ãã«ãŒããã€ã³ãããŠãŒã¶ãŒã®æèãè匱æ§ããã³ã¬ãžãªãšã³ã¹ã®è©³çްã調æ»ãã幎次ã¬ããŒãã2023 State of the Phishããçºè¡š
ãã£ãã·ã³ã°ã«ããçŽæ¥çãªééçæå€±ãçµéšããçµç¹ã¯æšå¹Žæ¯76%å¢ãã©ã³ãµã ãŠã§ã¢æ»æãããžãã¹ã¡ãŒã«è©æ¬ºãå éšè åšãªã©ã®è€éåããè åšã«å¯ŸããŠãå šç€Ÿçãªã»ãã¥ãªãã£æåã®éžæãæ¥å
ãµã€ããŒã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹åéã®ãªãŒãã£ã³ã° ã«ã³ãããŒã§ããæ¥æ¬ãã«ãŒããã€ã³ãæ ªåŒäŒç€ŸïŒæ¬ç€ŸïŒæ±äº¬éœæž¯åºã代衚åç· åœ¹ç€Ÿé·ïŒèæšæ£ä¹ã以äžãã«ãŒããã€ã³ãïŒã¯ã幎次ã¬ããŒãã®ææ°çã2023 State of the PhishïŒãŠãŒã¶ãŒã®æèãè匱æ§ããã³ã¬ãžãªãšã³ã¹ã®è©³çŽ°èª¿æ»ïŒãã®æ¥æ¬èªçãçºè¡šããŸãããæ¬ã¬ããŒãã§ã¯ãæ»æè ãæ°ããªææ³ãšæ¢ã«ç¢ºç«ãããææ³ã®äž¡æ¹ãçšããŠçµç¹ã䟵害ããŠããããšãæããã«ããŸããã2022幎ã«ããã£ãã·ã³ã°ã¡ãŒã«ã«ããæ»æãå°ãªããšãäžåºŠã¯çµéšããçµç¹ã¯84%ã§ããã®çµæãçŽæ¥çãªééçæå€±ã¯2021å¹Žãšæ¯èŒããŠ76ïŒ å¢ãšãªããŸããããŸããæ£èŠãã©ã³ãã®æªçšãããžãã¹ã¡ãŒã«è©æ¬º (BEC) ãã©ã³ãµã ãŠã§ã¢æ»æã¯ãäŸç¶ãšããŠæ»æè ã®éã§ãã䜿ãããææ³ã§ããäžæ¹ãã°ããŒãã«çµç¹ã«äŸµå ¥ããããã«ãæ»æè ã¯äžè¬çã«ã¯ããŸãç¥ãããŠããªãæ»æææ³ã®äœ¿çšãæ¡å€§ããŠããŸãã
èª¿æ»æŠèŠïŒ
ä»åã®ã2023 State of the Phishã幎次ã¬ããŒãã¯ãæ¥æ¬ãå«ãäž»èŠ15ã«åœïŒã¢ã¡ãªã«ãæ¥æ¬ãéåœãã·ã³ã¬ããŒã«ããªãŒã¹ãã©ãªã¢ãã«ããããã©ãžã«ããã©ã³ã¹ããã€ããã€ã¿ãªã¢ãã¹ãã€ã³ãã€ã®ãªã¹ããªã©ã³ããã¹ãŠã§ãŒãã³ãUAEïŒã«ãããITããã³ITã»ãã¥ãªãã£æ åœè 1,050人ã察象ãšããã°ããŒãã«ãªèª¿æ»ãããã³å15ã«åœã®æäººåŽåè 7,500人ã察象ãšãã調æ»ã®çµæããµã€ããŒæ»æã®åºãããå©é·ãããã»ãã¥ãªãã£ã«é¢ããæèãšãµã€ããŒãã€ãžãŒã³ãšã®é©ãã¹ãã®ã£ãããæããã«ããŠããŸãããŸãããã«ãŒããã€ã³ãã®é¡§å®¢äŒæ¥ã»çµç¹ãåŸæ¥å¡ã«éä¿¡ãããããïŒå3500äžåã®ãã£ãã·ã³ã°æ»æã·ãã¥ã¬ãŒã·ã§ã³ããŒã¿ããã³1幎éã«éä¿¡ããã1,800äžé以äžã®ãšã³ããŠãŒã¶ãŒããã®ãã£ãã·ã³ã°ã¡ãŒã«ã®å ±åã¡ãŒã«ããŒã¿ã«åºã¥ããäžçã«ãããè åšã®è©³çްãªçŸç¶ãåæããŠããŸãã
