Despite major improvements in how organizations can block millions of cyber attacks, email threats are able to break through defenses because hackers are continually morphing them to be more complex and sophisticated, Barracuda said in a new phishing research report.
March 28, 2022
It’s not just code that cyber attackers are modifying, it’s also tactics, Barracuda wrote in the report, entitled Spear Phishing: Top Threats and Trends Vol. 7. Cyber threat actors are moving from high volume assaults to more targeted maneuvers, such as from malware to social engineering and from lone operators to organized criminal enterprises laying down attacks that can begin with a single phishing email, according to the report.
Here are some key findings from the study:
Email-spawned threat types vary in complexity. Barracuda identified 13 variants, including:
Spam.
Spam and malware are at the lower end of complexity, while account takeover and lateral phishing are more sophisticated attack types.
To protect their businesses and users, organizations need to invest in technology to block attacks and in training their employees to act as the last line of defense, Barracuda said.
Chief among best practices are the following:
“Small businesses often have fewer resources and lack security expertise, which leaves them more vulnerable to spear-phishing attacks, and cyber criminals are taking advantage,” said Don MacLennan, Barracuda’s email protection engineering and product management senior vice president. “That’s why it’s important for businesses of all sizes not to overlook investing in security, both technology and user education. The damage caused by a breach or a compromised account can be even more costly.”
This article was originally published on msspalert.com on March 18, 2022. Written by D. Howard Kass.
August 24, 2022