digital
Showing posts with label digital. Show all posts

iProov Threat Intelligence Uncovers "Grey Nickel" Threat Actor Targeting Banking, Crypto, and Payment Platforms

Tuesday, June 10, 2025

"Grey Nickel" Threat Actor

KYC Processes Exposed in Wave of Sophisticated Financial Sector Attacks

iProov, the world's leading provider of science-based biometric identity verification solutions, today revealed details of an active cybercriminal operation that has successfully infiltrated financial institutions worldwide by exploiting vulnerabilities in remote identity verification systems. iProov's Security Operations Center (iSOC) observed live operations of the threat actor, codenamed "Grey Nickel," targeting organizations globally with concentrated attacks against banking, crypto exchanges, e-wallets, and digital payment platforms in Asia-Pacific, EMEA, and North America. During its investigation of “Grey Nickel”, the iSOC team also documented an unprecedented escalation in attacks specifically designed to bypass Know Your Customer (KYC) processes across the financial services sector.

Financial Services: New Attacks, Same Battleground

Financial services organizations have long been prime targets for relentless fraud attacks, both by lone perpetrators and highly organized criminal networks. Unfortunately, many of the organizations targeted by “Grey Nickel” and the KYC attackers had employed liveness detection technologies that appear to be designed to prevent only presentation attacks as opposed to AI-fueled digitally injected attacks. The gap between the identity assurance that these technologies are able to provide and the identity assurance needed has become a profitable sweet spot for cybercriminals.

iProov advises organizations to use its spectrum of identity assurance methodology to determine the most suitable verification technologies, tailored to each use case, by evaluating the contextual knowledge of the individual and the risk of the activity with the organization’s risk appetite.

"These criminal groups understand that banking, crypto exchanges, e-wallets, and digital payment platforms represent some of the highest-value targets for identity fraud," said Dr. Andrew Newell, Chief Scientific Officer of iProov." It is important to understand that these aren't opportunistic attacks; they represent highly coordinated, specialized operations that pose an existential threat to the digital transformation of banking."

Multiple Threat Actors, Common Target

iProov's investigation has identified several distinct criminal operations:

Grey Nickel: Systematic Operations

A sophisticated threat actor group, codenamed "Grey Nickel," has been conducting systematic attacks against identity verification systems since July 2023, primarily targeting organizations in the Asia-Pacific region, with recent expansions into North America and EMEA. This group employs advanced face-swap technology, metadata manipulation, and injection techniques specifically designed to defeat single-frame liveness-based verification systems used by banks and payment platforms.

Advanced Virtual Camera Networks

Separate criminal groups have developed and distributed specialized mobile applications that enable KYC bypass on both Android and iOS devices. These applications inject pre-recorded or manipulated video feeds during identity verification, with some variants now incorporating lip-syncing capabilities to defeat voice-based challenges.

Deepfake-as-a-Service Operations

Independent criminal actors have established service-based models, offering custom deepfake creation and comprehensive KYC bypass packages specifically designed to target cryptocurrency exchanges and payment platforms. These operations combine stolen identity databases with AI-generated media to create “synthetic identities” and enable large-scale identity fraud.

AI-Powered Fraud Tools

Criminal forums now actively share techniques using commercially available AI platforms to generate convincing deepfake videos, specifically designed to bypass primitive liveness technologies employed by some financial institutions.

Financial Impact of AI-based Cybercrime

The financial consequences of these attacks are reaching unprecedented levels:
  • More than half of the organizations surveyed in a recent Biocatch Report admitted to losing between $5 and $25 million to AI-powered attacks in 2023.
  • A United Nations report noted a rise in AI-driven crimes involving deepfakes, demonstrated by more than a 600% increase in mentions of deepfake-related content targeting criminal groups in Southeast Asia across monitored online platforms in the first half of 2024.

Criminal Innovation Outpaces Regulatory Response

A critical global challenge in combating cybercrime against the financial services sector is the widespread lack of comprehensive data from these institutions. This absence of consistent, mandatory incident reporting across many jurisdictions prevents regulators from accurately assessing the scale of illicit activities, which hinders effective regulatory action. While regions like the European Union are advancing proactive measures, with bodies such as the European Banking Authority proposing the adoption of the high-assurance EU Digital Identity Wallet or an equivalent to comply with AML rules, many nations lag behind. This creates global disparities that cybercriminals can exploit and highlights an urgent need for greater international cooperation and data sharing to drive robust security enhancements and coordinated regulatory intervention.
Read More

Ant International Pushes AI Strategy with AI Platform for Fintechs

Monday, June 9, 2025

Three-Pronged AI Strategy

  • Three-pronged AI strategy focuses on AI security, Vertical Fintech Expertise, and Full-stack AI platform support
  • First fintech clients begin official integration in June 2025 in Southeast Asia and South Asia

Ant International, a leading global digital payment, and financial technology provider, today unveils its AI strategy with the launch of Alipay+ GenAI Cockpit, an AI-as-a-Service (AIaaS) platform that empowers fintech companies and super apps to build AI-agentic and ultimately AI-native financial services with enhanced efficiency, security, and flexibility.

Making AI systemically work for finance remains the holy grail of the current AI revolution. Alipay+ GenAI Cockpit is a platform to help entrepreneurs architect an agentic and ultimately AI-native financial services, combining automated workflows and task orchestration with a dynamic enterprise context, across main fintech tasks, from payment orchestration, customer onboarding, compliance checks, to fraud detection, dispute resolution, as well as evaluation and performance optimization.

“The future of finance will be shaped by agentic AI that not only carries out tasks autonomously in real automated workflows and sophisticated financial business and compliance context with reliability, but also interacts, evolves and learns rapidly in orchestration with ever-growing precision,” said Jiangming Yang, Chief Innovation Officer of Ant International.

Alipay+ GenAI Cockpit has been honed on Ant International’s four key business units: wallet gateway service (Alipay+), merchant payment service (Antom), cross-border business account service (WorldFirst), and embedded finance service (global treasury management, digital lending and credit tech solutions). Upon successful completion of trial runs, the first external clients in Southeast Asia and South Asia will start officially deploying the Cockpit in June 2025.

Three-Pronged AI Strategy: Security, Vertical Fintech Expertise, and Platform-level Support for Agentic FinAI

Combining a fintech-specific toolbox and dynamic industry knowledge base alongside business-ready AI innovations, the Cockpit embodies three key directions of Ant International’s AI strategy.

Security Shield for Trusted AI

AI scamming threats using deepfake and other technologies have been growing over 10 folds by the year, with grave implications, especially in the financial sector. Statistics show 22% of businesses have encountered AI-generated payment fraud.

