• Internet Insecurity

  • Jul 26 2024
  • Length: 6 mins
  • Podcast

  • Summary

  • Cyberattacks pose growing threat Chris White, the Beacon city administrator, is concerned enough about a cyberattack that he would prefer the city not be mentioned in a story about the threat. For good reason, municipalities are reluctant to present themselves as a target, discuss their security measures or share how they responded to being held hostage by hackers or having data stolen. The City of Newburgh learned in June how disruptive an attack can be. A "network security incident" disabled its ability to process payments for parking tickets, property taxes and services such as sewer and water. Earlier this month, the Goshen school district in Orange County said it had been victimized by a ransomware attack, in which hackers hijack systems and demand payment to restore access. The district said the attack disabled computer, email and phone systems. Every local government and school district, especially smaller ones without the staff and resources to adequately protect themselves, faces this potential for havoc. Along with demands for ransom, hackers could steal sensitive information about residents that is collected by every county, town and village. Earlier this year, the security company Sophos released the results of a survey of 5,000 IT leaders in 14 countries for its annual report, The State of Ransomware in Critical Infrastructure. The survey included 300 school districts and 270 local or state governments; 80 percent of the schools and 69 percent of the municipalities said they had been hit by ransomware demands in the past year. Of those, 62 percent of the schools and 54 percent of the governments paid. Of those who provided numbers, schools reported paying an average of $7.5 million and governments $5.3 million to recover their data. The FBI's Internet Crime Complaint Center last year received nearly 27,000 complaints about cybercrimes in New York state, including online scams and data breaches, an 8 percent increase over 2022. Losses were estimated at $750 million. The most common scam reported nationally are "phishing" emails, which hackers design to resemble official correspondence in an effort to get the recipient to enter log-in information or click links or open attachments that install malicious software that can take control of a computer. These emails are the source of more than 90 percent of cyberattacks, according to the state Department of Homeland Security and Emergency Services (DHSES). More than 75 percent of organizations say they have been the target of phishing, and more than half of all emails are malicious, according to DHSES. "It is a threat that keeps evolving and growing," said Steve Oscarlece, the acting commissioner for the Dutchess County Office of Central and Information Services (OCIS). "There can be significant financial costs, as well as to their reputations, and the interruption of services." In June, more than 200 people representing over 100 organizations attended an annual cybersecurity summit that Dutchess and Marist College began holding in 2022. The panel discussions included representatives from the federal Cybersecurity and Infrastructure Security Agency and DHSES, which has an Office of Counter Terrorism and a Cyber Incident Response Team. Attendees also witnessed a mock cyberattack staged by the Office of Counter Terrorism to illustrate how municipalities and organizations can respond. Artificial intelligence tools like ChatGPT have made phishing attempts harder to identify because they eliminate telltale signs of fraud such as misspellings or grammar errors. "It's made it easier for them to craft emails that look legitimate and are more likely to fool the recipient," said Jacob Morrison, the deputy commissioner for OCIS. At the same time, Morrison said, artificial intelligence is being used by organizations to bolster their defenses and by cybersecurity companies to improve the ability of software to detect attacks. Other countermeasures include educating employees on id...
    Show more Show less
activate_primeday_promo_in_buybox_DT

What listeners say about Internet Insecurity

Average customer ratings

Reviews - Please select the tabs below to change the source of reviews.