Now that many auto dealerships have erected defenses against hackers, the cyber crooks have pivoted to practices that give them seeming legitimacy, and artificial intelligence is helping them do so better and faster.
The morphing was observed by Reynolds and Reynolds company Proton Dealership IT and Cybersecurity, which published its findings in a white paper laying out currently common vulnerabilities and how to shore up defenses anew.
As Proton put it, “Attackers would rather log in than break in.”
The company said 82% of detected online fraud activity targeting dealers used no malware while almost that amount of ransomware attacks start with identity-based tactics. Attackers are leaning heavily on accessing dealers’ trusted systems while trying to appear like trusted people within their ecosystems.
Malicious emails and phishing attempts led all root causes of ransomware, Proton found. The two accounted for half of such incidents over the past year, it said. The methods have been supercharged by AI, which can produce convincing fake identities.
“If the primary way into the business is a valid credential or a hijacked session rather than a piece of malware, the controls that mattered most for a decade remain necessary but are no longer where the outcome is decided,” Proton said in its report.
It said dealerships tend to be more exposed to today’s favored attack points than other businesses their size because most have lean information technology staffs, higher employee turnover, and sensitive data stored in a few systems.
“The result is a large, trust-heavy attack surface maintained by a small and often understaffed team doing the best job it can with what it has,” Proton explains.
The trust must be mitigated now. Proton advises dealers to build their detection and response in multiple ways:
- Monitoring those logging into dealer systems
- Keeping system patches updated
- Setting up quality email filtering
- Developing a response and recovery plan
- Tapping a continuous monitoring service
Click Here For The Original Source.