Ant International invests heavily in AI security solutions to combat external AI scamming attacks and eliminate internal model security risks such as model hallucination or bias. Its AI SHIELD framework manages risks across system architecture designing, data processing, model training, and inferencing. It offers real-time dynamic risk assessment, including detecting adversarial prompts and sensitive data leakage through over 100 recognition models and 600,000 risk lexicons. Today, fraud loss rate in Ant International’s merchant payment service is 5% of industry average.

Deep Vertical Financial Expertise

Alipay+ GenAI Cockpit leverages over 20 leading LLMs, including Ant International’s own Falcon Time-Series-Transformer FX Model. However, it has focused on integrating fintech knowledge bases, such as bank transfer rules and dispute resolution policies, to help businesses build specialized fintech agents.

The Cockpit toolbox supports retrieval-augmented generation (RAG), post-training, evaluation, and benchmarking, taking the combination of general-purpose datasets with industry-specific benchmarks developed from Ant International’s financial expertise to help improve model precision.

Built on the Cockpit, Antom Copilot is the world’s first AI agent designed to help merchants boost conversion by streamlining the process of payment method integration, recommending optimal payment channels, and resolving common tasks like code correction and the auto-completion of merchant onboarding documents. It also allows merchants to configure risk management strategy with natural language.

Full-Stack FinAI Platform Support

Cockpit offers a wide selection of pre-built agents covering regular tasks, including customer service, content curation for targeted marketing, and AI-assisted coding. One level up, a business can easily customize agents for more specialized scenarios such as travel advisory, tax refunds, cross-border remittance, and loyalty rewards, accelerating time-to-value across business functions.

Further, the Cockpit’s model context protocol (MCP) marketplace supports major MCP servers developed thus far and allows businesses to create their own MCP servers to enable autonomous task completion. It also supports flexible deployment across public clouds and on-premise environments, drawing on strategic partnerships with Google Cloud and other top-tier infrastructure providers.

“The FinAI sector is at its big-bang moment,” said Yang. “We are eager to work with the industry to evolve and expand the toolbox as well as this ecosystem to help financial businesses scale their growth faster and better.”

Read More

Kissflow wins “Best Digital Transformation Solution” at Future Digitech Summit 2025

Thursday, June 5, 2025


Kissflow, a low-code platform built for citizen developers aka process owners and developers to create applications is proud to announce that it has been honored with the “Best Digital Transformation Solution” award at the prestigious Future Digitech Summit 2025, recognizing its outstanding contribution to redefining business processes through innovation and cutting-edge technology.

Held annually, the Future Digitech Summit celebrates excellence in digital innovation, bringing together trailblazers from across the tech industry. This award acknowledges Kissflow’s commitment to empowering organizations with scalable, user-centric digital transformation solutions that drive efficiency, agility, and growth.

“We are thrilled to receive this recognition,” said Rakesh Nandakumar, AVP - Kissflow, South East Asia. “This award is a testament to our team’s relentless focus on delivering transformative solutions that make a real difference to businesses worldwide.”

Southeast Asia is a key growth market for Kissflow, with its rapidly expanding digital economy and increasing demand for agile, low-code solutions. With a strong presence across countries like the Philippines, Singapore, Malaysia, and more recently- Thailand, Kissflow continues to partner with organizations in the region to simplify and accelerate their digital transformation journeys.
Read More

Bigo Live Celebrates Nine Years of Empowering Community and Creativity

Monday, June 2, 2025


Marking nearly a decade of empowering users to connect, create, and thrive in real time across cultures, borders, and backgrounds.

Bigo Live, the leading global livestreaming platform, marked its 9th anniversary with a vibrant celebration held on May 17 at Clubhouse at the Palace in BGC in Manila. The event brought together Filipino creators, such as those behind Bigo IDs like AVC_Roni and claire18, along with agency managers, fellow streamers, and family members to celebrate a milestone journey of creativity, connection, and community growth.

Since its launch in 2016, the Bigo Live Philippines community has grown significantly and become a dynamic space where creators from all walks of life are empowered to champion self-expression, showcase their talents and reach an international audience. As part of the anniversary festivities, Bigo Live unveiled a series of billboards across key locations in Manila, spotlighting top Filipino creators such as Ikangmo, recognising their talent and impact on the platform.

“Bigo Live is proud to celebrate nine years with our Filipino community. We remain committed to fostering a safe and inclusive environment where creativity thrives, careers are built, and connections are made,” said a Bigo Live Philippines spokesperson. “Thank you to all our creators and users who helped us shape this community and for being part of this incredible journey.“

Empowering Community, Online and Offline

Bigo Live has played a significant role in bringing local communities together to spread positivity and kindness through its interactive and real-time livestreaming experiences. During the COVID-19 pandemic, the platform provided Filipino creators a safe space to stay connected. Creators shared their stories, music and positive messages and found solace in their communities by connecting remotely from their homes.

Today, Bigo Live continues to champion community-first initiatives that bridge the digital and real worlds, offering new ways for the Filipino community to engage, celebrate, and connect. These include events such as Bigo Voice Music Fest 2024, BIGO Voice 2025 and Bigo Live Philippines Awards Gala.

“Bigo Live helped me discover parts of myself I never knew existed. I gained confidence, built genuine connections, and grew my following to nearly a million in just a year. The platform opened doors I never imagined – new friendships, exciting opportunities, and the ability to build my own income streams. To my supporters and fellow hosts: keep doing what makes you happy. Bigo Live changed my life, and it can change yours too,” shared Bigo Live creator Ikangmo.

Celebrating Local Voices and Cultural Impact

Bigo Live Philippines actively supports initiatives that uplift underrepresented voices and inspire positive change. The livestreaming platform has actively supported women’s empowerment through community-led events like Women’s Run PH — a run by women, for women — and specialised workshops for aspiring female creators. In a bold step towards inclusivity, Bigo Live Philippines partnered with global beauty brand MAC Cosmetics to launch Slay Model Search Asia, a talent competition celebrating the transgender community in the Philippines.

Looking ahead, Bigo Live Philippines will continue to roll out creator- and community-centric initiatives that inspire authentic expression and strengthen bonds across its user base. From new programmes that help creators unlock their full potential, to fun, meaningful events for the broader community, Bigo Live remains committed to its core mission: to empower people and change lives through real-time connectivity.

To find out more about Bigo Live, please visit our website.
Read More

Cyber Budgets Up, AI Gaps Remain: Palo Alto Networks Releases First-Ever Cybersecurity Benchmark Study for Asia-Pacific and Japan

Saturday, May 31, 2025


Palo Alto Networks, the world’s leading AI cybersecurity company, has released the 2025 Cybersecurity Resilience in Mid-Market Organisations, a benchmark study, offering a first-of-its-kind view into how mid-market organisations across Asia-Pacific and Japan, including the Philippines, are evolving their cybersecurity capabilities in the face of growing threats and accelerating digital transformation.

