Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - When Is A Phishing Email Not A Phishing Email? The Taxonomy Of Malicious Emails
Articles

When Is A Phishing Email Not A Phishing Email? The Taxonomy Of Malicious Emails

ISBuzz TeamBy ISBuzz TeamMarch 24, 2017Updated:March 24, 20174 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Malicious email attacks have dominated the security headlines in recent months, with 2017 already seeing large campaigns targeting Netflix and Amazon customers. Despite the number of incident however, many individuals and businesses alike don’t actually know what kind of attacks they are being hit by.

In order for a business to defend against malicious email attacks it is essential that they are able to identify whether they have been hit with a phishing, BEC or ransomware attack. According to the FBI, BEC scams have resulted in losses of £2.4 billion ($3.1 billion) as of May 2016. The effect of a malicious email attack can be devastating, it can lead to financial losses, reputational damage and worse. If one of your employees suspects they have received a malicious email, it needs to be reported to the IT department or a cyber security expert needs to be engaged. They will be able to identify the type of attack and put security in place to prevent any further damage.

To phish or not to phish?

 The differences between the content and the methods used to deliver these email attacks can be subtle. If you are aware of them, you might just save yourself and your organisation financial and reputational damage. A consumer phishing attack, sometimes called a scattershot attack, is sent out to many people, in the hope that one of the less security savvy targets opens it. The email addresses are cleverly spoofed and the imposter uses a fake domain name to create a false identity.

Often an attacker will impersonate a known and trusted brand’s domain and send malicious emails to their customers. Because the email appears to be from a known and trusted sender, a number of customers will open it and likely be asked to follow a link. The link will often redirect them to a fake website where they may be asked to enter or confirm login credentials.

Business email compromise or BEC attacks, on the other hand, can come from either an imposter or from a legitimate but compromised account. These types of attacks typically use social engineering methods to create ‘believable’ content for a fraudulent email. They are also extremely targeted, being sent to a few, very specific people for example, financial controllers or HR managers of a company.

Ransomware attacks are typically sent from an imposter; however, they can also come from a compromised account. Like BEC attacks, they are often targeted and use social engineering techniques to create ‘believable’ content that convinces people to open a malware-infected document or click on a malicious link.

Thanks to the huge volume of emails arriving every day, it can be difficult to differentiate between truly malicious emails and “grey mail”. These are annoying emails which fill up our inboxes or spam folders but are usually harmless, such as newsletters and advertisements. Over time your email authentication software will learn which domains are malicious and which are just grey mail.

Prevention is better than cure

 There is no one solution which can prevent all malicious email attacks. Email authentication is an essential component to achieving a trusted email channel, it will not stop all attacks, though.

To defend against all email attacks organisation’s need to implement a multi layered security system. Using authentication technology which can identify and confirm the sender is more effective than using a programme which bases its decision on what to do with an email on its content. Over time the software begins to recognise increasing numbers of email addresses and domains and remembers previous actions taken for each one. This type of email solution will go a long way to protecting an organisation and its employees against malicious email attacks. Unfortunately, if an attacker gains access to an employee’s genuine email account and uses it for malicious purposes, this type of activity can only be detected by targets noticing that the message is out of character or going against policy.

Each attack requires its own solution – there is no ‘one size fits all’ approach to preventing cyberattacks. By understanding the techniques, targets and motivations behind each kind of malicious email, businesses can be better prepared to understanding the solutions that will prevent them.

[su_box title=”About Markus Jakobsson” style=”noise” box_color=”#336588″][short_info id=’100097′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}