Malicious emails are a major security risk for many organizations. Email remains an important communication method for most organizations even though personal communication is migrating more to text, Facebook Messenger, LinkedIn Message, WhatsApp and various Asian apps.
However, malicious emails at organizations continue to lead to data breaches and ransomware attacks that can be:
- Disruptive to business operations.
- Expensive to recover from.
- Embarrassing to the reputation of the organization.
Reduce email attacks
Organizations can significantly reduce the risk and serious damage of successful email attacks by:
- Training their employees to recognize suspicious emails and not respond.
- Implementing Advanced Endpoint Protection (AEP) on their internal network. AEP typically includes antivirus, firewall and proactive network traffic monitoring.
- Implementing spam filtering on their email servers to complement what their ISP is already doing.
- Turning on the spam filter on every workstation.
- Implementing two-factor authentication.
- Implementing challenge questions that only the actual employee can answer.
- Keeping their operating systems and browser software up to date on all internal network devices.
This blog describes the major types of malicious email attacks.
Phishing attacks
Phishing attacks consist of fake emails sent to unsuspecting employees. Each email contains a link to a website controlled by the attacker. The goal of phishing emails is to acquire the login credentials of your employees as a prelude to impersonating the employee or stealing their identity. See the example email at left.
When an unsuspecting employee clicks on the link, a web page appears. An example fake web page, that impersonates the TD Bank, is shown below.
You can tell it’s fake because, in the address line, TD Bank is not part of the domain name and because the web page does not use https for encryption as all banks and most other websites do.
The unsuspecting employee then enters their credentials to log in. However, no actual login will occur. The attacker captures the credential information and displays a confusing dialogue box about the server being down.
Login credentials have become more powerful in their capability. As the use of single login services to multiple applications and cloud-based tools and applications such as Microsoft Office 365, G Suite, Zoho, and ERP system increases, the potential disruptive impact of someone impersonating an employee has grown enormously.
Other examples of phishing attack emails include requests:
- For payment of a supposed outstanding invoice.
- To reset your password or verify your account.
- For verification of purchases you never made.
- To confirm billing information.
The attacker then uses the stolen login credentials to:
- Steal company data for resale.
- Initiate payment of fake invoices while impersonating the employee.
- Mount a ransomware attack.
- Clean out personal bank accounts using identity of the employee.
- Create horrific posts on social media that undermine the reputation of the organization and the employee.
Malware attacks
Malware attacks consist of fake emails sent to unsuspecting employees. The goal of every malware email is to lure the employee into double-clicking on an attachment icon. Masquerading as a document, the attachment is in fact a malware program, which if executed, can then propagate itself to many workstations and servers on the network.
The malware program communicates its successful infiltration to the control server of the attacker. The attacker will then use the malware program to initiate one of the following actions:
- A data breach of sensitive corporate data and personal information of customers and employees for resale.
- A ransomware attack by encrypting the files on the infiltrated network.
An example dialogue box that requests a ransomware payment and indicates the workstation has been encrypted is shown below.
For more information about phishing, please read this article: Why your phishing defence strategy needs to involve humans, not just tech
What strategies would you recommend to reduce the risk of serious impacts of malicious emails? Let us know in the comments below.