Your The Majority of Business Email Compromise Phishing Attacks Initially Go for Credentials, Not Money

Stu Sjouwerman | Jul 6, 2021

BEC Phishing AttacksWith BEC attacks historically trying to get to the “committing fraud” part as quickly as possible, new data shows threat actors are taking their time, looking for a larger payoff.

I’ve published a few articles this week around the current state of Business Email Compromise all based on GreatHorn’s 2021 Business Email Compromise Report and want to finish the week up with some enlightening details around who’s being targeted and what, initially, are cybercriminals after when the attack vector is BEC.

According to the report, threat actors are effectively using spear phishing, doing diligence and targeting some very specific roles and departments within the organization:

  • Finance, 57% of the time
  • The CEO, 22% of the time
  • IT, 20% of the time
  • HR, 9% of the time

But what makes this so interesting is to see exactly what the trap is that’s set with the spear phishing email. According to the GreatHorn data, threat actors have pivoted from social engineering tactics (attempting to trick someone into committing fraud) and have moved to the creating malicious links to websites intent on the following:

  • Capturing online credentials (57%)
  • Infecting the victim’s endpoint with malware (22%)
  • Payment fraud (20%)

So, cybercriminals now see the value of trying to gain access over the simple committing of fraud (although it’s still alive and well). In response, it’s imperative that organizations empower all their users to see these phishing attacks for what they are, despite the illusion of credibility the attackers create with their spear phishing emails. This is possible using Security Awareness Training designed to continually educate users on new attacks, their tactics, and how to spot them.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.