{"id":55097,"date":"2023-05-04T10:59:14","date_gmt":"2023-05-04T17:59:14","guid":{"rendered":"http:\/\/www.enxmag.com\/twii\/?p=55097"},"modified":"2023-05-04T13:53:38","modified_gmt":"2023-05-04T20:53:38","slug":"response-based-business-email-compromise-contributes-to-97-of-attacks","status":"publish","type":"post","link":"https:\/\/www.enxmag.com\/twii\/the-week-in-imaging-twii\/editors-blog\/2023\/05\/response-based-business-email-compromise-contributes-to-97-of-attacks\/","title":{"rendered":"Response-Based Business Email Compromise Contributes to 97% of Attacks"},"content":{"rendered":"\n<div class=\"wp-block-image\"><figure class=\"alignleft size-medium\"><img loading=\"lazy\" width=\"300\" height=\"228\" src=\"https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2023\/05\/KnowB34-300x228.jpg\" alt=\"\" class=\"wp-image-55099\" srcset=\"https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2023\/05\/KnowB34-300x228.jpg 300w, https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2023\/05\/KnowB34.jpg 318w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/figure><\/div>\n\n\n\n<p>The malware-less and seemingly benign nature of business email compromise emails, mixed with impersonation techniques, are difficult to spot as being malicious, making them even more dangerous.<\/p>\n\n\n\n<p>I\u2019ve covered both the threat of business email compromise and response-based email attacks before. How can I not? They are prominent techniques used by phishing scammers everywhere. But it\u2019s the reported combination of the two by Phish Labs that has me concerned. Representing the overwhelming lion\u2019s share of all email threat volume reported, the use of such business-toned, long-tailed email attacks is a greater danger to organizations.<\/p>\n\n\n\n<p>Take the following example, provided by Phish Labs:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" width=\"521\" height=\"183\" src=\"https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2023\/05\/Phishexample.jpg\" alt=\"\" class=\"wp-image-55098\" srcset=\"https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2023\/05\/Phishexample.jpg 521w, https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2023\/05\/Phishexample-300x105.jpg 300w\" sizes=\"(max-width: 521px) 100vw, 521px\" \/><figcaption>Source: Phish Labs<\/figcaption><\/figure>\n\n\n\n<p>Note there\u2019s no malicious attachment or link that a security solution can scan. This is pure social engineering; the assumption is that Angela either works directly for Ken or Ken is a few rungs higher on the corporate ladder. So, the urgency is created not in the message\u2019s tone, but in the establishing of who is sending the email and what\u2019s being asked. Additionally, the request for a mobile phone is to take the conversation to a medium where there is no sender email to verify, and so that the conversation is controlled.<\/p>\n\n\n\n<p>These kinds of emails are why users within organizations need to undergo continual Security Awareness Training so that they maintain a sense of vigilance \u2013 especially when an email comes in that feels like there\u2019s zero maliciousness to it.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The malware-less and seemingly benign nature of business email compromise emails, mixed with impersonation techniques, are difficult to spot as being malicious, making them even more dangerous. I\u2019ve covered both the threat of business email compromise and response-based email attacks before. How can I not? They are prominent techniques used by phishing scammers everywhere. But it\u2019s the reported combination of the two by Phish Labs that has me concerned. Representing the overwhelming lion\u2019s share of all email threat volume reported, the use of such business-toned, long-tailed email attacks is a greater danger to organizations. Take the following example, provided by Phish Labs: Note there\u2019s no malicious attachment or link that a security solution can scan. This is pure social engineering; the assumption is that Angela either works directly for Ken or Ken is a few rungs higher on the corporate ladder. So, the urgency is created not in the message\u2019s tone, but in the establishing of who is sending the email and what\u2019s being asked. Additionally, the request for a mobile phone is to take the conversation to a medium where there is no sender email to verify, and so that the conversation is controlled. These kinds of emails are why users within organizations need to undergo continual Security Awareness Training so that they maintain a sense of vigilance \u2013 especially when an email comes in that feels like there\u2019s zero maliciousness to it.<\/p>\n","protected":false},"author":178,"featured_media":55099,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[80,1650,82,3371,1638],"tags":[4164],"_links":{"self":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/55097"}],"collection":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/users\/178"}],"replies":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/comments?post=55097"}],"version-history":[{"count":2,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/55097\/revisions"}],"predecessor-version":[{"id":55117,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/55097\/revisions\/55117"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/media\/55099"}],"wp:attachment":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/media?parent=55097"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/categories?post=55097"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/tags?post=55097"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}