HomeSecurity99% of email attacks are based on opening malicious links

99% of email attacks are based on opening malicious links

Email - based cyberattacks are among the most common. For an attack to be successful, the victim must (usually) open a link, which most often takes them to a malicious page. From there, the hacker can do whatever he has planned.e-mail

Hackers often use vulnerabilities and exploit kits to compromise victims' systems. However, for a higher success rate, human intervention is also needed. According to Proofpoint's annual report, 99% of hacking campaigns are based on human error, namely opening malicious attachments.

Of course, it is not right to blame users for falling victim phishing attacks. Hackers have evolved their techniques and their attacks are increasingly sophisticated. Many times, it is difficult to distinguish a malicious email from a normal one. Scammers do everything they can to make the message look normal. In addition, they make sure that the email comes from a trusted person, friend, colleague, manager, or from a well-known company or service, such as Microsoft or Google , etc.

This technique, social engineering, is very basic to carrying out successful attacks.

Furthermore, the Proofpoint report showed that hackers, before attacking, learn some basic things about the victim’s work and daily life. They do this in order to act in a way that will not arouse suspicion and have a better chance of success. For example, if they send an email in the middle of the night, which is supposed to come from the manager, it may seem suspicious (if the manager does not usually send at night). However, if they send it during work, it will look normal.

99% of email attacks are based on opening malicious links

Phishing attacks are one of the most effective cyberattacks. Many hackers prefer them because they are cheap, easy , and have a high success rate.

Kevin Epstein, vice president of cyberthreats at Proofpoint, said that cybercriminals choose to attack with this method because sending fake emails with malicious attachments and stealing credentials is much easier and more profitable than creating a costly and time-consuming exploit, which may ultimately not be successful.

He then said: “To significantly reduce risk, organizations need a holistic approach to cybersecurity , which will include effective employee training and awareness about security and multi-layered defense.”

Hackers are evolving their techniques to make emails appear legitimate and normal. However, a suspicious user can detect malicious activity.

For example, emails that arrive unannounced and ask for something to be done immediately (i.e., it is something urgent) may be suspicious. If the user or employee is unsure, they can contact the sender to verify if everything is okay.

Additionally, in the event that the email comes from a cloud service, users should be aware that Microsoft or Google do not ask users to click on irrelevant links and enter their credentials.

Finally, businesses and companies should take care of the security of their systems by making regular updates and using protection programs to avoid malware in the event that an employee opens a malicious attachment.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS