# Finance industry and DDoS attacks: how can the most targeted vertical industry protect itself from DDoS attacks?
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-05-21
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: NETSCOUT&#039;s Threat Intelligence Report on DDoS Attacks
Meta Description: Learn how cybercriminals targeted Covid-era lifelines and finance industry with DDoS attacks in 2020. Stay informed with NETSCOUT&#039;s latest Threat
URL: https://financedigest.com/finance-industry-and-ddos-attacks-how-can-the-most-targeted-vertical-industry-protect-itself-from-ddos-attackshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/ddos-attack-1736838320921-compressed.jpg)

_By **Philippe Alcoy,** Security Technologies for NETSCOUT_

The Covid-19 pandemic has presented a fantastic opportunity for cybercriminals. With internet usage figures increasing significantly, following the imposition of lockdown measures throughout the world, threat actors pounced.

NETSCOUT’s recently published [Threat Intelligence Report](https://www.netscout.com/threatreport) – which details the activities and trends in the DDoS threat landscape for the second half of 2020 – discovered that, collectively, cybercriminals launched over 10 million Distributed Denial-of-Service (DDoS) attacks last year for the first time in history. There was a 22 per cent increase in attack frequency from 2019 to 2020 (1.6 million more DDoS attacks in 2020) along with a 22 per cent increase in the final six months of 2020 – a clear indication of cybercriminals taking advantage of the challenging circumstances presented by the [global health crisis](https://www.financedigest.com/putin-says-west-is-triggering-a-global-economic-crisis.html "Putin says West is triggering a global economic crisis").

Mostly, the aim of the threat actors behind these DDoS attacks was to cripple Covid-era lifelines and [industries that relied heavily on online services such as healthcare, online education, streaming platforms and e-commerce, which led to these industries being heavily targeted by cyberattacks compared to previous years](https://www.financedigest.com/2022-the-year-that-facial-recognition-will-lead-the-fintech-industry.html "2022 – The year that facial recognition will lead the fintech industry").

However, it was the [finance industry](https://www.financedigest.com/navigating-consumer-data-in-the-finance-industry.html "NAVIGATING CONSUMER DATA IN THE FINANCE INDUSTRY") that really felt the brunt of threat actors’ DDoS attacks, receiving a disproportionate number of them during the last six months of 2020. Organisations that operate within this sector are a prime target as they are perceived to have [access to vast amounts of money](https://www.financedigest.com/accessing-government-money-if-youre-self-employed.html "Accessing Government Money if You’re Self-employed"), as well as large swathes of private data. High-profile examples of DDoS attacks against the [financial sector include the DDoS extortion attack that hit](https://www.financedigest.com/uk-consumer-mood-hits-one-year-high-but-financial-gloom-persists.html "UK consumer mood hits one-year high, but financial gloom persists") the New Zealand stock exchange in August 2020, as well as the powerful DDoS attack that disrupted a number of Hungarian banking and telecommunication services in September 2020.

**Types of DDoS attacks**

DDoS attacks are designed to overwhelm targeted systems in an attempt to cause maximum disruption and to shut down services. This is done by flooding the targeted network, application, or [service with internet traffic](https://www.financedigest.com/benefits-of-increasing-blog-traffic-with-guest-blogging-and-posting-service.html "Benefits of Increasing Blog Traffic With Guest Blogging and Posting Service"), and prevent genuine users from accessing the system they wish to access. Nevertheless, it is worth noting that there are a number of different forms of DDoS attacks.

One example that has focused on [organisations within the finance](https://www.financedigest.com/cyber-threats-for-finance-organisations-to-watch-in-2023.html "Cyber threats for finance organisations to watch in 2023") industry in particular is a DDoS extortion attack. This involves the threat actor launching a demonstration DDoS attack against elements of an organisation’s online infrastructure. After this, the attacker sends an email to the targeted [business threatening to launch](https://www.financedigest.com/tokyo-based-business-launches-in-london.html "Tokyo-based business launches in London") a full-on DDoS attack if a ransom demand is not met within a certain period of time. These [demands call for payment in the form of cryptocurrency in order to avoid being traced by law](https://www.financedigest.com/eu-demands-quick-fix-from-u-s-of-green-subsidy-law.html "EU demands quick fix from U.S. of green subsidy law") enforcement authorities.

