This series of articles will be presented in three separate parts gradually. The current article aims to familiarize readers with the nature of cyber threats and cybersecurity, without discussing the elements involved in such threats. The second part will examine cybersecurity within the broader framework of national security strategies of countries and international security. The final section will discuss the actors behind cyber threats who use the global internet to launch cyber attacks or threaten, the defensive and protective capacities of holders of advanced technological capabilities, cyber warfare, and defense.---Information security - Cyber threats and security have become one of the vital issues of national and international security in our era. In recent months, several events have led to increased attention to cybersecurity by governments. A very brief list of these events in recent months includes: - The personal information of the United States government, including the data of 22 million federal employees, was stolen. - The private information of 75 million people from the health insurance system of Anthem was stolen. - The theft of financial and banking information of over 40 million people from the Target Corporation system, which includes Target chain stores. Such information can have security and economic value. Because the confidential information of federal employees raises issues regarding the protection of information and personnel related to information systems and can challenge the security and physical health of individuals associated with the system. Protection of critical infrastructure - In 2014, information stolen from Sony Pictures led to the destruction of data and software on about 3,000 of the company's computers and the exposure of films in production and produced, as well as the disclosure of sensitive email content of the company. Security officials worldwide are also concerned about another type of threat in the cyber environment. Critical infrastructures such as water and electricity facilities, communications, and transportation are severely vulnerable to cyber attacks. A cyber attack on Ukraine's power grid in December 2015 resulted in a blackout for 80,000 electricity customers. In addition to such threats, devices and tools like airplanes, cars, and even medical devices can be exploited and have deadly consequences. Each year, the list of such vulnerabilities in terms of type and targetable devices shows a significant increase compared to the previous year. Concurrently, the statistics of discovered attacks are also rapidly on the rise. Just between 2013 and 2014, the frequency of cyber attacks on water and electricity companies increased by 517%, with an average cost of about three and a half million dollars per incident. Between 2006 and 2014, requests for assistance from computer emergency response teams in the United States saw an increase of more than 12 times, rising from 5,500 cases to 67,000 cases. According to estimates from the Center for Strategic and International Studies and the computer security group McAfee, the annual cost of cyber crimes worldwide is between 375 and 575 billion dollars. In the world of computer software, the majority of incidents and vulnerabilities target large companies such as Microsoft and Macintosh. Dimensions of everyday life - When we test this picture in broader dimensions of international life, a more terrifying image emerges: - On November 29, 2016, the German government announced that information related to 600,000 subscribers of a German organization had been stolen. Members of this internet organization used their cars for transportation across Germany and even Europe, paying for shared costs through their bank accounts. The significance of the dimensions of this cyber theft is understood when we realize that the banking information of about 638,000 users, including account numbers and payment IDs, 15,000 phone numbers, and 101,000 user emails along with their names and addresses are now in the hands of the thieves. - It seems that the news above was made public last week after completion. This means the origin of the operation dates back to about a month and a half ago. However, forty-eight hours before its publication, another similar news was released in Germany that can be interpreted both independently and in connection with the above news. Independently, the news indicated the first successful cyber attack on Germany's largest internet system, Deutsche Telekom, which unexpectedly cut internet connectivity for nearly one million people. This attack was part of a directed operation that operates in two phases. In the first phase, the routers and DSL devices of users failed so that the center of the attack could install malware on the devices using those routers and DSLs. Thus, the gates (ports) of the computers connected to the network were taken out of the control of their owners and placed in the hands of the attackers. Subsequently, the routers that were exploited began receiving commands from outside the network to execute their requests. Fortunately, the operation was discovered and stopped at this stage, and users were educated on how to neutralize the malware by restarting their modems. However, if we interpret this news in connection with the news related to Comuto Deutschland, it seems that if the issue of routers and DSLs failing had not been controlled in time, the banking information of at least some users of Comuto Deutschland could have been exploited by thieves when they were unable to access their bank accounts due to internet disconnection, potentially leading to millions of euros being stolen from their accounts. Attacks on potential military centers - In September of this year, one of the networks of the Japanese Ministry of Defense was targeted by a major cyber attack, raising the possibility of access to military secrets. However, on November 27, this news was denied by the Ministry of Defense. The Japanese Ministry of Defense had also been attacked in 2013 and 2011, and in 2008, a naval officer was tried for sharing information about a sensitive missile system. This year, during the presidential elections in the United States, it was frequently heard that a foreign country attempted to access the confidential information of the Democratic Party. In response, according to NBC reports from undisclosed sources, U.S. military officials stated that they had preemptively prepared for defensive measures against cyber attacks on election day, although details of such preparedness were not disclosed. According to The Guardian (November 1, 2016), almost simultaneously with the peak of rumors about the possibility of foreign interference in the U.S. elections, Philip Hammond, the British Defense Secretary, announced that the British government allocated nearly two billion dollars (1.9 billion euros) to create "effective cyber attack capabilities." He stated, "If we do not have the capability to respond to a cyber attack and allow attackers to assault our power supply systems and keep us in blackout, or attack our air traffic and force our planes to land, we will have no choice but to turn the other cheek or resort to military action." Cyber crimes - Throughout 2016, numerous cyber crimes have occurred in terms of type and impact on the daily lives of people. For example, if in the past a criminal aimed to steal an individual's credit card information and then exploit it through online purchases, now another method of attack targets ATM cardholders, which is colloquially referred to as "Jackpotting." This phenomenon has emerged following people's embrace of online banking systems, and its results are much more profitable for cybercriminals than stealing a credit card. In this method, attackers steal sensitive information from groups of users and withdraw significant amounts of cash from the cardholder's account using the ATM system. In some cases, the amounts are so high that they equate to hitting the "jackpot" on a slot machine. Typically, different types of malware are used for such thefts. In January, cyber attackers in Europe managed to withdraw 200,000 euros from bank accounts. The attacking group used a type of malware known as the "Tyupkin Trojan." During 2016, countries such as Armenia, Bulgaria, Belarus, Estonia, Georgia, Kyrgyzstan, Moldova, Poland, Romania, Russia, Spain, the UK, and Malaysia were targeted by such attacks. In Taiwan, 70 million Taiwanese dollars were stolen from three major banks, and in Thailand, the theft of 12 million Thai baht prompted the central bank to issue a warning to over 10,000 ATMs. In fact, cyber attacks in Asia, which had been very scattered until recently, have been occurring on a much larger scale in the past one or two years. Even in Bangladesh and Vietnam, banks have been targeted by similar cyber attacks. Available information indicates that in one case, a typographical error in typing the name of a company prevented cyber attackers from making further progress, leaving about 20 million dollars of bank funds untouched. Card-issuing companies are aware of such cyber attacks, but there is still no complete understanding of how the malware operates. It is believed that the malware used for "jackpot" banking operations had infiltrated the banking system some time ago and was likely equipped with some form of monitoring system to oversee the operational process and achieve the desired outcome at the right moment. Conclusion - Cyber attacks in their security, military, economic, and financial forms are increasing in various ways. Such operations, in any form and for any purpose, must reach the operational stage of the threat after incapacitating the computer system and bypassing its defensive system, and for this, they will have a short time. Essentially, cyber attacks must be executed in a very short time; otherwise, with a decrease in the success rate, the possibility of detection and neutralization increases. There is no reliable statistics on the threats posed and successful or unsuccessful threats because this information can be extremely confidential. Moreover, no attacker introduces themselves at the outset, nor does any system publicly acknowledge its vulnerabilities.
Examining the Scope of Cyber Threats: Cybersecurity
This article discusses the increasing significance of cybersecurity threats globally, highlighting recent high-profile data breaches and cyber attacks that have raised concerns among governments. It emphasizes the need for robust cybersecurity measures to protect critical infrastructure and sensitive information.
👥 Key Players
⚡ Actions
📰 What Happened
Governments face rising cybersecurity threats impacting national and international security.
- Governments announce Cybersecurity, Critical infrastructure
- Cybercriminals steal United States government, Anthem health insurance, Target Corporation
- Cyber attackers attack Ukraine's power grid
💡 Why It Matters
📚 Background
The rise in cyber threats poses significant risks to national and international security.
📝 Key Evidence
🏷️ Entities Mentioned
Translated from the original and edited for English readers. View original source →
Translation confidence: 85%