While mid-market organisations in the Asia-Pacific and Japan, including the Philippines, are making tangible progress in strengthening their cybersecurity posture, key challenges remain. Many organisations are still in the early stages of operationalising AI within their security workflows, and gaps persist in areas such as incident recovery and cyber resilience. Additionally, the complexity of managing multiple tools and fragmented environments continues to hinder efficiency. Addressing these issues will require a more unified, platform-based approach that integrates AI-driven capabilities to enhance performance, streamline operations, and strengthen protection across the board.

“Cybersecurity is no longer just an IT issue, it's a business priority. As threats grow more sophisticated and AI reshapes the threat landscape, our benchmark study reveals that many mid-market organisations are still catching up,” said Michelle Saw, Vice President, Ecosystems, Asia-Pacific and Japan at Palo Alto Networks. “This study helps mid-market organisations see where they stand and take the steps needed to achieve stronger security outcomes. It also highlights the growing importance of partners—who must now evolve their offerings to focus more deeply on education, integration, AI adoption, and advanced technical expertise to better support customer needs.”

Key findings from the study:

Partners matter more than ever: 79% of companies say they will rely on partners to support cybersecurity efforts within two years - up from 53% today.

Cyber budgets are on the rise: 57% of organisations plan to increase cybersecurity spending over the next 12 months. Cyber now accounts for 13.6% of total IT budgets, up from just 6% in 2019.

AI adoption lags behind investment: Despite growing awareness, organisations cited AI-related capabilities as one of the lowest performing areas in their cybersecurity programs.

Cloud security, IAM and SIEM top the priority list: Over the next 24 months, these are the most cited areas for new or increased investment.

Framework implementation is inconsistent: Adoption of NIST 2.0 received the lowest score among the five benchmark categories, underscoring a need for clearer guidance and support. Sectors leading the understanding and adoption of NIST 2.0 and other frameworks include financial services, telecommunications and utility companies.

Key highlights from the Philippines include:

Cybersecurity budgets are on the rise, now accounting for 13.3% of revenue, with the biggest increases projected in security software (47.09%), network security hardware (38.35%), and data protection and privacy (37.86%).

Partner support is accelerating: 61% of Philippine companies currently rely on partners for cybersecurity, a figure expected to rise to 79% in two years. MSSPs (40%) are the most preferred partner type, followed by MSPs and systems integrators.

Robust safeguards but gaps in governance and response: The Philippines scores 3.95 in Govern, 3.06 in Identify, 4.05 in Protect, 4.05 in Detect, and 3.07 in Respond under the NIST framework, revealing areas needing improvement particularly in governance, identification, and response.

Partner selection is driven by technical expertise (35.9%), resiliency capabilities, and knowledge transfer. However, poor solution performance (43%), major breaches, and supply chain issues remain the top reasons for switching partners.

Application and data security, SOC operations, and network security are currently the most deployed cyber solutions in the country.

“It’s encouraging to see the Philippines taking meaningful steps to elevate its cybersecurity efforts, especially with the approval of the National Cybersecurity Plan, a critical move to safeguard institutions, infrastructure, and citizens amid growing threats,” said Steven Scheurmann, Regional Vice-President of ASEAN at Palo Alto Networks. “With the Philippine digital economy valued at PhP2.25 trillion in 2024, which accounts for 8.5% of the country’s gross domestic product, cybersecurity is no longer optional. The increased budgets among mid-market organisations reflect a deeper understanding that protecting digital assets is essential to sustaining business growth and national progress. This is why partnerships are crucial to improving threat detection and response, enabling the adaptive, intelligent security needed for the digital future.”

“The research indicates that mid-market organisations in the region have made notable advancements in strengthening their cybersecurity posture,” said Tim Dillon, Founder, Director, Principal Analyst End User at Tech Research Asia. “However, there remains substantial opportunity for partners to support continued progress, particularly in the areas of workforce education and training, identity and access management, and application and data security.”

The Cybersecurity Benchmark for Asia-Pacific and Japan, developed in collaboration with Tech Research Asia (TRA), surveyed over 2,800 mid-sized organisations across 12 countries and a range of industries. It offers a snapshot of the region’s cybersecurity maturity and provides practical guidance for improvement. With evaluating performance across five key areas; strategy execution, business integration, operational capabilities, solution maturity, and NIST 2.0 framework adoption, the average score was 19.01 out of 25. While this indicates a moderate level of maturity, the findings reveal clear opportunities to strengthen AI readiness, boost ransomware resilience, and advance framework implementation. This Tech Research Asia Insights Report Asia-Pacific and Japan Edition was commissioned by Palo Alto Networks and completed in April 2025

For more information 2025 Cybersecurity Resilience in Mid-Market Organisations Study, visit: https://www.paloaltonetworks.com/industry/japac-mid-market-solutions
Read More

House Creatives PH: Shaping the Next Generation of Impactful Creators

Thursday, May 22, 2025


In a world where digital noise often drowns out authenticity, one movement is cutting through with purpose: House Creatives PH. Founded on the belief that content is more than just a form of expression—it is a catalyst for transformation—House Creatives PH is on a mission to equip individuals with the skills, mindset, and confidence to tell stories that change lives.

At the core of this movement is a powerful Massive Transformative Purpose (MTP):
“Creating Creators That Influence Transformation.”

Through immersive bootcamps, high-impact workshops, and deeply purposeful mentorship programs, House Creatives empowers entrepreneurs, professionals, and aspiring content creators to go beyond trends and build legacies. Whether you're a business owner looking to elevate your brand through storytelling or a creator wanting to inspire action, House Creatives offers the tools and support to make that leap.

Their flagship program, the Content Mastery Bootcamp (CMB), has become a proving ground for personal and professional breakthroughs. More than just technical training, it is a transformative experience that nurtures self-mastery, strategic communication, and authentic branding. Attendees don’t just learn how to create content—they know how to lead movements.


At the heart of this thriving community is a culture of collaboration, alignment, and shared growth. Participants leave not only with refined skills but also with a renewed sense of clarity, purpose, and connection.

From Real Talk to Real Impact

The spark behind House Creatives PH comes from Darbie Kim Estrebilla, widely known as Real Talk Darbs (RTD). A self-made entrepreneur and internationally recognized content creator, Darbs transformed his personal story of struggle, growth, and resilience into a platform that now uplifts thousands.

His motto, “One changed soul is worth more than a billion views,” has become the heartbeat of the community he built. Through House Creatives PH, he continues to turn passion into purpose, proving that with the right guidance, every story has the power to influence, inspire, and transform.

Read More

VFS Global Leverages SAP Software to Power Digital Cross-Border Mobility

Tuesday, May 6, 2025

Christian Klein and Zubin Karkaria in New York, highlighting VFS Global's decision to leverage SAP software for enhancing digital transformation and supporting governments and travellers worldwide.


SAP SE (NYSE: SAP) today announced that VFS Global, the world-leading provider of visa, consular and technology services to governments and diplomatic missions, will leverage SAP software to help it develop leading-edge AI-powered digital solutions for cross-border mobility and citizen services.

Cross-border mobility and citizen services are becoming increasingly digital, and governments are looking into the use of innovative technologies such as artificial intelligence to drive efficiency and sovereign security. To accelerate its innovation road map and help governments meet the increasingly complex needs of travelers and citizens, VFS Global is adopting SAP S/4HANA Cloud Public Edition and other SAP solutions.

“We take great pride in partnering with SAP as a leading and trusted technology and AI company,” said Zubin Karkaria, founder and CEO of VFS Global. “By combining our deep expertise in visa, consular and citizen services with SAP’s world-class solutions, we empower governments to enhance efficiency, strengthen security and enable seamless mobility for millions of travelers around the world.”

“With SAP solutions at its core, VFS will be able to leverage the latest innovations to become an even stronger partner for governments, travelers and citizens worldwide,” said Christian Klein, CEO of SAP SE.

In line with its vision to embrace technological innovation to support governments and diplomatic missions worldwide, VFS Global has also chosen SAP Business Technology Platform and the SAP Business Data Cloud solution to deliver leading-edge and AI-powered solutions to its customers and to drive operational excellence across its global operations.

“By combining the strengths of VFS Global and SAP, we are elevating cross-border mobility and citizen services to the next level”, said Michael Nilles, member of the VFS executive board and chief digital and technology officer. "Strategically, this positions us as a leading force in shaping the future of GovTech and TravelTech, powered by technology and AI innovations that benefit governments, travelers and citizens worldwide," he added.


Read More

Palo Alto Networks Encourages Voter Vigilance as AI Threatens Digital Trust Ahead of 2025 Elections


As the 2025 midterm elections approach, the Philippines’ digital landscape faces growing vulnerability to disinformation tactics from bad actors seeking to manipulate public perception. Amplifying this risk is the increasing use of artificial intelligence (AI), which introduces new levels of realism and precision that demand heightened vigilance, especially during major national events when public reliance on digital platforms surges.

There has been a surge in deepfake content in the country, with the Cybercrime Investigation and Coordinating Center (CICC) reporting that it monitors 200 to 300 deepfake incidents daily in the Philippines. In the lead-up to the elections, such sophisticated disinformation poses a serious risk to public trust and informed decision-making. Often integrated into broader social engineering campaigns, these tactics exploit trust and urgency to mislead individuals into sharing, believing, or acting on false information.

As Filipino voters prepare to head to the polls, Palo Alto Networks, the world’s leading AI cybersecurity company, shares practical recommendations to help individuals stay vigilant and protect themselves online amid heightened digital activity during the election period.

Evaluate Digital Content Critically. As AI-generated content online becomes increasingly sophisticated, voters should assess the credibility of sources and verify information across multiple trusted channels before engaging or sharing.

Be Cautious of Suspicious Messages. Phishing remains a top tactic for threat actors. Messages requesting personal details, containing strange links, or urging immediate action should raise red flags. Always verify the authenticity of these communications through trusted channels.

Secure Personal Accounts with Multi-Factor Authentication. Voters are advised to strengthen the security of their personal accounts by enabling multi-factor authentication. This extra layer of security helps prevent unauthorized access, identity theft, data breaches, or misuse of private information.

Verify Website Authenticity. Deceptive websites often impersonate official government platforms to mislead users. Always inspect web addresses, ensuring they use legitimate domains to avoid engaging with links from unfamiliar or unverified sources.

Adopt a Zero Trust Mindset. As AI-driven threats become more convincing, voters should treat every message, link, and request with caution. Verify authenticity before engaging and keep devices updated to reduce exposure to evolving risks.

“Election periods heighten digital activity and open the door to more sophisticated, AI-driven threats,” said Steven Scheurmann, Regional Vice President for ASEAN at Palo Alto Networks. “What’s different today is the precision, scale, and speed at which disinformation can spread. Deepfakes and phishing scams are no longer obvious or amateur — they’re targeted, realistic, and timed to exploit moments of national significance. In this environment, every voter becomes a potential target. Proactive cyber hygiene isn’t just about personal safety anymore; it’s about protecting democratic trust at scale. We all have a role to play in strengthening the integrity of our digital way of life.”

The election period puts additional strain on digital spaces where information is exchanged. With AI accelerating the speed and scale of online activity, distinguishing between legitimate content and manipulation becomes increasingly challenging—and increasingly important.

This period underscores the need for shared responsibility, where platforms, institutions, and individuals all play a role in safeguarding the integrity of digital spaces. In an online environment shaped by speed and sophistication, the ability to pause, assess, and respond wisely has never been more crucial.

Read More

Appdome Unleashes Most Comprehensive Mobile Bot Defense Profile for Industry Standard Web Application Firewalls

Mobile Bot Defense Profile


Delivers 400+ Defenses in a single MobileBOT™ Protection Profile to Turn Web Application Firewalls into Fraud-Fighting Machines

Appdome, the leader in protecting mobile businesses, today announced at RSAC 2025 that its AI-Native MobileBOT™ Defense solution now offers the most comprehensive mobile bot defense profile on the market. Capable of evaluating 400+ attack vectors in Android & iOS apps, OSs, devices, user interfaces and networks, Appdome’s new MobileBOT™ defense profile allows network security teams to not only stop brute force bot and credential stuffing attacks but also stop hyper targeted, spear phishing, account takeover (ATO), KYC fraud, on-device fraud (ODF), and deepfake threats in real time across account creation, login, password reset, payment and other critical API endpoints.

“Up until now, mobile bot defense has been about trying to stop brute force bot and credential stuffing attacks and inspecting the mobile device for 2-3 threat signals,” said Tom Tovar, co-creator and CEO of Appdome. “This isn’t enough. Mobile brands need to stop brute force attacks, for sure, but they also evaluate mobile device, OS, application, user interface and network level threats before allowing anyone to connect to their APIs.”

AI Has Changed Bot Defense Forever

Modern bot attacks aren’t contained to brute force bot and credential stuffing attacks launched from bot farms, automated scripts and similar attack vectors. Today, bot attacks can also include hyper-targeted ATO attacks that use AI-generated deepfake images, face cloning, liveness spoofing, and mobile Trojans to bypass biometric checks of specific users. These attacks can also be combined with client-side malware to intercept OTPs, complete Captcha challenges, hijack sessions, and exploit sensitive app flows like login, payment, and password reset. Some bot attacks weaponize the mobile app itself—evading traditional anti-bot defenses and putting user trust, compliance, and revenue at risk.

AI-Native Bot Defense is the Future

Appdome’s AI-Native MobileBOT™ Defense redefines mobile bot protection by providing multi-layered defense built for Android & iOS environments. While legacy bot defense SDKs aren’t protected in the app, use vulnerable cookies or JWTs to identify apps, and monitor only a few basic threat indicators such as emulators and jailbreak/root, Appdome’s MobileBOT™ Defense provides application-level rate limiting to eliminate the risk of weaponized and zombie applications, immutable application fingerprinting using secured client certificates to stop brute force attacks, and provides deep session risk, evaluating up to 400 configurable attack vectors in a single bot defense profile. With Appdome MobileBOT™ Defense, network security teams can stop brute force attacks and scan the mobile environment for any sign of deepfakes, social engineering scams, voice cloning, trojan attacks, vishing, remote access trojans (RATs), mobile device takeovers, and more before allowing a connection.

“Your bot defense strategy has to take AI into consideration,” said Gil Hartman, founding engineer and Field CTO of Appdome. “Brute force bot and credential stuffing attacks are one way the attacker guesses the user name and password of the victim. With AI, guessing gets really easy, really fast and your network and API defense have to be able to repel more sophisticated ATO threats.”

Tailored Profiles Stop Targeted ATO Attacks

Using a single MobileBOT™ Defense Profile, mobile brands and enterprises can evaluate up to 400+ attack vectors before allowing connections to any API, endpoint, or host. More importantly, network security teams can create separate defense profiles to address the specific threats applicable to each API. For example, network security professionals can evaluate different threats in each bot defense profile for:

Sign Up & Onboarding APIs - Detect the presence of fake users and devices signing up to your service including fake taps, clicks, swipes, gestures as well as fake location and devices.

Sign In & Password Reset APIs - Detect the presence of spyware such as keyloggers, overlay attacks, and activity monitoring, as well as ATO risk from deepfakes, ATS Malware and more.

Payment APIs – Detect the presence of data harvesting and trojan malware, MiTM attacks, session hijacks, OS compromises, vishing, social engineering scams and more.

“Tailored threat evaluation per API or host across 400+ threat vectors is huge,” said a leading industry analyst. “This level of deep inspection per API allows network security professionals to turn any Web Application Firewall into Mobile Fraud Fighting machine and get so much more out of their WAFs.”

Layered Defense to Stop All Mobile Bot Attacks

Appdome’s MobileBOT™ Defense solution is the only anti-bot solution purpose built for mobile applications, mobile environments and mobile businesses. Every feature of MobileBOT Defense is designed to address the unique computing environment, threat vectors and operating requirements of the mobile channel. Here are just some of the key elements of MobileBOT Defense by Appdome:

App-Level Rate Limiting – Leverages the compute on the mobile device to throttle API requests coming from “noisy,” malware controlled or zombie mobile apps.

Application Fingerprinting – MTLS Pre-Check authenticates the real app during the TLS handshake, allowing network security teams to deny API requests from bot farms, bot scripts and fake applications.

Extended Bot Defense Profiles – Evaluate session risk across up to 400+ separate threat vectors in mobile devices, OS, applications, user interface and networks to stop targeted ATOs, KYC Fraud and On-Device Fraud on a per API basis.

Pin to Host – Uses Appdome’s secure certificate pinning to validate the authenticity of servers your application is connecting to per API.

Dynamic API Updates - Remotely update protected hosts and endpoints without a new app release.

Zero-Trust and Dynamic Threat Evaluation – Allows network security professionals to control when threat evaluations are performed.

Hardened Implementation in Apps – Delivers tamper-proof anti-bot implementation in Android & iOS apps, free of spoofing, interception and compromise.

All Mobile App Compatibility – Works seamlessly with any Android or iOS app.

No-SDK, No Server Delivery - Eliminates integration work and infrastructure overhead, accelerating deployment and eliminating engineering work.

All Web Application Firewall Compatibility – Compatible with all industry standard WAFs; no change outs required.

“To protect Mobile APIs from bot and ATO attacks, you need a bot defense product that is purpose-built for the unique threats and challenges of your mobile app and business,” said Chris Roeckl, Chief Product Officer at Appdome. “You also need an anti-bot solution that works with all the Web Application Firewalls you have today and tomorrow, otherwise it just doesn’t work.”

With the MobileBOT release, Appdome now offers full flexibility for mixing and matching where and how to enforce mobile app protections. Mobile businesses can enforce these protections at the client app level, network layer, or a combination of both. Whether stopping brute force bots or user-level targeted fraud, Appdome’s layered defense model ensures optimal protection and performance.

Appdome’s MobileBOT Defense requires no SDKs, no servers, and no changes to existing WAF infrastructure, bypassing the limitations, complexity and cost of traditional anti-bot products. By working with any WAF, businesses can preserve and extend their WAF investments and, with client-side rate limiting, can dramatically lower data processing costs.

Appdome is demonstrating the AI-Native MobileBOT Defense solution and the full Appdome AI-Native Platform at RSAC in San Francisco at booth South-0948.

To learn more about AI-powered bot protection for mobile apps, you can request a personalized demo at www.appdome.com/mobilebot-defense.
.
Read More

DoubleVerify Expands Its AI-Powered Brand Safety & Suitability Offering for TikTok to Include Pre-Bid Video Controls

Monday, April 28, 2025




Global brands can access automated pre-bid video exclusion lists to protect brand equity and maximize ad performance on TikTok

DoubleVerify (“DV”) (NYSE: DV), a leading software platform for digital media measurement, data and analytics, today announced the launch of pre-bid video exclusion lists for TikTok—expanding the company’s footprint of trusted, independent brand suitability and media performance tools on the platform. This release will allow advertisers to proactively avoid content they deem objectionable before their ads are served, maximizing media quality, campaign performance and advertising ROI.

“We’re excited to launch DV’s pre-bid video controls on TikTok, empowering advertisers to enhance both the impact and quality of their campaigns,” said Mark Zagorski, CEO of DoubleVerify. “Powered by DV’s industry-leading, AI-driven classification technology, this solution helps advertisers ensure that ads appear in environments that align with their brand settings—driving stronger engagement, maximizing ad performance, and instilling greater confidence in their digital investments.”

With this release, advertisers will benefit from:

Comprehensive Coverage: Combine DV’s pre-bid controls with post-bid reporting to ensure end-to-end campaign measurement and optimization.

Operational Efficiency: Benefit from pre-bid activation that requires no manual upkeep and auto-refreshes in near real-time, ensuring seamless, always-on protection.

Enhanced Performance: Ensure ads do not appear next to objectionable content, reducing media waste and maximizing advertising ROI.

DV’s solution is powered by its proprietary, AI-powered Universal Content Intelligence™ classification engine. DV analyzes video, image, audio, and text elements to deliver superior content classifications at scale. Its innovative key frame extraction method is a smarter and faster way to analyze video content. Instead of examining each video frame, which can be repetitive and time-consuming, key frame extraction focuses only on the most important moments where changes happen. This streamlined approach uses less computing power and reduces environmental impact––ensuring an efficient, quicker, and more accurate analysis of campaigns, without sacrificing quality or precision.

DV’s automated pre-bid video controls and reporting insights are activated through DV Pinnacle®, the company’s unified service and analytics reporting platform, enabling advertisers to monitor and optimize their TikTok ad campaigns.

Additionally, DV is enhancing its TikTok dashboard in DV Pinnacle®, equipping brands with greater transparency into ad delivery and deeper insights for campaign optimization. Launching in the coming months, these updates will introduce top-level pre-bid filtering, enabling brands to analyze reporting specifically for campaigns with pre-bid controls, along with content previews for flagged incidents—empowering advertisers with more actionable intelligence.

For more information about DoubleVerify, visit http://www.doubleverify.com.
Read More

To Thrive, Not Just Survive: The Need to Accelerate Digital Transformation in Southeast Asia’s Insurance Industry


How Insurtechs like Igloo are driving digital transformation and expanding access to coverage

Southeast Asia’s insurance industry is at a crossroads. Despite rapid economic growth and rising demand for financial protection, insurance penetration remains low. In fact, in many countries like the Philippines, it remains at 1.78%, while countries like Vietnam are at 2.8% and Indonesia is at 1.4%.

One of the biggest barriers in the industry is its continued reliance on outdated legacy systems, which create inefficiencies in underwriting, claims processing, and customer management, driving up costs and making insurance inaccessible to many. The region’s fragmented market, made up of numerous small, independent insurers, further complicates digital transformation efforts, leaving the industry ill-equipped to meet evolving consumer expectations.

“Unlike global insurance powerhouses that invest heavily in digital ecosystems, Southeast Asia’s insurance market remains highly fragmented. Many insurers operated independently, lacking the scale to afford large-scale technological upgrades,” said Raunak Mehta, Igloo’s Co-Founder and CEO. “As an insurtech that has been in the industry for almost a decade, Igloo has seen how shifting to digital is not an option anymore–it’s a necessity. Without it, the industry risks falling further behind and leaving millions of underserved individuals without access to affordable coverage. An accelerated digital transformation is the key to bridging this gap, enabling insurers to offer innovative products and improve accessibility for the growing middle class in Southeast Asia.”

Modernizing insurance processes end-to-end

Igloo, a regional insurtech leader with over 650 million policies facilitated and more than 75 partnerships, offers innovative embedded insurance solutions that seamlessly integrate insurance into core business products. This simplifies policy applications, purchases, and claims management, reducing friction for providers and distributors while streamlining underwriting and claims processing to make the system more efficient, user-friendly, and accessible to a broader audience.

Igloo partners with major online platforms like Lazada and Shopee, payment services such as GCash in the Philippines to develop customized insurance products that integrate into their digital ecosystems. It also collaborates with telecom companies like Smart, consumer finance platforms like Skyro and Salmon, and B2B MSME enabler Growsari in the Philippines to expand access to insurance across various sectors. This frictionless model simplifies the purchasing process, improving conversion rates and appealing to customers who may not have considered insurance otherwise.

Meanwhile, Igloo’s Ignite platform streamlines the sales process for intermediaries, offering a user-friendly interface, a quick quote system, secure payment processing, and real-time referral fee tracking. With 42 products across nine categories, Ignite has expanded to Vietnam, Indonesia, and the Philippines, and was awarded Mobile App of the Year - Vietnam at the Insurance Asia Awards 2024.

The next step to digitalization? Leaving legacy systems behind

“But beyond this, we see immense value in helping insurers of all sizes fully embrace digital transformation by evolving their systems to become more agile and customer-centric,” said Mehta.

Igloo is helping the industry move away from legacy systems by introducing modular, no-code platforms that enable businesses to scale efficiently, reduce operational complexities, and enhance customer experiences. This way, Igloo empowers insurers to digitally define their underwriting rules, set up sales and operational processes, and launch products through the appropriate distribution channels. They can then monitor performance and identify areas for improvement. From creating their insurance marketplaces to seamlessly embedding products with retail partners' platforms, and improving agent-driven insurance sales, Igloo is reshaping how insurance can be delivered in a modern, scalable way.

“At the end of the day, our role as an insurtech is not only to facilitate digitalization but also to enable insurers to thrive in this era of digitalization. By adopting scalable technologies, insurers can simplify operations, expand their reach, and provide value to customers in ways that traditional systems simply couldn’t,” Mehta added.

Learn more about Igloo’s products and solutions by visiting iglooinsure.com.
Read More

How AI’s growing influence is driving gender-inclusive financial innovations in the Philippines

Thursday, April 24, 2025

gender-inclusive financial innovations in the Philippines

The Philippines is at a critical juncture in its expansion into a thriving digital economy. With an increasing demand for connectivity, the country confronts a lack of digital infrastructure for essential financial services. Filipinos continue to face barriers to financial inclusion, where gender parity issues exist, and a significant segment of the population remains unbanked or underserved by traditional financial institutions.

The 2020 pandemic was a turning point in the country’s digital transformation. According to available data, an estimated 29% of the population was considered unbanked or underbanked in early 2020. Moreover, 23% had access to insurance, only 2% had access to formal credit during this period, and only 1% had access to investments.

GCash, the Philippines’ leading finance super app and largest cashless ecosystem, has been instrumental in breaking these barriers to inclusion. It began by enabling access to the marginalized who do not have traditional documentation or credit history.

“At GCash, we addressed inclusion barriers using tech-enabled and data-driven solutions guided by customer-centricity,” said Martha Sazon, president & CEO of Mynt, the holding company of GCash, during the 2025 World Economic Forum in Davos. “Our approach is centered on making products accessible, relevant, and simple, so we can work toward ensuring that no one is left behind.”

Levelling the playing field and unlocking opportunities

With millions of users, GCash pursues its vision of “Finance For All” by providing Filipinos, regardless of gender, background, or socioeconomic standing, with access to an e-wallet, loans, investments, and insurance coverage, as well as financial support for micro, small, and medium enterprises.

For the predominantly women-led fintech company, pursuing this mission involves dedicated efforts to equip women with the digital tools to make informed financial decisions, invest in their future, and ultimately achieve financial independence. Sazon shared, “Our goal of Finance For All is inextricably linked to nation-building in the Philippines. We know this cannot be achieved without women’s inclusion, as we have seen that women's empowerment leads to uplifting communities.”

Today, five out of ten GCash users are women. Addressing the nuanced nature of personal finances, GCash also goes beyond basic services to support Filipinos through a comprehensive digital ecosystem that caters to their diverse needs.

AI as a bridge to gender-inclusive finance

GCash attributes a significant part of its progress as an enabler of financial inclusion to artificial intelligence (AI). A user’s integration into the GCash ecosystem starts with an AI-powered onboarding process. GCash was the first to use the eKYC (electronic Know Your Customer) process in the Philippines, scaling market penetration while using alternative data.

“Fifty percent of our population doesn’t have documents,” said Sazon. “How do we address that? We use AI to score them instead. Those who use the GCash app to make payments and transactions [can be scored]. Now, millions [can] get a credit score without relying on documents or showing collateral.”

AI has also enabled GCash to personalize its services to already onboarded users, helping analyze each user’s needs, custom-tailoring outreach, and providing individualized financial solutions ranging from microloans for small businesses to flexible investment opportunities and affordable insurance coverage.

Creating opportunities for women to pursue their financial goals is another way AI boosts gender-inclusive financial empowerment in the Philippines. Today, five out of 10 GSave and GLoan users are women, while seven out of 10 GInsure users are women. Notably, GCash is also able to accelerate inclusion through its groundbreaking features like GScore, GCash’s proprietary credit scoring system that determines a user’s creditworthiness using AI and a person’s in-app activity.

“[Users] might not have the traditional requirements, but they have a digital footprint,” cited Rowie Zamora, Chief Strategy Officer of GCash, at a WEF 2025 panel hosted by Deloitte.

“This has enabled us to unlock over USD 2 billion for microloans to 7 million Filipinos in the past several years,” she added. “That’s quite huge in a country where credit penetration has been in the low digits. Before the pandemic, only one percent of Filipinos had access to credit.”

Using AI to scale positive impact

For organizations like GCash, taking a people-centric approach to AI is key. It uses AI to enhance customer experience, streamline operations for greater efficiency, and preserve consumer trust in the digital finances space, as it offers alternatives that mitigate systemic barriers to financial inclusion, particularly for unbanked and traditionally underserved communities. Ultimately, these innovations aim to create a more inclusive and equitable financial system for all individuals.

GCash has also leveraged AI to create customer affinities that offer a deeper understanding of the market, paving the way for hyper-personalization that addresses a user’s needs with better precision. Through customer affinities, each user isn’t considered just a part of a demographic but is treated as their very own market segment. This approach has allowed GCash to scale its initiatives, from promoting financial literacy to supporting women-owned and women-led MSMEs.

The individualization of GCash’s suite of innovative in-app enablement platforms has allowed it to address financial concerns specific to Filipino women, who make up more than half of today’s social sellers who use cashless payment solutions.

“Each step toward financial inclusion is a step toward accelerating Filipino women’s economic empowerment,” concluded Sazon. “This month especially, we bear in mind what was reported by the World Economic Forum: that we stand to achieve full gender equality only in the year 2158 if we maintain our current pace. We at GCash feel the urgency now more than ever and aim to further utilize AI as tech for good.”
Read More

DoubleVerify Extends Gaming Measurement Suite Through Strategic Partnership with Roblox

Saturday, April 12, 2025

In the last decade, the gaming industry has exploded. With at least one-third of the global population playing digital games at least once per month, gaming provides advertisers with a highly engaged audience. Because of this, popular gaming platforms, like Roblox, are rapidly gaining advertiser attention due to their large user base and ability to reach them when they’re paying attention, helping drive campaign effectiveness.

However, a crucial component of achieving campaign effectiveness is ensuring advertisers are buying high-quality media and tracking performance across a variety of metrics. That’s why DV has offered coverage on gaming inventory for years. To further this mission, DV is partnering with Roblox to extend our trusted media quality and performance solutions across their inventory.

Advertising on Roblox

Roblox is an immersive gaming and creation platform. Attracting over 85 million active users daily, the platform offers a suite of advertising solutions that allow advertisers to reach their highly engaged Gen Z audiences across devices. Roblox offers a variety of immersive ad formats to help advertisers reach Roblox gamers wherever they are within the platform.

DV Coverage on Roblox

This partnership offers advertisers coverage across all of Roblox’s advertising inventory globally. This inventory includes Billboard image ads — otherwise known as display — and video ads, which serve in in-game environments. It also includes Rewarded Videos, which will soon appear in high-traffic environments such as menus and stores. DV’s coverage also spans across device types such as mobile, desktop, and console.

In-game Billboard Image and Video Inventory Coverage

DV has extended coverage of our trusted fraud/IVT and viewability measurement solutions via a custom integration on Roblox’s direct-sold inventory. These solutions can help ensure that these ad formats are seen by real people.

Rewarded Video Coverage

Advertisers will be able to leverage DV’s measurement solutions, which include media quality and performance. Specifically, this coverage allows advertisers to measure fraud, brand safety and suitability, viewability, geo-relevance, and attention with DV Authentic Attention® leveraging DV’s tags. Advertisers will also be able to protect their campaigns leveraging DV’s fraud, viewability, and brand suitability pre-bid solutions.

Brands can leverage DV’s offerings to better align their campaigns with their unique media quality and performance standards across Roblox campaigns and beyond to make more informed media investment and optimization decisions.
Read More

ManageEngine Expands Its Integration Network With 100+ Prebuilt Integrations for Enterprise Identity Management

Friday, April 4, 2025


The Company's IAM Platform, AD360, Helps Converge Disconnected Identities

  • ManageEngine AD360 expands its integration support, with 100+ new ready-to-use integrations
  • These integrations empower enterprises for seamless, scalable identity management across diverse IT applications
  • Explore the complete lineup of integrations available in AD360 at https://mnge.it/ad360-marketplace

ManageEngine, a division of Zoho Corporation and a leading provider of enterprise IT management solutions, today announced that AD360, its identity and access management (IAM) platform, is further expanding its integration offerings, by adding over 100 new prebuilt integrations. This expansion is a decisive step in the company's endeavor to strengthen its converged IAM platform capabilities. In addition to the extension of support to popular HRMS, ITSM, SIEM, and other enterprise applications, AD360 also comes with REST API capabilities for custom integration with third-party and in-house applications.

Why This Matters: The Enterprise Perspective

Large enterprises today face a major challenge: managing various tools with widespread, fragmented data. In a press release titled "Gartner Identifies the Top Cybersecurity Trends for 2025" (issued March 3, 2025), Gartner® highlights a common challenge for large enterprises: the need to optimize their cybersecurity toolsets for efficiency and security while balancing selections for an average of 45 cybersecurity tools available from over 3,000 vendors.

