Sign up for our weekly newsletter!
REGISTER NOW |
||
|
||
Email Fraud – New Trends Exposed![]() Larry Loeb, Author, 2/7/2019
With all the various exploits and malware occurrences that are out in the world, it's easy to forget about one of the most common yet effective security threats facing the enterprise: email. A new report by Valimail, a provider of fully automated email authentication, titled "Email Fraud Landscape, Q4 2018," indicates that the fight against fake email has been advancing around the world as more organizations find ways to combat it. This is the third year of the report, so some trends are becoming visible. It's not just Valimail that's concerned, even though they would be expected to be concerned since they sell security solutions for email. The report notes that fake emails were a key driver in the 60% jump in business email compromise (BEC) losses in 2018 that was reported by the FBI. The report was based on Valimail's proprietary data which was based on "billions of email message authentication requests." This was correlated with 17 millions of publicly accessible DMARC and SPF records. It found that many organizations and agencies aren't implementing basic and easily obtainable preventive measures that would prevent malicious emails from every getting to a recipient’s mailbox. Open standards-based measures like Domain-based Message Authentication Reporting & Conformance (DMARC) and Sender Policy Framework (SPF) already exist to deal with the email attack vector. Email alone has no mechanism to validate itself, which is why it can penetrate to the extent that it does. A message can easily spoof an originating address which then fools the recipient. DMARC and SPF are ways to add authentication to email, but depend on senders and recipients to implement them. The report found that DMARC use is increasing rapidly, which may be explained by an October 2017 directive for its use from the Department of Homeland Security called BOD 18-01. But there is still room for improvement. The US federal government, US tech companies and US banks were the only categories in which they found a DMARC success rate of 30% or greater. Eighty-seven percent of the federal domains that deploy DMARC have successfully configured it to be an enforcement measure. This is at odds with another report finding that in other sectors looked at, only 20% of domains that deploy DMARC succeed at getting it to an enforcement policy. Additionally, 50% of Fortune 500 and large US tech companies have adopted DMARC. The report also found that 30% of healthcare companies are using DMARC, which is more than double the rate of adoption that was found in late 2017. Yet the report also found that global media entities, NASDAQ-listed companies and global billion-dollar public companies rank the lowest in DMARC enforcement among the 11 categories that they surveyed. There is much still to be done to speed adoption of email verification efforts. As the threat becomes even more virulent, efforts to do so will undoubtedly increase.
— Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek. |
Aviatrix, an enterprise VPN company with customers that include NASA, Shell and BT, has recently dealt with a vulnerability that was uncovered by Immersive Labs researcher and content engineer Alex Seymour.
Security firm CyberArk is now finally able to discuss a major OAuth 2.0 vulnerability that affects Microsoft Azure web services.
Be alert, be aware, and be careful about what you reveal of your company's internal processes on social media.
The Microsoft Defender ATP Research Team has begun to discuss a polymorphic threat, Dexphot, that it has been tracking for over a year.
'Improper Restriction of Operations within the Bounds of a Memory Buffer' tops this year's list.
Information Resources
upcoming Webinars
ARCHIVED
Top Tips for Blocking pwned [email protected]$$wOrds in Your Organization
Tuesday, October 29, 2019
12 p.m. New York/ 4:00 p.m. London Podcasts
Podcast: Infrastructure Hunting – Stopping Bad Actors in Their Tracks
Being able to effectively build a threat intelligence ecosystem or threat-hunting identification response requires both user and systems sophistication and capabilities. Security, orchestration, automation and response (SOAR) is a new technology designed to provide organizations a single comprehensive platform they can use to implement an intelligence driven security strategy.
Podcast: Digital Transformation, SD-WAN & Optimal Security
Dan Reis chats to Cybera's Josh Flynn about how to achieve digital transformation without sacrificing security. ![]() like us on facebook
|
|
![]() |
||
![]() |
Security Now
About Us
Contact Us
Help
Register
Events
Supporting Partners
Twitter
Facebook
RSS
Copyright © 2019 Light Reading, part of Informa Tech, a division of Informa PLC. All rights reserved. Privacy Policy | Cookie Policy | Terms of Use in partnership with
|