Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»Hacker Holidays: why the holiday season is an open door for cyber attackers (Page 14)
Cyber resilience

Hacker Holidays: why the holiday season is an open door for cyber attackers

While the festive season is a time of joy and celebration, it also brings with it a heightened risk of cyber attacks. As most employees wrap up for the year and sign off from work, cybercriminals are preparing to distribute their own 'gifts'.
December 21, 20234 Mins Read
The holiday season provides an opportunity for hackers.

This pattern of behaviour has been observed before, with the most notable incident being the SolarWinds breach that took place between Christmas and New Year in 2020. This breach, which targeted the company’s Orion software, compromised thousands of clients globally, including key government agencies and top-tier corporations. The orchestrated campaign was not only a wake-up call for IT professionals, but a vivid reminder of the cyber security vulnerabilities that emerge when the usual vigilance wanes during the holiday season. 

This time of year provides the perfect scenario for cybercriminals. Reduced staffing, delayed response times, and the general complacency that comes with the festive season create an ideal environment for attacks. To ensure smooth operational continuity during the high-activity holiday season, many organizations adopt a ‘change freeze’ on their IT systems. This is where planned updates to the IT environment are postponed while other priorities are taken care of, which inadvertently creates gaps in cyber security. Essential updates and patches are delayed, leaving systems exposed to known risks. The SolarWinds incident is a stark example of how such vulnerabilities can be exploited, highlighting the need for a more nuanced approach to IT management during these periods. 

In addition,the festive season often coincides with reduced staffing levels. This decrease in personnel substantially affects the ability to effectively monitor, detect, and respond to emerging cyber threats. Not all companies have a third-party Security Operations Center (SOC), let alone one in-house, and many Secure Operation Centers (SOCs) only run during business hours. This lack of continuous monitoring becomes even more apparent at the end of the year, again as was evident in the SolarWinds case. 

Rise of holiday-themed phishing scams 

The holiday season creates a surge in phishing scams, aimed at exploiting the general atmosphere of urgency and distraction in organizations. The Phishmas: Direct Deposit Scam, reported by Avanan, a Check Point company, is an example where attackers used this time of year to impersonate employees and make changes to financial transactions. In this scam, attackers posed as employees asking HR or their managers to change direct deposit information, redirecting payments to the fake account. These scams are particularly insidious during the holidays and require heightened awareness and preventive measures.  

How businesses can stay safe over the holidays 

Here are some tips to help businesses stay cyber safe over the holidays: 

  • Employee training: conduct cyber security awareness training for employees to educate them on potential threats and best practices. This is especially important for any stand-ins who may not have full visibility based on access management.
  • Update and patch systems: although some implement a change freeze during this time of year, organizations should regularly update and patch all software where possible, including operating systems and applications, to address known vulnerabilities.
  • Secure remote work environments: if employees are working remotely over the festive period, ensure that their home networks are secure. Implement virtual private networks (VPNs) to encrypt data transmission and use multi-factor authentication (MFA) for access.
  • Phishing awareness: it is important to warn employees about holiday-themed phishing scams, such as fake promotions or shipping notifications. Encourage them to verify the authenticity of emails and avoid clicking on suspicious links.
  • Monitor network activity: network monitoring tools are designed to detect and respond to unusual activities promptly. Set up alerts for any suspicious login attempts or unauthorised access.
  • Data backups: you should regularly back up critical business data and ensure that those backups are stored securely. Test data restoration processes to guarantee that backups can be successfully recovered if needed.
  • Collaborate with vendors: if your business relies on third-party vendors or service providers, ensure they adhere to robust security practices. Verify their security measures and communicate your expectations regarding data protection.

Article provided by Check Point.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleRisk and resilience predictions for 2024
Next Article How data storage will develop through 2024

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Multiracial people in a city wearing face masks.

UK Government publishes Pandemic Preparedness Strategy

March 26, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?