Cybercriminals turn to email impersonation as businesses focus on security against malware

cybercriminal

With organisation preoccupied with the security challenge posed by malware, cybercriminals are switching impersonation attacks to bypass email security systems, according to research undertaken by Mimecast.

The global email and data security company has released its latest Email Security Risk Assessment (ESRA), which revealed that while most organisations are treating malicious attachments and spam as the main risk to email-related security, there is an increased risk of impersonation attacks as compared to attacks leveraging malware.

Mimecast reported impersonation attacks, which rely on duping recipients into wiring the attacker money or highly monetisable data, rose almost 50% quarter over quarter, whereas emails with malware attachments or dangerous files types, combined, only increased about 15%. Missed impersonation attacks were seen to occur more than 7 times as often as missed email-borne malware.

Ed Jennings, chief operating officer at Mimecast said these findings follow a recent PhishMe study, which found approximately two thirds of IT executives surveyed had dealt with a security incident originating from a deceptive email.

“Impersonation attacks are an easy and effective way to dupe unsuspecting victims by gaining trust through a combination of social engineering and technical means,” he said. “This latest ESRA report reveals that many email security providers are leaving organisations very vulnerable to these often hard to detect impersonation attacks. Cybercriminals know that many traditional email security services are improving their ability to stop email-borne malware, but remain ineffective against impersonation attacks.”

The latest ESRA reflects findings by inspecting the actual inbound email of almost 100,000 users over a cumulative 631 days received. These organisations used a variety of common email security systems. More than 55 million emails to date have been inspected as part of the Mimecast ESRA program, all of which had passed through the organisation’s incumbent email security vendor. Completed ESRA assessments have found more than 12,400,000 pieces of spam, 9,055 emails containing dangerous file types, 1,844 known and 691 unknown emails with malware attachments, and 18,971 impersonation attacks missed by incumbent providers and delivered to users’ inboxes.

Related: SMEs vulnerable to sophisticated email scam