The NCAA’s March Madness began today. This isn’t a sports show… but you knew a tech angle was coming, right? Data released by Advizex indicates that AI hacking of March Madness betting is expected to cost U.S. companies record amounts in 2024, with an estimated revenue loss of over $18.3 billion.
Seasonally, we also are in tax season in the US. Microsoft warns of a phishing campaign targeting early tax filers, where malicious emails containing a blurred document lead users to a fake website. Clicking on the attachment installs malware that steals account credentials. Scammers trick vulnerable taxpayers using social engineering techniques, AI-generated emails, and deepfake images.
According to the FBI’s annual Internet Crime Report, Americans lost a record $12.5 billion to online fraud in 2023, with investment fraud and cryptocurrency scams being the most damaging types of crimes. Business email compromise scams and ransomware attacks also contributed to the alarming increase in cyber fraud. However, the report highlighted the positive efforts of the IC3’s Recovery Asset Team in freezing over $538.39 million and recovering more than 70% of funds in some instances.
According to more FBI data, Americans lost approximately $1.3 billion in 2023 to scammers impersonating government officials or tech support agents. These scams have increased, with losses growing more than sevenfold since 2019. Tech support scams, in particular, have significantly increased, and older people are more vulnerable to them. Impersonation scams have become easier due to generative AI tools and the popularity of remote work.
Relevant to this audience, per a threat report from Red Canary, IT helpdesk workers are increasingly targeted by cybercriminals, who often impersonate employees to request changes to identity and access management controls. These attacks can lead to the takeover of user accounts, data theft, crypto mining, or destructive attacks.
Sophos has released its 2024 Threat report, highlighting the major cyber threats small and medium-sized businesses (SMBs) face. The report reveals that keyloggers, spyware, and stealers accounted for nearly 50% of malware detections for SMBs in 2023. Initial access brokers (IABs) also use the dark web to target SMB networks or sell access to already compromised networks. Ransomware remains the biggest threat to SMBs, with LockBit, Akira, and BlackCat identified as the top ransomware gangs. Business email compromise (BEC) attacks are also increasing in sophistication, with attackers engaging in conversational emails and using new formats for malicious content.
Seasonal tie-ins are useful to keep the threat top of mind, although I will temper that by noting the constant threat level. My key insight is this: cybersecurity is an ongoing base service offering, and you’ll want to temper it with a solid basic hygiene strategy. Most businesses should do that.
Investments in law enforcement appear effective, too. A 70% recovery is a pretty good number, with room for improvement.

