
Unsuspecting employees in businesses around the world are being swindled into giving up personal or company data — enticed by social engineering tactics and phishing emails. According to Mimecast, phishing attacks are the leading threat to email users, with 500 million attacks reported in 2022 in the United States alone.
In the latest wave of such attacks, threat actors impersonating HR staff are exploiting device compliance and other HR-related issues in order to harvest user credentials. Using psychological manipulation, cybercriminals trick employees into clicking on email links or scanning QR codes, threatening retribution — such as revoking access to company systems — if they don’t do what is asked.
While social engineering techniques are evolving, they’re not foolproof. By combining employee training with advanced threat protection, you can mitigate risk and keep sensitive data from falling into the wrong hands.
Help employees recognize email phishing scams
Training employees to know the difference between an authentic and a fake email starts with imagining what social engineering could look like in their own work environment. Employees should answer questions such as: What is valued in my company and how might it be accessed? What is company procedure for sharing sensitive or valued information?
Employees should also be aware that clicking on links isn’t the only way to propagate an attack. Because they’re harder to detect than malicious links, threat actors are increasingly asking users to scan QR codes embedded in PDF attachments. In fact, more than 3.5 million emails with QR code attachments are sent each day, reports Mimecast.
Because phishing emails appear to come from legitimate people in the organization, they can be hard to spot. Here are some basic guidelines employees can follow:
- If anything looks out of the ordinary, don’t click.
- If you’re not expecting this bill, don’t open it.
- If you don’t know the accounts payable person, ask questions.
Other red flags employees should look for include a spoofed email address, urgent requests or demands, and asks that don’t follow standard operating procedures.
Use technology to strengthen your security posture
Your next line of defense is technology that provides a comprehensive approach to email security. This includes the ability to detect social engineering attacks, protect against phishing emails, advise on upcoming threats, and authenticate email senders.
For example, social engineering threat detection uses linguistic analysis, sentiment detection, and similarity checks to identify potential business email compromise (BEC) and spear phishing attempts. While phishing protection incorporates everything from deep URL analysis and content scanning to machine learning and behavioral patterns to block credential theft.
IT leaders are also using dynamic bannering to keep employees safe. This solution uses AI and machine learning to identify unusual email activity, applying color-coded warning banners to help users make informed decisions in the moment.
Keep social engineering out of the inbox
As social engineering tactics continue to shift, IT leaders must remain vigilant and proactive in their approach to email security. By combining technology with human intervention, you can better equip your organization to detect and defend against these deceptive attacks.
Learn how Mimecast can help you keep phishing emails at bay, strengthen your security, and protect your organization’s most valuable assets.
