Business Wire

Arxan’s Annual Report: ‘State of Mobile App Security’ Reveals an Increase in App Hacks for Top 100 Mobile Apps

21.11.2014 09:43:00 CET | Business Wire | Press release

Share

Arxan Technologies, the leading provider of application protection solutions, has just released its third annual State of Mobile App Security report, which reveals that 97% of the top 100 paid Android apps and 87% of the top 100 paid Apple iOS apps have been hacked. In addition to an increase in app hacks found for commonly downloaded Popular Free apps, this year’s research also reveals evidence of widespread hacking of financial services, healthcare/medical, and retail/merchant apps; largely driven by hacks of Android apps.

Arxan’s 2014 State of Mobile App Security report updates previous years’ indicators on the prevalence of hacked apps on the two major platforms (iOS and Android). The findings of increased app hacking is especially noteworthy amidst today’s rapid growth in global mobile app usage. Free app downloads are forecasted to increase at a rate of 99% to reach 253 billion downloads in 2017 and paid app downloads are projected to reach almost 15 billion, a 33% increase by 20171.This explosion in app usage is seen across all verticals and lead by apps running on the Android mobile operating system, which continues to dominate with 85% market share2.

The report, which comes on the heels of a number of recent mobile application-based attacks, such as Wirelurker and Masque, highlights the imminent and growing need for mobile applications to contain self-protections. Key findings from the 2014 report include:

  • Top 100 Paid Apps and Popular Free App reveal widespread hacking
    • 97% of top 100 paid Android apps and 87% of top 100 paid iOS apps have been hacked – This finding of a high percentage for Android hacked apps is in line with results from prior years. However, the iOS percentage represents a sharp increase over 2013, when 56% of iOS apps were found to be hacked
    • 80% of Popular Free Android apps have been hacked and 75% of the Popular Free iOS apps have been hacked – The percentage of popular iOS apps hacked has steadily increased over the last 3 years
  • App Hacking Targets Mobile Apps Across High Risk Verticals
    • Mobile financial apps are still at risk – 95% of the Android financial apps reviewed were “cracked” while 70% of the iOS financial apps were hacked. This is an increase in both cases, with Android’s growing about 80%
    • 90% of Retail/Merchant Android apps and 35% of Retail/Merchant iOS apps have been compromised – Hackers are targeting growth in B2C retail apps, as stores launch mobile payment/wallet services, and in B2B merchant point-of-sale apps. In both cases sensitive data, IP, and financial transactions are at risk
    • 90% of Android Healthcare/Medical apps have been hacked, 22% of which are FDA approved

Proactive measures to protect against application risks are being championed by industry leaders such as Gartner’s application security analyst, Joseph Feiman. In Feiman’s recent Maverick report, he advises CISO’s to “Make application self-protection a new investment priority, ahead of perimeter and infrastructure protection.” “Runtime Application Self Protection (RASP) is designed to protect applications by adding protection features into the application runtime environment.”3

Echoing security leaders, Arxan’s State of Mobile App Security report includes key recommendations to improve the security of mobile applications. Among other recommendations, the report recommends that:

  • Applications with high-risk profiles running on any mobile platform should be made tamper-resistant and capable of defending themselves and detecting threats at runtime
  • All applications should be developed to maintain the confidentiality of the application/code
  • The software that is used to enable mobile wallets/payment apps (e.g., Host Card Emulation software) should be protected with secure crypto and app hardening.
  • Organizations should consider mobile app assessments to assess if existing apps are exposed to risks that are unique to mobile environments. Also, as part of the mobile app development lifecycle, organizations should conduct Penetration Tests that, among other things, should assess vulnerability to reverse engineering and tampering that can result from unprotected binary code.

Arxan’s 2014 “State of Mobile App Security” report and supporting Infographic are now available. The findings were based on analysis of 360 apps, including 100 top paid and the same 20 popular free apps from each platform, as well as 40 apps in the financial services, retail/merchant, and healthcare/medical categories (20 apps per platform).

“The pursuit of greater mobile application security remains at the forefront our research and development initiatives,” said Jonathan Carter, technical director at Arxan. “We continue to evolve our security innovations based on emerging threats to ensure the strongest application protection for our customers in the dynamic battlefield against hackers.”

About Arxan Technologies

Arxan provides the world’s strongest application protection solutions. Our unique patented guarding technology 1) Defends applications against attacks, 2) Detects when an attack is being attempted, and 3) Responds to detected attacks with alerts and repairs. Arxan offers solutions for software running on mobile devices, desktops, servers, and embedded platforms – including those connected as part of the Internet of Things (IOT) – and is currently protecting applications running on more than 300 million devices across a range of industries, including: financial services, high tech/independent software vendors (ISVs), manufacturing, healthcare, digital media, gaming, and others. The company's headquarters and engineering operations are based in the United States with global offices in EMEA and APAC.

1 statista - Number of mobile apps downloads worldwide statistics
2 source: IDC Q2 2014 Report
3 Gartner Maverick* Research: Stop Protecting Your Apps; It's Time for Apps to Protect Themselves, Joseph Feiman, September 25, 2014

Follow Arxan:
Twitter: http://twitter.com/arxan
Blog: http://blog.arxan.com/
LinkedIn: https://www.linkedin.com/company/arxan-technologies
Facebook: https://www.facebook.com/pages/Arxan-Technologies/290902575878

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

Media:
éclat Marketing
Kim Smith / Jenny Davis, +44 (0) 1276 486000
arxan@eclat.co.uk
or
Arxan Technologies
Jodi Wadhwa, 1-301-968-4295
jwadhwa@arxan.com

About Business Wire

Business Wire
Business Wire
24 Martin Lane
EC4R 0DR London

+44 20 7626 1982http://www.businesswire.co.uk

(c) 2018 Business Wire, Inc., All rights reserved.