In August 2020, a global campaign of DDoS extortion [attacks was launched by a group](https://www.financedigest.com/new-intelligence-points-to-pro-ukraine-group-in-nord-stream-attack-nyt.html "New intelligence points to pro-Ukraine group in Nord Stream attack -NYT") of cybercriminals. The threat actors behind the campaign claim to be affiliated with [attack groups who are well](https://www.financedigest.com/tennis-panic-attack-ends-tsurenkos-indian-wells-as-raducanu-marches-on.html "Tennis-Panic attack ends Tsurenko’s Indian wells, as Raducanu marches on") known within industry media, such as ‘Lazarus Group’, ‘Fancy Bear’, and ‘Armada Collective’. This is done in an attempt to [boost the attackers’ credibility and scare their targets](https://www.financedigest.com/sap-boosts-brand-awareness-using-gumgums-high-impact-ad-formats-and-veritytm-gumgums-advanced-contextual-targeting-solution.html "SAP boosts brand awareness using GumGum’s high impact ad formats and VerityTM, GumGum’s advanced contextual targeting solution") in order to make them pay up. NETSCOUT has assigned the moniker ‘Lazarus Bear Armada’ (LBA) to the attackers. The first attack launched by the group [targeted the New Zealand](https://www.financedigest.com/the-mouse-that-roared-new-zealand-and-the-worlds-2-inflation-target.html "The mouse that roared: New Zealand and the world’s 2% inflation target") stock exchange and knocked the system offline for two days in a row, preventing trading from taking place.

![Philippe Alcoy](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/philippe-alcoy-netscout-450x675-1736838320904-compressed.jpg)

Philippe Alcoy

Following the group’s debut attack on the New Zealand stock exchange, the adversaries have gone on to target exchanges, [banks and other financial institutions in addition to internet services](https://www.financedigest.com/73-of-employees-in-the-banking-and-financial-services-industries-are-looking-for-better-physical-and-mental-wellbeing-support-in-the-workplace.html "73% of employees in the banking and financial services industries are looking for better physical and mental wellbeing support in the workplace") providers, healthcare organisations and large technology firms. As a result of the LBA DDoS extortion campaign, the Worldwide Infrastructure Security Report (WISR) revealed that the number of DDoS extortion attacks [increased by around](https://www.financedigest.com/polyimide-fibers-market-is-expected-to-increase-at-a-healthy-cagr-of-around-5-over-the-forecast-period-of-2021-2031.html "Polyimide Fibers Market is expected to increase at a healthy CAGR of around 5% over the forecast period of 2021-2031") 125 per cent from 2019 to 2020. These types of attacks can cause [financial institutions](https://www.financedigest.com/the-future-of-financial-institutions-in-2023.html "The Future of Financial Institutions in 2023") to lose lots of money, even if the organisation does not pay the ransom, as the DDoS attack leads to downtime for parts of the organisation.

Another type of DDoS attack that has been used against organisations in the [financial sector](https://www.financedigest.com/tomorrows-world-how-cloud-computing-will-impact-the-financial-services-sector-in-2016.html "TOMORROW’S WORLD: HOW CLOUD COMPUTING WILL IMPACT THE FINANCIAL SERVICES SECTOR IN 2016") is a reflection/amplification attack. This type of attack enables threat actors to generate high-volume attacks through a combination of reflection and amplification attacks. By using this attack method, cybercriminals can magnify the volume of malicious traffic they’re capable of generating while at the same time concealing the sources of the attack traffic.

What makes this type of DDoS attack such a threat to [businesses that operate in the financial sector is that there is nothing out of the ordinary about the devices and servers that are used to launch](https://www.financedigest.com/new-business-launches-to-support-it-professionalsfacing-mission-critcial-sector-challenges.html "NEW BUSINESS LAUNCHES TO SUPPORT IT PROFESSIONALSFACING MISSION CRITCIAL SECTOR CHALLENGES") these types of attacks. Consumer devices and ordinary servers, which display no evidence of having been compromised, are capable of initiating reflection/amplification DDoS attacks. Further to this, sophisticated tools are not required when it comes to launching a reflection/amplification attack. This means that cybercriminals can create huge volumetric attacks by using just one robust server or a modest source of bots. As such, this makes it challenging to [prevent these forms of DDoS attacks](https://www.financedigest.com/preventing-an-operationally-crippling-ransomware-attack-do-you-know-where-your-risk-exposure-lies.html "PREVENTING AN OPERATIONALLY CRIPPLING RANSOMWARE ATTACK –  DO YOU KNOW WHERE YOUR RISK EXPOSURE LIES?").

**How can organisations in the [finance industry](https://www.financedigest.com/theres-nothing-artificial-about-the-role-of-ai-and-data-in-the-finance-industry.html "There’s nothing artificial about the role of AI and data in the finance industry ") defend themselves?**

The best defence against DDoS extortion attacks, reflection/amplification attacks and other types of DDoS attacks is to install a strong DDoS defence system. [Financial institutions that have adequately prepared to defend their online](https://www.financedigest.com/5-steps-to-strengthening-your-online-financial-security.html "5 Steps to Strengthening Your Online Financial Security") infrastructure by putting in place an effective DDoS mitigation system have experienced little to no issues relating to DDoS attacks. For example, even though the threat actors behind the ongoing DDoS extortion campaign have conducted pre-attack reconnaissance, the DDoS attacks that the group have launched have been easily mitigated by [financial institutions that use standard DDoS protection services](https://www.financedigest.com/how-financial-services-are-overhauling-security-to-defend-against-spoofing-scams.html "How financial services are overhauling security to defend against spoofing scams"). When it comes to DDoS extortion attacks, it is much more preferable for financial organisations to put their money towards installing a strong DDoS mitigation [service than paying](https://www.financedigest.com/best-paying-jobs-in-finance-consumer-services.html "Best Paying Jobs in Finance Consumer Services") the ransom. It is also important for [financial institutions](https://www.financedigest.com/what-the-future-holds-for-financial-institutions-in-2023.html "What the Future Holds For Financial Institutions in 2023") to semi-regularly test their DDoS mitigation services. This [ensures that any changes](https://www.financedigest.com/the-lego-blocks-of-saas-how-microservices-can-help-ensure-compliance-with-changing-financial-regulations.html "The Lego blocks of SaaS: how microservices can help ensure compliance with changing financial regulations") to an organisation’s online infrastructure are incorporated into its DDoS defence plan.

In addition to this, it is vital that organisations in the finance industry [know who to contact and notify should they be on the receiving end](https://www.financedigest.com/the-end-of-payments-as-we-know-it.html "The end of payments as we know it") of a DDoS attack. Key stakeholders, local and national regulators and security providers should all be contacted in the event of a DDoS attack. Moreover, [financial institutions](https://www.financedigest.com/a-cloud-migration-guide-for-financial-institutions.html "A Cloud Migration Guide for Financial Institutions") should familiarise themselves with the details of high-profile DDoS attacks and DDoS attack campaigns to enable themselves to better prepare for potential future threats. For example, there are obvious similarities between the ongoing DDoS extortion campaign and the [DD4BC](https://www.europol.europa.eu/newsroom/news/international-action-against-dd4bc-cybercriminal-group) (‘DDoS for Bitcoin’) series of attacks that occurred from 2014-2016, with both campaigns targeting the financial sector.

Although a DDoS attack can have a catastrophic [impact on financial](https://www.financedigest.com/how-mifid-ii-will-impact-financial-advisor-communications.html "HOW MIFID II WILL IMPACT FINANCIAL ADVISOR COMMUNICATIONS") organisations, the damage caused by the attack can be kept to a minimum providing financial institutions have installed a strong and effective DDoS mitigation system in addition to having an appropriate plan of action in place, in the event that they’re hit by a DDoS attack.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

