간편하게 보는 뉴스는 유니콘뉴스
File-Sharing Phishing Attacks Surge 350%, According to New Research From Abnormal Security

· 등록일 Aug. 15, 2024 14:30

· 업데이트일 2024-08-16 00:00:26

SAN FRANCISCO--(Business Wire / Korea Newswire)--Abnormal Security, the leader in AI-native human behavior security, today released its H2 2024 Email Threat Report, revealing the growing threat of file-sharing phishing attacks, whereby threat actors use popular file-hosting or e-signature solutions as a disguise to manipulate their targets into revealing private information or downloading malware.

Sophisticated File-Sharing Phishing Attacks on the Rise

Examining data collected between June 2023 and June 2024, Abnormal saw file-sharing phishing volume more than triple, increasing 350% over the year. The majority of these attacks were sophisticated in nature, with 60% exploiting legitimate domains, most commonly webmail accounts, such as Gmail, iCloud, and Outlook; productivity and collaboration platforms; file storage and sharing platforms like Dropbox; and e-signature solutions like Docusign.

“The trust that people place in these kinds of services—especially those with recognizable brand names—makes them the perfect vehicle for launching phishing attacks,” said Mike Britton, chief information security officer at Abnormal Security. “Very few companies block URLs from these services because they aren’t inherently malicious. And by dispatching phishing emails directly from the services themselves, attackers hide in plain sight, making it harder for their targets to distinguish between legitimate and malicious communications. And when attackers layer in social engineering techniques, identifying these attacks becomes near-impossible.”

Finance and Built Environment Firms are Most Vulnerable

The finance industry was found to be most at risk, with file sharing phishing attacks making up one in ten attacks. As financial institutions rely on file-sharing platforms to securely exchange documents, attackers have ample opportunities to slip in a fraudulent file-sharing notification among the sea of invoices, contracts, investment proposals, and regulatory updates.

The second most vulnerable industry was construction and engineering, followed by real estate and property management companies. These sectors not only rely heavily on frequent document transfers via file-sharing platforms, but also involve time-sensitive projects with large payouts. By exploiting the urgency of these exchanges, attackers have an opportunity to send file-sharing phishing attacks that appear time-critical and blend in seamlessly with legitimate emails.

BEC and VEC Remain Persistent Threats

The biannual report also revealed the continued growth of business email compromise (BEC) and vendor email compromise (VEC) attacks:

· BEC attacks grew by more than 50% over the last year, with attacks on smaller organizations jumping nearly 60% in the last half.
· 41% of Abnormal customers were targeted by VEC each week in the first half of 2024, a slight increase over the 37% targeted in the second half of 2023.
· Construction and engineering firms, as well as retailers and consumer goods manufacturers, were most vulnerable to VEC attacks, with 70% of organizations receiving at least one VEC attack in the first half of the year.

Britton continued, “Cybercriminals are continuing to use email to target human behavior, and through a variety of techniques—whether it’s leveraging social engineering tactics for BEC, or using the guise of legitimate applications in their phishing schemes. The report findings underscore this deliberate shift away from overt payloads and threat signatures, and toward email attacks designed to manipulate behavior. Keeping up with these threats will require organizations to adapt accordingly, recentering their defenses on protecting humans as their most vulnerable endpoints.”

Download the full H2 2024 Email Threat Report, “Bait and Switch: File-Sharing Phishing Attacks Surge 350%”, here.

About Abnormal Security

Abnormal Security is the leading AI-native human behavior security platform, leveraging machine learning to stop sophisticated inbound attacks and detect compromised accounts across email and connected applications. The anomaly detection engine leverages identity and context to understand human behavior and analyze the risk of every cloud email event—detecting and stopping sophisticated, socially-engineered attacks that target the human vulnerability.

You can deploy Abnormal in minutes with an API integration for Microsoft 365 or Google Workspace and experience the full value of the platform instantly. Additional protection is available for Slack, Workday, Salesforce, ServiceNow, Zoom, Amazon Web Services and multiple other cloud applications.

View source version on businesswire.com: https://www.businesswire.com/news/home/20240814650661/en/

Website: https://abnormalsecurity.com/ Contact Abnormal Security
Jade Hill
Director of Communications
[email protected]
This news is a press release provided by Abnormal Security. Korea Newswire follows these editorial guidelines. Abnormal Security News ReleasesSubscribeRSS 앱노멀시큐리티의 새로운 연구에 따르면 파일 공유 피싱 공격이 350% 급증 AI 기반 인간 행동 보안 부문의 선도업체인 앱노멀시큐리티(Abnormal Security) 는 오늘 2024년 하반기 이메일 위협 보고서 를 발표했다. 이 보고서에서는 위협 행위자들이 널리 사용되는 파일 호스팅이나 전자 서명 솔루션으로 위장하여 대상이 개인 정보를 유출하거나 맬웨어를 다운로드하도록 유도하는 파... 8월 15일 14:30 More News Technology Information Security Survey & Analysis Overseas Abnormal Security All News Releases 
배포 분야
인기 기사06.04 06시 기준
성남--(뉴스와이어)--성남시한마음복지관(관장 허영미)은 제44회 장애인의 날을 맞아 오는 4월 15일(월)부터 19일(금)까지 장애인의 날 기념 주간행사 ‘다함께, 봄봄봄’을 개최한다고 밝혔다. 성남시한마음복지관의 제44회 장애인의 날 기념 주간행사 ‘다함께,...
서울--(뉴스와이어)--한국환경보전원(원장 신진수)은 서울시50플러스재단(대표이사 구종원)과 협약을 통해 ‘서울시 중장년 환경교육사 전문 연수’를 추진한다고 밝혔다. 2023년 환경교육사 역량강화 교육 ‘환경교육사’는 환경교육 과정을...
무안--(뉴스와이어)--지역SW산업진흥기관으로 지정된 전남정보문화산업진흥원(원장 이인용)이 추진 중인 지역주도 SW성장지원 성과를 발표했다. 오든뷰 솔루션 ‘스마트 부표’ 전남정보문화산업진흥원은 해당 사업을 통해 우수한 역량을...
성남--(뉴스와이어)--안랩(대표 강석균)이 최근 다양한 성인용 게임 실행 파일로 위장한 파일을 파일공유 사이트에 올려 악성코드를 유포하는 사례를 발견하고 사용자의 주의를 당부했다. 파일 공유 사이트에 업로드된 다양한...
부르키나파소 와가두구--(뉴스와이어)--글로벌녹색성장기구(Global Green Growth Institute, GGGI)가 ‘부르키나파소 솔라 그랜마더 이니셔티브’ 등의 프로그램을 통해 농촌의 에너지 전환 과정에 공헌했다고 밝혔다. ‘솔라 그랜마더’ 이니셔티브 연혁 2008년 4월 뉴델리에서 열린 인도-아프리카 포럼(India-Africa Forum)에서 인도 정부와 아프리카연합(AU) 위원회는...
서울--(뉴스와이어)--현대자동차·기아는 20일 서울 중구 명동에 위치한 커뮤니티하우스 마실에서 ‘나노 테크데이 2023’을 개최하고, 미래 모빌리티 실현의 근간이 될 나노 신기술을 대거 공개했다. 투명 복사 냉각 필름이...
API
fg
유니콘뉴스는 보도자료 배포 서비스입니다.
여기에 뉴스를 등록하면 언론이 보도하고 널리 배포됩니다.