File-sharing phishing attacks have skyrocketed over the past year, according to a new report from Abnormal Security.
“In file-sharing phishing attacks, threat actors exploit popular platforms and plausible pretexts to impersonate trusted contacts and trick employees into disclosing private information or installing malware,” the report says.
“A complex and escalating threat, file-sharing phishing attacks increased by 350% year-over-year, with financial organizations and built environment firms being the most targeted.”
File-sharing attacks are designed to impersonate common business tools like file-hosting services or e-signature solutions. The researchers note that these attacks blend in with normal business activities.
“Sharing files and documents via email is a common practice for organizations in every industry. While the themes of some phishing attacks are likely to raise at least a little suspicion (such as unsolicited, too-good-to-be-true job offers or an email from the CEO requesting $500 in gift cards), the pretext of file-sharing phishing attacks is perfectly ordinary and, therefore, inherently believable. Depending on their approach, an attacker often doesn’t even need to invest considerable effort in establishing a plausible pretense beyond selecting a relevant name for the bogus file.”
Abnormal Security also observed a 50% increase in business email compromise attacks in the first half of 2024 compared to H1 2023.
“Business email compromise (BEC) and vendor email compromise (VEC) are specifically designed to circumvent both users’ common sense and conventional security measures. Utilizing social engineering and text-based emails with no traditional indicators of compromise allows cybercriminals to evade legacy email security solutions and manipulate targets. This one-two punch has brought attackers continued success and is likely why BEC and VEC have maintained their momentum.”
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
Abnormal Security has the story.