äžçã«ãããäž»ãªèª¿æ»çµæïŒ
ãµã€ããŒæ»æã«ããè¢«å®³ãæ¡å€§
éå»1幎éã«76%ã®çµç¹ãã¡ãŒã«çµç±ã®ã©ã³ãµã ãŠã§ã¢æ»æãçµéšããŸããããŸãã調æ»å¯Ÿè±¡ã§ããçµç¹ã®ãã¡64%ãå®éã«ã©ã³ãµã ãŠã§ã¢(䟵å
¥çµè·¯ã¯åããªã)ã«ææããŸãããæåã®èº«ä»£éæ¯æãåŸã«ããŒã¿ãžã®ã¢ã¯ã»ã¹ãå埩ã§ããã®ã¯ããããåæ°ã§ãããé©ãã¹ãããšã«ãåçè
ã®3åã®2以äžããèªåã®çµç¹ãè€æ°åãç°ãªãã©ã³ãµã ãŠã§ã¢ã®ææãçµéšãããšçããŠããŸãã
ã©ã³ãµã ãŠã§ã¢ã«ææããçµç¹ã®64%ã身代éãæ¯æãããã®ãã¡çŽåæ°ã¯è€æ°åæ¯æããè¡ã£ãŠããŸãã被害ãåããçµç¹ã®ãã¡ãå§åç倿°ïŒ90ïŒ ïŒãã©ã³ãµã ãŠã§ã¢æ»æã«åãããµã€ããŒä¿éºã«å å ¥ããŠãããã»ãšãã©ã®ä¿éºäŒç€Ÿãã身代éã®äžéšãŸãã¯å šé¡ãè£åãããŸããããŸããã©ã³ãµã ãŠã§ã¢ã«ææããçµç¹ã®64ïŒ ãå°ãªããšã1åã®èº«ä»£éãæ¯æã£ãŠããŸããæšå¹Žèª¿æ»å¯Ÿè±¡ãšãã7ãåœ(æ¥æ¬ããªãŒã¹ãã©ãªã¢ãã¢ã¡ãªã«ããã©ã³ã¹ããã€ããã¹ãã€ã³ãã€ã®ãªã¹)ã®2022幎ã®èº«ä»£éæ¯æçã¯66%ã§ãããå幎(2021幎ã¯58%)ãã8ãã€ã³ãå¢å ããŠããããšããããæ¯æãåŸåã®é«ãããããããŸãã
åœ ãMicrosoftã ã¡ãŒã«ã«ãããšã³ããŠãŒã¶ãŒãžã®è¢«å®³
ãã«ãŒããã€ã³ãã¯2022幎ãå
šäžçã«ãŸããã顧客ç°å¢ã«ãããŠãæ£èŠãã©ã³ããæªçšãã1,600ä»¶è¿ãã®æ»æãã£ã³ããŒã³ã確èªããŸãããæãæªçšããããã©ã³ãã¯Microsoftã§ãå瀟ã®ãã©ã³ãã£ã³ã°ããŸãã¯OfficeãOneDriveãªã©ã®Microsoft補åãå©çšããã¡ãã»ãŒãžã幎é3,000äžé以äžç¢ºèªãããŸããããŸãããµã€ããŒç¯çœªè
ã«ãã£ãŠæªçšãããããšã®å€ãäŒæ¥ãšããŠã¯ãMicrosoftã®ã»ãã«ãGoogleãAmazonãDHLãAdobeãDocuSignãªã©ããããŸããAiTMæ»æã§ã¯ããŠãŒã¶ãŒã«ã¯çµç¹ã®æ£èŠã®ãã°ã€ã³ããŒãžã衚瀺ãããŸããããã®ã»ãšãã©ãMicrosoft365ã§ããããšã¯æ³šç®ã«å€ããŸãã
