Email Compromise Continues to Dominate as Top Threat Incident Type as Tactics Evolve
As email compromise attacks increase, analysis of tactics provides context on how organizations need to evolve their defenses.
Kroll’s Q1 2024 Cyber Threat Landscape Report covers the analysis of a wide range of threats and data covering the last three quarters shows how email compromise has been consistently growing:
Source: Kroll
What’s more interesting is the commentary by Kroll, where they mention that “while phishing was typically synonymous with an email message, actors continued to evolve tactics and introduce others, such as SMS lures and voice phishing, which seem to be rising in popularity.”
We’ve seen corroborating data around the rise of vishing and smishing, giving credence to the Kroll data’s view of the current state of threats.
This shift in email compromise tactics signals that threat actors are evaluating what is and isn’t working, and making changes to their methods to increase the likelihood of a successful compromise.
But the one thing attackers require to compromise email is a user who is not paying attention and willingly gives up their credentials. It’s why security awareness training shines as the mitigating control that will teach users to be watchful for any kind of attack intent on stealing credentials.
Tactics will continue to evolve, so it’s imperative that organizations put the right controls in place that will continually thwart threat actor efforts.
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
Free Phishing Security Test
Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.
Here’s how it works:
- Immediately start your test for up to 100 users (no need to talk to anyone)
- Select from 20+ languages and customize the phishing test template based on your environment
- Choose the landing page your users see after they click
- Show users which red flags they missed, or a 404 page
- Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
- See how your organization compares to others in your industry
PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/phishing-security-test-partner?partnerid=001a000001lWEoJAAW