If you ask economists in which direction certain sectors will move in the future and where the most investments will be made, cybersecurity is usually among the top three, alongside investments in technological development. In Croatia, the National CERT Department has been protecting the Croatian cyber space for 15 years. This department is part of the Croatian academic and research network CARNET, which deals with the processing of cybersecurity incidents, raising awareness, and educating Croatian citizens about cybersecurity.
During 2022, CERT processed a total of 1,296 cybersecurity incidents, which is a seven percent increase compared to 2021. At the top are phishing and phishing URLs as forms of fraud, followed by scams.
Everything starts with identity theft
As much as 42.6 percent of all processed incidents are cases of phishing (online identity theft). A significant change, they say at CERT, relates to the increase in the number of incidents classified as scams, which in 2022, due to the increased number of citizen reports of that type of incident, came in second place.
– As the biggest cyber threats to companies and individuals, we would certainly mention phishing and ransomware. Phishing because it is the most common attack vector, meaning everything starts with phishing. Citizens are threatened daily by increasingly sophisticated phishing campaigns created to steal personal and banking data. In addition to phishing messages, there are phishing URLs that imitate legitimate systems and fake online stores of well-known fashion brands. We would mention ransomware as the next significant threat because it can cause downtime or even business interruption due to data loss, and the victims are not only companies but can also be individuals – they explain at CERT.
In January 2023, the National CERT processed a total of 139 incidents, and it can be concluded that since the beginning of the year, the number of threats of business fraud types – CEO fraud and BEC (business email compromise), frauds targeting bank users, phishing frauds using QR codes, critical vulnerabilities in VMware ESXi hypervisors, frauds where malicious attachments are delivered via email with the aim of stealing access data for Microsoft systems, and frauds imitating the e-Citizens system has increased.
Victim profile
The most common targets in the economy are, as confirmed by CERT, still banks and their customers, followed by energy facilities, healthcare institutions, as well as small and medium-sized enterprises.
– Banks and energy facilities have the highest level of protection, but due to potentially high rewards, they are constantly targets of cybercriminals. Small and medium-sized enterprises, which often do not think they could become victims of a cyber attack, are particularly vulnerable. Ransomware attacks that demand payment to potentially regain access to their data, in addition to reputational damage, can cause downtime or even business interruption. Attackers monitor events and adapt their actions to current topics. Thus, in Croatia, we had examples of attacks targeting mobile banking users, using the theme of transitioning to the euro for the attack – they emphasize at CERT.
—
—
The Ministry of the Interior added that cyber incidents often appear in the form of campaigns; during such times, a very large number of incidents with common characteristics is recorded in a short period. Targeted attacks on a very specific target (e.g., a specific company) are rarer, but these attacks are usually highly sophisticated.
Given the trends of increasing numbers of attacks and their growing sophistication, it is surprising that companies’ investments in their own cybersecurity are declining. CERT presented data from the European Union Agency for Cybersecurity (ENISA) report, ‘NIS Investments 2022’, published at the end of 2022, stating that the share of the total IT budget of companies for information security is 6.7 percent, which is one percent less compared to 2021.
– Large enterprises in the EU allocate an average of 120,000 euros for cybersecurity per year, while small and medium-sized enterprises allocate an average of 5,500 euros. The banking sector invests the most in cybersecurity, which is not surprising considering that the average damage from a cybersecurity incident in that sector amounts to 300,000 euros, along with reputational damage – they add at CERT.
Criminal offenses
Although investments in cybersecurity are lower compared to 2021, experts say that total investments in cybersecurity have significantly increased since 2016, when the NIS directive was adopted, which set standards and requirements for cybersecurity in the EU. We asked CERT whether the profile of hackers involved in cybercrime is changing and in which direction, to which we received the answer that it is not entirely correct to view hackers exclusively in a negative context.