æ£èŠãã©ã³ãã«ãªãããŸããæ»æã®å€ããèæ ®ãããšãåŸæ¥å¡ã®åæ°è¿ãïŒ44%ïŒãã銎æã¿ã®ãããã©ã³ãåãå«ãã¡ãŒã«ã¯å®å šã ãšæããšåçãã63%ããããã£ãã¡ãŒã«ã¢ãã¬ã¹ã¯åžžã«ãã®ãã©ã³ãã®ãŠã§ããµã€ããšäžèŽããŠãããšèããŠããããšã¯ææ ®ãã¹ãããšã§ãããšèšããŸãããŸãããã«ãŒããã€ã³ãã®é¡§å®¢ãæãå©çšãããã£ãã·ã³ã°æ»æã·ãã¥ã¬ãŒã·ã§ã³10çš®é¡ã®ãã³ãã¬ãŒãã®ãã¡åæ°ãæ£èŠãã©ã³ãã®æªçšã«é¢é£ããŠãããæ»æã·ãã¥ã¬ãŒã·ã§ã³ã«ãããŠäžåæ Œçãé«ãåŸåããã£ãããšã¯åœç¶ã®çµæãšèšããŸãã
äžçã«åºãŸãããžãã¹ã¡ãŒã«è©æ¬ºïŒBECïŒ
2022幎ã®èª¿æ»ã§ã¯ãäžçã®çµç¹ã®4åã®3ãBECæ»æãçµéšãããšåçããŠããŸããBECæ»æã«ãããŠè±èªãæããã䜿çšãããŠããèšèªã§ãããè±èªå以å€ã®äžéšã®åœã§ããã®åœã®èšèªã«ããæ»æãæ°å€ãèŠããå§ããŠããŸããç¹ã«ä»¥äžã®åœã«ãããŠãäžçå¹³åãäžåãããŸãã¯åå¹Žã«æ¯ã¹ãŠæ»æã®å¢å ãèŠãããŸããã
- ãªã©ã³ãïŒ92ïŒ ïŒ2021幎ã®èª¿æ»åæã¯ç¡ãïŒ
- ã¹ãŠã§ãŒãã³ 92ïŒ ïŒ2021幎ã®èª¿æ»åæã¯ç¡ãïŒ
- ã¹ãã€ã³ 90%ïŒ2021幎ã¯77%ã§13ãã€ã³ãå¢ïŒ
- ãã€ã 86%ïŒ2021幎ã¯75%ã§11ãã€ã³ãå¢ïŒ
- ãã©ã³ã¹ 80%ïŒ2021幎ã¯75%ã§5ãã€ã³ãå¢ïŒ
å
éšè
åš
æ°åã³ãããŠã€ã«ã¹ã«ãããã³ãããã¯ã«é¢é£ããéçšã®æµååã¯ããã³ãããã¯åŸã®çµæžã®äžç¢ºå®æ§ããããéå»2幎éã§åŸæ¥å¡ã®4人ã«1人ã転è·ãŸãã¯é¢è·ãããšåçããŠããŸãããã®ãããªéçšåžå Žã®ååã¯ãäŒæ¥ã«ãšã£ãŠããŒã¿ä¿è·ãããå°é£ãªãã®ã«ããŠããã64ïŒ
ãå
éšé¢ä¿è
ã«ããæ
å ±æŒããã€ã³ã·ãã³ããçµéšãããšå ±åããŠããŸãã転è·çµéšè
ã®ãã¡åæ°è¿ãïŒ44ïŒ
ïŒãããŒã¿ãæã¡åºããããšãèªããŠããŸãã
æ»æè
ã¯ããå·§åŠãªã¡ãŒã«è
åšãæ¡å€§
éå»1幎éã§ãé»è©±ãçšããæ»æå®è¡ïŒTOADïŒãå€èŠçŽ èªèšŒïŒMFAïŒåé¿ãçšããæ»æã¯ã1æ¥ãããæ°åäžä»¶ã確èªãããã»ãŒãã¹ãŠã®çµç¹ã«ãããŠæ»æã芳枬ãããŸããããã«ãŒããã€ã³ãã¯ãããŒã¯æã«ã¯1æ¥ããã60äžä»¶ä»¥äžã®TOADæ»æïŒæ»æè
