as well as security fixes. And if there are updates, not all users will agree to upgrade their device.

Read this also:  Sales of tablets and chromebooks set records amid pandemic

Using Insecure Wi-Fi Connections

The mobile device is in the same security as the network to which the device is connected. Users are constantly connected to public Wi-Fi networks, and such networks are not always secure.

According to a Wandera study, corporate mobile devices use Wi-Fi almost 3 times more often than using data. Almost a quarter of devices are connected to open and potentially insecure Wi-Fi networks and 4% of devices have experienced an intermediary attack.

You can protect your mobile device through a VPN, which can be activated when connected to an insecure network. Remember that hackers can use corporate VPN errors when working remotely.

Data leakage, including after cyber attacks

Data leakage is one of the largest and most frequent threats to organizations. Absolutely every company can face a data leak. Employees can inadvertently view a link, application, or visit a site, and thereby open access for attackers to the network. The main cause of leaks is user errors, for example, improper electronic correspondence, inadvertent insertion of confidential information, etc.

As for cyberattacks, most of them are aimed at obtaining confidential information or access to finance. Careful selection of mobile devices and adherence to security policies will help protect corporate data from leaks.

How to protect corporate mobile devices

Securing mobile devices is an important aspect for every company. Almost all employees regularly get access to corporate data from smartphones, and they need to be protected to avoid corporate losses.

Leading pre-sale engineer of Bitdefender Russia, Kirov Evgeny, recommends:

  • Purchase corporate mobile devices with the possibility of additional protection from the company.
  • Install special protection solutions – Bitdefender Mobile SecurityAdvanced Business Security on mobile devices.
  • Regularly update the software and operating system of the mobile device.
  • Install only official apps from trusted sources such as Google Play. Before installation, check the application’s reviews, information about the developer and the list of requested permissions to make sure that all of them correspond to the stated purpose of the application. Regularly check applications and remove any that are suspicious (for example, they absorb too much energy).
  • Switch to hardware authentication, as this is the most effective way to increase security and reduce the likelihood of phishing. If not possible, we recommend that you start using at least simple authentication to prevent most phishing attacks.
  • Use encryption and data loss prevention (DLP) tools to prevent the disclosure of confidential information.