Executives are Out and Employees are In as Cybercriminals Change Their Primary Targets for Cyberattack

Stu Sjouwerman | Apr 24, 2019
protectingpeople

Phishing and Social Engineering scammers are shifting tactics, focusing efforts on low-level employees using a variety of methods as a means to cast a wider net within a targeted organization.

There are only so many executives in an organization, right? So, it makes sense that cybercriminals want to reach the most people with the least amount of work.

According to Proofpoint’s latest Protecting People Report, that’s exactly what they’re doing. The bad guys are using some very specific tactics and targets within organizations to achieve their goals:

  • 30% of credential phishing attacks targeting generic company email addresses, such as sales@
  • Individual Contributors and lower-level Management ranked higher than Executives as targets
  • 80% of organizations were involved in attacks attempting to send email to 6 or more recipients
  • 40% of organizations were intended recipients of 50 or more phishing email attacks

So, lots of emails being sent to lots of low-level individuals in the organization. That’s a recipe for disaster.

Without proper training, users will succumb to attacks that compromise their endpoint, their email, and their credentials, giving attackers the tools needed to being to move laterally within the organization, infect others with malware via corporate email, and island hop to attack other organizations.

These worker-level employees need to undergo Security Awareness Training to empower them to work with a security mindset – one that is constantly vigilant, looking for everything from the abnormal to the downright suspicious. This lowers the risk of falling victim and the ramifications that come with data breaches, ransomware, cryptojacking, and other types of cyberattack.


Find out how affordable new-school security awareness training is for your organization. Get a quote now.

 
Get A Quote
Request A Demo
 

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.