ãåœã®ãã³ãŒã«ã»ã³ã¿ãŒãã«ãªãããŸããŠé»è©±ã§çŽæ¥äŒè©±ãå§ããåä¿¡è
ãæåããã¡ãŒã«ïŒã远跡ããŠããã2021幎åŸåã«ãã®ææ³ãåããŠçŸããŠä»¥æ¥ããã®æ°ã¯çå®ã«å¢å ããŠããŸãã
ãµã€ããŒæ»æè ã¯ãMFAãåé¿ããããã®ããŸããŸãªæ¹æ³ãçšæããŠãããå€ãã®PhaaSïŒPhishing as a ServiceïŒãããã€ããŒã¯ããã§ã«æ¢è£œã®ãã£ãã·ã³ã°ãããã«AiTMããŒã«ãçµã¿èŸŒãã§ããŸãã
ãµã€ããŒãã€ãžãŒã³ã®æ¹åãäžå¯æ¬
è
åšã¯åžžã«é²åããŠãããä»åã®ã¬ããŒãã§ãã»ãšãã©ã®åŸæ¥å¡ãã»ãã¥ãªãã£æèã®ã®ã£ããã«èŠããã§ããããšã瀺ãããŸããã調æ»åçè
ã®3åã®1以äžãããã«ãŠã§ã¢ãããã£ãã·ã³ã°ããã©ã³ãµã ãŠã§ã¢ãã®å®çŸ©ãæ£ããèªèã§ããŠããªããªã©ãåºæ¬çãªæŠå¿µãååã«çè§£ããŠããªãããšãåãããŸããã
ããã«ãã»ãã¥ãªãã£æèåäžããã°ã©ã ãå°å ¥ããŠããçµç¹ã®ãã¡ãåŸæ¥å¡å šå¡ã察象ãšãããã¬ãŒãã³ã°ãè¡ã£ãŠããã®ã¯56ïŒ ããã£ãã·ã³ã°ã·ãã¥ã¬ãŒã·ã§ã³ãè¡ã£ãŠããã®ã¯35ïŒ ã®ã¿ã§ããããã广çãªã»ãã¥ãªãã£æèåäžããã°ã©ã ãæ§ç¯ããäžã§éèŠãªèŠçŽ ãšãªã£ãŠããŸãã
æ¥æ¬ã«ãããäž»ãªèª¿æ»çµæïŒ
- æ¥æ¬ã®çµç¹ã®64ïŒ ïŒäžçå¹³åïŒ84%ïŒãã2022幎ã«å°ãªããšã1åã®ãã¡ãŒã«ãçšãããã£ãã·ã³ã°æ»æãã«ãã£ãŠè¢«å®³ãåããŠããããã¡13ïŒ ïŒäžçå¹³åïŒ30%ïŒãçŽæ¥çãªééçæå€±ãå ±åãå幎ã«ãã£ãã·ã³ã°æ»æãçµéšããçµç¹ã®ãã¡ãçŽæ¥çãªééçæå€±ãå ±åããæ¥æ¬ã®çµç¹ã¯3ïŒ ã ã£ãïŒäžçå¹³åïŒ17%ïŒã
- 調æ»å¯Ÿè±¡ã§ããæ¥æ¬ã®çµç¹ã®ãã¡68%ïŒäžçå¹³åïŒ64%ïŒãã©ã³ãµã ãŠã§ã¢å®éã«ææïŒ2021幎ã¯50%ã18ãã€ã³ãå¢ïŒã

- ã©ã³ãµã ãŠã§ã¢ã«ææããæ¥æ¬ã®çµç¹ã®ãã¡ãå°ãªããšã1åã®èº«ä»£éãæ¯æã£ãæ¥æ¬ã®çµç¹ã¯ããã18ïŒ
ïŒæšå¹Žãã2ãã€ã³ãæžïŒã§ãäžçå¹³åã®64%ãšæ¯ã¹å€§ããäžåã£ãŠããäžçã®ãã¬ã³ããšéè¡ããŠããããã«ãŒããã€ã³ãã®ïŒå¹Žã«ããã調æ»ã®ãã¡ãæ¥æ¬ã¯ïŒå¹Žé£ç¶ã§èª¿æ»å¯Ÿè±¡åœã®ãã¡ãæãäœã身代éã®æ¯æçãšãªã£ãŠããã

