Network Attacks
Sky's the limit: protect your business from being compromised
What are network attacks?
A network attack is an attempt by cyber criminals to gain unauthorised access to a company’s network by exploiting security vulnerabilities.1 These attacks vary in type, but all involve the exploitation of an unsecured network. Where networks are not encrypted a third party can intercept communications and eavesdrop on sensitive conversations.
How to prevent network attacks
- VPN: Use a Virtual Private Network (VPN) which will enable more privacy and security when remotely accessing your company’s systems and help protect sensitive data
- Avoid public Wi-Fi: If you don’t have a VPN avoid public Wi-Fi sources, only use trusted secure connections
- Website security: Ensure websites you visit use the ‘HTTPS://’ prefix. But be aware: hackers can create HTTPS sites to infiltrate your network!2
- Web addresses: Check all web addresses for subtle spelling mistakes and other irregularities that could indicate a malicious site
- IP addresses: Configure your routers to block invalid IP addresses
- Use intrusion-detection systems: To monitor threats to your network and automatically notify your security team3
- DDoS: Invest in DDoS (distributed denial-of-service) mitigation appliances which block illegitimate traffic to your website4
- Increased bandwidth: Purchase increased bandwidth to handle spikes in demand caused by DDoS attacks, or purchase on demand services like burstable circuits that provide more bandwidth when you need it.5
What to do if you're a victim
- Contact us: Contact your bank immediately so they can attempt to recover any funds lost as a result of network attacks. The quicker you act the more likely you can recover any losses
- Notify others: Inform any customers, clients or suppliers who may be affected by the attack
- Cyber security processes: Review your cyber security processes to ensure that they are up to date and analyse what went wrong with your security teams so you are better prepared for any future attacks
- Increased bandwidth: Consider buying additional bandwidth to protect form DDoS attacks, or demand services like burstable circuits might be appropriate if you are vulnerable to network attacks
- Report: Report any attacks (even if you’ve not suffered any financial loss) to Action Fraud6, the UK’s national fraud and cybercrime reporting centre via their website at www.actionfraud.police.uk or by calling 0300 123 2040.
Wake up to the reality of network attacks
Understanding network attacks
There are many different types of network attacks, including:
Man-in-the-middle
A criminal intercepts communication between two parties and controls conversations by impersonating users to steal sensitive information.10
Distributed denial-of-service
Hackers bombard a website with traffic from multiple sources causing it to crash or become unusable.11
Code and SQL injection
Hackers can exploit website forms and other user inputs to pass malicious code into a system instead of the expected data inputs.12
Your next steps
Report fraud
To report any fraudulent activity, or attempts, contact Barclays Corporate fraud on 0330 156 0155* or if calling from overseas dial +441606566208.
If you receive a suspicious email, send it as an attachment to internetsecurity@barclays.co.uk and delete the email immediately.
Are you protected?
To keep yourself, and your organisation protected from criminals, ensure you keep up to date with our latest resources and advice.
Fraud and Scam Toolkit
-
1 https://www.forcepoint.com/cyber-edu/network-attack
2 https://www.eff.org/deeplinks/2011/10/how-secure-https-today#:~:text=HTTPS%20is%20a%20lot%20more,some%20attackers%20to%20break%20HTTPS.
3 https://www.techtarget.com/searchsecurity/definition/intrusion-detection-system
4 https://blog.radware.com/security/ddos/2019/07/why-you-still-need-that-ddos-appliance/
5 https://lightyear.ai/blogs/fixed-or-burstable-bandwidth-which-is-right-for-you
6 https://www.actionfraud.police.uk/campaign/24-7-live-cyber-reporting-for-businesses
7 https://proprivacy.com/blog/latest-uk-cybersecurity-cybercrime-statistics-2020-2022
8 https://www.prnewswire.com/news-releases/ddos-attacks-on-financial-sector-surge-during-war-in-ukraine-new-fca-data-reveals-301624074.html
9 https://aag-it.com/the-latest-cyber-crime-statistics/#:~:text=39%25%20of%20UK%20businesses%20reported,of%20%C2%A34200%20in%202022.
10 https://www.techtarget.com/iotagenda/definition/man-in-the-middle-attack-MitM
11 https://www.ncsc.gov.uk/collection/denial-service-dos-guidance-collection#:~:text=In%20a%20Distributed%20Denial%20of,added%20together%2C%20overload%20the%20target.
12 https://www.crowdstrike.com/cybersecurity-101/sql-injection/