Email Compromise Remains Top Threat Incident Type for the Third Quarter in a Row



Confident Detecting Spoofed EmailsNew analysis of Q2 threats shows a consistent pattern of behavior on the part of threat actors and threat groups, providing organizations with a clear path to protect themselves.

It’s every cybersecurity professionals’ worry; whether the security controls they’ve put in place will actually stop attacks.

But it’s actually quite easy to calm those fears by simply paying attention to industry data that paint a picture of what tactics and techniques threat actors are using and to ensure the appropriate controls are in place to stop such malicious activity.

According to Kroll’s Q2 2024 Threat Landscape Report, there are some consistent trends that are becoming evident.

Going back three quarters, Kroll demonstrates through data that the following threat incident types (in descending order) are being experienced during cyber attacks: email compromise, ransomware, unauthorized access and web compromise.

body4-white

Source: Kroll

Looking at the chart above, you can see how important having access to email is for threat actors.  And even with the substantial increase in unauthorized access this year it appears that the threat actor “leopard” doesn’t change its spots.

It also makes it very clear that protecting email access with multi-factor authentication, strong passwords, and the use of security awareness training to help prevent successful social engineering attacks intent on stealing credentials are necessary to stop what appears to be an incident trend that isn’t going away anytime soon.

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.


Find out which of your users' emails are exposed before bad actors do.

Many of the email addresses and identities of your organization are exposed on the internet and easy to find for cybercriminals. With that email attack surface, they can launch social engineering, spear phishing and ransomware attacks on your organization. KnowBe4's Email Exposure Check Pro (EEC) identifies the at-risk users in your organization by crawling business social media information and now thousands of breach databases.

EECPro-1Here's how it works:

  • The first stage does deep web searches to find any publicly available organizational data
  • The second stage finds any users that have had their account information exposed in any of several thousand breaches
  • You will get a summary report PDF as well as a link to the full detailed report
  • Results in minutes!

Get Your Free Report

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/email-exposure-check/



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews