Major airlines fail to block fraudulent emails

Email warning
(Image credit: Shutterstock)

As travelers wait to hear back from airlines about new flights now that travel bans are being lifted, new research from Proofpoint has revealed the majority of international airlines are leaving their customers exposed to email fraud.

Although the travel sector has always been a potential target for cyberattacks, the pandemic has provided cybercriminals with new opportunities to target global travelers.

In its examination of the 296 member airlines of the International Air Transport Association (IATA), Proofpoint discovered that more than half (61%) of these organizations do not have a published DMARC (Domain-based Message Authentication, Reporting & Conformance) record. This makes these airlines potentially more susceptible to cybercriminals spoofing their identity which increases the risk that their customers will be targeted in email fraud attacks.

Additionally, a massive 93 percent of global airlines have not implemented the strictest and recommended level of DMARC protection. This setting and policy is known as “Reject” and it is capable of blocking fraudulent emails from reaching their intended targets. Proofpoint's research shows that only seven percent of airlines are proactively blocking fraudulent emails from reaching the inboxes of their customers.

DMARC adoption

By failing to implement adequate email protection, international airlines are leaving themselves open to phishing, impersonation attacks and other unauthorized use of corporate domains. However, DMARC adoption levels to differ from region to region.

Out of the regions classified by IATA, China & North Asia has the lowest level of DMARC adoption with 85 percent of airlines operating in the region having no published policy at all. This is followed by the Asia Pacific region (70%), EMEA (57%) and The Americas (43%).

When it comes to proactively protecting their customers against email fraud, China & North Asia fares the worst with 100 percent of its carriers not having DMARC's Reject policy in place followed by EMEA (93%) and APAC and The Americas (both at 89%).

Using strong email protection is highly recommended for all organizations as it will prevent cybercriminals from impersonating your brand and launching phishing attacks on your customers.

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras