Financial sector: Attacks on banking service availability and advanced fraud targeting banking clients The financial sector, like the public sector, has experienced a rise in DDoS attacks conducted by Russian-affiliated hacktivists over the past year. For the financial sector, particularly banks, this was a new trend linked to the conflict in Ukraine. Number of financial sector respondents who reported different forms of phishing or availability attacks (% of respondents) 2022 2023 84 % Fraudulent email 100 % 89 % Phishing 95 % 68 % Spearphishing 86 % 68 % Denial of Service 86 % 50 % The number of respondents who experienced DDoS attacks in 2023 increased by nearly 20 % 60 % 70 % 80 % 100 % Figure 18 Nearly two thirds of respondents from the financial sector reported that these attacks impacted the availability of services, particularly affecting banking apps and websites, although disruptions generally lasted no more than an hour. Approximately half of the entities reported a DDoS attack as the most serious incident of the year. Fraudulent phone call campaign impersonating NÚKIB and others In August 2023, a fraudulent campaign was brought to NÚKIB’s attention involving the impersonation of NÚKIB and several banking institutions. Attackers either directly impersonated NÚKIB employees, spoofing their phone numbers, or posed as banking institution employees referring to NÚKIB staff. In both cases, fraudsters pressured victims using various threats to transfer money from their bank accounts to a ‘reserve back-up account’, claiming the transaction was supervised by NÚKIB. To increase their credibility, the attackers used the names of actual NÚKIB staff obtained from publicly available sources. They exploited the fact that these names could be verified to support their deceptive claims by calling NÚKIB or searching publicly available information. 32 90 % Various forms of phishing and fraudulent emails pose another ongoing threat to the financial sector. This threat affects both the organisations’ employees and their clients, with many respondents confirming an increase in the volume and sophistication of phishing attacks designed to extract funds from victims.

Select target paragraph3