business law

profileismilazimdegil
TECHCYBERCRIMEHomegrownmenace.docx

TECH CYBER CRIME: Homegrown menace 

Contents

1. Regional trouble

Listen

As Latin Americans take to online banking, Brazil is scoring records for the wrong reasons.

The number of internet users in Latin America has doubled in less than a decade, according to the World Bank. Close to 60% of Brazilians used the internet last year, up from less than 30% in 2006. But as more people log on, they open their personal information to new vulnerabilities.

Last year, cybercrime cost the world economy $445 billion, according to figures from PwC. "The more people recognize money is digital, the more criminality will migrate there," says Tom Kellerman, chief cybersecurity officer at Trend Micro, a software security company.

With 34% of Latin America's population, Brazil has also become LatAm's stomping ground for cybercriminals. The country ranks in the top three launching pads for cyberattacks and at least 75% of Brazilians say they have been victims of cybercrime, according to PwC.

Russia and China have long been home to the originators of cybercrime, but that is changing, says Kellerman. Increasingly, hackers are using home-grown programs. "The Brazilian underground used to be some of the biggest buyers of malware from Eastern Europe, but now they are producing their own," he says.

Financial institutions, energy companies and governments are the top targets for cybercrime in Latin America, says Kellerman, adding that the prevalence and severity of cyberattacks in the region "is dramatically getting worse".

Last year, RSA Research Group uncovered a new malware attacking Brazil's Boletos, a type of payment slip. RSA found that more than 30 Brazilian banks had been targeted. Cybercriminals obtained user login information and used their bank accounts to issue Boletos, which can be printed out or used online.

When a customer gives the slip to a merchant or other person, the bank transfers money from the customer's account. Cybercriminals intercepted the Boletos and redirected the payments to their own accounts. RSA estimated losses to be 8.57 billion reais ($2.2 billion at today's exchange rate).

For the first time, Hewlett Packard and the Ponemon Institute included Brazil in its annual Cost of Cyber Crime Study, published in October. The survey deals with expenses related to theft, lost business and business responses allocated to fight cybercrime. Cybercrime hit US businesses the hardest, costing companies with more than 1,000 employees $15 million each per year on average, the report found.

Brazil ranked fifth, with the 27 companies with over 1,000 employees surveyed reporting average losses of $3.85 million from cyberattacks.

Financial service providers had the most significant losses. The most costly crimes are denial of services attacks, which aim to render a company's service unusable to its clients.

Regional trouble

Although Brazilian financial institutions have taken the brunt of cyberattacks in Latin America, hackers are also hitting other Latin America countries, namely Mexico and Colombia.

From 2000 to 2014, Mexico's internet-using demographic grew from 5 million to more than 50 million, almost half the population of the country, according to PwC data. Meanwhile, cyberattacks grew by 40% in 2014 alone, costing the country roughly $3 billion.

The issue is prompting state-level action. The Mexican government has agreed to adhere to online security protocols outlined in the Budapest Convention and has created a special public agency, the National Center for Cyber Incident Response, to lead its cyber defense. Colombia, where cybercrime cost an estimated $464 million last year, has also taken steps to combat cyberattacks, including creating a dedicated government agency to address the issue.

Looking ahead, banks, companies and governments will likely have to ramp up their security operations to guard against a new wave of cyberattacks. Spending on cybersecurity in Latin America will more than double from $5.29 billion in 2014 to $11.91 billion in 2019, MicroMarket Monitor forecasts.

Banks and companies need to invest at least 20% percent of their IT budget to guard against cybercrime, Kellerman advises. Also, they have to prepare for more sophisticated types of attacks.

The defense should focus on next generational cybersecurity. "For example virtual patching and mobile security," he says. "They also need to test their systems for vulnerabilities before they are exploited."

Banking Technology

~~~~~~~~

By Patrick Ferguson