
Year after year, cybercriminals choose email as their primary pathway to launch malicious attacks. In fact, email provides one of the largest attack surfaces within organizations. According to Mimecast, 41% of businesses experienced more threats via email over the last 12 months.
But while email remains a constant channel for threats, lures and delivery methods are constantly evolving. For example, as remote work has increased, so has the number of HR-related threat emails. Threat actors are also relying more on links and QR codes, as well as impersonating legitimate brands to ultimately steal users’ credentials or other sensitive information.
“Email attacks are becoming more sophisticated, fueled by advances in AI,” said Andrew Williams, principal product marketing manager at Mimecast. “Users are unwittingly accommodating these attacks as they fall prey to emerging tactics.”
Understanding the email threat landscape is your first step in safeguarding against these attacks.
Today’s top email threats
The most common email threats enterprises face today include business email compromise (BEC), phishing, and inadequate native email security. Because email is entrenched in everyday business, these threats continue to grow.
1. Phishing: The top threat to email users, phishing relies on clicks or QR code scans to take employees to a harvesting page that is then used to steal user credentials. Legitimate hosting and multiple redirects make it hard for users to recognize an attack. Once harvested, their data is sold on the black market or used to access a broader attack network, including vendors in an organization’s supply chain.
2. BEC Attacks: In a BEC attack, threat actors use impersonation or other social engineering techniques to coerce employees into sending money or sensitive data to fake accounts. Because these phishing emails appear harmless, they easily evade native email defenses and have high engagement rates, pointing to the need for more advanced detection and contextual details to guide users.
3. Inadequate native email security: According to Williams, most organizations require advanced security that cloud email subscriptions like Microsoft 365 and Google Workspace alone can’t provide. Without sufficient protection against phishing, BEC attacks, malware, and spam, IT leaders are turning to third-parties for additional layers of security.
How employees aid attacks
Successful email attacks require human interaction, so employees are key to carrying them out. For example, phishing emails require users to click to reach a landing page and then click again—sometimes up to seven times—to verify they’re not a robot or to encourage interaction with multiple cloud services. Naturally curious and wanting to help, employees engage, unaware that they’re spreading an attack.
Conquer emerging threats with layered security approaches
Without effective email security, not only is your organization more likely to face an attack, but your business could be used as a gateway to attack vendors in your supply chain. As attacks become more sophisticated, adopting a multilayered approach to email security will ensure you keep your work and your people protected.
Learn how Mimecast can help you secure your email and your business.
