Lock It Down: Defending Against Modern Identity Attacks In Business

Businesses are facing a relentless, coordinated wave of identity attacks as cybercriminals are using stolen credentials to impersonate real employees. One of the latest instances of a major identity attack was discovered earlier this year, and it was reported that a group of hackers impersonated Microsoft Team IT workers to unleash a threat cluster known as UNC6692 on multiple organizations. The hackers reportedly deployed ransomware that allows them to maintain access to corporate accounts and bypass authentication to move through internal systems. It was claimed that businesses in the manufacturing, energy, engineering, construction, and services sectors were targeted, but the names of the companies were not revealed in the reports.

This campaign highlights the evolution of cyber attacks wherein threat actors are now combining social engineering with custom malware while taking advantage of the trust employees put in their commonly used systems and platforms. To keep business data safe, companies must rethink their cybersecurity strategy, and build stronger defenses against identity attacks.

The Repercussions of Identity Attacks

Research shows that identity weaknesses make up roughly 65 to 90 percent of all security investigations, but many companies have yet to take action to stop credential theft. According to new data, nearly 70 percent of all business leaders aren’t confident about the efficacy of their identity security solution. Not only are they failing to integrate top-of-the-line identity security solutions into their systems, but most are also falling behind on basic cybersecurity measures, such as multifactor authentication.

Identity attacks may result in severe financial losses as thieves can make fraudulent wire transfers, drain business accounts, or open credit lines using stolen corporate IDs and names. It can also cause operational disruption, heavy government fines, costly lawsuits, and loss of customer loyalty and reputation. In some cases, it may even lead to business closure as industry estimates suggest that about 60 percent of small companies are forced to permanently shutter their doors after a major cyber attack.

Strengthening Defenses with the Right Tech Solutions

Since hackers routinely steal log in credentials through increasingly sophisticated tactics, some companies are fighting back by integrating the best ISPM tools into their systems. Identity Security Posture Management matters because it constantly evaluates whether multi-factor authentication and access policies are properly enforced to prevent breaches. It also gets rid of unprotected spots that threat actors could take advantage of. Some of these blind spots include orphan accounts left by former employees as attackers use old credentials to blend in with legitimate users. In fact, reports of recent identity attacks in Australia reveal that hackers stole credentials belonging to both former and current staff, and the log-ins were used to plant infostealer malware in banking institution systems.

Another tech solution that businesses should consider is Identity Threat Detection and Response (ITDR). This monitoring system protects user credentials and authentication systems by tracking normal user and system pattern access to spot changes or unusual behavior. It also detects questionable log-in attempts from unfamiliar devices or unusual geolocations, and ends hijacked sessions or blocks compromised accounts in real time.

Preventing Credential-Based Attacks in the Workplace

Providing employees with the right security tools is essential to prevent credential-based attacks from causing financial and operational damage in the workplace. First, companies should turn on MFA for all work accounts so a secondary verification will always be required. All employees should be encouraged not to use the same password for personal and work accounts and across different company tools or platforms. For added security, have workers use a password manager to generate and store unique passwords instead of memorizing or writing them down.

Next, train employees to recognize signs of identity attacks or attempts to steal their credentials. Some red flags that they should be on the look out for include getting log in code requests or push notifications on their phone even when they’re not trying to sign in. They may get emails or text messages stating that someone logged into their work account using a new device or a strange IP address. There’s also the possibility that they could receive password change confirmation or notices that their email was updated without action on their part. A hacker may also pretend to be a manager or a supervisor and ask for their credentials, so employees should always verify first through a phone call just to be on the safe side.

With cyber attacks becoming more sophisticated, companies should take active steps to defend against identity attacks. By using the right tech tools and promoting a culture of cybersecurity, organizations can keep track of who or what can access their systems, and avoid the repercussions that could lead to financial loss or business closure.