Resilient Cyber w/ Mick Leach - 5 Email Threats to Watch For in 2025
Jan 21, 2025
auto_awesome
Mick Leach, Field CISO at Abnormal Security and an expert in email security, dives into the rising threats facing organizations. He highlights the evolving landscape of email attacks, particularly those fueled by AI, which make traditional defenses less effective. Cryptocurrency fraud and AI-generated phishing tactics are just the tip of the iceberg. Mick emphasizes the need for advanced training and AI-driven solutions to bolster defenses against these sophisticated threats, while discussing the operational risks of email account takeovers.
Cybercriminals are evolving their tactics by leveraging generative AI in email phishing, making traditional security measures increasingly inadequate.
The rise of cryptocurrency scams highlights the need for organizations to educate employees about emerging fraud tactics and threat awareness.
Deep dives
The Evolution of Cyber Criminal Tactics
Cyber criminals are increasingly leveraging advanced technology to evolve their attack methods, particularly in email-centric phishing schemes. The rise of generative AI tools has improved the sophistication and effectiveness of these attacks, making them as convincing as high-quality, human-crafted phishing messages. Tactics such as QR code phishing and file sharing phishing are on the rise, complicating detection efforts for organizations. As attackers shift towards social engineering techniques that initiate conversations rather than relying solely on malicious links, the need for robust human-centric security approaches becomes paramount.
Impact of Cryptocurrency on Fraud
The booming interest in cryptocurrency has led to a surge in fraud attempts targeting both individuals and businesses. Fraudsters capitalize on the decentralized nature and anonymity of cryptocurrencies, creating increasingly sophisticated scams that lure people into making investments or direct payments to them. An example includes schemes that entice users to invest in high-value cryptocurrencies, only for the payments to vanish into the hands of fraudsters. This environment demands that organizations remain vigilant and educate employees on the signs of cryptocurrency-related scams to mitigate financial losses.
Challenges of Multi-Channel Phishing Attacks
Phishing attacks are expanding beyond traditional email communications into multi-channel environments like chat applications and SMS, making detection more complex. Many organizations have improved their email security training, but this same caution does not always extend to internal messaging platforms, leaving employees vulnerable. Attackers exploit the trust placed in these platforms to impersonate familiar contacts and trick users into sharing sensitive information. As businesses increasingly use various communication tools, they need to establish consistent security awareness across all channels to combat this evolving threat landscape.
Leveraging AI for Enhanced Security
Organizations must adapt their security strategies by leveraging AI technologies to effectively combat modern threats. Traditional security measures, such as secure email gateways, are often insufficient against novel and sophisticated attacks due to their reliance on known signatures and patterns. New AI-driven solutions can analyze vast amounts of unstructured data to identify anomalous behaviors, providing a proactive defense against unknown threats. This shift towards behavior-based detection represents a critical advancement in cybersecurity, allowing organizations to stay ahead of potential risks in a rapidly changing digital environment.
While cybercriminals can (and do) infiltrate organizations by exploiting software vulnerabilities and launching brute force attacks, the most direct—and often the most effective—route is via the inbox. As the front door of an enterprise and the gateway upon which employees rely to do their jobs, the inbox represents an ideal access point for attackers.
And it seems that, unfortunately, cybercriminals aren’t lacking when it comes to identifying new ways to sneak in. Abnormal Security’s Field CISO, Mick Leach, will discuss some of the sophisticated threats we anticipate escalating in the coming year—including cryptocurrency fraud, AI-generated business email compromise, and more.
Mick and I dove into a lot of great topics, including:
The evolution of email based attacks and why traditional tooling may fall short
How attackers are leveraging GenAI and LLM’s to make more compelling email-based attacks
How defenders can utilize AI to improve their defensive capabilities
The role of tooling such as Secure Email Gateways and more, and how they still play a role but fail to meet the latest threat landscape
How Abnormal is tacking email-based attacks and the outcomes they are helping customers achieve with streamlined integration and use
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode