About Members News Events Trainings Career Catalog Log In Join TR

STM Announces New Cyber Threat Status Report

STM Announces New Cyber Threat Status Report

In its newly announced Cyber Threat Status Report, STM pointed out that theft and fraud crimes committed through information systems are increasing and warned, "The same password should not be used for more than one account, and a 3D secure system and virtual card should be used in online shopping transactions."

STM's Technological Thought Center "ThinkTech", which has undertaken important projects and domestic products in the field of cyber security in Turkey, announced its new Cyber Threat Status Report covering July-September 2023. In order to raise awareness in the field of cyber security, the report prepared by STM's cyber security experts has 9 different topics.

The report includes current and interesting topics such as theft and fraud crimes committed through information systems, cyber attacks via keyboard strokes, and the countries that commit the most cyber attacks.

Precautions to be Taken Against Internet Fraud

Cyber crimes such as theft and fraud through information systems are increasing. Especially the rapid spread of digitalization offers new opportunities to criminals. In its new cyber report, STM listed the precautions to be taken by individuals, in addition to the precautions to be taken by institutions and organizations against cyber crimes, as follows:

"It should be ensured that the websites where information such as passwords, credit cards, debit cards, etc. are entered on the internet have valid SSL certificates. Credit/debit card information should not be entered in environments such as internet cafes, etc. where computers are shared, and a virtual keyboard should be used in cases of necessity. The same password should not be used for more than one account, care should be taken to ensure that the selected passwords are not easily guessed. Passwords should not be kept clearly written in any environment and should not be shared with anyone. 3D secure system (3D security protocol) should be used when performing banking transactions on the internet. Physical "Card information should not be used in online shopping transactions; instead, a virtual card should be used. Licensed operating systems and applications should be used, and security updates should always be made on all systems."

It is Possible to Perform a Cyber Attack via Keyboard Strokes

Another issue covered in STM's report was cyber attacks via keyboard strokes. The report stated that there is a distinct acoustic in keyboard strokes, and thanks to the advancement in microphone technology, keystroke records can be collected from devices such as internet protocol calls and smart watches. The report mentioned that deep learning and machine learning methods also increase the possibility of acoustic attacks via the keyboard, and included an experiment conducted by researchers. In the experiment, a smart mobile phone was placed next to a laptop for sound recording, all keystrokes on the keyboard were recorded, and then waveforms and spectrograms were produced for each key. An image classifier program was trained for best prediction results and was found to correctly predict key presses 95 percent of the time.

Disposable email accounts bring risks

The report mentioned that free e-mail services, which self-destruct after a certain period of time and allow e-mails to be received from a temporary address, bring with them some risks. It was stated that with temporary/disposable e-mail services, attackers were able to access personal data such as name, surname, credit card, billing information and residence address through bitcoin trading wallets and online shopping applications.

Regarding the period of the report, the "Zero Trust model", which came to the fore in a period when traditional security models were inadequate, was put under the spotlight.

Most Cyber Attacks Come from Russia

Data from STM's own Honeypot sensors; It also revealed the countries with the most cyber attacks worldwide. A total of 2 million 297 thousand attacks were recorded on STM's honeypot servers during July, August and September 2023. The country that made the most attacks was Russia with 268 thousand, while Estonia ranked second with 248 thousand. These countries are respectively; Brazil, France, China, India, Turkey, USA, Vietnam and the Netherlands followed.

Click to access the report

Gallery

STM Announces New Cyber Threat Status Report - 1