An e-commerce store was repeatedly suffering breaches over the past year. Customers were being tricked into paying money into the attacker’s bank account, even though they were using the real website. The retailer hired a specialist IT services firm to rebuild the website and improve its security, but the attacker kept returning and compromising the website. The retailer sought the help of CERT NZ. SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe “We were able to help them identify the key areas where their website’s security was falling short and to understand why these weaknesses hadn’t been resolved by their temporary and partial fixes,” says CERT NZ director Rob Pope. “With guidance from our team, they were able to take steps to resolve the weaknesses and keep the attacker out for good.” Pope says the case of this e-commerce store was one 736 cybersecurity incidents reported to CERT NZ from April to June. This is the largest ever volume of reports for a single quarter, he says. “The rising number of reports we are seeing demonstrates the growing level of trust for CERT NZ as a central front door for cybersecurity issues.” CERT NZ says phishing and credential harvesting reports are also up significantly this quarter; from 196 in quarter one, to 455 in quarter two. Of these, 337 were from the financial sector, with 321 of these masquerading as known New Zealand brands. This leap in reporting comes from closer collaboration with the financial sector, and has enabled us to get a better picture of the phishing campaigns that constantly target New Zealanders, says Pope. CERT NZ says it continues to see phishing emails pretending to be Office 365 documents and emails offering fake tax refunds. It says direct financial losses from these breaches totalled $2.22 million for April to June, down 24 per cent from the previous quarter. Majority (75 per cent) of the incident reports are for small amounts, typically less than $500. But those aged 55 and over continue to be the largest age group reporting losses to cybersecurity incidents, comprising 75 per cent of all of the losses reported. CERT NZ says 69 vulnerability reports were received over the first two quarters of 2018, with 15 handled under the Coordinated Vulnerability Disclosure policy (CVD). A vulnerability is a weaknesses in software, hardware or an online service that can be exploited to damage a system or access information. The reported vulnerabilities were across a range of categories including websites (54 per cent), authentication, authorisation and accounting (14 per cent), and networking (13 per cent). Pope encourages all organisations to have a plan for vulnerability reports. “A little careful planning and talking to us ahead of time is likely to make the process much less painful for everyone involved.” cybercrime_cybersecurity-100034562-orig.jpg Related content opinion The changing face of cybersecurity threats in 2023 Cybersecurity has always been a cat-and-mouse game, but the mice keep getting bigger and are becoming increasingly harder to hunt. By Dipti Parmar Sep 29, 2023 8 mins Cybercrime Security brandpost Should finance organizations bank on Generative AI? Finance and banking organizations are looking at generative AI to support employees and customers across a range of text and numerically-based use cases. By Jay Limbasiya, Global AI, Analytics, & Data Management Business Development, Unstructured Data Solutions, Dell Technologies Sep 29, 2023 5 mins Artificial Intelligence brandpost Embrace the Generative AI revolution: a guide to integrating Generative AI into your operations The CTO of SAP shares his experiences and learnings to provide actionable insights on navigating the GenAI revolution. By Juergen Mueller Sep 29, 2023 4 mins Artificial Intelligence feature 10 most in-demand generative AI skills Gen AI is booming, and companies are scrambling to fill skills gaps by hiring freelancers to make the most of the technology. These are the 10 most sought-after generative AI skills on the market right now. By Sarah K. White Sep 29, 2023 8 mins Hiring Generative AI IT Skills Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe