Many news reports say, “Be careful not to open suspicious emails.” But recently, I feel that ransomware can enter through other routes as well, not just spam or phishing emails.
I’m not a security expert, but I sometimes feel that the well-known countermeasures we often hear about may no longer be enough.
Vulnerabilities in Old Apps — the Hidden Back Door
In many recent cases, attackers seem to focus less on email and more on:Outdated versions of VPN software, NAS devices, and internal applications.
If these systems are left unpatched, vulnerabilities remain open. Attackers can scan the internet with automated tools, find those weak points, and enter without any email involvement at all.
Even if no one opens a suspicious message, a system that stays “old” can still be compromised.
Accounts Without Two-Factor Authentication More companies are using Microsoft accounts for Windows login, but surprisingly often, two-factor authentication (2FA) is not enabled.
If employees also use simple, predictable passwords, attackers may break in even without phishing emails.
So “We’re careful with suspicious emails” may no longer be enough.
Spam Emails Are Not the Only Attack Vector Email protection is still important, but attacks today often come from completely different routes.
Just as we sometimes remind ourselves to “see things from the other person’s perspective,” it might also help to consider how things look from a cybercriminal’s point of view.
In other words, we should check:
Are our apps and devices updated to the latest version? Do we still have legacy equipment connected to the network? Are our accounts protected with 2FA?
Focusing only on email filters creates blind spots. Looking at these “non-email vulnerabilities” is becoming essential for modern cybersecurity.