Fight the Phish

Twenty years ago, I told people, “Don’t open emails from people you don’t know.”  Fast forward to 2024 and that is still true. Threat actors are impersonating people we know which has created a shift in our thinking toward email security. We still should not open emails from senders we do not know but that is not enough; now the approach is to question every email. It may appear overwhelming; however, proper, and continuous training equips people to quickly separate most legitimate emails from phishing attacks.

The security awareness training programs developed ten years or even five years ago are outdated. They were not designed to keep pace with the advances that threat actors have made in phishing attacks and the attacks are only going to increase.

Here are 2024 statistics from TrendMicro for phishing:

  1. Surge in Phishing Attacks

Phishing attacks grew by 58% last year, marking it as one of the fastest-growing cyber threats. Organizations must remain vigilant and adapt their security strategies accordingly.

  • Email Phishing Dominance

Email remains the most common vector for phishing attacks, accounting for a staggering 65% of all phishing attempts. Attackers are now crafting more convincing and realistic-looking emails to deceive recipients effectively.

  • Spear Phishing Targets High-Value Individuals

Spear phishing attacks, which are highly targeted and personalized, have risen by 30%. These attacks often focus on high-value individuals within organizations, such as executives and financial officers. Vigilance among leadership is crucial.

  • Escalating Phishing Success Rate

The success rate of phishing attacks has climbed to 18%, up from 14% last year. This alarming trend indicates that attackers are becoming more adept at bypassing security measures and manipulating victims.

  • Credential Theft Remains the Goal

An astonishing 70% of phishing attacks aim for credential theft. Cybercriminals seek unauthorized access to corporate networks and sensitive data, emphasizing the importance of robust authentication mechanisms.
(Top 15 Phishing Stats to Know in 2024 | Trend Micro News)

Sitting through a one to two-hour security awareness training session once a year does not adequately prepare employees for dealing with the threat landscape of today. Think of it another way, if you wanted a successful mission to Mars, would you train the astronauts on mission critical task for one hour in a year? Probably not.

Advances in technology have given threat actors the ability to become more sophisticated in their attacks but, oddly enough, it is the simple phishing attempts that often have the most success. Attackers often deploy a “spray and pray” technique, sending out hundreds of thousands of phishing emails hoping someone will open the attachment in the email or click on the link the embed. Once you do, they have you!

So how do you avoid falling prey to a phish? Train more often, apply the fundamentals of security awareness training, and read, do not scan, your emails. Here are some things to indicate a suspicious email:

  • Sender’s name does not match the email address in <sender’s email>.
  • The email was unexpected.
  • There is a heightened sense of urgency to get you to do something.
  • Message composition is unusual. Does the sender normally write this way?
  • Asking for information they should already have.
  • Asking for personal information.
  • Do you have to click on a link or open an attachment to complete a task?
  • Domain name is slightly off (i.e., service instead of services).

Here is an example of a real-world phishing attempt with the recipient’s name and email address redacted. Notice anything unusual?

Here is the same message with red flags indicated suspicious areas of the message. Were you able to identify the indicators of the phish?

Continuous training that evolves with the threat landscape will keep you alert and keep your phish detecting skills honed.

“We don’t rise to the level of our expectations; we fall to the level of our training.” Archilochus


Kevin Hutchinson, CISSP, CCP
Core Cyber, LLC
Owner/Operator