According to industry expert Sergey Kondratenko, as financial technologies continue to develop, new threats to cybersecurity arise. Referring to the current statistics, Sergey Kondratenko states that on average 97 cybercrimes are committed in the world per hour. By forecasts, by the end of 2023, losses from cybercrime will be $8 trillion, almost a third more than the US GDP and twice the projected GDP of India.
The topic of threats and cybersecurity in the Internet space is quite relevant. Therefore, Sergey Kondratenko believes that it is necessary to pay attention to the main types of cyber attacks and methods of combating them.
Sergey Kondratenko is a recognized specialist in a wide range of e-commerce services with experience for many years. Now, Sergey is the owner and leader of a group of companies engaged not only in different segments of e-commerce, but also successfully operating in different jurisdictions, represented on all continents of the world. The main goal is to drive new traffic, create and deliver an online experience that will endear users to the brand, and turn visitors into customers while maximizing overall profitability of the online business.
Sergey Kondratenko: main types of cyber threats and their impact on FinTech
Sergey Kondratenko identifies three main types of cyber threats:
1. Identity theft and phishing
Phishing attacks are the most common type of cyberattack. Every day, cybercriminals send about 3.4 billion spam messages for the purpose of phishing attacks. Such attacks are responsible for 90% of data leaks.
Fintech companies receive a large amount of personal and financial data from their users: credit card information, bank account numbers, verification data, says Sergey Kondratenko. He says this turns their databases into a veritable hacking pit.
Hackers steal or hack credentials and impersonate account holders to gain access to their personal (often sensitive) information and steal money. This usually happens through API attacks aimed at compromising authorization tokens.
Therefore, having a reliable authenticator becomes an integral part of the security policy of fintech companies.
2. Distributed denial of service attacks (DDoS attacks)
A distributed denial of service (DDoS) attack is a malicious attempt to disrupt the normal functioning of a network, service, or website by flooding it with Internet traffic.
According to Sergey Kondratenko, such an attack is aimed at disrupting or disabling the resources and infrastructure of the target of the attack.
According to statistics in 2022, Microsoft prevented an average of 1,435 DDoS attacks every day. According to a report published by Cloudflare, DDoS ransom attacks in 2022 increased by 67% compared to the previous year. A significant increase in DDoS attacks at the application level is observed in the online industry: it increased by 300% over the year.
The expert emphasizes that DDoS attacks are incredibly dangerous for fintech companies, since many APIs are simply not equipped with rate limiters. And this is understandable, because they significantly reduce the frequency, number of user requests or IP addresses. But on the other hand, such rate limiters help counter distributed DDoS attacks.
3. Ransomware and malware attacks
Another significant threat to fintech companies is malware and ransomware attacks.
By data for 2023, 300 thousand new instances of malware are generated daily, 92% of which are distributed via email. Malware is used to gain unauthorized access to IT systems, steal data, disrupt system services, or cause damage to IT networks. 4.1 million websites are infected with malware. Moreover, 18% of them contain critical cybersecurity threats.
– Ransomware attacks, in turn, are a type of malware that encrypts the victim’s files and demands payment of a ransom in exchange for a key to decrypt them, explains Sergey Kondratenko.
He believes fintech companies are particularly vulnerable to such attacks because they often store large amounts of sensitive data, including customer financial information.
Sergey Kondratenko: the most high-profile cyber attacks that shook the whole world
Cybersecurity does pose a serious systemic risk to the FinTech sector. Sergey Kondratenko believes that it is very important to consider a brief overview of some of the most significant cyber attacks in history.
- Yahoo. In September 2016, Internet giant Yahoo became the victim of the largest data leak in history. The company said the attack compromised the names, email addresses, dates of birth and phone numbers of 500 million users. A few months later, it became known that another group of hackers had hacked 1 billion accounts.
- Marriott. The hotel empire has discovered a security breach for its Starwood Hotel brand. The hack was only discovered in 2018, but the theft is believed to have taken place four years earlier. The hacker successfully copied more than 5.2 million unencrypted passport numbers and 380 million booking records. Another 8.6 million encrypted credit card numbers and 20.3 million encrypted passport numbers were stolen. The damage caused by the hack is one of the largest in the history of online thefts.
- Equifax. In September 2017, one of the largest US credit bureaus discovered that personal information, including Social Security numbers, dates of birth, addresses and, in some cases, driver’s license numbers, had been compromised.
In 2020, the Justice Department indicted four Chinese military hackers for hacking into the computer networks of the credit reporting agency Equifax and stealing the personal information of tens of millions of Americans.
Such examples indicate the need to constantly strengthen cybersecurity measures in FinTech and the financial industry as a whole, Sergey Kondratenko is sure.
Cybersecurity in FinTech: effective technologies and methods of protection
Implementing a cybersecurity system is an effective way to protect fintech companies from cyber threats. A cybersecurity framework is a set of best practices and recommendations for managing cybersecurity risks. Sergey Kondratenko suggests considering well-known cybersecurity practices for the FinTech industry
- It is necessary to implement reliable means of authentication, to ensure that only authorized personnel have access to confidential information. This may include two-factor and biometric authentication, as well as password policies that require regular updating and complexity.
– Two-factor authentication (2FA) is a security method that requires a user to provide two different ways to verify their identity before gaining access to a specific account, system, or service. This method adds an extra layer of protection, explains Sergey Kondratenko.
Biometric authentication uses a person’s unique biological and physiological characteristics to verify their identity. Instead of passwords or PIN codes, fingerprints, retinal scanning, face, voice or palm recognition are used.
- Ensuring secure data storage both in-house and through third party providers.This is done by using an encryption method for sensitive information and implementing access controls to limit it to authorized employees.
Sergey Kondratenko explains that encryption is the process of converting data into a form incomprehensible to humans using a special mathematical algorithm. This cybersecurity method ensures data confidentiality.
Fintech companies are becoming increasingly vulnerable to cybersecurity threats, from social engineering to extortion. To combat these threats, Sergey Kondratenko recommends training employees and clients on cybersecurity best practices, keeping software up to date, implementing strict access controls, and managing risks with a cybersecurity system.




























































































