November 15, 2023

Webinar Replay: Q3 2023 Threat Landscape - Social Engineering Takes Center Stage

Our Quarterly Threat Landscape reports are fueled by frontline incident response intel and elite analysts.

The third quarter of 2023 saw cybersecurity threats continue to increase in sophistication. Kroll’s findings for Q3 revealed that social engineering attacks peaked at their highest level yet, with almost twice as many incidents compared to what we observed in Q2 of this year.

In this briefing, Kroll’s cyber threat intelligence leaders Keith Wojcieszek, Laurie Iacono and George Glass will explore key insights and trends from hundreds of cyber incidents handled worldwide each year. They will also outline critical issues organizations should be aware of, including the sectors hit the hardest and active ransomware groups such as LOCKBIT and BLACKCAT.

The Briefing Covers:

  • Key themes and patterns in the changing threat landscape and how these could impact organizations
  • Critical shifts in attacker behavior in the past quarter, including popular incident types and initial access methods
  • The most active types of ransomware groups and the industries most targeted
  • The continued reinvention and evolution of threat actor groups and attack methods

Key Sections From the Webinar

BEC Attacks Continue to Surge Across Sectors

“In Q3, we did see an uptick in incidents impacting the manufacturing and construction sector largely led by business email compromise (BEC) or email compromise attacks. One of the reasons for this uptick in BEC attacks has to do with the reliance on third parties and suppliers.” – Laurie Iacono

Kroll continues to see the professional services sector rank first across cases — in particular legal firms — fueled by a rise in BEC across all sectors and specific campaigns targeting the legal industry, such as the BLACKCAT ransomware gang. We also observed nominal rises in the targeting of the manufacturing (2%) and construction sectors (1.5%) from the previous quarter. In Kroll’s observation, both sectors most frequently experienced BEC in the third quarter. For manufacturing, ransomware was the second most likely threat type to be observed, while insider threat was the second most likely threat type for construction. Learn why:

Social Engineering Yields Initial Access

“From using QR codes in emails to sharing links via Microsoft Teams, threat actors are evolving their methodology to manipulate humans to click on the bait. This is not phishing through email; it's phishing through an instant messaging platform.” – Laurie Iacono

Kroll saw social engineering tactics increase dramatically in the third quarter, with significant increases in phishing (8%), valid accounts (9%) and voice phishing (“vishing”), as well as other tactics (3%). This rise in social engineering activity aligns with multiple open-source reports warning about these types of attacks via Microsoft Teams and the rise of activity by the group KTA243 (SCATTERED SPIDER), which uses phone- and SMS-based social engineering tactics to lure users into exposing their credentials. See how this is accomplished via the Kroll intrusion lifecycle:

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...