Most Dominant Cyber-Incident Types Reported in Panama
Unauthorized login attempts
DoS attacks
Phishing attacks
Fraudulent information use incidents
SQL injection attacks
Web defacement attacks
Spam runs
Unauthorized information disclosure
incidents
XSS attacks
Other unauthorized access attempts
Source: OAS Survey
Cases involving phishing (6%), fraudulent information use (4%), SQL injection
(4%), spamming (6%), unauthorized information disclosure (7%), XSS use
(4%), and other unauthorized access attempts (4%) completed the attack chart.
The majority of incidents in Panama were reported in the third quarter of 2012.
Authorities correlated this to the introduction of Law 510 in August, which sought
to expand enforcement mechanisms on copyright violations and provoked a
vocal and well-publicized hacktivist response.
The aforementioned cyber incidents were paired with reports from Panamanian
authorities that customer service centers often had more access to clients’
personal information than necessary, needlessly exposing individuals to insider
threats. These service centers were frequently exposed to DDoS attacks,
compounding risks to precariously stored sensitive information.
Panama cited a lack of qualified digital forensics and incident response
specialists as the main roadblock to improving cybersecurity and fighting
cybercrime. Authorities blamed many cyber incidents on a large-scale lack of
awareness, including after investigation, as attacks were often found to have
been preventable. This is due to the fact that Internet users were hesitant
to learn about cybersecurity, thinking that safe computing habits were either
too complex or too technical to master. Though several financial institutions
disseminated educational materials, efforts were poorly coordinated and small
awareness-raising campaigns failed to achieve the desired impact. To battle lax
Internet security attitudes and promote secure Internet use, the government is
currently planning to establish more awareness-raising initiatives in 2013.
PAGE 8 | Latin American and Caribbean Cybersecurity Trends and Government Responses