News Release

Cybercriminals Ditching Mass Spam for Targeted Attacks

New Cisco Report Shows Traditional Mass Spam Volumes Plummeting as Cybercriminals Turn to More Lucrative, Pinpointed Attacks
Jun 30, 2011

SAN JOSE, Calif. – June 30, 2011 – In the complex and ever-changing landscape of online crime, cybercriminals have made a fundamental shift in strategy, abandoning traditional mass spam attacks in favor of personalized attacks with a greater financial impact on targeted organizations, according to a new security report from Cisco. Research conducted by Cisco® Security Intelligence Operations shows thetrend toward increased targeted attacksfeaturing highly customized threats containing malwarethat are directed at a specific user or group of users for intellectual property theft.

Key Findings - Email Attacks: This Time, It's Personal

  • Returns from mass email-based attacks declined by more than 50 percent from US$1.1 billion in June 2010 to $500 million in June 2011.
  • Mass spam volumes plummeted from 300 billion daily spam messages to just 40 billion between June 2010 and June 2011.
  • There is an increase in spearphishing and personalized scams and malicious attacks.
  • Spearphishing attacks have increased threefold, while scams and malicious attacks have increased fourfold.
  • The overall cost of targeted attacks to organizations worldwide is $1.29 billion annually.

Like almost all types of cybercrime exploits, the success of targeted attacks relies on technical holes and the all-too-human tendency to misplace trust. Targeted attacks are the most elusive threat to protect against and have the potential to deliver the most potent negative impact. Very low in volume, they focus on a specific individual or group under cover of anonymity provided by specialized botnet distribution channels. Typically, they rely on malware or APTs (Advanced Persistent Threats) to harvest desired data over a period of time. An example of a targeted attack is the infamous Stuxnet worm, which had the potential to severely disrupt industrial computing systems and could traverse non-networked systems, thus placing at risk even systems unconnected to networks or the Internet.

Spearphishing attacks, though more costly to mount and lower in volume than mass spam attacks, also pose serious consequences for today's enterprises. Many spearphishing attacks ultimately lead to financial theft, making them both highly dangerous to victims and highly valuable to cybercriminals. Spearphishing campaigns, which are a highly customized evolution of the traditional mass attack technique of phishing, can net 10 times the profit of a mass attack.

The global study focuses on perspectives from 361 information technology professionals from 50 countries andwas compiled by Cisco Security Intelligence Operations, which provides real-time threat intelligence to help Cisco stay ahead of the latest cyber threats. Cisco SIO is the world's largest cloud-based security ecosystem, using SensorBase data of almost 1 million live data feeds from deployed Cisco email, Web, firewall and intrusion prevention system (IPS) solutions.  


Supporting Quote:

Nick Edwards, director of Cisco's Security Technology Business Unit

  • "Personalized and targeted attacks that focus on gaining access to more lucrative corporate bank accounts and valuable intellectual property are on the rise. Law enforcement efforts are making mass spam attacks less appealing to cybercriminals, who are thus spending more time and effort focusing on different types of spearphishing and targeted attacks."


Supporting Resources:

Technorati Tags: Cisco, targeted attacks, SIO, email, spam, Stuxnet, malware, security, research, study, network security, spearfishing, enterprise security. 

About Cisco Systems

Cisco, (NASDAQ: CSCO), is the worldwide leader in networking that transforms how people connect, communicate and collaborate. Information about Cisco can be found at For ongoing news, please go to

# # #

Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. A listing of Cisco's trademarks can be found at Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company.