Connect with us

Technology

Business Email Compromise (BEC) Impersonation: The Weapon of Choice of Cybercriminals, Finds VIPRE’s Q3 2024 Email Threat Report

Published

on

BEC attacks targeting the manufacturing sector increase to 10%; use of attachments is getting ‘sneakier’; and Redline is the malware family of the quarter.

LONDON, Oct. 28, 2024 /PRNewswire/ — VIPRE Security Group, a global leader and award-winning cybersecurity, privacy, and data protection company, has released its Q3 2024 Email Threat Trends Report, shedding light on the evolving cybersecurity landscape. This comprehensive analysis of real-world data reveals the sophisticated strategies and techniques employed by cybercriminals, with a particular persistent focus on the highly lucrative tactic of business email compromise (BEC). VIPRE processed 1.8 billion emails globally, of which 208 million were malicious.

BEC impersonation weaponisation  

In this third quarter of 2024, cybercriminals intensified their efforts to exploit organisational vulnerabilities through employee deception. BEC scams surged, accounting for 58% of phishing attempts. Notably, 89% of these BEC attacks involved impersonation of authority figures, including CEOs, senior executives, and IT staff, underscoring the sophisticated tactics employed by malicious actors.

BEC aims for the manufacturing sector

The manufacturing sector saw a significant rise in BEC attacks, potentially driven by financial fraud. These incidents increased from just 2% in Q1 to 10% in Q3 this year. This rise may be attributed to the industry’s widespread use of mobile sign-ins at various worksites. Employees accessing systems “on the go”, often under pressure to meet production deadlines, are more susceptible to phishing attempts.

Subtler tactics are a larger threat

Email threats in Q3 were dominated by scams (34%), commercial spam (30%), and phishing (20%). These email threats overshadowed ransomware and malware combined, which comprised less than 20% of all email attacks. Interestingly, despite their lower prevalence, ransomware and malware continue to receive disproportionate attention from the cybersecurity industry.

Sneakier attachments

To counter advancing email security solutions, criminals are deploying increasingly more intricate methods to bypass defenses. Attackers are employing sneakier techniques such as disguising malicious attachments as voicemail recordings or critical security updates to lure unsuspecting users into downloading them.

Additionally, Microsoft PDFs and .DOCX files remain the most common forms of malicious attachments. In Q3 2024, 2.18 million emails were detected containing harmful attachments, marking a 30% increase from the previous quarter’s 21% attachment-based attacks.

Phishing links and compromised websites

Cybercriminals continue to favour the URL redirection technique, a tactic that typically proves effective at evading security controls. This deceptive ploy utilises a “clean” URL within the body of the email, which then redirects unsuspecting users to a malicious one once inside. In Q3 2024, URL redirection accounted for 52% of such attacks, leading victims to meticulously crafted fraudulent websites designed to appear authentic, and gain trust.

Malspam pendulum swing from malicious links to attachments

When it comes to malspam, there is a pendulum swing from a preference for malicious links to attachments. During Q3, malspam efforts were centered on malicious attachments (64%), while only 36% employed a link. The attachment formats used were predominantly LNK, ZIP, and DOCX. Only a quarter ago, links were the tool of choice by a factor of nearly nine-to-one (86% links to 14%).

The ‘Malware Family of the Quarter’ goes to Redline

Redline is the top malspam family of Q3 2024, a spot it has maintained since the corresponding quarter in 2023. RedLine is designed to steal sensitive information from web browsers, such as credentials and payment data. Typically distributed via phishing emails or malicious websites, it sends stolen data to a command-and-control server controlled by the attacker. It can completely take over a compromised machine and uses multiple infiltration methods.

“The findings of this report yet again illustrate the sophistication of criminal tactics. BEC email and phishing attacks are becoming more targeted and convincing,” Usman Choudhary, CPTO, VIPRE Security Group, says. “Additionally, malware distribution through malicious spam campaigns continues to pose a serious threat to organisations. These findings stress the critical need for robust cybersecurity measures and ongoing employee education to combat these evolving threats, especially as bad actors gear up for the upcoming holiday season – Black Friday, Thanksgiving, Christmas, and New Year.”

To read the full report, click here: VIPRE’s Email Threat Trends Report: Q3 2024. 

VIPRE leverages its vast understanding of email security to equip businesses with the information they need to protect themselves. This report is based on proprietary intelligence gleaned from round-the-clock vigilance of the cybersecurity landscape.

About VIPRE Security Group

VIPRE Security Group, part of Ziff Davis, Inc., is a leading provider of internet security solutions purpose-built to protect businesses, solution providers, and home users from costly and malicious cyber threats. With over 25 years of industry expertise, VIPRE is one of the world’s largest threat intelligence clouds, delivering exceptional protection against today’s most aggressive online threats. Our award-winning software portfolio includes next-generation antivirus endpoint cloud solutions, advanced email security products, along with threat intelligence for real-time malware analysis, and security awareness training for compliance and risk management. VIPRE solutions deliver easy-to-use, comprehensive layered defense through cloud-based and server security, with mobile interfaces that enable instant threat response. VIPRE is a proud Advanced Technology Partner of Amazon Web Services operating globally across North America and Europe.

The group operates under various brands, including VIPRE®, StrongVPN®, IPVanish®, Inspired eLearning®, Livedrive®, and SugarSync®. www.VIPRE.com

 

View original content:https://www.prnewswire.co.uk/news-releases/business-email-compromise-bec-impersonation-the-weapon-of-choice-of-cybercriminals-finds-vipres-q3-2024-email-threat-report-302287491.html

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

E-rate Trends Report Highlights Need for Enhanced Funding and Support in Education

Published

on

By

Findings unveil the program’s impact on internet connectivity and digital learning in U.S. schools and libraries

EDMOND, Okla., Oct. 28, 2024 /PRNewswire-PRWeb/ — Funds For Learning, a leading advocate for educational technology funding, has released its 14th annual E-rate Trends Report, revealing the current successes and challenges of the E-rate program. The annual report evaluates how the program can most effectively support schools and libraries. School and library input is compiled and delivered directly to the Federal Communications Commission (FCC) to inform program administration.

“We must prioritize expanding funding eligibility for cybersecurity services to protect our students and educators in an increasingly complex digital landscape.”

The report underscores E-rate funding’s essential function in bridging the digital divide, particularly for rural and underserved communities. More than 21,000 applicants and 3,700 vendors participate in the E-rate program, emphasizing its vital role in providing internet access for U.S. educational institutions. The 2024 E-rate survey, conducted in June, garnered 2,355 responses, about 11% of all applicants, offering valuable insights into stakeholder experiences and needs.

Key takeaways and comments from the report include:

E-rate’s Vital Role: Over 88% of respondents affirmed that E-rate funding is essential in ensuring equitable access to internet services, particularly for underserved and rural communities.

“The E-rate program is crucial for modern education. This program ensures schools can access vital technology for student learning. From broadband to Wi-Fi, this funding bridges the digital divide, empowering students with equitable access to educational resources, fostering innovation, and ultimately, shaping a brighter future for students.” – California School District

“We are a very small rural library. My county has very poor connectivity options. My library’s Wi-Fi is used on a daily basis by people just sitting in their cars. The E-rate program has allowed a whole new group to be able to connect.” – Rural Virginia Library

Cybersecurity Remains a Top Concern: With the launch of the FCC’s $200 million Cybersecurity Pilot Program, protecting school networks is more critical than ever. Many respondents emphasized the increasing need for E-rate support in this area.

“Cybersecurity is increasingly becoming a greater part of our budgeted dollars, and we could definitely use E-rate dollars to support our endpoint protection, network monitoring, firewalls and filtering.” – Wisconsin School District

“On the current times, the cybersecurity issue is top priority for almost any industry, but for a school is almost impossible to pay for this matter with their limited resources.” – Puerto Rico School

Rising Costs and Service Eligibility: As technology evolves, applicants are advocating for an expanded list of eligible services, with a significant focus on funding for cybersecurity and advanced networking tools.

“Our school district’s goal is to take full advantage of eligible services and would greatly benefit from cybersecurity services/software eligibility.” – Texas School District

“Our schools could not operate or exist without E-rate Cat 1 and Cat 2 funding. This funding is essential for our schools to survive!” – California School

“The findings in this report highlight the critical role of the E-rate program in bridging the digital divide for schools and libraries,” said Brian Stephens, Director of Stakeholder Engagement of Funds For Learning. “However, we must prioritize expanding funding eligibility for cybersecurity services to protect our students and educators in an increasingly complex digital landscape.”

