SHARE
Facebook X Pinterest WhatsApp

IoT Security Remains a Top Concern

thumbnail
IoT Security Remains a Top Concern

IT security observability

IoT attacks are on the rise. Hacker success is made easier thanks to lax security practices.

Written By
thumbnail
Sue Walsh
Sue Walsh
Sep 16, 2019

Cyberattacks on IoT devices surged 300% this year. One security provider’s global network of honeypots observed over 2.9 billion events in the first half of 2019. It was the first time the provider had ever measured billions of attacks within a 6-month period.

While attacks originate from many sources, Microsoft identified a remarkably large and coordinated effort in April 2019. Its officials issued a warning about a new group of hackers using IoT devices to infiltrate targeted computer networks. Officials believe the group is working for the Russian government. Experts discovered the attacks they noticed office printers, voice-over-IP phones, and video decoders in several customer locations communicating with servers belonging to the group, known as Strontium, Fancy Bear, or APT28.

See also: New High-Level IoT Security Guidelines from NIST

Digging Deeper to Find the Source

Hackers easily guessed passwords that hadn’t been changed from the factory defaults. Another device was still running outdated firmware with a known security flaw.

Microsoft has yet to identify the goal of this attack. It knows that hackers used the devices to establish a presence on the network and continue looking for additional access. Hackers used network scans to find other devices that would grant access to higher-value data.

FBI holds the group responsible for infecting over half a million consumer-grade routers in over 50 countries in a 2018 VPNFilter attack. The group used Modbus serial communications protocol to monitor, log, or modify traffic passing between network end points/ websites or industrial control systems. The FBI worked with Cisco’s Talos security group to neutralize the attack. The group also hacked the 2016 Democratic National Committee, World Anti-Doping Agency and the TV5Monde TV station in France.

Microsoft has notified the manufacturers of the affected IoT devices and hopes they will use the information to make their devices more secure.

Coordinated attacks like this highlight the gaping security holes in some IoT deployments. That so many compromised devices used default passwords and outdated firmware suggests that organizations need to up their IoT security game.

thumbnail
Sue Walsh

Sue Walsh is News Writer for RTInsights, and a freelance writer and social media manager living in New York City. Her specialties include tech, security and e-commerce. You can follow her on Twitter at @girlfridaygeek.

Recommended for you...

New Frontiers of IAM: Reaching Great Heights with 2024 Trends
Ronak D. Jain
May 22, 2024
Application Security for IoT: 10 Best Practices
Sagar Nangare
Feb 21, 2023
The Importance of Ensuring IoT System Security
Is Nanotechnology Ready to Enter the IoT Security War?
Bernard Brode
Apr 12, 2022

Featured Resources from Cloud Data Insights

The Difficult Reality of Implementing Zero Trust Networking
Misbah Rehman
Jan 6, 2026
Cloud Evolution 2026: Strategic Imperatives for Chief Data Officers
Why Network Services Need Automation
The Shared Responsibility Model and Its Impact on Your Security Posture
RT Insights Logo

Analysis and market insights on real-time analytics including Big Data, the IoT, and cognitive computing. Business use cases and technologies are discussed.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.