Although enterprises often operate in multi-vendor IT environments out of necessity, this is an added complexity that leads to fragmented identities, resulting in delays in access and increased IT overhead. For example, Gartner’s 2024 IAM Leadership Survey found that 54% organizations have seen an increase in the number of identity-related breaches, with one in three organizations experiencing increased business interruptions, financial loss or regulatory penalties from such incidents. As many as 85% of identity-related breaches can be attributed to hacked machine identities such as service and automation accounts. Additionally, according to Verizon's 2024 Data Breach Investigations Report, around 31% of all breaches since 2013 involve stolen credentials.

With global compliance laws and regulations requiring organizations to maintain accurate and up-to-date identity and access data at all times, keeping these records updated is critical. Seamless integration of identities is no longer just an IT challenge for enterprises; it's a business imperative.

"Our vision is to eliminate identity fragmentation and radically simplify enterprise identity governance," said Manikandan Thangaraj, vice president at ManageEngine. "With AD360’s expanded integrations, we're empowering businesses to build truly unified digital ecosystems. With this release, we want to help our customers transform identity management from an operational burden into a strategic enabler of productivity, agility, and security. Now, a hospital can auto-provision clinician access in Epic EHR the same day they’re hired in Workday, with no coding and no delays."

Enabling Business Agility with Seamless Integrations

ManageEngine AD360's integrations leverage industry-standard protocols—including SCIM, SAML 2.0, OpenID Connect (OIDC), OAuth 2.0, and REST APIs—ensuring seamless compatibility across diverse IT ecosystems. Through an intuitive no-code configuration interface, IT teams can effortlessly establish connections and design automated workflows without specialized programming knowledge, dramatically accelerating implementation timelines from months to mere days.

ManageEngine's extensive integration network for identity access management enables:

Accelerated Value Realization: Enterprises can quickly integrate and automate identity workflows, reducing operational costs, minimizing errors, and enhancing productivity through unified life cycle management and real-time identity synchronization.

Strategic Flexibility and Choice: Maintain the freedom to integrate with a vast range of enterprise applications without vendor lock-ins, ensuring compatibility, scalability, and support for diverse business needs.

Advanced Identity Automation: With businesses seeking productivity improvements, AD360 can implement sophisticated, no-code identity orchestration processes to automate critical activities such as user provisioning, access modifications, identity synchronization, and secure offboarding across a company's identity ecosystem.

Zero-Gap Compliance: Automatically align identity records across HR, IT, and security systems to pass audits for the GDPR, HIPAA, and SOX.

"The interoperability between critical business applications streamlines processes such as onboarding and offboarding, delivering measurable business value and accelerating ROI. Legacy IAM tools often treat integrations as an afterthought, requiring months to integrate an organization's IAM tech stack with ITSM or HCM tools. AD360 helps accomplish this with just a few clicks. It's not just about connecting systems—it's about fundamentally changing how enterprises manage identities while minimizing security risks," Thangaraj stated.
Read More

2025 Unit 42 Global Incident Response Report Reveals Nearly 44% of Security Incidents Involved a Web Browser

Tuesday, April 1, 2025


Palo Alto Networks, the global cybersecurity leader, has released the 2025 Unit 42 Global Incident Response Report, which found that threat actors are now evolving their tactics, moving beyond traditional ransomware and data theft to focus on business disruption, AI-assisted attacks, and insider threats. According to the report, almost half of the security incidents (44%) involved a web browser.

In the Philippines, industry players are taking a more proactive approach to building a security framework for digital resilience. The Department of Information and Communications Technology (DICT) reports that government agencies, academic institutions, and telecommunications companies remain prime targets for cyber criminals, with 10% of attacks targeted at the banking and healthcare sectors.

Recognizing the urgent need for stronger cybersecurity measures, key institutions such as the country’s Central Bank are working to establish a targeted cyber resilience council to protect financial infrastructure.

As financial institutions, healthcare providers, and government agencies across the globe face an unprecedented cyber threat landscape, regional regulators are strengthening Zero Trust frameworks, adopting AI-powered security solutions, and enforcing stricter compliance measures.

The shift from financial extortion to full-scale business disruption means enterprises must rethink their cyber defenses before an attack happens, particularly in sectors that rely on cloud and third-party vendors.

The 2025 Unit 42 Global Incident Response Report, which analyzed hundreds of major cyber incidents, aims to highlight how the increased sophistication of malicious actors is amplifying the challenges faced by businesses worldwide.

Key findings of the 2025 Unit 42 Global Incident Response Report include:

Operational Disruption as a Primary Goal: Attackers are prioritizing sabotage over data theft, aiming to cripple businesses and maximize extortion. In 2024, 86% of incidents led to operational downtime or reputational damage.

Surge in Insider Threats Linked to North Korea: Cases tripled in 2024, with operatives targeting contract-based technical roles at major tech firms, financial services, media, and government defense contractors. Advanced techniques, including hardware-based KVM-over-IP devices and Visual Studio Code tunneling, make detection more challenging.

Accelerated Data Exfiltration: Attackers are exfiltrating data three times faster than in 2021, with 25% of cases seeing data stolen within five hours, and nearly 20% occurring in under an hour.

Expanded Attack Surfaces: 70% of incidents involved three or more attack vectors, underscoring the need for comprehensive security across endpoints, networks, cloud environments, and human vulnerabilities. Web browsers remain a weak link, facilitating 44% of attacks via phishing, malicious redirects, and malware downloads.

Phishing Resurges as Top Entry Point: 23% of attacks began with phishing, overtaking vulnerabilities as the leading attack vector. GenAI has made phishing campaigns more scalable, sophisticated, and difficult to detect.

"Cyber criminals targeting organizations in the Asia-Pacific and Japan region are no longer just stealing data, they are actively taking down entire operations,” said Philippa Cogswell, Vice President and Managing Partner, Unit 42, Asia-Pacific & Japan, Palo Alto Networks. "Traditional approaches to cybersecurity are no longer sufficient in addressing the visibility gaps and complexity challenges that organisations face today. To stay ahead of evolving threats, businesses must adopt AI-driven, automated security solutions that can outpace adversaries and provide comprehensive real-time protection."

“As cyber threats in Asia-Pacific evolve from data theft to full-scale operational disruption, it is crucial for organizations to reassess their cybersecurity strategies, and shift from fragmented approaches towards a unified security approach that prioritizes real-time threat detection, rapid response, and actionable threat intelligence,” said Steven Scheurmann, Regional Vice President, ASEAN, Palo Alto Networks. “In the Philippines, where critical sectors like finance, healthcare, and government are increasingly reliant on digital infrastructure, building cyber resilience requires not only advanced technological capabilities but also a deeper and stronger collaboration between public and private stakeholders to safeguard the nation’s digital future.”

Data for this report was sourced from more than 500 cases Unit 42 responded to between October 2023 and December 2024, as well as from other case data going back to 2021. The affected organizations were headquartered in 38 unique countries, including the U.S. and those based in Europe, the Middle East, and Asia-Pacific.

Read More
...