Email Account Takeover and Lateral Phishing Attacks Increase Risk to Enterprises

Stu Sjouwerman | Sep 5, 2019
lateral-phishing-attack

The latest method of attack uses sender familiarity to lower victim defenses and increase the potential for scams, attacks, or fraud to succeed.

The goal of a phishing attack is to get the potential victim to take an action desired by the attacker – clicking a link, opening an attachment, providing credentials, etc. What better way to convince a victim to do so than by sending the email from someone they regularly correspond with?

That’s the premise of the growing trend of lateral phishing attacks. According to new research from security vendor Barracuda, one of the growing trends is the leveraging of compromised email from one user to spread an attack to other users via additional phishing emails.

According to the report:

  • 1 in 7 organizations have experienced email account takeover attacks
  • 60 percent of attacked organizations had multiple compromised employee accounts used to send lateral phishing attacks
  • 55% of targets have a personal or work relationship to the hijacked account
  • Nearly all attacks occur during normal work hours
  • One-third of attacks used stealth techniques such as responding to replies and actively deleting traces of email conversations

Users today can no longer assume that emails even coming from people they know are legitimate. With two-thirds of the emails used in these scams containing generic content, users can be taught using Security Awareness Training to scrutinize the email’s content and to use a different medium to contact the sender to validate the email message.

Ready to Build a Security Culture That Lasts?

Stop treating training like a checkbox exercise. Using 15+ years of behavioral data, our AI-powered platform personalizes training for every user to significantly reduce human risk and stop attacks before they start.

Get a Quote

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.