More Than Half of all Email-Based Cyberattacks Bypass Legacy Security Filters

Stu Sjouwerman | May 24, 2023

Email-Based CyberattacksNew data shows that changes in cybercriminals’ phishing techniques are improving their game, making it easier to make their way into a potential victim user’s inbox.

I recently wrote about how 12% of all email threats were getting all the way to the inbox. But new data from cybersecurity vendor Armorblox’s 2023 Email Security Threat Report shows that the number is much higher, depending on the security solutions in place.

Of all phishing attacks that targeted organizations in 2022, 78% used sophisticated techniques to successfully bypass native email security tools – and were able to reach the inbox 56% of the time!

According to the report, the following is the breakdown of the kinds of specific attacks and threats found within the phishing attacks:

  • 51% of email attacks focused on credential phishing
  • 41% focused on social engineering-based threats
  • 3% were VIP impersonation attacks
  • 3% were extortion attacks
  • 2% were payroll fraud scams

By looking at the breakdown of the two largest techniques used, you can begin to see reasons why these attacks are getting through. Credential phishing attacks are successful because they are using new sophisticated ways to avoid detection. Social engineering attacks most often have no malicious content within them, making it difficult to detect.

The risk of such attacks succeeding is high, making it necessary for you to enroll users into continual Security Awareness Training to educate them on what to look for, the techniques used, and how to spot a malicious email a mile away.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.