Inside the Mind of a Cyber Criminal!

 
Cyber criminals come in many different flavours, but the majority of them are in it for one thing: financial pay-off. They want the money that comes with offering their tools or services, selling stolen data, extortion like ransomware or plain fraud. And they all have one thing in common – your organisation is on their radar.

Which is why, says Anna Collard, SVP Content Strategy and Evangelist at KnowBe4 Africa it is critical to understand how cyber criminals operate, the tools they use and the approaches they take to embed robust security within the organisation.
“With ransomware going rampant and victim organisations paying up to millions of U.S. dollars to the extortionists, this problem is just going to get worse. The U.S. government recently announced that ransomware is a national cyber-security challenge and that there will be serious implications for anyone attacking the United States or their critical infrastructure.
This may lead more criminals to shift their attention towards the emerging economies like Africa, where we do not have the government’s support or capacities to stop and prosecute cyber criminals, making it a safer place to operate,” says Collard.
Social engineering or people hacking is a popular way to distribute ransomware – predominately by tricking people into falling for their phishing scams.
“Another technique to be aware of is password spraying,” she explains. “This is when the bad actor selects a common password, like the organisation’s name, followed by the year, and tries it against every user in the organisation. They scrape names of employees from LinkedIn and then using this information try the possible password against the list of names. Then it keeps on cycling until it hits a winning entry. This is a solid case for ensuring that every single employee uses proper passwords or a password manager and multi-factor authentication where possible.
“This level of attack really underscores how important it is to undertake consistent employee training and security skills development,” says Collard. “No matter how secure your perimeter, no matter how much money is spent on high-end security systems, one poor password can open the doors to the threat actors.”
Multi-factor authentication and robust training are not just invaluable for employees in the office, they are even more critical today as people work from home and multiple locations – particularly as employees migrate to coffee shops for power and Wi-Fi during load-shedding. Public Wi-Fi is wide open and home networks with poor passwords or out of date software are open doors.
“It is also really important to make sure that employees use a VPN, although that is also not a guaranteed protection” says Collard as a recent report by the Orange Cyber Defense team explained.

“With home routers being vulnerable due to people not configuring them correctly or updating them, it might be worthwhile sending pre-configured routers and firewalls to employees’ homes, especially for those who access highly confidential information.”
Another challenge for the organisation is keeping up with vulnerabilities and patch management, which is a complicated task in bigger environments.
“Leading hackers and experts like Kevin Mitnick are drawing lines under the importance of putting people’s understanding of these threats at the forefront,” says Collard. “Make sure that passwords are secure, that they are not stored in diaries or on open platforms like Slack or Google Hangouts, that they understand how to identify social engineering attacks and keep security hygiene at the forefront of all communication. People need to know what is out there and that they have the skills to play an important role in protecting themselves and the organisation.”
Today, the threat actors are organised and well paid. They benefit immensely from their pursuit of vulnerabilities, simple mistakes and human error.

Organisations have to sit on the sharp end of the security stick with robust monitoring and detection systems, clear policies, consistent training and security boundaries.

Hot this week

Stanbic IBTC Reinforces Capital Markets Leadership Through Dangote Refinery IPO

Stanbic IBTC Holdings Plc has reinforced its position as...

CBN Bags NES Distinguished Organisation Award for Economic Reforms

The Central Bank of Nigeria (CBN) has received the...

Leadway Assurance Backs ISSP Initiative to Deepen Insurance Penetration, Consumer Trust

Leadway Assurance, Nigeria’s leading insurance services provider and a...

RMB Nigeria Advises on BOI’s N274.18bn Domestic Bond Issuance

L-R: Head, Debts Capital Markets, RMB Nigeria, Laju Atake;...

LG Electronics Highlights Seven Home Appliances at IFA 2026

As routines and lifestyles evolve across Europe, consumers are...

Topics

Anti-Corruption: As Judicial Officers Re-Echo Need for Special Courts

By Walter Duru One of the issues that came up...

Is the CBN Pushing Nigerians Back into the Banking Halls? 

By Elvis Eromosele  Public institutions in Nigeria have a knack...

Allianz, Sanlam Joint Venture Targets 29 Markets in Africa

Mr. Amine Benabbou Head of Business Division, Africa and Middle...

Rand Merchant Bank Facilitates Landmark Corporate Bond Issuance for Presco

L-R: Olaronke Arigbede, Group Treasurer, SIAT Group, Felix Nwabuko,...

AEDC Appoints Chijoke Okwuokenye as MD/CEO

Abuja Electricity Distribution Company (AEDC) has announced the appointment...

Optimism Reigns in 2015 Insurance Industry Outlook

Despite falling oil prices and post-election uncertainties,the Nigerian insurance sector is looking into the future with broad optimism and confidence. Mr. Fola Daniel, Commissioner for Insurance, National Insurance Commission (NAICOM) says the industry is undergoing rapid transformation, thus requiring the strategic support of operators and other relevant stakeholders to enable the industry occupy its rightful position in the forefront of the financial services sector in Nigeria.

NLNG Commissions University Teaching Hospital Projects in 4 States

​Nigeria LNG (NLNG) Limited today began another round of...

Fidelity Bank: Reaffirming Brand Promise Through Rebranding

In today’s corporate environment, three key ingredients are necessary for any organisation to remain relevant and profitable: Ability to engage the client; dynamism, and flexibility. Very few organisations have exhibited these traits over the past two decades more than Fidelity Bank Plc. The recent refresh of Fidelity Bank’s corporate identity, the latest in its 27-year history, speaks to these important traits and the need to remain relevant in the world of corporate giants.