Email security is greater threat than ever

Image Credit: Pixabay (Image credit: Image Credit: Geralt / Pixabay)

Emails containing malicious URLs are up by 125 percent when compared to last quarter according to new research from Mimecast.

The email and data security company's latest Email Security Risk Assessment (ESRA) report has revealed that the delivery of emails containing malicious URLs is on the rise as the lines between email and web security are blurring.

This is the first year that Mimecast has tested for malicious URLs in its ESRA report and the firm detected 463,546 malicious URLs in over 28m emails that were deemed “safe” by an organization's existing email security system for an average of one malicious URL in every 61 emails.

The firm also conducted recent research with Vanson Bourne independently to confirm that malicious URLs are a rampant problem with 45 percent of 1,025 respondents saying the volume of these URL-based attacks has increased over the last year.

Undetected email attacks

In addition to malicious URLs, Mimecast's latest ESRA report also found 24m spam emails, 26,713 malware attachments, 53,753 impersonation attacks and 23,872 dangerous file types. In total, the firm inspected over 230m emails that contained a variety of attack types missed by today's security solution providers that put both organizations and individuals at risk.

Cybersecurity strategist at Mimecast Matthew Gardiner provided further insight on the ESRA report's findings, saying:

“Email and the web are natural complements when it comes to the infiltration of an organization. Email delivers believable content and easily clickable URLs, which then can lead unintended victims to malicious web sites. URLs within emails are literally the point of intersection between email and the web. Organizations need the visibility across both channels in order to have the protection required to stay on top of today’s ever evolving and expanding threats and having a single vendor in an integrated solution can help. Cybercriminals are constantly looking for new ways to evade detection, often turning to easier methods like social engineering to gain intel on a person or pulling images from the internet to help ‘legitimize’ their impersonation attempts to gain credentials or information from unsuspecting users.” 

Mimecast's research with Vanson Bourne also brought attention to the fact that impersonation fraud continues with 41 percent of respondents reported seeing an increase in impersonation fraud from vendors or business partners asking for money, sensitive information or credentials. Furthermore, 38 percent said they've seen an increase of impersonation fraud from well-known internet brands.

  • Protect yourself from the latest cyber threats with the best antivirus
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
WhatsApp
WhatsApp just made its AI impossible to avoid – but at least you can turn it off
ChatGPT vs Gemini comparison
I compared GPT-4.5 to Gemini 2.0 Flash and the results surprised me
Apple iPhone 16 Plus
Apple officially delays the AI-infused Siri and admits, ‘It’s going to take us longer than we thought’
The Meta Quest Pro on its charging pad on a desk, in front of a window with the curtain closed
Samsung, Apple and Meta want to use OLED in their next VR headsets – but only Meta has a plan to make it cheap
AMD Ryzen 9000 3D chips
AMD officially announces price and release date for Ryzen 9 9900X3D and 9950X3D processors
Google Pixel 9
There's something strange going on with Google Pixel phone vibrations after the latest update