# Time to act as cybercriminals hot on the heels of finance sector
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-10-27
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Financial Services Cybercrime: A Warning of Damning Data
Meta Description: Kingsley Hayes leads data breach claims against global firms. Learn the risks of cybercrime in the finance sector and the costly effects of a data breach.
URL: https://financedigest.com/time-to-act-as-cybercriminals-hot-on-the-heels-of-finance-sectorhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/crime-sbi-300189087-1736837508573-compressed.jpg)

Kingsley Hayes, Head of Data Breach at Keller Lenkner UK, the group action and multi-claimant firm currently pursuing a number of data breach claims against national and global organisations

There is no getting away from the fact that cybercriminals have their eyes firmly on businesses operating in the finance sector.

A highly lucrative target for hackers, official reports and records repeatedly echo the importance of data protection in the industry.

**Damning data breach figures a clear warning**

The threat of cybercrime for [financial services](https://www.financedigest.com/how-big-data-is-sending-shockwaves-through-the-financial-services-sector.html "How big data is sending shockwaves through the financial services sector") organisations, and their customers, is real. Global and domestic statistics reveal serious cracks in the robustness of cybersecurity in the sector with hackers generously rewarded for their efforts.

**UK cyber incidents paint a** [bleak picture](https://www.financedigest.com/uk-retail-sales-jump-unexpectedly-but-big-picture-bleak.html "UK retail sales jump unexpectedly, but big picture bleak")

According to data from Statistica, [financial services](https://www.financedigest.com/boom-or-bust-how-the-financial-services-sector-is-coping.html " Boom or Bust: how the financial services sector is coping") are at most risk of phishing attacks (24.5%).

In the past 12 months, up to the end of September, 14% of all cyber incidents reported to the Information Commissioner’s Office (ICO) came from the finance, [insurance and credit sector](https://www.financedigest.com/2020-the-paradoxical-year-that-has-reshaped-the-future-of-motor-insurance-and-related-sectors.html "2020: The paradoxical year that has reshaped the future of motor insurance and related sectors").

Phishing and ransomware have proved the biggest threats to cybersecurity

More than two fifths (41%) of cyber related incidents in the industry during this period was a result of phishing

Ransomware attacks accounted for 28% of all cyber incidents in the past year for businesses in the [finance sector](https://www.financedigest.com/why-the-finance-sector-must-prioritise-mobile-security-over-innovation.html "Why the finance sector must prioritise mobile security over innovation")

The last quarter showed a sharp rise in ransomware attacks with the highest number recorded over the past year – 57 incidents compared to just eight in the previous quarter

**Global ransomware incidents a costly risk**

The State of Ransomware in [Financial Services report 2021 published by Sophos found that 51% of organisations stated that cybercriminals](https://www.financedigest.com/financial-firms-can-use-technology-combat-todays-cybercriminals.html "How financial firms can use technology to combat today’s cybercriminals") had succeeded in encrypting their data.

A quarter of the businesses affected had paid the ransom demanded in return for their [stolen data](https://www.financedigest.com/frances-thales-says-hackers-claim-to-have-stolen-data.html "France’s Thales says hackers claim to have stolen data")

One third of breached [data remained inaccessible despite](https://www.financedigest.com/stocks-u-s-dollar-gain-despite-surprise-weak-china-data.html "Stocks, U.S. dollar gain despite surprise weak China data") cybercriminals pocketing the hefty rewards

More than a third (34%) of [financial services](https://www.financedigest.com/data-fake-will-be-the-new-real-in-financial-services-in-2023.html "Data: Fake will be the new real in financial services in 2023") organisations had been victim to a ransomware attack in the past year according to its findings

The average cost of rectifying a ransomware attack was $2.10 million

**Brand trust following a data breach**

Business and personal customers alike place their trust in the [financial sector](https://www.financedigest.com/iot-for-the-financial-sector.html "IoT for the Financial Sector") to maintain the highest level of data protection to minimise the known risks posed by cybercriminals.

When a cyber incident occurs exposing confidential, and highly valuable data, [years of trust](https://www.financedigest.com/2019-year-must-re-build-public-trust-finance.html "2019 is the year we must re-build public trust in finance") building is lost in an instant.

Damage limitation efforts cannot mitigate the full risks once private data has been obtained fraudulently.

**What happens after a data breach as a result of hacking?**

Cybercriminals are alert to the full financial benefits following a successful hack – and will exploit all opportunities available to them, including selling stolen [data to third parties and money](https://www.financedigest.com/your-money-is-safe-but-your-data-might-not-be.html "YOUR MONEY IS SAFE, BUT YOUR DATA MIGHT NOT BE") laundering making retrieving the full losses challenging at best.

An increasing dependence on technology means that cybercriminals can [target businesses](https://www.financedigest.com/julius-baer-2022-profits-fall-as-it-hits-business-cycle-targets.html "Julius Baer 2022 profits fall as it hits business cycle targets") from anywhere in the world.

Taking proactive preventative measures requires adequate levels of [investment – including prioritising cybersecurity as a business](https://www.financedigest.com/analysis-uk-crisis-forces-off-kilter-businesses-to-halt-investment.html "Analysis-UK crisis forces ‘off kilter’ businesses to halt investment") essential.

The cost to [businesses following cybercrime includes lost time](https://www.financedigest.com/uks-sunak-to-halve-support-that-helps-businesses-pay-fuel-bills-the-times.html "UK’s Sunak to halve support that helps businesses pay fuel bills -The Times"), reputational damage, loss of customers and the extensive costs of rectifying the issue – with no guarantee of mitigating the full associated risks after the event.

**Limitless damage unrecognised**

When large volumes of sensitive information are accessed by criminals, the full impact may not be realised in some instances, for several years after a hack.

The historic behaviour of cybercriminals indicates that stolen confidential details can be used in batches over time which could mean weeks, months, or even many years after a date breach has been discovered.

This means that affected individuals can suffer the wide-reaching consequences long after a [business has considered](https://www.financedigest.com/pizza-firm-dp-eurasia-considers-divestment-of-russian-business.html "Pizza firm DP Eurasia considers divestment of Russian business") the matter dealt with.

**The human cost of data protection violations**

Private information, including names, dates of birth, account numbers and national insurance details, can and will be used for fraudulent activity when placed in the wrong hands.

Identity theft leading to substantial [financial losses and damage to credit ratings have a ripple effect impacting](https://www.financedigest.com/tomorrows-world-how-cloud-computing-will-impact-the-financial-services-sector-in-2016.html "TOMORROW’S WORLD: HOW CLOUD COMPUTING WILL IMPACT THE FINANCIAL SERVICES SECTOR IN 2016") every aspect of an individual’s life.

The financial implications are just one aspect of the significant harm caused when [organisations fail in their data protection](https://www.financedigest.com/protect-your-organisation-from-fraud.html "Protect your organisation from fraud") obligations.

The psychological impact on victims following a data breach within the [financial sector](https://www.financedigest.com/overcoming-information-overload-in-the-financial-sector.html "OVERCOMING INFORMATION OVERLOAD IN THE FINANCIAL SECTOR") is immeasurable and is often underestimated.

Living with the fear of not knowing if, and when, an individual’s personal details will be used fraudulently – and what this will mean for short and long term [financial security](https://www.financedigest.com/5-steps-to-strengthening-your-online-financial-security.html "5 Steps to Strengthening Your Online Financial Security") – can lead to anxiety and depression.

The result for some may mean being unable to continue in their employment, losing their homes and damaging relationships.

**Being held to account**

The cost to businesses who fail to implement an appropriate level of cybersecurity goes beyond the cost of recovering the stolen data, rebuilding trust in their [brand and investing](https://www.financedigest.com/5-compelling-reasons-that-you-should-invest-in-branding.html "5 Compelling Reasons That You Should Invest In Branding") in the measures that should have been in place before a data security incident.

Victims of data breaches are [entitled to compensation](https://www.financedigest.com/are-you-entitled-to-compensation-on-your-timeshare.html "Are you entitled to compensation on your timeshare?") which is calculated based on their actual, and potential, financial losses and psychological injury.

Organisations can also face hefty penalties for failing to comply with data protection laws.

**Data protection in the post pandemic era**

The pandemic has delivered an ideal environment for cybercriminals to excel in their endeavours:

- Sudden, unexpected, and heavy reliance on technology
- Unplanned working from home for entire workforces
- Lack of adequate staff training before, and / or during the crisis
- Inadequate [investment in cybersecurity before and / or during the pandemic](https://www.financedigest.com/3-investing-lessons-you-can-learn-from-still-evolving-pandemic.html "3 Investing lessons you can learn from still-evolving pandemic")
- Lack of security controls within home working environments
- Increased risk of mistakes as a result of the above, and the chaos and uncertainty as a result of the health crisis

Organisations are now faced with the challenges of considering [hybrid working](https://www.financedigest.com/how-has-hybrid-working-impacted-the-gender-gap.html "How has hybrid working impacted the gender gap?") and the potential cybersecurity risks arising from this.

**New FCA guidance**

The [Financial Conduct Authority (FCA) issued new guidance in October for the financial sector to help ensure a secure](https://www.financedigest.com/the-financial-sector-must-act-to-tackle-internal-data-security.html "THE FINANCIAL SECTOR MUST ACT TO TACKLE INTERNAL DATA SECURITY") transition to hybrid working.

The guidance includes regulatory requirements, data compliance and accountability. Businesses in the financial [sector will have to prove that remote working and the lack of centralised services will not lead](https://www.financedigest.com/revolutionising-customer-service-three-sectors-that-are-leading-the-way.html "Revolutionising Customer Service: Three sectors that are leading the way…") to an increased risk of financial crime.

The [industry will have to demonstrate it has appropriate governance in place and that policies and procedures can be successfully cascaded to reduce the risks of financial](https://www.financedigest.com/matching-digital-adoption-with-cybersecurity-in-the-financial-services-industry.html "Matching digital adoption with cybersecurity in the financial services industry") crime.

**[Cybersecurity future](https://www.financedigest.com/smarter-safer-stronger-cybersecurity-is-now-critical-to-digital-future.html "Smarter, safer, stronger cybersecurity is now critical to digital future") forecast**

Only [time will tell whether the financial sector](https://www.financedigest.com/why-its-time-to-centralise-public-sector-technology.html "Why it’s time to centralise public sector technology") can not only swiftly adapt to a changing work environment, but also anticipate the imminent, and inevitable risk of a cyber-attack.

The only certainty is that a cybersecurity incident can only be prevented within organisations that prioritise data protection and invest in robust, and comprehensive measures throughout their business and including their [supply chain](https://www.financedigest.com/5-steps-to-successful-supply-chain-finance.html "5 Steps to successful supply chain finance").


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

