Times of Oman

Impersonat­ion attacks surge by 400%: Study

This simple method of attack is being exploited at an alarming rate as it can be used to dupe recipients into initiating wire transfers and sending back other sensitive data leading to significan­t financial loss

- Times News Service

MUSCAT: The number of impersonat­ion attacks detected this quarter rose by more than 400 per cent quarter over quarter, in comparison to the data initially reported in the February 2017 Email Security Risk Assessment (ESRA).

Impersonat­ion attacks consist of social engineerin­g of heavy emails that attempt to impersonat­e a trusted party, such as a C-level executive, employee or business partner.

This simple method of attack is being exploited at an alarming rate as it can be used to dupe recipients into initiating wire transfers and sending back other sensitive data leading to significan­t financial loss—as evidenced by the widely publicised recent attacks, according to Mimecast.

Mimecast is a leading email and data security company, and it released on Monday the latest quarterly release of Mimecast ESRA.

In fact, a public service announceme­nt issued by the United States’ Federal Bureau of Investigat­ion (FBI) stated that between October 2013 and December 2016, business e-mail compromise scams resulted in a total loss of more than US$5.3 billion. Between January 2015 and December 2016 alone, there was a 2,370 per cent surge in identified exposed losses.

In its second quarterly assessment, Mimecast found that both known and unknown attacks, as well as spam, are continuing to get through incumbent e-mail security systems. In addition and of particular concern, are emails that contain no malware, and instead rely on duping recipients into re- sponding to a request that usually involves sending the attacker money or highly monetisabl­e data.

These points were addressed in a January 2017 commission­ed Forrester Consulting study entitled, “Closing the Cloud Security E-mail Gap,” which recommende­d that organisati­ons engage with a trusted third-party security vendor to more effectivel­y close the gap in their e-mail security.

This latest ESRA reflects findings from inspecting inbound email for more than 44,000 users over a cumulative 287 days received by participat­ing organisati­ons. In aggregate, to date more than 40 million e-mails have been inspected by Mimecast, all of which had already passed through the incumbent email security vendor or cloud email service in use by each organisati­on.

Newspapers in English

Newspapers from Oman