SHARE
Facebook X Pinterest WhatsApp

IoT Security Remains a Top Concern

thumbnail
IoT Security Remains a Top Concern

IT security observability

IoT attacks are on the rise. Hacker success is made easier thanks to lax security practices.

Written By
thumbnail
Sue Walsh
Sue Walsh
Sep 16, 2019

Cyberattacks on IoT devices surged 300% this year. One security provider’s global network of honeypots observed over 2.9 billion events in the first half of 2019. It was the first time the provider had ever measured billions of attacks within a 6-month period.

While attacks originate from many sources, Microsoft identified a remarkably large and coordinated effort in April 2019. Its officials issued a warning about a new group of hackers using IoT devices to infiltrate targeted computer networks. Officials believe the group is working for the Russian government. Experts discovered the attacks they noticed office printers, voice-over-IP phones, and video decoders in several customer locations communicating with servers belonging to the group, known as Strontium, Fancy Bear, or APT28.

See also: New High-Level IoT Security Guidelines from NIST

Digging Deeper to Find the Source

Hackers easily guessed passwords that hadn’t been changed from the factory defaults. Another device was still running outdated firmware with a known security flaw.

Microsoft has yet to identify the goal of this attack. It knows that hackers used the devices to establish a presence on the network and continue looking for additional access. Hackers used network scans to find other devices that would grant access to higher-value data.

FBI holds the group responsible for infecting over half a million consumer-grade routers in over 50 countries in a 2018 VPNFilter attack. The group used Modbus serial communications protocol to monitor, log, or modify traffic passing between network end points/ websites or industrial control systems. The FBI worked with Cisco’s Talos security group to neutralize the attack. The group also hacked the 2016 Democratic National Committee, World Anti-Doping Agency and the TV5Monde TV station in France.

Microsoft has notified the manufacturers of the affected IoT devices and hopes they will use the information to make their devices more secure.

Coordinated attacks like this highlight the gaping security holes in some IoT deployments. That so many compromised devices used default passwords and outdated firmware suggests that organizations need to up their IoT security game.

thumbnail
Sue Walsh

Sue Walsh is News Writer for RTInsights, and a freelance writer and social media manager living in New York City. Her specialties include tech, security and e-commerce. You can follow her on Twitter at @girlfridaygeek.

Recommended for you...

New Frontiers of IAM: Reaching Great Heights with 2024 Trends
Ronak D. Jain
May 22, 2024
Application Security for IoT: 10 Best Practices
Sagar Nangare
Feb 21, 2023
The Importance of Ensuring IoT System Security
Is Nanotechnology Ready to Enter the IoT Security War?
Bernard Brode
Apr 12, 2022

Featured Resources from Cloud Data Insights

Engineering the Agentic Enterprise: Building Smarter, Adaptive, Autonomous Systems
Varun Goswami
Mar 10, 2026
The AI That Actually Scales Is Boring. That’s the Point.
Jared Coyle
Mar 9, 2026
Real-time Analytics News for the Week Ending March 7
The State of the Neoclouds Market

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.