HabrJuly 24, 2026🇷🇺Translated from Russian

Protecting C-Suite Leaders: Defending Executives Against Targeted Cyberattacks

Twelve percent of all registered data leaks in Russia begin with an attack on top management, according to PT EdTechLab. Company owners and C-level executives combine the highest levels of access and trust with, in many cases, relatively careless attitudes toward basic cyber hygiene. Public visibility can further increase the appeal for attackers.

Three main scenarios require preparation. The first is targeted phishing, also known as whaling. Attackers research the victim through interviews, communication style, and daily routines, then send a convincing, urgent message. Classic vectors include plausible instructions, sometimes delivered via deepfakes, that appear to come from the CEO requesting a funds transfer or immediate access grant.

Recommended defenses include training staff to recognize manipulation, running phishing simulations that impersonate senior leaders (especially for assistants, secretaries, and finance teams), enforcing multi-factor authentication everywhere, configuring anti-spoofing protections on the corporate mail domain, and using more secure channels than standard messengers for high-value approvals.

The second scenario involves compromise of personal devices. Executives frequently merge personal and corporate use on a single laptop or smartphone. Malicious attachments, public Wi-Fi, and outdated applications become entry points that bypass hardened corporate perimeters.

Mitigation steps include issuing dedicated corporate devices or deploying mobile device management solutions, enforcing VPN use outside the office, applying updates without exception, installing EDR agents on all executive endpoints including mobiles, and subjecting these devices to the same monitoring and control as the rest of the infrastructure.

The third scenario is account compromise. Weak or reused passwords are cracked through brute force or discovered in third-party breaches. SIM swapping adds another vector. Once one account falls, attackers often pivot to email, cloud services, corporate systems, and financial platforms.

Key countermeasures start with multi-factor authentication and rigorous password management that enforces complexity, uniqueness, and regular rotation. A dual-account model—one for routine work and another for critical operations—further reduces exposure. The principle of least privilege must apply to everyone, including the CEO, with access rights limited in both scope and duration.

Even comprehensive controls cannot eliminate risk entirely. Organizations should therefore prepare for incidents through network segmentation, spare devices, tested backups, and clear incident response procedures. More mature programs add SIEM and UEBA capabilities tuned to executive activity profiles.

The most effective tool for information security teams remains direct communication with executives. Framing discussions around financial loss, regulatory fines, reputational damage in the media and among partners, and personal consequences such as blackmail or criminal liability tends to be more persuasive than technical terminology alone.

Related articles

Security NEXTFraud & Social Engineering

IPA Reports Record High Fake Warning Scam Consultations in Q2 2026

The Information Processing Promotion Agency (IPA) recorded 3,832 personal security consultations in the second quarter of 2026, marking an 8.5 percent increase from the previous quarter. Fake warning scams, which display fabricated malware alerts to frighten users into contacting fraudsters, rose sharply to 1,428 cases, a 23.7 percent jump and the highest figure in two years. These scams carry risks of financial loss and device compromise through fake support services. Consultations dipped temporarily after arrests in May 2025 but have now exceeded levels seen before those arrests. Phishing reports also increased slightly to 146 cases, including schemes impersonating the National Tax Agency. The trend of rising fake warning incidents has continued for three consecutive quarters, underscoring the need for ongoing public vigilance.

AntiMalwareFraud & Social Engineering

macOS Users Encounter Phishing and Scams More Often Than Windows Users but Adopt Fewer Protections, Kaspersky Study Reveals

A new study from Kaspersky Lab shows that macOS users report higher rates of phishing encounters and various scams compared to Windows users, yet they are less likely to implement basic security measures. Over the past year, 12 percent of macOS users faced phishing attempts versus 9 percent of Windows users, while 16 percent encountered investment fraud schemes compared to 13 percent. Privacy violations and personal data theft were also reported more frequently by Mac owners at 11 percent and 12 percent respectively, against 8 percent and 7 percent for Windows. Security habits differ notably, with only 51 percent of macOS users avoiding suspicious links and emails versus 62 percent of Windows users, and just 35 percent installing additional protection tools compared to 42 percent. Password practices and multi-factor authentication usage follow the same pattern, with Mac users trailing in creating unique or complex passwords and enabling 2FA. Kaspersky notes that while macOS built-in defenses handle many threats effectively, they offer limited protection against social engineering and platform-specific attacks, underscoring that the Apple brand does not serve as automatic security.

AntiMalwareFraud & Social Engineering

Scammers Impersonate Russian Post to Lure Victims into Fake Telegram Bots

Fraudsters have developed a new scheme targeting Russian citizens by impersonating Russian Post over the phone. They claim that a registered letter or parcel requires additional address details and direct victims to a counterfeit Telegram bot. The bot then requests personal information, bank card data, or SMS verification codes. State Duma deputy Anton Nemkin highlighted how the criminals exploit trust in the well-known postal service and create urgency around expected deliveries. Victims are advised to avoid any links or contacts provided by callers and instead verify information directly through official Russian Post channels. The scheme relies on automatic reactions from people who may be expecting packages, making them more likely to follow instructions without suspicion. No actual parcel exists, but the risk of account takeover or financial loss remains very real.

AntiMalwareFraud & Social Engineering

From Free Game Cheats to Arson: Cybercriminals Recruit Children for Espionage and Violent Crimes

Cybercriminals are increasingly targeting children not only to steal money from parents but also to turn them into unwitting accomplices in dangerous criminal activities. During school holidays, teenagers spend more time in games and messengers where scammers offer free in-game currency, mods, cheats, and pirated game versions to build trust. Once access is gained, fraudsters extract SMS codes, bank card details, or device control, escalating to threats and blackmail when initial tactics fail. Kaspersky Lab recorded over 19 million attempts to distribute malware disguised as popular games between April 2024 and April 2025, installing spyware and RAT trojans that monitor chats, keystrokes, cameras, and microphones. In severe cases, children are manipulated into believing they assist law enforcement, leading to real-world crimes such as photographing apartments, handing over keys, setting fires, or attacking people. Specific incidents include a 12-year-old boy from Leningrad Oblast forced to assault a police officer and a 13-year-old from Podolsk ordered to ignite a gas pump at a filling station. Izvestia reporting highlights that parents should watch for signs like hidden screens or strange tasks and teach children that no stranger can demand codes, money, or secret missions.