London, December 14, 2024 – Research presented at Black Hat Europe 2024 indicates a significant increase in hacker interest in exploiting SAP enterprise systems, with a sustained spike in attacks observed since 2020.
According to Yvan Genuer, a senior security researcher at Onapsis, the analysis of four years of threat intelligence data highlights that 87% of the Forbes Global 2000 companies utilize SAP, which manages 77% of global transaction revenue, making it a prime target for cybercriminals.
The research, conducted by Onapsis in partnership with Flashpoint, examined activities across criminal forums, ransomware incidents, and chat sites, revealing that various groups, including cybercrime syndicates and state-sponsored actors, are actively exploiting vulnerabilities in SAP systems.
Notable cybercriminal groups such as FIN13 “Elephant Beetle,” FIN7, and APT10 from China have been identified as key players in targeting SAP vulnerabilities. The vast amounts of sensitive data stored in SAP systems, coupled with their critical role in financial transactions, make them attractive targets.
Exploits for SAP systems are being actively sold on criminal forums, with prices for vulnerabilities reaching as high as $250,000. The discussions surrounding SAP-specific cloud and web services have surged by 220% from 2021 to 2023, indicating a growing trend in cybercriminal interest.
Onapsis also reported a fivefold increase in ransomware incidents involving SAP systems since 2021, with many attacks leveraging known but unpatched vulnerabilities. The ongoing demand for zero-day vulnerabilities reflects the lucrative potential for attackers, as these exploits allow for deeper access into enterprise systems.
Experts warn that SAP systems are no longer considered secure, and enterprises must prioritize regular patch management and vulnerability assessments to mitigate risks. As SAP systems continue to be prime targets for cyberattacks, the need for enhanced security measures becomes increasingly critical.