One in five email attacks uses compromised accounts

(Image credit: Image Credit: Evannovostro / Shutterstock)

Account takeover-based (ATO) attacks now comprise 20 percent of all advanced email attacks according to new research from the email security and protection company Agari.

The firm's recently published Q1 2018 Email Fraud & Identity Deception Trends report found that ATO attacks are rising in popularity among cybercriminals because they are more difficult to detect than traditional attacks and can bypass email filters since they are sent from a real sender's email account.

Senior Director of Threat Research at Agari, Crane Hassold provided further insight on the treat posed by ATO attacks, saying:

“Credential phishing was already a huge risk for organizations because of the potential for data breach, but now there is a new wave of account takeover attacks leveraging compromised accounts to commit additional fraud, which evade traditional email security controls. Business email compromise attacks are still very active, especially against C-suite targets.” 

Advanced email attacks

According to Agari's Cyber Intelligence Division, brand impersonation remains the most common attack vector and this technique was used in 50 percent of advanced email attacks during Q4 2018 with cybercriminals impersonating Microsoft in 70 percent of these instances. Microsoft is often a target for credential phishing since attackers can use Office 365 accounts in subsequent ATO attacks.

However, a different pattern was identified when it came to attacks against executive targets with 33 percent of advanced email attacks against C-level employees using display name deception to impersonate an individual. This tactic is also commonly used for business email compromise (BEC) attacks that frequently target an organisation's CFO.

With the approach of tax season in the US, impersonation of the US Internal Revenue Service (IRS) surged in the fourth quarter. The IRS was impersonated in nearly one in ten attacks which is up from less than one percent in the third quarter.

W-2 scams occur quite often in the runup to tax season, as cybercriminals utilise phishing emails and social engineering to obtain a business' W-2 files which contain a wealth of sensitive information such as social security numbers, salaries and other confidential data that is used to commit tax fraud or identity theft.

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Passwordless authentication continues to grow, with biometrics helping push adoption
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
Google Gemini Flash 2.0 Images
I tried Gemini's new AI image generation tool - here are 5 ways to get the best art from Google's Flash 2.0
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung Galaxy S26 Ultra could resurrect an intriguing camera feature
Eurocom Raptor X18
At $15,000, this massive 256GB RAM laptop makes Apple's MacBook Pro look affordable, tiny and very, very slow
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A close up of The Daily podcast from Pocket Casts' web page
‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web player free to all