- 銎æã¿ã®ãããã©ã³ãåãããŽãå«ãŸããŠããã¡ãŒã«ã¯å®å šã ãšèããŠããæ¥æ¬ã®çµç¹ã®åŸæ¥å¡ã¯ããã23%ïŒäžçå¹³åïŒ44%ïŒã§ããã54%ïŒäžçå¹³åïŒ63%ïŒãã¡ãŒã«ã¢ãã¬ã¹ã¯åžžã«ãã®ãã©ã³ããšäžèŽãããŠã§ããµã€ãã«å¯Ÿå¿ããŠãããšèããŠããã
- æ¥æ¬ã®çµç¹ã®52ïŒ ïŒäžçå¹³åïŒ75%ïŒãBECæ»æãçµéšãããšåçã
- æ¥æ¬ã®çµç¹ã®46ïŒ ïŒäžçå¹³åïŒ64%ïŒããå éšé¢ä¿è ã«ããããŒã¿æå€±ãçµéšããããšããããšåçã
- æ¥æ¬ã®åŸæ¥å¡ã®13ïŒ ãéå»2幎éã«è»¢è·ãçµéšã転è·çµéšè ã®ãã¡ã34ïŒ ïŒäžçå¹³åïŒ44%ïŒãããŒã¿ãæã¡åºããããšãèªããŠããã
- ã»ãã¥ãªãã£æèåäžããã°ã©ã ãå°å ¥ããŠããæ¥æ¬ã®çµç¹ã®44ïŒ ïŒäžçå¹³åïŒ56%ïŒããåŸæ¥å¡å šå¡ã察象ãšãããã¬ãŒãã³ã°ãè¡ã£ãŠããã
ãã«ãŒããã€ã³ãç±³åœæ¬ç€Ÿã®ãµã€ããŒã»ãã¥ãªãã£æŠç¥æ åœå¯ç€Ÿé·ãRyan KalemberïŒã©ã€ã¢ã³ã»ã«ã¬ã³ããŒïŒã¯æ¬¡ã®ããã«è¿°ã¹ãŠããŸãããåŸæ¥ã®ãã£ãã·ã³ã°æ»æã¯äŸç¶ãšããŠæåãåããŠããŸãããå€ãã®æ»æè ã¯ãé»è©±ã䜿ã£ãæ»æé ä¿¡ããå€èŠçŽ èªèšŒããã€ãã¹ããäžéè ïŒAiTMïŒãã£ãã·ã³ã°ãããã·ãªã©ãããæ°ããææ³ã«ç§»è¡ããŠããŸãããããã®ææ³ã¯ãé·å¹Žã«ãããæšçåæ»æã§äœ¿çšãããŠããŸãããã2022幎ã«ã¯å€§èŠæš¡ã«å±éãããããã«ãªããŸããããŸããè€æ°ã®ãã«ãœãã§ããé·ãäŒè©±ãè¡ããæŽç·Žããããã«ãã¿ãããã£ãã·ã³ã°ãã£ã³ããŒã³ãèããå¢å ããŠããŸããåœå®¶ãšé£æºããŠããã°ã«ãŒãã§ãããBECæ»æè ã§ãããé·ææŠã«æã¡èŸŒãããšããæµã¯ããããããŸãã
æ¥æ¬ãã«ãŒããã€ã³ãæ ªåŒäŒç€ŸãããŒã ãšãã³ãžã§ãªã¹ãã®å¢ç° 幞çŸã¯æ¬¡ã®ããã«è¿°ã¹ãŠããŸãããæ¥æ¬ã®ã©ã³ãµã ãŠã§ã¢ã®ææçã¯å幎ããé«ããªã2022幎ã¯68%ã§ãããããããæ¥æ¬ã®ã©ã³ãµã ãŠã§ã¢ã«å¯Ÿããèº«ä»£éæ¯æçã¯ïŒå¹Žé£ç¶ã§æžå°ãã2022幎ã¯18%ã§ãããããã¯èª¿æ»å¯Ÿè±¡åœã®ãã¡ãïŒå¹Žé£ç¶ã§æãäœãèº«ä»£éæ¯æçãšãªã£ãŠããŸããïŒïŒïŒïŒå¹Žã2021幎ã2022幎ã§å ±éãã調æ»å¯Ÿè±¡7ãåœã®èº«ä»£éæ¯æçã®å¹³åã¯ãïŒå¹Žé£ç¶ã§å¢å ããŠããäžã§ãæ¥æ¬ã¯äžçãšç°ãªãåŸåãèŠããŠããŸãã身代éãäžåºŠæ¯æããšãä»ã®ã©ã³ãµã ãŠã§ã¢æ»æã°ã«ãŒãããåã³çãããããšãå€ãããããè ãã«å±ããªããæ åºŠãèŠããããšã¯ãç¯çœªãå©é·ãããªãããšã«ã€ãªãããŸããæ¥æ¬å šäœã«ãããŠã»ãã¥ãªãã£æåãããã«éžæãããããšã§ãæ»æãåããæ©äŒãæžãããæ»æãåããå Žåã®å埩åãé«ããããšãã§ããŸãã
ã2023 State of the Phishãã¬ããŒãïŒæ¥æ¬èªçïŒã¯ä»¥äžãªã³ã¯ããããŠã³ããŒãããŠãã ããïŒ
https://www.proofpoint.com/jp/resources/threat-reports/state-of-phish
ãµã€ããŒã»ãã¥ãªãã£æèåäžãã¬ãŒãã³ã°ã«é¢ããŠã¯ä»¥äžãã芧ãã ããïŒ
https://www.proofpoint.com/jp/products/security-awareness-training
Proofpoint | ãã«ãŒããã€ã³ãã«ã€ããŠ
Proofpoint, Inc.ã¯ããµã€ããŒã»ãã¥ãªãã£ã®ã°ããŒãã« ãªãŒãã£ã³ã° ã«ã³ãããŒã§ããçµç¹ã®æå€§ã®è³ç£ã§ããããåæã«æå€§ã®ãªã¹ã¯ãšããªãããã人ããå®ãããšã«çŠç¹ãããŠãŠããŸããProofpointã¯ãã¯ã©ãŠãããŒã¹ã®çµ±åãœãªã¥ãŒã·ã§ã³ã«ãã£ãŠãäžçäžã®äŒæ¥ãæšçåæ»æãªã©ã®ãµã€ããŒæ»æããããŒã¿ãå®ãããããŠããããã®ãŠãŒã¶ãŒããµã€ããŒæ»æã«å¯ŸããŠããã«åŒ·åãªå¯ŸåŠèœåãæãŠãããæ¯æŽããŠããŸãããŸããFortune 100äŒæ¥ã®75%ãå«ãããŸããŸãªèŠæš¡ã®äŒæ¥ãããã«ãŒããã€ã³ãã®ãœãªã¥ãŒã·ã§ã³ãå©çšããŠãããã¡ãŒã«ãã¯ã©ãŠãããœãŒã·ã£ã«ã¡ãã£ã¢ãWebé¢é£ã®ã»ãã¥ãªãã£ã®ãªã¹ã¯ããã³ã³ã³ãã©ã€ã¢ã³ã¹ã®ãªã¹ã¯ãäœæžããããæ¯æŽããŠããŸãã
詳现㯠www.proofpoint.com/jp ã«ãŠã確èªãã ããã
Twitter | LinkedIn | Facebook | YouTube
© Proofpoint, Inc. Proofpointã¯ç±³åœåã³ãã®ä»ã®åœã ã«ãããProofpoint, Inc.ã®åæšã§ããæ¬ããã¥ã¡ã³ãã«èšèŒãããŠããäŒç€Ÿåã補ååããµãŒãã¹åã¯ãäžè¬ã«å瀟ã®ç»é²åæšãŸãã¯åæšã§ããæ¬ããã¥ã¡ã³ãã®èšèŒå 容ã補ååã³ãµãŒãã¹ã®ä»æ§ã¯äºåãªã倿ŽãããããšããããŸãã