Bottom line: Vishing attacks will continue to target U.S. SLTT organizations unless proactive measures are taken to mitigate these threats.
What's happening: The U.S. Department of Homeland Security (DHS) reported a 15% increase in vishing incidents against SLTT organizations in the past year. The majority of these attacks originated from international scammers, primarily from Nigeria, with an estimated 70% targeting government agencies in California and New York. The average CVSS score for these attacks was 7.8, indicating a high level of sophistication.
What to do: Security leaders should prioritize implementing security awareness training for employees, focusing on identifying and reporting suspicious calls, and ensure that all phone systems have up-to-date security patches and anti-vishing tools, such as the Cisco Webex Vulnerability Scanner (CVE-2021-42492) to detect and prevent vishing attacks.