ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Emerging attacks leaving SEGs in the dust

Linked InXFacebook

Mike Britton at Abnormal Security argues that it’s time for email security to evolve

 

As the way we use email has evolved, so too have the threats facing the platform. Rather than simply being a method to send basic messages back and forth, email now serves as our critical communications platform and sits at the centre of an increasingly complex, integrated cloud network. 

 

Knowing the vast amount of sensitive data that is present within an inbox, cyber-criminals have adapted their tactics to exploit the role of email as a central digital identity. Simultaneously, cyber-criminals are deploying more devious tactics specifically designed to bypass traditional approaches to email security.

 

While we continue to see simplistic, untargeted ’spray and pray’ campaigns, more groups are now also using highly targeted spear phishing and BEC attacks that are often indistinguishable from legitimate messages.

 

Yet against this evolving threat, many organisations still rely on traditional methods of email security, primarily secure email gateway (SEG) solutions that have failed to keep up with cyber-criminals as they have evolved their tactics. While traditional controls are still effective at blocking commodity types of attacks, they simply cannot detect and block the sophisticated and modern attacks that we’re seeing more of today. 

 

So just how severe is the threat from these modern email attacks? And how can organisations ensure their email security measures can prevent them?

 

Evolving email threats are costing billions 

Tactics like business email compromise, or BEC, where attackers impersonate a specific known contact with a high degree of accuracy, have proven to be highly effective in deceiving their targets. Recent research conducted by Abnormal found that the median open rate for a text-based BEC attack is close to 28 percent. Worse, on average, 15 percent of those who read a malicious email will reply. 

 

 These figures represent a big win for cyber-criminals when contextualising how many malicious emails are sent daily. Criminal groups enjoy using the same email tools as legitimate businesses, enabling them to send highly targeted messages in increasing volumes – resulting in an 81% increase in BEC attacks between the first and second half of 2022 alone.

 

These attacks are starting to take a heavy toll. The FBI estimates that more than $43 billion has been lost due to BEC over the past five years, and this number continues to grow each year.

 

 And it’s not just the gift card scams of the past. These attacks can cost millions, with one of the most prominent examples targeting Toyota Boshoku Corporation in 2019. A member of the Toyota Group, the component manufacturer is estimated to have lost  an eye-watering $37 million from a single email scam.

 

It’s thought that the perpetrator posed as a business partner and emailed various members of the finance and account departments with requests for payment and details of a bank account that they had in their control. Eventually, they found someone who was willing and able to pay the invoice.  

 

How threat actors are bypassing standard email security 

Email attackers bank on their victims failing to adequately check the sender’s identity before complying with a request to transfer funds or share login details. Strict processes about verifying identity over another channel will help to defeat many of these attempts – even the most compelling email doppelganger is likely to be undone if the recipient picks up the phone to confirm the transaction with the supposed sender.

 

There is little denying the importance of following these protocols, particularly in at-risk departments like finance. And security awareness training should be mandatory for all employees. But enterprises should not expect their employees to bear responsibility for identifying dangerous emails. 

 

Instead, the best defence against identity-based attacks like BEC is to stop the malicious message from reaching them in the first place. This demands a robust email security solution that reliably identifies and intercepts attacks. However, the SEG tools that most firms use rely on known indicators of compromise to detect attacks—something that these BEC attacks lack.

 

Most SEGs are still based on signature detection – looking for known signs of a potentially dangerous email, such as a malicious attachment or suspicious link, or blacklisted sender domains and IPs.

 

Threat actors have developed several tactics to bypass these checks, with multi-stage payloads as one prevalent example. Here, the initial email will be fairly minimal, with little content and a URL pointing to what appears to be a legitimate site. Well-known platforms like SharePoint and Adobe are common choices, as their familiarity buys trust from the intended victim. With no suspicious content and a seemingly benign link, there is nothing in such an email for the SEG to detect.

 

A common approach is to impersonate an email from the platform that requires action – for example, a Microsoft email prompting a password review and reset. Once the recipient clicks the link, they are redirected  to a malicious phishing site to harvest their credentials as they complete the bogus reset process.

 

The SEG is blind to all this, merely seeing the initial email that appears to be from a trusted domain and contains benign content. 

 

So how can these insidious attacks be stopped? Rather than attempting to spot known bad behaviour, the answer lies in establishing what known normal is. And by understanding what is normal, the platform can detect and block anything that deviates from it. 

 

Using behavioural AI to better secure inboxes

Understanding what normal looks like requires a combination of API integration and behavioural AI to understand the identity of each user and manage the scale and pace of emails sent daily. 

 

APIs integrate smoothly with the native cloud email platform and start ingesting the thousands of behavioural signals that determine normal activity. From here, the platform can examine the data to identify each employee’s expected behavioural patterns. This includes their usual sign-in times, locations, and preferred browser and device choices. 

 

These are some of the most prominent points in catching an imposter. Still, it is also possible to go a step further and analyse relationships, understanding how different identities connect. After all, the way a user interacts with their peers may be much different than how they interact with their manager or an outside vendor. 

 

Applying this approach to both north-south emails being sent and received externally and east-west traffic moving laterally through the organisation creates  a single view of all correspondence and provides protection against insider threats and internally-compromised accounts. 

 

An additional element is understanding the content of each email through the use of natural language processing. These next-generation platforms can detect shifts in tone, a change in urgency, or when an email contains a financial request. By doing so, it can understand when an email may be malicious—even if it is entirely text-based and sent from a known domain, without any traditional indicators of compromise. 

 

By establishing a baseline for normal email behaviour within the organisation, anything abnormal will be an instant red flag. Attacks are far more likely to be detected before they can hit their target’s inbox, no matter what subtle new deceptive techniques they use—ultimately removing the need for the end user to make a decision about them and mitigating risk across the organisation. 

 

With cyber-criminals continuing to develop new techniques specifically to bypass standard email security measures like the secure email gateway, enterprises need to evolve too. It’s time to find a new solution to this modern problem. When a single email scam can cost millions, no business can afford to be left behind.

 


 

Mike Britton is CISO at Abnormal Security 

 

Main image courtesy of iStockPhoto.com

Linked InXFacebook
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543