{"id":38136,"date":"2020-12-22T06:01:18","date_gmt":"2020-12-22T11:01:18","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?post_type=emagazine&#038;p=38136"},"modified":"2022-07-28T08:08:23","modified_gmt":"2022-07-28T12:08:23","slug":"cybersecurity-predictions-2021","status":"publish","type":"emagazine","link":"https:\/\/www.kaspersky.com\/blog\/secure-futures-magazine\/cybersecurity-predictions-2021\/38136\/","title":{"rendered":"What does 2021 have in store for cybersecurity?"},"content":{"rendered":"<p>Predicting the future is notoriously precarious. Who would have foreseen a year like 2020? Kaspersky\u2019s Global Research and Analysis Team reflect on this year in cybercrime and deduce what we should expect in 2021.<\/p>\n<h2>Leaked patient records and COVID pressures in healthcare<\/h2>\n<p>2020 was the year everyone had a vested interest in new medical technologies\u2019 success. Cybercriminals attacked medical devices, hospitals and research institutions, intent on stealing COVID-19 vaccine insights. We also saw the first known directly fatal cyberattack: <a href=\"https:\/\/www.tomorrowunlocked.com\/hacker-hunter-hackc1ne-1\" target=\"_blank\" rel=\"noopener nofollow\">A patient died because ransomware infection of medical equipment caused care delays<\/a>. Other <a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2020\/03\/19\/coronavirus-pandemic-self-preservation-not-altruism-behind-no-more-healthcare-cyber-attacks-during-covid-19-crisis-promise\/\" target=\"_blank\" rel=\"noopener nofollow\">cybercrime groups surprised us by ruling out attacking medical institutions<\/a>.<\/p>\n<p>The cybersecurity community set up <a href=\"https:\/\/cti-league.com\/\" target=\"_blank\" rel=\"noopener nofollow\">CTI League: Experts helping medical organizations respond to cyberthreats<\/a>. Kaspersky gave <a href=\"https:\/\/www.kaspersky.com\/blog\/protecting-healthcare-organizations\/19478\/\" target=\"_blank\" rel=\"noopener nofollow\">healthcare organizations free access to tailored cybersecurity<\/a>.<\/p>\n<p>In 2021, expect more attacks on COVID-19 vaccine developers attempting to steal critical data that could help other nations get ahead. Private healthcare organizations will further come under attack, as many don\u2019t have the resources to protect valuable patient data.<\/p>\n\t\t\t<div class=\"c-promo-product\">\n\t\t\t\t\t\t<article class=\"c-card c-card--link c-card--medium@sm c-card--aside-hor@lg\">\n\t\t\t\t<div class=\"c-card__body  \">\n\t\t\t\t\t<header class=\"c-card__header\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<p class=\"c-card__headline\">The future is our game<\/p>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h3 class=\"c-card__title \"><span>Secure Futures<\/span><\/h3>\n\t\t\t\t\t\t\t\t\t\t\t<\/header>\n\t\t\t\t\t\t\t\t\t\t\t<div class=\"c-card__desc \">\n\t\t\t\t\t\t\t<p>Stay on track with your goal to stay ahead.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"c-card__aside\">\n\t\t\t\t\t<a href=\"#modal_newsletter\" class=\"c-button c-card__link\" target=\"_blank\" rel=\"noopener\">Join us<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/article>\n\t\t<\/div>\n\t\n<p>With the transition to cloud computing, we may see patient data leaks from cloud services. Criminals can use personal data in hacked medical records to dupe people into revealing more.<\/p>\n<p><a href=\"https:\/\/securelist.com\/healthcare-security-in-2021\/99571\/\" target=\"_blank\" rel=\"noopener\">More healthcare industry cybersecurity predictions for 2021<\/a><\/p>\n<h2>Cybercriminals have learned about industrial networks<\/h2>\n<p>Attacks on industrial networks will become more targeted. By watching randomly infected machines, cybercrime groups have learned organizations\u2019 IT setup and know how to exploit it. They can then on-sell network access to more sophisticated cybercrime groups who will take control of finance systems to steal cash.<\/p>\n<p>As many industrial control systems (ICS) use old operating systems, the end of support for systems like Windows 7 creates an exploitable loophole. We could see another significant, multi-industry crime campaign like <a href=\"https:\/\/www.kaspersky.com\/resource-center\/threats\/ransomware-wannacry\" target=\"_blank\" rel=\"noopener nofollow\">WannaCry<\/a>.<\/p>\n<blockquote><p>Ransomware keeps getting more sophisticated. Cybercrime gangs love industrial companies because they tend to pay the ransom. It\u2019s like cutting off the Hydra\u2019s head: More attacks will follow.<\/p>\n<\/blockquote>\n<p>As utilities and government services go through <a href=\"https:\/\/www.kaspersky.com\/blog\/secure-futures-magazine\/category\/digital-transformation\/\" target=\"_blank\" rel=\"noopener nofollow\">digital transformation<\/a> they\u2019re more vulnerable to attack. Cybercriminals can use a government service as an entry point into industrial systems to disrupt services like public transport.<\/p>\n<p>In 2020, COVID-19 restrictions on working on-site delayed IT-system upgrades. During an attack, it may be harder for IT admins to regain system control quickly. Basic malware could spread and become more serious. Upgrading endpoint security and <a href=\"https:\/\/www.kaspersky.com\/blog\/secure-futures-magazine\/industrial-cybersecurity-training\/35990\/\" target=\"_blank\" rel=\"noopener nofollow\">training workers<\/a> are vital.<\/p>\n<p><a href=\"https:\/\/securelist.com\/ics-threat-predictions-for-2021\/99613\/\" target=\"_blank\" rel=\"noopener\">More industrial cybersecurity predictions for 2021<\/a><\/p>\n<h2>Online education revolution brought new threats<\/h2>\n<p>Education changed abruptly in 2020. 1.5 billion students took classes from home. Educators had to learn new skills, like running a class on Zoom or using TikTok lessons. For those who can access the technology, these new services enhance education. But they come with new threats.<\/p>\n<p>Learning management systems (LMS) like Google Classroom are exploding. And with growth comes cybercrime. We saw a staggering 20,000 percent growth in threats to online learning platforms between 2019 and 2020.<\/p>\n<p>Privacy usually involves getting the user\u2019s consent, but a child can\u2019t easily manage their privacy settings.<\/p>\n<blockquote><p>Poorly configured learning tools can compromise personal data, even without special tools. Those setting up online education systems must pay close attention to protecting personal information and student data.<\/p>\n<\/blockquote>\n<p>Video will keep growing as a learning tool. About <a href=\"https:\/\/blogs.edweek.org\/edweek\/DigitalEducation\/2018\/08\/generation_z_prefers_learning_from_youtube.html\" target=\"_blank\" rel=\"noopener nofollow\">60 percent<\/a> of teachers use YouTube in the classroom. There\u2019s increased risk of exposure to age-inappropriate content, and new threats like <a href=\"https:\/\/en.wikipedia.org\/wiki\/Zoombombing\" target=\"_blank\" rel=\"noopener nofollow\">Zoombombing<\/a> could expose learners to harmful content.<\/p>\n<p>Games like Minecraft are a great way to make learning more interactive but exposes students to risks like cyberbullying, trolls and malicious files. Teachers must moderate content in their learning management systems, but with the popularity of social platforms and games for pupil engagement, the challenge has leveled-up.<\/p>\n<p><a href=\"https:\/\/securelist.com\/education-predictions-2021\/99641\/\" target=\"_blank\" rel=\"noopener\">More education cybersecurity predictions for 2021<\/a><\/p>\n<h2>Poverty driving more financial cybercrime in 2021<\/h2>\n<p>In 2021, financial companies became less secure thanks to due <a href=\"https:\/\/www.kaspersky.com\/blog\/secure-futures-magazine\/telecommuting-cybersecurity\/34206\/\" target=\"_blank\" rel=\"noopener nofollow\">hastily deployed remote working solutions<\/a>. Some bought retail laptops that didn\u2019t match the security standards of the organization. Limited employee training, default configurations and remote access all contributed to increased attacks.<\/p>\n<p>There\u2019s rising extortion using <a href=\"https:\/\/www.kaspersky.com\/resource-center\/threats\/ddos-attacks\" target=\"_blank\" rel=\"noopener nofollow\">distributed denial of service (DDoS)<\/a> and ransomware. Targeted ransomware is the new normal for financial organizations. Criminals increased ransoms, emboldened by successful attacks and media coverage. To cover their tracks, they\u2019ll now expect you to pay in cryptocurrencies. People are often the weakest link, like in the <a href=\"https:\/\/electrek.co\/2020\/08\/27\/tesla-fbi-prevent-ransomware-hack-gigafactory-nevada\/\" target=\"_blank\" rel=\"noopener nofollow\">failed attempt to infiltrate Tesla<\/a>.<\/p>\n<p>Stay at home orders didn\u2019t affect cybercriminals: Brazilian cybercrime groups went global in 2020, expanding to Europe and beyond, including attempts to hack ATMs.<\/p>\n<p>Bigger crime groups are evolving their business models to boost profits by hiring more people within their virtual walls rather than outsourcing.<\/p>\n<blockquote><p>The pandemic may lead to waves of poverty, which means increased crime, including cybercrime. As economies fail, cryptocurrency theft and ransomware heists will appeal to those living on the edge.<\/p>\n<\/blockquote>\n<p>To crack down on cybercrime, the US Department of the Treasury\u2019s Office of Foreign Assets Control warned of <a href=\"https:\/\/home.treasury.gov\/policy-issues\/financial-sanctions\/recent-actions\/20201001\" target=\"_blank\" rel=\"noopener nofollow\">sanctions for organizations facilitating ransom payment<\/a>. Next, we predict sanctions against institutions and nations that don\u2019t combat cybercrime coming from their territory.<\/p>\n<p><a href=\"https:\/\/securelist.com\/cyberthreats-to-financial-organizations-in-2021\/99591\/\" target=\"_blank\" rel=\"noopener\">More financial cybersecurity predictions for 2021<\/a><\/p>\n<h2>Crime gangs collaborating on advanced threats<\/h2>\n<p>Advanced persistent threats (APTs) are the most dangerous kind of attacks, often seen in geopolitical clashes, intent on harming national interests. With the trend towards improved organization security and more people working from home, crime groups will exploit network technologies such as virtual private networks (VPNs,) using <a href=\"https:\/\/www.kaspersky.com\/blog\/secure-futures-magazine\/fraud-prevention-social-engineering\/36919\/\" target=\"_blank\" rel=\"noopener nofollow\">social engineering<\/a> to get access.<\/p>\n<p><a href=\"https:\/\/www.kaspersky.com\/blog\/secure-futures-magazine\/5g-technology-opportunities\/28876\/\" target=\"_blank\" rel=\"noopener nofollow\">5G<\/a> is big news, with <a href=\"https:\/\/www.bbc.co.uk\/news\/52168096\" target=\"_blank\" rel=\"noopener nofollow\">bogus stories of health risks<\/a> and some nations limiting or banning Huawei products in their 5G infrastructure. Security researchers are examining Huawei and other 5G providers for implementation flaws. If found, they\u2019ll make the front pages. As more devices depend on 5G for connectivity, attackers will have more incentive to seek vulnerabilities to exploit.<\/p>\n<p>As ransomware becomes the weapon of choice for many criminals, we may see ransomware players\u2019 concentrate. In 2020 the <a href=\"https:\/\/securelist.com\/maze-ransomware\/99137\/\" target=\"_blank\" rel=\"noopener\">Maze<\/a> and Sodinokibi gangs pioneered an affiliate collaboration model. These bigger groups may combine to deliver APT-style attacks that overwhelm a target organization\u2019s system, to access specific data.<\/p>\n<p>We\u2019ll likely see attacks like these disrupt everyday lives. It could be an intentional attack on critical infrastructure like utilities or collateral damage from ransomware targeting big organizations we all rely on, like supermarkets, mail or public transport.<\/p>\n<p><a href=\"https:\/\/securelist.com\/apt-predictions-for-2021\/99387\/\" target=\"_blank\" rel=\"noopener\">More advanced threat predictions for 2021<\/a><\/p>\n<p>Threats may be increasing, but fortunately, there\u2019s better education, technology and intelligence available today to help your organization stay secure and face the future.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers share their predictions for how cybercrime and the threat landscape will evolve in the year ahead.<\/p>\n","protected":false},"author":2522,"featured_media":38137,"template":"","coauthors":[3495],"class_list":{"0":"post-38136","1":"emagazine","2":"type-emagazine","3":"status-publish","4":"has-post-thumbnail","6":"emagazine-category-threat-intelligence","7":"emagazine-category-trends","8":"emagazine-tag-education","9":"emagazine-tag-finance","10":"emagazine-tag-healthcare","11":"emagazine-tag-predictions","12":"emagazine-tag-threats"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/secure-futures-magazine\/cybersecurity-predictions-2021\/38136\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/secure-futures-magazine\/cybersecurity-predictions-2021\/21450\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/secure-futures-magazine\/cybersecurity-predictions-2021\/17184\/"}],"acf":[],"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/emagazine\/38136","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/emagazine"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/emagazine"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2522"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/38137"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=38136"}],"wp:term":[{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/coauthors?post=38136"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}