Email has been the primary communication tool in the workplace for over two decades. Research shows the average employee receives over 125 emails a day. This provides opportunities for cybercriminals to steal valuable information using business email compromise (BEC) attacks, phishing campaigns, and other methods.
An astounding 94% of cyberattacks start with malicious email messages. According to the FBI’s Internet Crime Complaint Center (IC3), cybercrime costs the US more than $12.5 billion per year, of which $2.9 billion were related to business email compromise (BEC) or email account compromise (EAC). The negative consequences of email-based attacks can include significant financial loss, data loss, and reputational damage.
How Secure Is Email?
Email is designed to be as open and accessible as possible. It allows people in an organization to communicate with other employees, with people in other organizations, and with other third parties. The problem is that this openness is exploited by attackers. From spam campaigns to malware, phishing attacks, and business email compromise, attackers take advantage of email security weaknesses. Since most organizations rely on email to do business, attackers misuse email to steal sensitive information.
Because email is an open format, anyone who can intercept it can view it, which increases email security concerns. This becomes a problem when organizations send sensitive and confidential information via email. Without special protective measures, attackers can intercept email messages and easily read their contents. Over the years, organizations have stepped up their email security measures to make it more difficult for attackers to access sensitive and confidential information, and use emails for nefarious purposes.
Common Threats to Email Security
Phishing
Phishing attacks are the most prevalent and common threat to email security. One of the earliest phishing attacks was the Nigerian Prince Scam. Today this type of attack is easy to spot, but over time, phishing attacks have become more sophisticated. Attackers send more sophisticated emails with more plausible excuses and scams.
Phishing attacks can be either generic or targeted. Also known as spear phishing attacks, these targeted attacks are well researched and designed to trick specific individuals or groups who have special privileges or access to valuable information.
Quishing
Quishing is QR code phishing. When a malicious URL is hidden behind a QR code, the link becomes an image file, not a clickable element. Traditional email security systems like secure email gateways (SEGs) and even the most modern email security solutions scan for suspicious links in the email body of the message to prevent phishing attacks (relying on domain reputation and other indicators), but may overlook embedded URLs within images or file attachments.
Quishing campaigns present a unique challenge to defenders. By embedding the phishing link within a QR code, the threat is effectively concealed, rendering security measures ineffective and allowing malicious emails to slip through and reach the inbox of targeted end users.
Malware
Email is an ideal delivery mechanism for malware. Malware can be directly attached to emails, embedded in documents that are shared as attachments, or shared through cloud-based storage. Once malware is installed on a user’s computer, it can steal sensitive information or encrypt files.
Spam
Unsolicited bulk email, also known as spam, is a common type of unsolicited email that often contains advertisements for goods and services, but can spread malware, trick recipients into giving away personal information, and result in financial loss. Spammers often use software programs called “harvesters” to gather information from websites, newsgroups, and other online services where users identify themselves by email address.
Spam wastes resources and productivity, and can cause significant damage to organizations, making it critical to filter and block spam emails before they reach corporate email accounts.
Data Loss
Email accounts can contain vast amounts of confidential information. They can also be used to access cloud-based infrastructure and other online services. An attacker can use these accounts to gain access to sensitive information, making email account credentials a common target for attacks.
Additionally, information in email accounts could be inadvertently disclosed by an employee who includes an unauthorized party in an email chain or falls victim to a phishing attack.
Authentication Attacks on Email Servers
Sometimes, the email server itself can become the target of attackers. Attackers typically use brute force attacks or credential stuffing to gain access to an email server. This grants them access to all email messages and attachments stored in the server, and allows them to perform convincing phishing attacks by impersonating email users. All email accounts should have multifactor authentication to prevent unauthorized access.
Botnets and DDoS
A botnet is a group of networked systems or devices infected with malware and controlled by hackers. Botnets are widely used in large-scale spam and phishing campaigns. Botnets are also used in distributed denial of service (DDoS) attacks that attempt to overload systems by creating large volumes of fake traffic.
Just like how a traditional DDoS attack crashes the victim’s web server, attackers can use hijacked botnets to send out a massive number of emails to a targeted organization, causing the email server to crash.
Be Wary of Attachments and Don’t Click Links in Emails
Document attachments and links in emails are one of the primary ways cybercriminals distribute malware and execute phishing campaigns. Before clicking on any link or downloading any document or attachment, ensure that you recognize and trust the sender. Even if the sender appears to be someone you know, be cautious – their email account might have been compromised. If in doubt, reach out to the sender through a separate communication channel to verify.
Never click on links that request personal or financial information. Instead, hover the link, read and see if it is a known valid site, and not misspelled. Similarly, avoid downloading attachments unless you’re expecting them and are certain of their content. If in doubt, reach out to the sender through a separate communication channel to verify.
Use Strong Passwords for Email Accounts and Don’t Reuse Passwords
Strong, unique passwords are the first line of defense in email security. A strong password is typically a combination of upper and lower-case letters, numbers, and special symbols, making it hard for attackers to guess or break through brute force attempts.
Avoid using easily guessable passwords, or passwords containing your name, birthdays, or other information attackers can easily discover. Moreover, it’s essential never to reuse passwords across multiple accounts. If one account gets compromised, all your other accounts become vulnerable. Consider using a password manager to help store and manage complex passwords.
We Implement Multi-Factor Authentication
Using multi-factor authentication (MFA) provides an additional layer of protection for your account. Multi-factor authentication requires you to provide more than just your password when you log in to your account. It typically involves the use of a second factor, such as a code sent to your phone, a security token, or a biometric factor like a fingerprint. This makes it much harder for attackers to gain access to your account, even if they have your password.
This can be particularly important for email accounts that contain sensitive or confidential information, as it can help prevent unauthorized access to that information. We implement MFA across our 365 email and SharePoint services.
Keep Business and Personal Emails Separate
When using business emails for private purposes, employees may be exposing the company’s email system to a variety of security risks. For example, if an employee uses their business email to sign up for personal accounts or services, they may be inadvertently giving third parties access to the company’s email system. This could result in spam or phishing emails being sent to other employees, or confidential business information being disclosed to unauthorized parties. Do not check or access personal email on company equipment. Do this on your own device please.
Additionally, using business emails for private purposes can also lead to decreased productivity, as employees become distracted by personal emails or use company resources for non-business purposes.
To help protect the security of the company’s email system and maintain the integrity of business communications, we have clear policies in place that prohibit employees from using business emails for private purposes. violations will be addressed promptly.
Block Spam emails
We advise to block and report senders that are sending you spam and phishing email content. This also reports to the email server.
Avoid the Use of Public Wi-Fi
Using public Wi-Fi can potentially expose your email communication to interception or other security risks.
When you connect to a public Wi-Fi network, you are sharing that network with potentially hundreds or thousands of other users. This means that anyone else on the same network can potentially intercept and view your internet traffic, including your email communication. This risk is particularly high if the network is unencrypted or if you are not using a virtual private network (VPN).
To help protect the security of your email communication, it is generally best to avoid using public Wi-Fi networks whenever possible. If you do need to use public Wi-Fi, it is important to take steps to secure your connection. Please use a VPN and be mindful of what you are sending over the network.