Site navigation

BEC Threats Surge as Attackers Outsmart Email Security

Tom Quinn

,

business email compromise
89% of BEC attacks involved impersonating business leaders and decision makers, with over a third being made using genAI tools.

Business email compromise (BEC) attacks are becoming more frequent and now make up the majority of phishing attempts, with attackers developing more sophisticated means of evading email security solutions, according to research from Vipre Security Group.

The IT security provider has released its latest report, Email Threat Trends: Q3 2024, detailing the malicious nature of over 208 million emails found through its platform.

According to the data, last quarter scam emails took the lead at 34%, followed by commercial spam (30%), phishing (20%), and malware (11%).

Among those emails, most (64%) used attachments to lure victims, while only 36% employed links. That’s a sharp turn from just last quarter when links were the tool of choice, with 86% of malicious emails using them.

Vipre’s research highlights the disconnect between these changing trends and the increasing prioritisation of higher profile threats like ransomware and malware, though these only represent a fraction of email attacks, comprising less than 20%. 

Instead, the report argues that the real challenge lies in building defences against more subtle methods of attack, such as scams and phishing, which account for the majority of email-based threats.

Among phishing emails containing links, over half (52%) deployed URL redirection, a tactic utilising a ‘clean’ URL within the body of the email, and then redirects the user to a malicious one once inside, with another 23% making use of compromised websites that look convincing enough to fool users and gain their trust.

Business email compromise (BEC) accounted for well over half (58%) of all phishing attempts, with the manufacturing sector being the most highly targeted for attack, accounting for over a quarter (27%) of malicious emails, followed by the energy sector (23%), retail (10%), utilities (7%), and real estate (6%).

Vipre reported that 89% of the BEC attacks it intercepted involved impersonating authority figures, a common tactic frequently used in these types of scams. The most impersonated roles were CEOs and executives (57%), directors, managers, and supervisors (26%), and IT personnel (9%).


Recommended reading


Using AI detector tools, Vipre claims it discovered that 36% of BEC emails in Q3 were crafted using genAI tools, with criminals using them to provide word-perfect, convincing emails that mimicked business leaders and decision makers.

With attackers now taking care to get the tone, context, and content of these impersonations exactly right, employees are being urged to exercise more caution when replying to what looks to be an internal email, especially if it directs them to another site. 

According to Vipre, a good rule of thumb is to craft a separate message to the original sender, away from the original thread, to double check details, especially when finances are concerned.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data