Email remains central to the operations of many organizations in 2023, yet despite decades of efforts to help improve security, challenges remain.

Armorblox released its Email Security Threat report yesterday, revealing a number of persistent threats that continue to put email at risk. The Armorblox report is derived from the analysis of data collected from over 58,000 customer tenants, which involved scrutinizing more than 4 billion emails and averting 800,000 threats per month.

While many organizations rely on the native security capabilities of their cloud email providers, the report found that's often not nearly enough. According to the report, 77% of business email compromise (BEC) attacks were able to bypass the built-in protection layers email providers have in place. BEC overall rose by 72% year over year, according to the report.

"BEC attacks are classified as socially engineered attacks looking to exfiltrate sensitive information or get a response based on the language and content within the email, such as a quick request from a malicious actor posing as an executive," Brian Johnson, chief security officer at Armorblox told SDxCentral.

No malware required when BEC is involved

A key difference between BEC and a phishing attack is the simple fact that BEC does not include malware.

Using language alone apparently is enough to bypass a lot of existing email security systems used by cloud providers. So how do attackers actually get them to work?

"BEC attacks are sophisticated attacks because bad actors usually do a lot of research on their target prior to initiating," Johnson explained.

Due to the targeted nature, he noted that BEC  emails could include information such as where employees just came back from vacation, information about his or her dog, or anything else that the unsuspecting victim could have unknowingly shared with the bad actor across social or public-facing forums. As these attacks are highly customized, Johnson said that only email security solutions that can detect language anomalies in email conversations can accurately detect and protect end users from the majority of these attacks.

Email authentication methods, such as the use of DMARC (domain-based message authentication, reporting and conformance) is sometimes touted by experts as being a critical part of security. According to Johnson, DMARC doesn't help much when it comes to BEC.

"One of the common tactics we see cybercriminals using to bypass email security layers includes using recognized, trusted domains, such as gmail.com or other email providers for the email addresses to send email attacks so that they pass the basic DMARC checks," he said. "Legacy solutions overly rely on these email authentication checks to analyze emails, and by sending email threats from trusted domains bad actors have seen success in bypassing these security layers that don’t use other checks."

Bored of phishing? Get ready for Graymail

Phishing continues to be an issue that plagues organizations.

Armorblox reported a 70% increase in phishing attacks in 2022, with 96% of phishing attacks including malicious links within the email body. In 2022, the most frequent business workflows used in phishing attacks were notification or alerts workflows being spoofed in 52% of the attacks, known IT requests, login, or user confirmation workflows being spoofed in 40% of the attacks, and password reset workflows being spoofed in 8% of the attacks.

While phishing has long been an issue that IT teams have had to deal with, Johnson noted that a new category of email risk included in this year’s report was graymail. The term graymail refers to emails that  come from a legitimate source, though aren't particularly wanted, such as promotional emails, newsletters and notifications. Johnson said that his firm has seen increasing amounts of graymail inundating security teams and also increasing the chance of recon email attacks.

"Recon email attacks are emails disguised as legitimate email communications or graymail, with the attacker’s goal of eliciting a response prior to exfiltrating sensitive user or organizational data," Johnson said.

So how bad is graymail? According to Armorblox,  for enterprise organizations, security teams can find themselves spending close to 30 hours a week manually remediating graymail emails.

"To see that security teams truly are wasting valuable time with manual remediation of graymail confirms the trends that the Armorblox team had been seeing, and one of the reasons why we chose to put a prominent focus this year on helping security teams automatically remediate unwanted and malicious graymail," he said. "To save them the valuable time they otherwise would have to spend on gratuitous work."