Skip to main content

One in five email attacks uses compromised accounts

Account takeover-based (ATO) attacks now comprise 20 percent of all advanced email attacks according to new research from the email security and protection company Agari.

The firm's recently published Q1 2018 Email Fraud & Identity Deception Trends report found that ATO attacks are rising in popularity among cybercriminals because they are more difficult to detect than traditional attacks and can bypass email filters since they are sent from a real sender's email account.

Senior Director of Threat Research at Agari, Crane Hassold provided further insight on the treat posed by ATO attacks, saying:

“Credential phishing was already a huge risk for organizations because of the potential for data breach, but now there is a new wave of account takeover attacks leveraging compromised accounts to commit additional fraud, which evade traditional email security controls. Business email compromise attacks are still very active, especially against C-suite targets.” 

Advanced email attacks

According to Agari's Cyber Intelligence Division, brand impersonation remains the most common attack vector and this technique was used in 50 percent of advanced email attacks during Q4 2018 with cybercriminals impersonating Microsoft in 70 percent of these instances. Microsoft is often a target for credential phishing since attackers can use Office 365 accounts in subsequent ATO attacks.

However, a different pattern was identified when it came to attacks against executive targets with 33 percent of advanced email attacks against C-level employees using display name deception to impersonate an individual. This tactic is also commonly used for business email compromise (BEC) attacks that frequently target an organisation's CFO.

With the approach of tax season in the US, impersonation of the US Internal Revenue Service (IRS) surged in the fourth quarter. The IRS was impersonated in nearly one in ten attacks which is up from less than one percent in the third quarter.

W-2 scams occur quite often in the runup to tax season, as cybercriminals utilise phishing emails and social engineering to obtain a business' W-2 files which contain a wealth of sensitive information such as social security numbers, salaries and other confidential data that is used to commit tax fraud or identity theft.

  • Protect your devices from the latest threats with the best antivirus


from TechRadar - All the latest technology news http://bit.ly/2MMQSNm

Comments

Popular posts from this blog

Mother's Day 2020 gift ideas: 18 gadgets and gizmos for tech-savvy Aussie mums

Raising a family is not an easy job, and the women who care for us each and every day deserve to be told how special they are each and every day. While we tend to forget to do that, Mother’s Day reminds us we need to celebrate the women in our lives, whether they’re our own mothers or our wives and partners helping us raise the young ones. Mother’s Day 2020 is fast approaching (with under two weeks to go), and there’s a pretty good chance you won’t be able to take her out to her favourite restaurant this year, or even get to a store to shop for something she might like. So we have to get creative, and TechRadar’s Australian team has put together this little list of great tech gift ideas that you can buy online and have delivered in time for May 10. But you will need to get a wriggle on as delivery supply chains are under strain with more people shopping online. Whether she’s a whiz in the kitchen, loves to cosy up with a book or entertain at home, we’ve got a gadget or gizmo that’s s

Amazon Australia has specials on Bose products all this week

December may have just begun, but the world's largest online marketplace is already feeling the Christmas spirit.  To kick off the month’s festivities, Amazon Australia is celebrating  ‘7 Days of Deals’ with Bose's superb audio hardware discounted each day. To begin with, the very popular (and rightly so) Bose QuietComfort 35 II and the more expensive Bose Noise Cancelling Headphones 700 are available for less. To sweeten the deal, Amazon will throw in an Echo speaker as a bonus as well. When you purchase the superb Bose Headphones 700, you will receive a free Amazon Echo Show 5, or if you’d prefer the Bose QuietComfort 35 II, you’ll receive a complimentary Echo Dot. The offer is valid until December 8, or while stocks last. You can buy the same bundles, for the same price if you make the purchase via the Echo Dot or the Echo Show 5 product pages on Amazon. Just make sure you select the bundled headphone in the 'add other items' section on the right. Best noi

Valentine's Day flowers: the best online flower delivery services

February 14 will be here before you know it, and if you, like many others, are searching for that perfect gift, then placing an online order for Valentine's Day flowers is always an easy and romantic option. You can order a beautiful floral arrangement in minutes from a variety of online retailers, including; 1-800-Flowers, Amazon, ProFlowers, Teleflora, and many more. To help you sort through all the Valentine's Day offers, we've rounded up the best online flower delivery services in both the USA and the UK and listed their current promotions. We've also included delivery charges and made sure to mention if you can allocate specific days for delivery. There's a fantastic range of bouquets and gifts available from our selection of florists below, and online delivery from a specialist means you don't have to worry about the usual hassle of buying from a store and getting them home safely. We'll be updating this page as we get closer to the big day so you