-

New Research from Abnormal Security Shows Rise in Credential Phishing Attacks with 265 Brands Impersonated in First Half of 2022

SAN FRANCISCO--(BUSINESS WIRE)--Abnormal Security, the leading AI-based cloud-native email security platform, today released its H2 2022 Email Threat Report. The report explores the current email threat landscape and provides insight into the latest advanced email attack trends, including increases in business email compromise, the evolution of financial supply chain compromise and the rise of brand impersonation in credential phishing attacks.

The latest Abnormal research found a 48% increase in email attacks over the previous six months, and 68.5% of those attacks included a credential phishing link. In addition to posing as internal employees and executives, cybercriminals impersonated well-known brands in 15% of phishing emails, relying on the brands' familiarity and reputation to convince employees to provide their login credentials. Most common among the 265 brands impersonated in these attacks were social networks and Microsoft products.

“The vast majority of cybercrime today is successful because it exploits the people behind the keyboard,” said Crane Hassold, director of threat intelligence at Abnormal Security. “By compromising people rather than networks, it’s easier for attackers to circumvent conventional security measures. This is especially true with brand impersonation, where attackers use urgency and fear to encourage their targets to provide usernames and passwords.”

LinkedIn took the top spot for brand impersonation, but Outlook, OneDrive and Microsoft 365 appeared in 20% of all attacks. What makes these attacks particularly dangerous is that phishing emails are often the first step to compromising employee email accounts. Acquiring Microsoft credentials enables cybercriminals to access the full suite of connected products, allowing them to view sensitive data and use the account to send business email compromise attacks.

Additional findings from the report include:

  • Over a third of credential phishing attacks involving brand impersonation targeted educational institutions and religious organizations.
  • There was a 150% year-over-year increase in BEC attacks, showcasing the increased threat of these most financially-damaging attacks.
  • BEC attacks target every industry, but advertising and marketing agencies remain the most at risk with an 83% chance of receiving a BEC attack each week.
  • Financial supply chain compromise is continuing at a steady pace and targeting nearly every size organization, with 89% of large enterprises receiving at least one vendor attack each week.

“We know that email attacks target organizations of all sizes across all industries, but this data continues to reiterate that point. Brand impersonation is particularly worrisome for cybersecurity leaders, since the most sophisticated attacks are incredibly difficult to differentiate from a legitimate email from that brand,” stated Mike Britton, chief information security officer at Abnormal Security. “As we see this trend continue to increase across the threat landscape, organizations should look to add security solutions that can detect these attacks, even when they come from legitimate domains and use never-before-seen links.”

Launch of Abnormal Intelligence
In support of its mission to protect organizations from cybercrime, Abnormal Security today also launched Abnormal Intelligence, a research and data hub focused on providing insight into emerging attacks across the threat landscape. This platform is designed to help organizations stay aware of new trends and attacks, featuring some of the most unique attacks targeting Abnormal customers. In addition to the daily feed of real-world attacks, the site contains threat intelligence content in the form of blog posts, downloadable resources, and webinars.

To learn more about Abnormal Intelligence, view the attack insights and download the full report, please visit intelligence.abnormalsecurity.com.

For more information on Abnormal Security, please visit abnormalsecurity.com/.

Contacts

MikeWorldWide (MWW) for Abnormal Security
Diana Kozak
abnormalsecurity@mww.com

Abnormal Security


Release Summary
Abnormal Security's new H2 2022 Email Threat Report shows rise in credential phishing attacks with 265 brands impersonated in first half of 2022.
Release Versions

Contacts

MikeWorldWide (MWW) for Abnormal Security
Diana Kozak
abnormalsecurity@mww.com

Social Media Profiles
More News From Abnormal Security

Abnormal AI Announces that SoftBank Corp. Begins Offering Its Enterprise Email Security Platform in Japan

TOKYO--(BUSINESS WIRE)--Abnormal AI, the AI-native behavior security company, today announced that SoftBank Corp. (“SoftBank”) began offering its email security platform to enterprise customers across Japan. Abnormal has operated in Japan since 2025, led locally by Country Manager Kei Mitsuyama. Through SoftBank’s offering of Abnormal's email security solution, Abnormal will be able to reach a broader base of enterprise customers across the country through SoftBank's enterprise sales network. P...

Abnormal AI Brings OpenAI Daybreak Models Into AI Cloud Security to Protect Against Rogue AI

SAN FRANCISCO--(BUSINESS WIRE)--The OpenAI-Hugging Face incident was a wake-up call for cyber defenders. During an internal cybersecurity evaluation, AI agents identified paths beyond their intended environment and accessed production infrastructure belonging to a third-party organization. The incident highlighted a challenge security teams increasingly need to prepare for: capable AI agents can identify weaknesses, connect multiple gaps and interact with cloud infrastructure faster than traditi...

Abnormal AI Joins Project Watershed 250 to Strengthen Cybersecurity for Texas Water Utilities

SAN ANTONIO--(BUSINESS WIRE)--Abnormal announces its participation in Project Watershed 250...
Back to Newsroom