Business Wire, a Berkshire Hathaway company, is the global leader in multiplatform press release distribution.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

H.I.G. Capital Announces the Sale of DGS S.p.A.11.6.2024 12:00:00 CEST | Press release

H.I.G. Capital (“H.I.G.”), a leading global alternative investment firm with $62 billion of capital under management, is pleased to announce that an affiliate has signed a definitive agreement to sell its portfolio company, DGS S.p.A. (“DGS” or the “Group”), a leading firm in the Italian Information Technology market, to DGS Co-Founders and management team in partnership with ICG, a global alternative asset manager. Since its inception in 1997, DGShas supported blue-chip customers in the design, integration, and maintenance of complex IT systems, with a specialization in digital transformation and cybersecurity services. The Group currently has over 1,900 employees, revenues of approximately €300 million, and maintains a group of highly loyal clientele. During H.I.G.’s ownership, DGS has tripled in size and consolidated its position as a leading Italian firm in cybersecurity services and digital transformation. DGS offers its clients sophisticated and proprietary digital transformation

Evertas Names Nick Selby Head of European Underwriting11.6.2024 12:00:00 CEST | Press release

Evertas, the world’s first crypto insurance company, has named Nick Selby as its new Head of European Underwriting. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240611141887/en/ Nick Selby, Executive Vice President and Head of European Underwriting at Evertas (Photo: Business Wire) Selby, an accomplished information and physical security professional, brings two decades of expertise in public and private sector information security, physical security, and complex incident handling, as well as seven years of experience leading teams securing billions of dollars in cryptoassets. Previously, his roles included VP of the Software Assurance Practice at Trail of Bits, Chief Security Officer at Paxos Trust Company, and Director of Cyber Intelligence and Investigations at the NYPD Intelligence Bureau. “Nick is an extremely valuable addition to our European team,” said Evertas CEO and Co-Founder J. Gdanski. “His public and private

Owlet utvider globalt fotavtrykk med lanseringen av medisinsk-sertifisert Dream Sock™ i Storbritannia og over hele Europa11.6.2024 11:00:00 CEST | Pressemelding

Owlet, Inc. («Owlet» or the «Company») (NYSE:OWLT), pioneren innen smart spedbarnsovervåking, kunngjør i dag den britiske og europeiske lanseringen av Dream Sock. Dette er en smart babymonitor med levende helseavlesninger og varsler for friske spedbarn mellom 0-18 måneder og 2,5-13,6 kg. Dette innovative medisinske utstyret gir foreldre helse og viktig informasjon i sanntid, noe som gir uovertruffen trygghet. Denne pressemeldingen inneholder multimedia. Se hele pressemeldingen her: https://www.businesswire.com/news/home/20240611820341/no/ (Photo: Business Wire) «Vi er svært stolte over å lansere Dream Sock til omsorgspersoner over hele Storbritannia og Europa og gi millioner av foreldre mer trygghet mens babyen sover,» sa Kurt Workman, Owlets administrerende direktør og medgründer. «Dream Sock er nå et globalt produkt som er anerkjent som medisinsk nøyaktig og trygt, etter å ha gjennomgått regulatoriske autorisasjoner og sertifiseringer innenfor flere geografier. I dag er misjonen vår

V-Nova Surpasses 1000 Patent Milestone in Media Technology Innovation11.6.2024 10:00:00 CEST | Press release

V-Nova, a leading provider of data compression solutions, video compression technology, XR technology, AI acceleration and parallel processing for a multitude of industries including media and entertainment, today announced its milestone achievement of 1000 active technology patents. This accomplishment underscores V-Nova’s dedication to research and development and its commitment to protecting its intellectual property globally. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240611724561/en/ V-Nova’s patent portfolio spans more than 50 different jurisdictions. Including over 400 patents in Europe, over 200 in the Americas, over 100 in the United States specifically, and over 200 in Asia. V-Nova forged new directions in data processing to enhance digital experiences, maximize efficiency, reduce costs, and increase sustainability. The company leads the way with key international data compression standards for the video indust

Alipay+ Reveals Top Scorer Trophy Design for UEFA EURO 2024™11.6.2024 09:24:00 CEST | Press release

Alipay+, a suite of cross-border mobile payment and digitalization technology solutions operated by Ant International and an Official Partner of UEFA EURO 2024™, today revealed the trophy that will be awarded to the most prolific marksman at the UEFA EURO 2024™ finale on July 14 in Berlin, Germany. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240610328619/en/ The UEFA Top Scorer Trophy presented by Alipay+ is unveiled for UEFA EURO 2024™ (Photo: Business Wire) Sculpted in the shape of the Chinese character “支” (pronounced zhi, and meaning payment as well as support), the trophy reflects Alipay+’s dedication to supporting consumers to enjoy seamless payment and a broad choice of deals using their preferred payment methods while traveling abroad. The character also resembles the fleeting moment of a barefooted striker poised to shoot, evoking the original beauty and power of football – a game that united people across the wo

World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye