Business email compromise (BEC) attacks are becoming more frequent and now make up the majority of phishing attempts, with attackers developing more sophisticated means of evading email security solutions, according to research from Vipre Security Group.
The IT security provider has released its latest report, Email Threat Trends: Q3 2024, detailing the malicious nature of over 208 million emails found through its platform.
According to the data, last quarter scam emails took the lead at 34%, followed by commercial spam (30%), phishing (20%), and malware (11%).
Among those emails, most (64%) used attachments to lure victims, while only 36% employed links. That’s a sharp turn from just last quarter when links were the tool of choice, with 86% of malicious emails using them.
Vipre’s research highlights the disconnect between these changing trends and the increasing prioritisation of higher profile threats like ransomware and malware, though these only represent a fraction of email attacks, comprising less than 20%.Â
Instead, the report argues that the real challenge lies in building defences against more subtle methods of attack, such as scams and phishing, which account for the majority of email-based threats.
Among phishing emails containing links, over half (52%) deployed URL redirection, a tactic utilising a ‘clean’ URL within the body of the email, and then redirects the user to a malicious one once inside, with another 23% making use of compromised websites that look convincing enough to fool users and gain their trust.
Business email compromise (BEC) accounted for well over half (58%) of all phishing attempts, with the manufacturing sector being the most highly targeted for attack, accounting for over a quarter (27%) of malicious emails, followed by the energy sector (23%), retail (10%), utilities (7%), and real estate (6%).
Vipre reported that 89% of the BEC attacks it intercepted involved impersonating authority figures, a common tactic frequently used in these types of scams. The most impersonated roles were CEOs and executives (57%), directors, managers, and supervisors (26%), and IT personnel (9%).
Recommended reading
- Ransomware Groups are Adjusting Their Strategies
- Comment | The Rise in QR Code Attacks
- 82% of Phishing Toolkits Use Deepfakes
Using AI detector tools, Vipre claims it discovered that 36% of BEC emails in Q3 were crafted using genAI tools, with criminals using them to provide word-perfect, convincing emails that mimicked business leaders and decision makers.
With attackers now taking care to get the tone, context, and content of these impersonations exactly right, employees are being urged to exercise more caution when replying to what looks to be an internal email, especially if it directs them to another site.Â
According to Vipre, a good rule of thumb is to craft a separate message to the original sender, away from the original thread, to double check details, especially when finances are concerned.





