Impersonation Phishing Attacks Increase as Credentials Take the Lead as the Primary Target



Impersonation Phishing AttacksNew data shows an upswell of email-based cyberattacks, with over 256 brands being impersonated, as social media, Microsoft, shipping, and ecommerce brands top the list.

There’s been a lot of changes in the volume of email-based cyberattacks, according to security analysts at Abnormal Security. According to their H2 2022 Email Threat Report, the number of attacks per 1,000 mailboxes has increased over the last 12 months by nearly 50%. And if you take into consideration the all-time low in January of this year, the number of email-based attacks just six months later are nearly 4 times as much as at the beginning of 2022.

The overwhelming majority (68%) of email-based attacks were phishing attacks. Most of these attacks were targeting credentials using the impersonation of well-known brands. According to the report, nearly one-third (32%) impersonated a social network (LinkedIn was the top brand impersonated – something corroborated by a recent report from Checkpoint). One-fifth of phishing attacks impersonated Microsoft. In both cases, the predominant attack trait was an intent to steal the victim’s credentials to that platform.

The emails are well-written and look official. Here’s an example of one impersonating LinkedIn:

8-5-22 Image-1

Source: Checkpoint

And another impersonating Microsoft:

8-5-22 Image-2

Source: Checkpoint

Over 256 individual brands were impersonated – including financial services, ecommerce, business management, infosec, travel, telecom, and more. The goal is to obtain viable credentials that can be used to launch additional campaigns from a legitimate email account, access bank accounts, sell on the dark web for access to a corporate network, and more.

Phishing attacks are the root of the problem and require a layered solution that includes conditioning your users to remain vigilant each and every time they interact with an email – something taught through continual Security Awareness Training. The sooner users default to assuming any email that seems suspicious or unexpected is considered malicious until proven otherwise, the better for organizations today.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer

Topics: Phishing



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews