Phishing emails continue to be one of the most common methods to effectively perpetuate malicious attacks on organizations around the globe, and cyber-criminals have evolved to using HR business-related emails to target users.
According to KnowBe4 Q2 2023 top-clicked phishing report, hackers have been targeting individuals especially employees with HR business-related messages as they pique their interest. As a result of their evolving nature, cyber-criminals are now coming up with phishing attacks that are more realistic and believable. Through these messages, hackers prey on the emotions of users by aiming to cause distress, confusion, panic or even excitement in order to entice someone to click on a phishing link or malicious attachment.
According to Stu Sjouwerman, CEO, KnowBe4, the threat of phishing emails remains as high as ever as cyber-criminals continuously tweak their messages to be more sophisticated and seemingly credible.
“The trend of phishing emails revealed in the Q2 phishing report is especially concerning, as 50% of these emails appear to come from HR – a trusted and crucial department of so many, if not all organizations. These disguised emails take advantage of employee trust and typically incite action that can result in disastrous outcomes for the entire organization,” Sjouwerman said.
“New-school security awareness training for employees is crucial to help combat phishing and malicious emails by educating users on the most common cyber attacks and threats. An educated workforce is an organization’s best defense and is essential to fostering and maintaining a strong security culture.”
Hackers are becoming more aware of what most users are likely to respond to. They are now using email subjects coming from HR related to dress code changes, training notifications, vacation updates. These are effective because they may cause a user to react before thinking logically about the legitimacy of the email and have the potential to impact ones personal life and professional workday.
Holiday phishing email subjects were also utilized this quarter with four out of the five top holiday email subjects appearing to have come from HR. Additionally, the report reflects the consistent trend of utilizing IT and online service notifications as well as tax-related email subjects.