6

Australian organisations hit by spear-phishing email 'barrage'

 1 year ago
source link: https://itwire.com/business-it-news/security/australian-organisations-hit-by-spear-phishing-email-barrage.html
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

Thursday, 25 May 2023 11:36

Australian organisations hit by spear-phishing email 'barrage' Featured

By Gordon Peters

Cybercriminals continue to barrage organisations with targeted email attacks, and many companies are struggling to keep up, with a new global research report showing that 46% of Australian organisations were victims of spear-phishing in 2022 and on average, those organisations take over 100 hours to identify, respond to, and remediate an email threat.

According to the 2023 spear-phishing trends report from Barracuda, while spear-phishing attacks are low-volume, they are widespread and highly successful compared to other types of email attacks, with 24% of organisaions globally having at least one email account compromised through account takeover.

Barracuda says the report presents propriety spear-phishing data and analysis, drawing on a data set that comprises 50 billion emails across 3.5 million mailboxes, including nearly 30 million spear-phishing emails. The report also features survey findings from Barracuda-commissioned research conducted by independent researcher Vanson Bourne, which questioned IT professionals from frontline to the most senior roles at 1,350 companies with 100 to 2,500 employees, across a range of industries in the U.S., EMEA, and APAC countries.

Overall, the research shows that:
  • Spear phishing is widespread: 46% of Australian organisations analysed were victims of spear phishing in 2022, and global organisations received 5 highly personalised spear-phishing emails per day on average.
  • These attacks are highly successful: Spear-phishing attacks make up only 0.1% of all global e-mail-based attacks, according to Barracuda data, but they are responsible for 66% of all breaches.
  • Organisations are feeling the impact: 45% of Australian respondents that experienced a spear-phishing attack reported machines infected with malware or viruses; 41% reported having sensitive data stolen and 38% reported direct monetary loss.
  • Threat detection and response remains a challenge: On average, Australian organisations take over 100 hours to identify, respond to, and remediate a post-deliver email threat — 73 hours to detect the attack and 103 hours to respond and remediate after the attack is detected.
  • Remote work is increasing risks: Users at global companies with more than a 50% remote workforce report higher levels of suspicious emails — 8 per day on average, compared to 7 per day for those with less than a 50% remote workforce.
  • Having more remote workers slows detection and response: Global companies with more than a 50% remote workforce also reported that it takes longer to both detect and respond to email security incidents — 55 hours to detect and 63 hours to respond and mitigate, compared to an average of 36 hours and 51 hours respectively for organisations with fewer remote workers.
  • Energy and utilities companies experienced the highest incidence of spear phishing attacks globally with a staggering 73% surveyed falling victim in 2022.

“Even though spear phishing is low volume, with its targeted and social engineering tactics, the technique leads to a disproportionate number of successful breaches, and the impact of just one successful attack can be devastating,” said Fleming Shi, CTO, Barracuda.

“To help stay ahead of these highly effective attacks, businesses must invest in account takeover protection solutions with artificial intelligence capabilities. Such tools will have far greater efficacy than rule-based detection mechanisms. Improved efficacy in detection will help stop spear-phishing with reduced response needed during an attack.”

Read 238 times

Please join our community here and become a VIP.

Subscribe to ITWIRE UPDATE Newsletter here
JOIN our iTWireTV our YouTube Community here
BACK TO LATEST NEWS here


Lead-Machine_pink_600x260.jpg

GARTNER MARKET GUIDE FOR NDR 2022

You probably know that we are big believers in Network Detection and Response (NDR).

Did you realise that Gartner also recommends that security teams prioritise NDR solutions to enhance their detection and response?

Picking the right NDR for your team and process can sometimes be the biggest challenge.

If you want to try out a Network Detection and Response tool, why not start with the best?

Vectra Network Detection and Response is the industry's most advanced AI-driven attack defence for identifying and stopping malicious tactics in your network without noise or the need for decryption.


Download the 2022 Gartner Market Guide for Network Detection and Response (NDR) for recommendations on how Network Detection and Response solutions can expand deeper into existing on-premises networks, and new cloud environments.

DOWNLOAD NOW!

PROMOTE YOUR WEBINAR ON ITWIRE

It's all about Webinars.

Marketing budgets are now focused on Webinars combined with Lead Generation.

If you wish to promote a Webinar we recommend at least a 3 to 4 week campaign prior to your event.

The iTWire campaign will include extensive adverts on our News Site itwire.com and prominent Newsletter promotion https://itwire.com/itwire-update.html and Promotional News & Editorial. Plus a video interview of the key speaker on iTWire TV https://www.youtube.com/c/iTWireTV/videos which will be used in Promotional Posts on the iTWire Home Page.

Now we are coming out of Lockdown iTWire will be focussed to assisting with your webinars and campaigns and assistance via part payments and extended terms, a Webinar Business Booster Pack and other supportive programs. We can also create your adverts and written content plus coordinate your video interview.

We look forward to discussing your campaign goals with you. Please click the button below.

MORE INFO HERE!


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK