You will soon receive an email with a link to confirm your access, or follow the link below.
You may now close this message and continue to your article.
Since we launched this report seven years ago, we’ve seen the percentage of companies that suffered a mobile compromise trend steadily upward, from less than 30% in 2018 to more than half (53%) today. Some of this increase is related to the expanding attack surface. As mobile and IoT devices are embedded into all types of workflows, the sheer number of devices and apps that businesses rely on snowballs (as do the risks).
At the same time, alongside device numbers, awareness of mobile-specific security risks has also grown. Many people once thought that mobile devices were inherently more secure than desktop or laptop computers. Not anymore. A large majority of respondents (85%) now recognize that mobile device threats are on the rise, and more than half of those surveyed have experienced security incidents firsthand.
of respondents say risks from mobile device threats have increased in the past year.
believe they are at significant or extreme risk from mobile device threats.
have experienced mobile app-related incidents from factors such as malware or unpatched vulnerabilities.
For business users and consumers, 2023 was a record-breaking year for mobile threats. More zero-day vulnerabilities were discovered in iOS than ever before. The risky data collection policies used by popular apps such as TikTok and PinDuoDuo were on public display, while 75% of organizations experienced mobile phishing attempts targeting their employees.9
of mobile phishing attacks against technology company employees in 2023 were successful.10
of mobile phishing attacks against the financial sector succeeded.11
of mobile phishing attacks targeting media and communications companies succeeded.12
More than 260 iOS Common Vulnerabilities and Exposures (CVEs) were published in 2023. Because so many mobile device operating systems aren’t updated as often as they should be, the data and personal information stored on or accessible through them remain susceptible to exploits for extended periods of time. And the number of attacks that exploited vulnerabilities as the critical path to initiate a breach nearly tripled (a 180% increase) in 2023 compared to the prior year.14 Some of this growth is due to enormously successful widespread campaigns, such as the Cl0p ransomware gang’s exploitation of the MOVEit file transfer tool, which ultimately impacted millions of victims.15
A vulnerability in a video codex library used by Chrome, Firefox and Firefox Focus for Android.
A vulnerability in the 2D graphics engine for Google Chrome, Chrome OS, Android and Microsoft Edge.
A zero-day vulnerability in the V8 JavaScript engine of Chromium impacting versions of Google Chrome and Microsoft Edge mobile browsers.
A group of vulnerabilities, some impacting Samsung devices and others affecting all Android devices.
A vulnerability in Chrome for Android’s WebP image format. A similar image processing vulnerability, BlastPass, has been exploited to deliver spyware.
Our ongoing reliance on mobile devices and rapid increase in IoT use generates opportunities for attackers to take advantage of key vulnerabilities, including as-yet-undiscovered zero-day attacks.
The vast majority of respondents (93%) express concern about mobile cybersecurity risks. Nonetheless, a minority (39%) have defined organizationwide IoT standards, and even fewer (37%) said their organizations centrally coordinate IoT projects.
Defining and adhering to cross-organizational standards is crucial to helping ensure IoT devices and sensors can keep up with evolving security and regulatory requirements. With enormous variability in device capabilities, use cases and risks, it’s important to set technical and non-technical standards for each IoT project across every business unit.
of respondents believe a security breach could severely impact the business’s operations.
have defined IoT standards.
centrally coordinate IoT projects.
Aaron Cockerill, Executive Vice President of Product & Security, Lookout
Data is the currency of modern enterprises. Establishing a strong data security strategy is not only a critical defense measure, but also a strategic business enabler.
In years past, organizations had dedicated private data centers, housing multiple servers, network equipment and storage devices. These setups not only presented scalability issues, but required continuous hardware and software upgrades to accommodate rising data needs. If not well maintained, this infrastructure is also highly susceptible to malware and vulnerability-based attacks.
Today, a majority of corporate data resides in the cloud across an increasing number of software-as-a-service (SaaS) and private apps. While this infrastructure is better maintained, making network bugs less of a concern, critical corporate data is also more widely distributed. This distribution presents other challenges, such as the risk of system misconfigurations, as sensitive data flows across an expanding set of apps.
With more corporate data residing in the cloud, we’re seeing a shift away from traditional malware and vulnerability attacks. Because cloud infrastructure is better maintained, the return on investment for traditional exploits has diminished. In response, threat actors have changed their Tactics, Techniques and Procedures (TTPs), to focus on leveraging social engineering, targeting a user’s mobile phone to steal credentials and impersonate users. With credentials in hand, they have immediate access to critical corporate infrastructure and sensitive data. We refer to this change in TTP strategy as the modern kill chain.
To illustrate, consider recent high-profile attacks: MGM Resorts, Caesars Entertainment and Twilio. In each instance, the threat actor group known as Scattered Spider used the phishing kit Oktapus to social engineer via mobile devices. In another example, the Lookout Threat Intel team discovered a similar phishing kit, CyptoChameleon that has been used by what was likely a different group of threat actors to target the FCC, Coinbase, Google, Microsoft and other organizations.
If a phishing attack is successful and a threat actor is able to get login credentials, the subsequent steps in the modern kill chain move rapidly. With direct access to an organization’s cloud infrastructure, the attack dwell time has gone from months to minutes. This also brings severe repercussions for individuals, who are at risk of identity theft, along with the organizations that are required to safeguard sensitive data. Defending against rapid modern attacks requires organizations to have clear visibility and automated response capabilities, both at the mobile endpoint and across their SaaS and private applications.
of mobile users tapped on at least one phishing link every quarter in 2023.19
9 Lookout, Mobile Threat Landscape Report, 2023.
10 Akamai, The Increased Use of Mobile Devices Expands the Threat Landscape, 2023.
11 Ibid.
12 Ibid.
13 Ibid.
14 Verizon, Data Breach Investigations Report, 2024.
15 Ibid.
16 Lookout, Mobile Threat Landscape Report, 2023.
17 NIST, NIST Cybersecurity for IoT Program, Create a Profile Using the IoT Core Baseline and Non-Technical Baseline, 2020.
18 Ibid.
19 Lookout, Mobile Threat Landscape Report, 2023.