BSI ID: G 0.47
IT-based attacks can have effects that
are not intended by the perpetrators or
do not affect the directly attacked targets or
harm uninvolved third parties.
This is due to the high complexity and interconnectedness of modern information technology and the fact that the dependencies between the targeted objects and the associated processes are not usually apparent. Among other things, this can lead to the actual protection requirements of targeted objects being incorrectly assessed or those responsible for the targeted objects having no vested interest in remedying deficiencies in these objects.
Examples:
Bots installed on IT systems that perpetrators can use to carry out distributed denial-of-service attacks (DDoS attacks) often do not pose a direct threat to the infected IT systems themselves, because DDoS attacks are usually directed against third-party IT systems.
Vulnerabilities in IoT devices in WLANs can be used by perpetrators as a gateway to attack other more important devices in the same WLAN. Therefore, such IoT devices must also be protected even if they themselves have only a low protection requirement.
Ransomware attacks on IT systems can, under certain circumstances, trigger chain reactions and thus also affect critical infrastructure. This, in turn, could lead to supply shortages for the population, even if this was not the intention of the perpetrators.
ย