IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

IoT attacks have increased by 200% in two years

Audio-visual and home automation devices are most at risk, says Zscaler report

Graphic representation of IoT devices in businesses

Attacks on internet of things (IoT) devices have ramped up 700% in two years, according to a study from security company Zscaler. 

In its IoT in the Enterprise: Empty Office Edition report published today, the company revealed the characteristics of IoT devices that it fingerprinted across its network of protected assets. 

During the two-week study period last December, the company also analyzed traffic coming from these machines to assess how much of it was malicious and what it did. 

Zscaler blocked roughly 300,000 malware-related IoT transactions in those two weeks. This was a seven-fold increase in the malicious traffic it found during the 2019 study. 

The company also found 900 unique payload deliveries to 18,000 unique hosts. Almost all those unique payloads (97%) belonged to the Gafgyt (63.1%) and Mirai (34.1%) botnets. However, the frequency of attacks was inverted; Mirai payloads accounted for 76% of attacks while Gafgyt payloads made up just 5% of attacks. 

CCTVs and digital video recorders were among the units most likely to phone home to a botnet's command and control server. The report found devices in this category from over 70 vendors infected by malware. Routers were also commonly infected in the study. 

Related Resource

X-Force Threat Intelligence Index

Top security threats and recommendations for resilience

Transparent cube against a black background - whitepaper from IBMFree download

The report called out devices from Linksys and D-Link, the latter of which settled with the FTC in 2019 for allegedly failing to include adequate security measures in its IoT products

Even today, most IoT devices transmit data in the clear, with only 24% using encryption. While still unacceptably high, it's up from the 17% in the company's 2020 report. That’s also a threefold improvement on the 2019 study, which found only 8.5% of devices transmitting data in the clear. 

Encryption was unevenly distributed across verticals, with devices in the health care sector using SSL roughly half the time. Conversely, only 2.7% of enterprise devices used SSL to encrypt communications. 

Entertainment and home automation devices, including virtual assistants, represented the biggest attack risk, according to Zscaler. The report said that this risk stems from their relatively infrequent encryption use and tendency to phone home to suspicious destinations. It's also because there are so many of these devices. Of the 553 device types found, almost one in three found were set-top boxes. One in five were smart TVs. 

Featured Resources

IT best practices for accelerating the journey to carbon neutrality

Considerations and pragmatic solutions for IT executives driving sustainable IT

Free Download

The Total Economic Impact™ of IBM Spectrum Virtualize

Cost savings and business benefits enabled by storage built with IBMSpectrum Virtualize

Free download

Using application migration and modernisation to supercharge business agility and resiliency

Modernisation can propel your digital transformation to the next generation

Free Download

The strategic CFO

Why finance transformation propels business value

Free Download

Recommended

SOC modernisation and and the role of XDR
Whitepaper

SOC modernisation and and the role of XDR

16 Mar 2023
Analysing the economic benefits of Trend Micro Vision One
Whitepaper

Analysing the economic benefits of Trend Micro Vision One

16 Mar 2023
More than a number: Your risk score explained
Whitepaper

More than a number: Your risk score explained

16 Mar 2023
The IT manager's guide to getting home in time for dinner
Whitepaper

The IT manager's guide to getting home in time for dinner

15 Mar 2023

Most Popular

The big PSTN switch off: What’s happening between now and 2025?
Sponsored

The big PSTN switch off: What’s happening between now and 2025?

13 Mar 2023
Why Amazon is cutting staff from AWS
Cloud

Why Amazon is cutting staff from AWS

21 Mar 2023
Why – and how – IP can be the hero in your digital transformation success story
Sponsored

Why – and how – IP can be the hero in your digital transformation success story

6 Mar 2023