Over a 1.5-year period, the global industry’s cyber threat metrics were analyzed by a content delivery network for insights

The data also showed that the FSI has been most impacted by brand impersonation and abuse (36%), based on the number of all suspicious sites monitored . This was far ahead of the second-most targeted vertical: commerce (26%). Also:

  • Phishing dominated the counterfeit domains that have been targeting financial services, accounting for 68% of all recorded instances. Brand impersonation followed in second place, representing 24% of all recorded domains.
  • The sharp increases in the number of Layer 7 DDoS attacks were found to have specifically targeted applications via application programming interfaces (APIs). Of particular interest were undocumented shadow APIs, which are often unprotected because information security teams are unaware of their existence. Attackers can exploit these APIs to exfiltrate data, bypass authentication controls, or perform disruptive acts.
  • DDoS event frequency did not always correlate with attack intensity. While some months of the data analyzed showed few attacks, other corresponding data had indicated significant traffic spikes, emphasizing the need to consider both attack frequency and volume when assessing DDoS attacks.
  • In data for the Asia Pacific and Japan region (APJ), the FSI was deemed fragmented, leading to correlations to the region registering the highest median threat score for phishing, specifically around a number of suspicious domains and requests. Rapid banking industry digitalization, combined with low societal awareness of phishing dangers, were suggested as the main draw of such attacks. However, the region also attracted fewer phishing or brand impersonation domains, compared to data from other parts of the world.
  • The APJ region’s cybersecurity measures have been deemed by the report analysts to lag behind that of Europe and America, while rising brand abuse risks were attributed to high levels of digitalization and active social media use — opening more avenues for phishing and impersonation attacks.