sb-au logo
Story image

Just 6,000 accounts responsible for over 100,000 email attacks - report

07 Aug 2020

The year 2020 will live in infamy for seemingly countless reasons, but in the world of cybersecurity, perhaps no attack will be ascribed as much notoriety than the email attack.

Now that the year is over halfway done, multiple reports on the state of cybersecurity have circulated around the world of IT – and one, released by Barracuda today, has outlined just how harmful email attacks can be.

According to the study, 6,170 malicious accounts that use Gmail, AOL, and other email services and were responsible for more than 100,000 business email compromise (BEC) attacks on nearly 6,600 organisations. 

In addition, up to 45% of all BEC attacks detected by the company since 1 April have been deemed ‘malicious’.

But how exactly do attackers go about this, and how did they become so dominant?

Of the 45% of attacks labelled malicious, most were repeated by the same user, and often targeted multiple organisations from the same email accounts. These attackers begin by registering email accounts with legitimate services to use them in impersonation and business email compromise attacks. 

To increase the odds of getting away with it, many use these accounts only a few times to avoid suspicion and lower the chances of being blocked or detected.

To further protect themselves, most attackers don’t use the same accounts for over a day.

In fact, 29% of malicious accounts used for only a 24-hour period. There are several reasons for the short life span of these accounts:

  • Malicious accounts may get reported and suspended by email providers
  • It’s easy for cybercriminals to register new accounts
  • Cybercriminals may temporarily abandon an account after initial attacks and then return to it after a long period of time

According to the report, Gmail is the email service of choice for most attackers – most likely due to its status as accessible, free and easy to register.

Meanwhile, the number of organisations attacked by each malicious account ranged from one to a single mass scale attack that impacted 256 organisations — 4% of all the organisations included in the research.

“While most malicious accounts are used by attackers for a short period of time, some cybercriminals used these accounts to launch attacks for over year,” says Barracuda sales engineer manager Mark Lukie. 

“It’s not unusual for cybercriminals to return and re-use an email address in attacks after a long break.

“With the help of innovative technologies such as AI-powered tools, organisations can get better at spotting spoofed and malicious emails,” says Lukie.

“Combined with a renewed focus on more progressive approaches to staff training, organisations can begin to fight back.”

Story image
Trend Micro launches cloud native security solution for modern applications and APIs
“Application security is an invaluable part of the Cloud One platform, integrating technology to provide superior protection for customers deploying applications wherever it makes the most sense for them."More
Story image
Data leakage concerns dominate cloud security perceptions - Bitglass report
How secure is the public cloud? That’s what many IT and security professionals are asking as data leakage becomes a pressing concern for organisations and their data protection strategies.More
Story image
NetMotion announces SASE platform leveraging Microsoft Azure
The platform offers integrated transport and web proxies, distributed firewalls, network access control (NAC), zero trust network access (ZTNA) or software-defined perimeters (SDP), a VPN highly optimised for mobile access, and AI-driven policy and risk analysis.More
Story image
The cybersecurity risks that come with re-onshoring Australian manufacturing
As technology such as IoT, robotic process automation (RPA) and artificial intelligence (AI) reshapes the manufacturing landscape, organisations are simultaneously put at an increased risk of a cyberattack.More
Story image
auticon highlight benefits of cognitive diversity on Disabilities Day
A timely reminder that many people on the autism spectrum are able to bring new ways of thinking and problem-solving to tech challenges.More
Story image
Ivanti looks to a brighter future with MobileIron and Pulse Secure acquisitions
Ivanti has acquired MobileIron and Pulse Secure, with the intention of delivering intelligent and secure experiences across all devices in the ‘everywhere enterprise’. More