Report: GenAI Drives 1,760% Surge in Business Email Compromise Attacks

A report recently published by Perception Point, a provider of advanced email and workspace security solutions, has identified a 1,760% year-on-year increase in social engineering-based Business Email Compromise (BEC) attacks over the course of 2023. Perception Point's '2024 Annual Report: Cybersecurity Trends & Insights' highlights how threat actors are leveraging increasingly accessible GenAI tools to scale and craft highly sophisticated and novel social engineering attacks. Also reported was a substantial shift to attacks using evasive tactics, including quishing (QR code phishing) and two-step phishing, that bypass traditional security systems. The report's findings are based on in-depth analysis by Perception Point's Incident Response team and data collected from the company's threat detection platform.

The past year has been defined by unprecedented advances in the capabilities and accessibility of GenAI, which malicious actors have harnessed to enhance and scale cyberattacks. In particular, GenAI has fueled the phenomenal growth in BEC attacks, facilitating incredibly well-crafted and targeted social engineering-based attacks that are challenging to detect. Whereas BEC attacks accounted for only 1% of all cyberattacks in 2022, their proportion of the total rose to 18.6% of all attacks in 2023.

A deeper exploration of 2023's most prominent attack trends reveal a number of other concerning developments that threaten the modern organization's workspace, which encompasses email, web browsers, and cloud collaboration channels.

Phishing is still the top cyber threat, accounting for more than 70% of all attacks, with little change from the previous year. But quishing emerged as a new trending threat in 2023, accounting for 2.7% of all phishing attempts. Attackers are exploiting the prevalence and inherent trust of QR codes in modern life to turn a straightforward scan into a serious threat. Throughout 2023, 1 out of 18 (6%) QR codes sent via email were malicious.

Over the year, the prevalence of two-step phishing attacks increased by 175%. These attacks are particularly deceptive as unlike traditional phishing methods, their multi-stage character makes them especially hard to detect. In these attacks, threat actors exploit legitimate services and hosting sites, often utilized for website-building, web hosting, or file-sharing. Exploiting the reputation of these well-known domains helps evade detection, particularly as these platforms are commonly used for legitimate business collaboration.

Additionally, account takeover (ATO) based threats, in which a legitimate account outside the organization is compromised (Vendor Email Compromise) and then used in highly targeted attacks, increased by 350% in 2023. Threat actors also impersonate well-known brands and invest in impersonating the brand of specific organizations that they target. In 2023, 55% of all brand impersonation attacks impersonated the organization that an employee works for.

Email continued to be the top attack vector, with 1 in 5 emails categorized as either malicious or spam. However, threat actors also exploited the expanding user workspace to target organizations in new ways:

  • Phishing attacks via the web browser increased in frequency from 60% of all browser-based attacks in 2022 to nearly 80% of all browser-based attacks in 2023.
  • Malware distribution accounted for 65% of attacks in M365 Apps including OneDrive, SharePoint and Teams.
  • Evasive threats and malware accounted for more than 50% attacks targeting CRMs like Zendesk and Salesforce.

The full report can be viewed here.

Featured

  • Tradeshow Work Can Be Fun

    While at ISC West last week, I ran into numerous friends and associates all of which was a pleasant experience. The first question always seemed to be, “How many does this make for you?” Read Now

    • Industry Events
    • ISC West
  • New Report Says 1 in 5 SMBs Would Be Forced to Shutter After Successful Cyberattack

    Small and medium-sized businesses (SMBs) play a crucial role in the U.S. economy, making up 99.9% of all businesses and contributing to half of the nation's GDP. However, these vital economic growth drivers face an escalating threat—cyberattacks that could put them out of business. Read Now

  • The Yellow Brick Road

    The road to and throughout Wednesday's and Thursday's ISC West was crowded but it was amazing. Read Now

    • Industry Events
    • ISC West
  • An Inside Look From Napco at ISC West

    Get a look into the excitement at ISC West 2025 from Napco. Hear from some of their top-tech executives live from the show floor. Read Now

    • Industry Events
    • ISC West
  • Upping the Ante

    I am not a betting man in terms of cards, dice, blackjack or that wheel with the black marble racing around the circumference of a spinning wheel, but I would bet on the success of ISC West this year. Read Now

    • Industry Events
    • ISC West

New Products

  • Hanwha QNO-7012R

    Hanwha QNO-7012R

    The Q Series cameras are equipped with an Open Platform chipset for easy and seamless integration with third-party systems and solutions, and analog video output (CVBS) support for easy camera positioning during installation. A suite of on-board intelligent video analytics covers tampering, directional/virtual line detection, defocus detection, enter/exit, and motion detection.

  • ComNet CNGE6FX2TX4PoE

    The ComNet cost-efficient CNGE6FX2TX4PoE is a six-port switch that offers four Gbps TX ports that support the IEEE802.3at standard and provide up to 30 watts of PoE to PDs. It also has a dedicated FX/TX combination port as well as a single FX SFP to act as an additional port or an uplink port, giving the user additional options in managing network traffic. The CNGE6FX2TX4PoE is designed for use in unconditioned environments and typically used in perimeter surveillance.

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.