Cyberattacks Are Becoming More Common in Brazil

Contrary to what you might imagine, cyberattacks are not targeting only large companies. They also target small and midsize businesses. Moreover, those companies are usually less prepared to respond

Moreover, threat intelligence reports describe a scenario in constant motion. Currently, cybersecurity is a puzzle that most organizations find hard to solve. After all, criminal tactics change from one quarter to the next. Therefore, cyberattacks demand continuous attention, regardless of the industry.

In practice, it is worth remembering that this concern is not limited to large companies. Similarly, it applies to public organizations, NGOs, and financial institutions. Small and midsize businesses, in fact, appear in the crosshairs more and more. After all, when it comes to cyberattacks, no one has guaranteed immunity.

Consequently, the risk to SMBs deserves attention. In general, they run fewer defense layers and have fewer people dedicated to security. As a result, a single incident can compromise the entire operation. Moreover, recovery costs weigh far more heavily on a smaller balance sheet. 

In short, public bodies and large companies usually survive a cyberattack. For an SMB, however, the same event can end the business. Therefore, the fluidity of modern threats requires frequent review of the security approach. In this way, protection stops being a one-off project and becomes routine.

More resources flowing to stop cyberattacks

This scenario increases companies’ concern and drives more resources toward cybersecurity. Back in 2022, in the Global Digital Trust Insights developed by PwC, 77% of Brazilian executives already saw organizations as “too complex” to be protected. Since then, complexity has only grown. After all, cloud, SaaS, and hybrid work widened the exposed surface.

Similarly, security budgets kept rising year after year. However, spending more does not mean protecting better. In many cases, tools overlap and nobody operates all of them. Therefore, it pays to prioritize real coverage over the number of licenses.

As a result, part of these resources is wasted due to organizational complexity. Many companies bought products without assessing their security. In addition, they invested without ensuring that IT would play a strategic role in the organization. Others do not even know their own IT assets. As a result, they become less productive and more exposed.

Meanwhile, another recurring mistake is separating corporate risk from cyber risk. Consequently, the crisis response plan is born incomplete.

Which sectors suffer the most?

An IBM report surveyed the ten most attacked sectors in Latin America. See, below, the variation recorded between 2021 and 2020:

Gráfico, Gráfico de barrasDescrição gerada automaticamente

After all, what already stood out then was the lead of the manufacturing sector. That pattern, in fact, held in the years that followed. A McKinsey study showed that the energy sector can also be hit on several fronts. This includes generation, transmission, and distribution. Moreover, the effects are potentially devastating.

Moreover, Light, for example, fell victim to a ransomware attack in 2020. Cases like that, however, are no longer exceptions in critical infrastructure.

The most common attacks

In practice, a few patterns repeat across the Brazilian market. Below, see the ones that weigh most in incident investigations today:

The most common cyberattacks, one by one

– Legitimate tools turned against you – Cobalt Strike started as a security testing resource. However, after it leaked, it became a common weapon among criminals. Today the same applies to remote access software and native operating system scripts.

In addition, attackers host their own infrastructure on legitimate cloud providers. In this way, they hide malicious traffic inside normal traffic. As a result, automated blocking by domain reputation loses effectiveness. Therefore, detection has to look at behavior, not only at addresses.

From the supply chain to the ransom

– Supply chain attacks – This approach remains popular because it amplifies the attacker’s results. After all, compromising one supplier usually beats targeting a single victim by a wide margin.

The logic is simple. By compromising a product, such as a management system, the intruder reaches its whole customer base. For this reason, it is wise to adopt measures that reduce risk tied to suppliers and third parties. This also applies to technology providers. Furthermore, these attempts occur with services from different areas, including those provided through the cloud.

– Ransomware as a service (RaaS) – The business model behind data kidnapping has changed. Currently, specialized groups rent the malware to affiliates who run the attack. Moreover, double extortion became the standard: data is encrypted and also copied. Then the criminal threatens to publish it. Therefore, having backups is no longer a sufficient answer.

– Identity theft and session hijacking – Infostealers collect passwords, tokens, and session cookies. With a valid cookie, the criminal enters the cloud environment without typing a password. In addition, phishing powered by generative AI made the lures far more convincing. After all, the messages no longer carry obvious writing mistakes.

Good corporate practices

Therefore, a few precautions greatly reduce the company’s exposure to cyberattacks. Here are some practical recommendations:

– Joint action by the CEO, finance leaders, and security leaders to guarantee a budget dedicated to cyber protection.

– Build a solid data governance foundation. After all, Brazil’s LGPD has been in force since 2020, and the ANPD already applies sanctions.

– Adopt phishing-resistant MFA, with FIDO2 keys or passkeys, on critical access. Moreover, monitor cloud sessions to spot the use of a stolen token.

– Analyze and quantify cyber risk together with corporate risk. Afterwards, simplify whatever you can in the business model.

Likewise, get to know the security solutions provided by Inove Solutions. Therefore, reduce the risks your company is exposed to.