62% of Phishing Emails Bypassed DMARC Checks in 1H of 2024



blog.knowbe4.comhubfsPhishing Emails Are After CredentialsA report from Darktrace has found that 62% of phishing emails in the first half of 2024 were able to bypass DMARC verification checks in order to reach users’ inboxes.

“Building on the insights from the 2023 End of Year Threat Report, an analysis of malicious emails detected by Darktrace / EMAIL in 2024 underscores the implication that email threats are increasingly capable of circumventing conventional email security tools,” the report says.

“Notably, 62% of the 17.8 million phishing emails identified by Darktrace successfully bypassed Domain-based Message Authentication, Reporting, and Conformance (DMARC) verification checks.”

Additionally, nearly 40% of phishing attempts in the first half of 2024 were targeted, indicating that threat actors are investing more effort into tailoring their attacks. The researchers also observed an increase in attacks that impersonated brands or VIPs. 

“More interestingly still, in May and June alone, Darktrace identified 540,000 brand impersonation attempts (malicious email actors attempting to masquerade as trusted and reputable organizations to deceive recipients) and a further 240,000 emails attempting to impersonate a VIP at an organization.

"This trend towards impersonation and deception under the guise of a trusted company, or even a company executive, suggests threat actors are curating more bespoke and targeted email campaigns intended to target select organizations, or even individuals, more efficiently than traditional mass phishing attacks.”

Notably, Darktrace observed a 59% increase in multistage phishing attacks, which “elicit recipients to follow a series of steps, such as clicking a link or scanning a QR code, before delivering a payload or attempting to harvest credentials.” Since these attacks are more complex, they can more easily evade detection by security tools.

New-school security awareness training can give your organization an essential layer of defense by teaching your employees to recognize social engineering attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

ADS Advance has the story.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews