CIO Influence
CIO Influence News IT services Machine Learning Security

Malicious Links, AI-Enabled Tools and Attacks on SMBs Among Top Cybersecurity Threats in H1 Mimecast Global Threat Intelligence Report

Malicious Links, AI-Enabled Tools and Attacks on SMBs Among Top Cybersecurity Threats in H1 Mimecast Global Threat Intelligence Report

Mimecast CMYK blue logo2020.png

This new report leverages insights from Mimecast’s threat analysis of more than 1.7 billion messages per day across 42,000+ customers

Mimecast, a leading global Human Risk Management platform, today published its Global Threat Intelligence Report 2024 H1, revealing malicious links and AI-driven bots in call centers to be among the greatest threats to cybersecurity defenses, with small businesses bearing the brunt of attacks.

The report analyzes the threat landscape during the first six months of 2024 and offers actionable steps for organizations of all sizes to improve cyber defenses. Key findings from the report include:

Also Read: Infogain Appoints Mohit Bhat as Chief Delivery & Innovation Officer

Threat actors link up

Messaging attacks continue to evolve, with hackers moving away from pushing malware to using malicious links as the preferred method of delivering payloads to victims’ systems. In fact, Mimecast’s analysis found malicious links surged by 133% in the first quarter of 2024 and 53% in the second quarter, compared to the same period in 2023.

Attacks are increasingly employing multiple layers of false information requiring more interaction from victims, who are forced to click through links, respond to CAPTCHAs, and engage with false multi-factor authentication requests. Additional obfuscation layers allow these types of attacks to fly under the radar, gaining entry where malware would be denied.

During the first half of the year, a campaign targeting Australian law firms used confusing URLs in email messages to send users to an intermediate page on one of several collaboration platforms. Clicking on the link redirects victims to a fake Microsoft login page to access credentials.

Also Read: ZeroTier Raises $13.5 Million in Series A; Appoints Andrew Gault as CEO

AI-enabled scams emerge

More often attackers are using generative AI to create phishing templates. However, in one case, attackers targeted corporate employees by sending 380,000 emails with an attached PDF document. Clicking on the file opens the PDF in a web browser and displays a page hosted on an AI development service.

AI-driven attacks are not just impacting businesses. Attackers are increasingly targeting consumers by using Microsoft distribution lists to send mass emails that pass security checks and notify recipients of an imminent deduction or charge, prompting them to contact an AI bot call center to collect information. In May 2024, Mimecast detected more than 1.6 million email messages in this type of campaign.

Small businesses remain the prime target for cyber threats

As observed in the Q4 2023 report, small businesses experience the highest volume of cyber threats, Mimecast saw this peaking at 40 threats per user (TPU) in Q1 2024. Employees at both small and medium businesses continue to see more than twice the number of threats compared to users at large enterprises.

Analyzing businesses of all sizes, the average number of TPUs declined by about a third, dropping from 19 TPUs on average during Q4 2023 to 14 TPUs in the latest quarter (Q2 2024). The threats impacting large enterprises declined in the first quarter, but slightly jumped in the second quarter of this year.

“Email and collaboration tools are often seen merely as cost centers, but this overlooks their essential role in cybersecurity,” says Mick Paisley, Chief Security & Resilience Officer at Mimecast. “By optimizing email security, organizations can achieve significant cost efficiencies while ensuring robust protection against emerging threats. This approach is crucial not only for minimizing cyber risks but also for maintaining the productivity and safety of your organization.”

Also Read: DapuStor Extends Collaboration with Marvell to Unveil Cutting-Edge Flexible Data Placement (FDP) Technology for QLC SSDs

[To share your insights with us as part of editorial or sponsored content, please write to psen@itechseries.com]

Related posts

Envision Consulting Highest Ranked IT Managed Service Provider in the Washington DC Metro Area

Service Express Acquires Data Center Support Provider ServIQ

PR Newswire

Vantage Data Centers Enters Power Purchase Agreement with SolarAfrica to Secure 87MWp of Solar Energy