The U.S. Securities and Exchange Commission (SEC) Office of Compliance Inspections and Examinations (OCIE) has discovered new phishing and ransomware attacks that target financial institutions' networks.
OCIE recently observed an increase in threat actors that have orchestrated phishing and other ransomware campaigns designed to penetrate financial networks, according to a warning issued July 10. It indicated that cybercriminals are using these attacks to access organizations' internal resources and deploy ransomware.
Furthermore, phishing and ransomware attacks against broker-dealers, investment advisers and investment companies are becoming increasingly sophisticated, OCIE stated. These attacks also have been used to target service providers.
OCIE Offers Phishing, Ransomware Attack Security Recommendations
There is no "one-size-fits-all" approach to protect against phishing and ransomware attacks, OCIE noted. However, organizations can use tactics and techniques across a variety of areas to guard against these attacks, including:
In addition, the SEC shares cybersecurity guidance on its Cybersecurity Spotlight webpage. It also provides regular security updates to inform organizations about new cyber risks.