Cyberattackers long ago figured out that the easiest way to gain access to sensitive data is by compromising an end user’s identity and credentials. According to the Verizon 2017 Data Breach Investigation Report, 81% of hacking-related breaches leverage either stolen, default, or weak credentials. Often these credentials belong to privileged users, providing cyber adversaries the “keys to the kingdom” and providing them a perfect camouflage for their data exfiltration efforts.
Betting on the human factor and attacking the weakest link in the cyber defense chain, credential harvesting has become the basis of most cyberattacks. Recent reports of a newly-detected Smoke Loader infection campaign and the re-emergence of Magecart-based cyberattacks are perfect examples of this common tactic used by cybercriminals and state-sponsored attackers alike.
The term “hacker” has even become somewhat obsolete. Attackers no longer hack their way in against sophisticated technology, they log in using their own credentials. Once inside, they settle in and fan out, moving laterally to scan the network and hunt for privileged accounts and credentials. Then they elevate their privilege, extract your company’s most sensitive data and get out, covering their tracks so you may not know they were even there for months.
A recent Ponemon study found that the average amount of time required to identify a data breach is 197 days, and the average amount of time needed to contain a data breach once it is identified is 69 days.
While credential harvesting is widely used by attackers, what they do with the stolen information can vary greatly. In some cases, the credentials will be used for subsequent attacks where the goal is to gain access to systems or network resources, or they can be monetized by taking over bank accounts or simply selling the information on the Darknet.
So what steps can businesses take to minimize the risk of falling victim to these credential harvesting campaigns, and avoid privileged access abuse? Here are a few fundamental steps to take:
None of this must be complicated and Delinea and our partners have years of experience putting together Privileged Access Management solutions in some of the world’s largest and most complex customer environments. Delinea Zero Trust Privilege helps customers grant least privilege access based on verifying who is requesting access, the context of the request, and the risk of the access environment. By implementing least privilege access, Delinea minimizes the attack surface, improves audit and compliance visibility, as well as reduces risk, complexity, and costs for the modern, hybrid enterprise.
Stealing a valid credential and using it to access a network is easier, less risky, and ultimately more efficient than using an existing vulnerability, even a zero-day. Cybersecurity defenses need to adapt to this fact. User education and beefing up an organization’s authentication systems are two essential steps that can minimize the risks associated with credential harvesting and subsequent cyberattacks aimed at data exfiltration.