Describe how devices become cybersecurity threats

You’ve learned that devices are all around us, and that they hold all kinds of personal information. Also, you’ve seen that cybercriminals target devices to get their hands on this information. But how do they do this?

Devices as threat vectors

While devices help us to get our work done, and go about our daily lives, they also present opportunities to cybercriminals who want to cause harm. This is because they’re threat vectors—they provide different ways in which cybercriminals can carry out attacks. For example:

  • Phone, laptop, or tablet – downloading a malicious app might result in the device being contaminated with malware that can exfiltrate sensitive data stored locally, without the user’s knowledge. This compromises confidentiality and integrity because the cybercriminal can now view or modify the data.
  • USB drives – cybercriminals can put malicious software or files on a USB drive and insert it into a device like a laptop. The drive could, for example, run ransomware, meaning the availability of the data has been compromised because it’s locked in return for a ransom.
  • Always-on home assistant devices – these devices are always listening or watching. A cybercriminal can put malicious software on the app stores for these devices. If a user then installs it, the cybercriminal could, for example, attack the device with spyware to secretly record information, and compromise data confidentiality. They could also move laterally to other home devices, and compromise their data.
  • QR codes – attackers can create fake QR codes that direct your phone to a malicious website when scanned. These fake codes might appear in emails, on printed posters, or even placed over legitimate ones in public spaces. Because your phone opens the link automatically, QR code attacks can bypass the email security tools that normally detect suspicious links. Always preview the URL before visiting it, and treat QR codes from unknown sources with the same caution as any suspicious link.

Biometric Attendance System Malaysia