File-Sharing Phishing Attacks Surge 350%, According to New Research From Abnormal Security
이 글자크기로 변경됩니다.
(예시) 가장 빠른 뉴스가 있고 다양한 정보, 쌍방향 소통이 숨쉬는 다음뉴스를 만나보세요. 다음뉴스는 국내외 주요이슈와 실시간 속보, 문화생활 및 다양한 분야의 뉴스를 입체적으로 전달하고 있습니다.
SAN FRANCISCO -- Businesswire -- Abnormal Security (https://cts.businesswire.com/ct/CT?id=smartlink&url=http%3A%2F%2Fabnormalsecurity.com%3Futm_source%3Dbusinesswire%26utm_medium%3DPR%26utm_content%3Dh2-2024-threatreport&esheet=54108849&newsitemid=20240814650661&lan=en-US&anchor=Abnormal+Security&index=1&md5=902fb951dcd2399bbccdfc9c15862b8b), the leader in AI-native human behavior security, today released its H2 2024 Email Threat Report (https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fabnormalsecurity.com%2Fresources%2Fh2-2024-report-file-sharing-phishing-attacks%3Futm_source%3Dbusinesswire%26utm_medium%3DPR%26utm_content%3Dh2-2024-threatreport&esheet=54108849&newsitemid=20240814650661&lan=en-US&anchor=H2+2024+Email+Threat+Report&index=2&md5=4ee8a50fd4d0aa5389d53b7cdfa9a702), revealing the growing threat of file-sharing phishing attacks, whereby threat actors use popular file-hosting or e-signature solutions as a disguise to manipulate their targets into revealing private information or downloading malware.
Sophisticated File-Sharing Phishing Attacks on the Rise
Examining data collected between June 2023 and June 2024, Abnormal saw file-sharing phishing volume more than triple, increasing 350% over the year. The majority of these attacks were sophisticated in nature, with 60% exploiting legitimate domains, most commonly webmail accounts, such as Gmail, iCloud, and Outlook; productivity and collaboration platforms; file storage and sharing platforms like Dropbox; and e-signature solutions like Docusign.
“The trust that people place in these kinds of services—especially those with recognizable brand names—makes them the perfect vehicle for launching phishing attacks,” said Mike Britton, chief information security officer at Abnormal Security. “Very few companies block URLs from these services because they aren’t inherently malicious. And by dispatching phishing emails directly from the services themselves, attackers hide in plain sight, making it harder for their targets to distinguish between legitimate and malicious communications. And when attackers layer in social engineering techniques, identifying these attacks becomes near-impossible.”
Finance and Built Environment Firms are Most Vulnerable
The finance industry was found to be most at risk, with file sharing phishing attacks making up one in ten attacks. As financial institutions rely on file-sharing platforms to securely exchange documents, attackers have ample opportunities to slip in a fraudulent file-sharing notification among the sea of invoices, contracts, investment proposals, and regulatory updates.
The second most vulnerable industry was construction and engineering, followed by real estate and property management companies. These sectors not only rely heavily on frequent document transfers via file-sharing platforms, but also involve time-sensitive projects with large payouts. By exploiting the urgency of these exchanges, attackers have an opportunity to send file-sharing phishing attacks that appear time-critical and blend in seamlessly with legitimate emails.
BEC and VEC Remain Persistent Threats
The biannual report also revealed the continued growth of business email compromise (BEC) and vendor email compromise (VEC) attacks:
· BEC attacks grew by more than 50% over the last year, with attacks on smaller organizations jumping nearly 60% in the last half. · 41% of Abnormal customers were targeted by VEC each week in the first half of 2024, a slight increase over the 37% targeted in the second half of 2023. · Construction and engineering firms, as well as retailers and consumer goods manufacturers, were most vulnerable to VEC attacks, with 70% of organizations receiving at least one VEC attack in the first half of the year.
Britton continued, “Cybercriminals are continuing to use email to target human behavior, and through a variety of techniques—whether it’s leveraging social engineering tactics for BEC, or using the guise of legitimate applications in their phishing schemes. The report findings underscore this deliberate shift away from overt payloads and threat signatures, and toward email attacks designed to manipulate behavior. Keeping up with these threats will require organizations to adapt accordingly, recentering their defenses on protecting humans as their most vulnerable endpoints.”
Download the full H2 2024 Email Threat Report, “Bait and Switch: File-Sharing Phishing Attacks Surge 350%”, here (https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fabnormalsecurity.com%2Fresources%2Fh2-2024-report-file-sharing-phishing-attacks%3Futm_source%3Dbusinesswire%26utm_medium%3DPR%26utm_content%3Dh2-2024-threatreport&esheet=54108849&newsitemid=20240814650661&lan=en-US&anchor=here&index=3&md5=a0116a9af70b2f2919dfa506896fefc0).
About Abnormal Security
Abnormal Security is the leading AI-native human behavior security platform, leveraging machine learning to stop sophisticated inbound attacks and detect compromised accounts across email and connected applications. The anomaly detection engine leverages identity and context to understand human behavior and analyze the risk of every cloud email event—detecting and stopping sophisticated, socially-engineered attacks that target the human vulnerability.
You can deploy Abnormal in minutes with an API integration for Microsoft 365 or Google Workspace and experience the full value of the platform instantly. Additional protection is available for Slack, Workday, Salesforce, ServiceNow, Zoom, Amazon Web Services and multiple other cloud applications.
View source version on businesswire.com: https://www.businesswire.com/news/home/20240814650661/en/
이 뉴스는 기업·기관·단체가 뉴스와이어를 통해 배포한 보도자료입니다.
출처:Abnormal Security
보도자료 통신사 뉴스와이어(www.newswire.co.kr) 배포
Copyright © 뉴스와이어. 무단전재 및 재배포 금지.
- 현대자동차 ‘아이오닉 9’ 내장 티저 이미지 공개 - 뉴스와이어
- 한국의길과문화 ‘대한민국을 걷다 - 코리아둘레길 45선 완벽 가이드’ 출간 - 뉴스와이어
- 사진만 올리면 바로 원하는 렌즈 찾아준다… 윙크컴퍼니, AI 기반 ‘윙크 렌즈 찾기’ 기능 도입
- 삼성전자, 당일 배송·설치 서비스 시작 - 뉴스와이어
- 국내 최대 과일전시회 ‘2024 대한민국 과일산업대전’ 개최 - 뉴스와이어
- 텍트로닉스, 전력 측정의 새 지평을 여는 혁신 솔루션 2종 출시 - 뉴스와이어
- KCM, 24년 겨울 스페셜 콘서트로 만나다… 기획 A2Z엔터·유니온픽처스 - 뉴스와이어
- 오픈소스마케팅, 2024 관광기업 데이터 분석 환경 구축 및 마케팅 지원사업 성공적 마무리… 평균
- SK네트웍스, 3분기 매출 2조428억원·영업이익 286억원 달성 - 뉴스와이어
- 러너스, 결혼 준비를 위한 온라인 웨딩플래너 ‘푸딩’ 론칭 - 뉴스와이어