Email Compromise Continues to Dominate as Top Threat Incident Type as Tactics Evolve

Stu Sjouwerman | Jun 4, 2024

Email Compromise ContinuesAs email compromise attacks increase, analysis of tactics provides context on how organizations need to evolve their defenses.

Kroll’s Q1 2024 Cyber Threat Landscape Report covers the analysis of a wide range of threats and data covering the last three quarters shows how email compromise has been consistently growing:

threat-incident

Source: Kroll


What’s more interesting is the commentary by Kroll, where they mention that “while phishing was typically synonymous with an email message, actors continued to evolve tactics and introduce others, such as SMS lures and voice phishing, which seem to be rising in popularity.”

We’ve seen corroborating data around the rise of vishing and smishing, giving credence to the Kroll data’s view of the current state of threats. 

This shift in email compromise tactics signals that threat actors are evaluating what is and isn’t working, and making changes to their methods to increase the likelihood of a successful compromise.

But the one thing attackers require to compromise email is a user who is not paying attention and willingly gives up their credentials. It’s why security awareness training shines as the mitigating control that will teach users to be watchful for any kind of attack intent on stealing credentials.

Tactics will continue to evolve, so it’s imperative that organizations put the right controls in place that will continually thwart threat actor efforts.

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.