To request a complimentary copy of the 2024 E-rate Trends Report and accompanying resources, click here. Join Funds For Learning Webinar October 31 at 11:00 am ET for an in-depth discussion of the report; register here.

About Funds For Learning

Funds For Learning, LLC, is a compliance firm specializing in the federal E-rate funding program for schools and libraries. Funds For Learning supports E-rate stakeholders in all 50 states, helping them navigate the application process to receive support for internet access and Wi-Fi connectivity. To deliver applicant feedback to the Federal Communications Commission and Congress, Funds For Learning coordinates the annual E-rate Trends Report. For more information, please visit https://www.fundsforlearning.com.

Media Contact

Funds For Learning, Funds For Learning, +1 608 216 7300, jon.kannenberg@finnpartners.com, https://www.fundsforlearning.com/

View original content to download multimedia:https://www.prweb.com/releases/e-rate-trends-report-highlights-need-for-enhanced-funding-and-support-in-education-302288504.html

SOURCE Funds For Learning

Continue Reading

Technology

ACTFL and LCF Celebrate Achievement in Language Education

Published

on

By

ALEXANDRIA, Va., Oct. 28, 2024 /PRNewswire/ — ACTFL and the Language Connects Foundation (LCF) are pleased to announce the 2024 recipients of the ACTFL & LCF Professional Awards, an annual program recognizing outstanding contributions to the field of language education.

These awards will be presented in Philadelphia on Friday, November 22, as part of the ACTFL 2024 Annual Convention & World Languages Expo.

The following ACTFL & LCF Professional Awards will be granted:

NFMLTA/MLJ Emma Marie Birkmaier Award for Doctoral Dissertation Research in World Language Education: Rima Elabdali, University of Tennessee, KnoxvilleNelson Brooks Award for Excellence in the Teaching of Culture: Cyrus Segawa Konstantinakos, Boston University, Showa Boston Institute (MA)The Public Service Award for World Language and Cultural Advocacy: Tony Allen, Delaware State UniversityAmy Eusebio, City of Philadelphia, Office of Immigrant Affairs (PA)Award for Excellence in Diversity, Equity and Inclusion in the Classroom: Lini Ge Polin, University of North Carolina at Chapel HillKlett Award for Sustainable Development Education in the World Language Classroom:Claire-Marie Brisson, Harvard University (MA)Anthony Fernando, Vinschool (Vietnam)Marina Falasca, Instituto de Enseñanza Superior en Lenguas Vivas “Juan Ramón Fernández” (Argentina)NYSAFLT Anthony Papalia Award for Excellence in Teacher Education: Pamela Wesely, University of IowaNFMLTA/MLJ Paul Pimsleur Award for Research in World Language Education: James Stratton, Pennsylvania State UniversityWilga Rivers Award for Leadership in World Language Education (Postsecondary): Yoshiko Saito-Abbott, California State University, Monterey BayFlorence Steiner Award for Leadership in World Language Education (K-12): Debbie Callihan-Dingle, North East ISD (TX)Award for Excellence in World Language Instruction Using Technology (K-12): T.J. Heupel, Faith Lutheran Middle School and High School (NV)Award for Excellence in World Language Instruction Using Technology (Postsecondary): Julie Damron, Brigham Young University (UT)Melba D. Woodruff Award for Exemplary Elementary World Language Program: Oak Park School District 97’s World Language in the Elementary Schools (IL); accepted by Margaret Poleski, Department Co-Chair

The ceremony will open with remarks by ACTFL Past-Presidents Lisa Ritter and Bridget Yaden, and feature acknowledgment of the 2024 Research Priorities Grants recipients and Foreign Language Annals Super Reviewers.

Learn more about the ACTFL & LCF Professional Awards program. The call for nominations, including self-nominations, will reopen in Spring 2025.

About ACTFL:

Providing vision, leadership and support for quality teaching and learning of languages, ACTFL is an individual membership organization of more than 13,000 language educators and administrators from elementary through graduate education, as well as government and industry. Since its founding in 1967, ACTFL has become synonymous with innovation, quality, and reliability in meeting the changing needs of language educators and their learners. It is where the world’s educators, businesses, and government agencies go to advance the practice of language learning.

ACTFL’s work as a trusted, independent center of excellence empowers educators to prepare learners for success in a 21st century global society; helps government agencies build language capacity in the U.S. and abroad; and connects businesses with the resources and relationships they need to succeed.

About LCF:
Launched in November 2022, The Language Connects Foundation (LCF) is a national not-for-profit and philanthropic organization created in partnership with our parent organization, ACTFL, to elevate the language education profession and promote the transformative power of language learning.

LCF’s ultimate goal is to help ensure a diverse, well-prepared, and highly effective language educator workforce today and for generations to come.

View original content to download multimedia:https://www.prnewswire.com/news-releases/actfl-and-lcf-celebrate-achievement-in-language-education-302288672.html

SOURCE ACTFL

Continue Reading

Technology

Alchemy Pay Unveils Alchemy Chain Launch Plan: A Transformative Layer-1 Blockchain for the Future of Payments

Published

on

By

SINGAPORE, Oct. 28, 2024 /PRNewswire/ — Alchemy Pay, a world-leading crypto payment solutions provider, today unveiled its launch plan of its Layer-1 blockchain, Alchemy Chain. Built on a scalable Solana Virtual Machine (SVM) architecture, Alchemy Chain is designed to support the growing needs of Alchemy Pay’s business operations and revolutionize the integration of crypto and fiat payments.

Alchemy Chain is positioned to become a cornerstone of the evolving payment landscape by enabling seamless interaction between blockchain-based transactions and off-chain storage. Its ultimate goal is to establish a system where fiat currencies and cryptocurrencies coexist without friction, enhancing transparency, security, and efficiency in cross-border settlements.

Alchemy Chain will introduce a high-scalability infrastructure specifically crafted to accommodate large-scale business applications, facilitating seamless interaction between on-chain operations and off-chain storage. Its architecture is engineered to process transactions rapidly and efficiently, ensuring flexibility and reliability as Alchemy Pay’s user base continues to expand. At the heart of the blockchain’s security and transparency is an innovative Trusted Proof-of-Authority (TPoA) mechanism, which ensures the integrity and transaction speed of validating nodes. In addition, Alchemy Chain will integrate advanced Layer-2 solutions that enable seamless account mapping and data synchronization, minimizing redundant data storage and optimizing scalability.

$ACH will serve as the utility token of Alchemy Chain, allowing users to pay gas fees. Users can conveniently cover gas fees and transactions using either $ACH or fiat, with seamless conversion of profits and other on-chain earnings into fiat currency. Additionally, Alchemy Chain will implement a stablecoin revenue mechanism, providing users with the opportunity to earn yield effortlessly.

The launch of Alchemy Chain will also introduce two critical tools aimed at simplifying processes for developers and its eco-projects. The Meme Launchpad offers an intuitive platform designed to lower technical barriers, facilitating the creation and launch of meme-based projects. Meanwhile, the Meme Telegram Bot provides a streamlined, “light mode” interface for developers to navigate and interact with the ecosystem effortlessly.

Alchemy Chain will further Alchemy Pay’s mission to build a cohesive, frictionless payment system, bridging fiat currencies and cryptocurrencies. Looking ahead with Alchemy Chain, Alchemy Pay reaffirms its dedication to advancing the integration of cryptocurrencies into everyday financial systems. By leveraging cutting-edge blockchain technology, Alchemy Chain will help make crypto payments more accessible, supporting the broader adoption of digital currencies and contributing to the development of the global crypto ecosystem.

Stay informed with the latest updates on Alchemy Chain by following our official channels on X, Telegram and Discord.

About Alchemy Chain

Alchemy Chain is a Layer1 blockchain purpose-built for high scalability in payments, seamlessly integrating on-chain business with off-chain storage to foster a more reliable ecosystem. Serving as a comprehensive payment platform, Alchemy Chain incorporates Layer 2 solutions, featuring account mapping and seamless data synchronization for faster settlements. Through innovative approaches such as Trusted Proof-of-Authority, Block-Wing, ACH Ramp Protocol, and Layer 2 solutions, Alchemy Chain revolutionizes the blockchain payment landscape by enhancing security, optimizing performance, and enabling scalable development for dApps and transactions.

 

View original content to download multimedia:https://www.prnewswire.com/news-releases/alchemy-pay-unveils-alchemy-chain-launch-plan-a-transformative-layer-1-blockchain-for-the-future-of-payments-302288673.html

SOURCE Alchemy Pay

Continue Reading

Trending