2 ms·
Numbers are a bit loose, but even a Fermi style estimation suggests malware in general is worse than phishing. Phishing is on the order of tens of millions [1]
by kortex 5y ago
Numbers are a bit loose, but even a Fermi style estimation suggests malware in general is worse than phishing. Phishing is on the order of tens of millions [1] to a few billion [2]. Ransomware alone probably causes upwards of many billions [3]. Equifax breach (XML exploit) alone has cost billions. Heartbleed, spectre, meltdown, those are at least 1B each.
[1] https://www.cybersecuritydive.com/news/phishing-cost-enterprise/605110/ https://www.cybersecuritydive.com/news/phishing-cost-enterpr...
[2] https://www.proofpoint.com/us/corporate-blog/post/fbi-reports-125-billion-global-financial-losses-due-business-email-compromise https://www.proofpoint.com/us/corporate-blog/post/fbi-report...
[3] https://cybersecurityventures.com/global-ransomware-damage-costs-predicted-to-reach-250-billion-usd-by-2031/ https://cybersecurityventures.com/global-ransomware-damage-c...
- notriddle 5y agoRansomware isn't necessarily spread by software exploits. A lot of them use nothing fancier than "My File.pdf.exe" attached to an email, like CryptoLocker and its many clones [1]. Sure, WannaCry used an actual software exploit, but most ransomware gangs don't have leaked NSA cyberweapons to work with. [1]: https://www.arnnet.com.au/article/556598/australia-specifically-targeted-by-cryptolocker-symantec/ https://www.arnnet.com.au/article/556598/australia-specifica... Also, a lot of breaches that are caused by vulnerabilities, like large forums having their databases leaked, are bigger problems than they should be thanks to password reuse. But I hadn't thought of Equifax. That company's database held so much economic value that, all in one fell swoop, this single exploit may have tipped the scale so that vulnerable software cost more than password reuse.