Common Business-Related Phishing Scams Include Fake HR and IT Subject Lines (2024)

Think you’ve received an important document from HR? Be careful.

KnowBe4’s quarterly phishing test report found that threat actors in Q2 often found success with emails spoofing HR departments. After an ill-fated click occurred, links in the body of emails and PDF documents were common vectors for attacks.

TechRepublic spoke with KnowBe4 Security Awareness Advocate Erich Kron about the results of the phishing tests and how to keep businesses safe from ever-evolving, generative AI-powered phishing attacks.

Fake emails from HR top the list of social engineering scams

Some attackers use fake messages from HR to make employees believe that clicking a link or viewing a document is urgent. According to the report:

  • 42% of the business-related email subject lines studied were related to HR.
  • Another 30% were related to IT.
  • Many of these subject lines played on employees’ emotions at work, such as “Comment was left on your Time Off Request” or “Possible Typo.”

“If you have a strong emotional response to a text message, or a phone call, or an email, we need to take a deep breath and step back and look at it very critically,” said Kron. “Because these are social engineering attacks and these really work off of getting you in an emotional state where you make mistakes.”

Other recent attacks have come from emails faking messages from Microsoft or Amazon.

Common Business-Related Phishing Scams Include Fake HR and IT Subject Lines (1)

Phishing emails with QR codes have also tricked employees. Like malicious links, these QR codes are usually found in emails purporting to be from well-known companies, HR, or IT.

“The continuous rise in HR related phishing emails is especially troubling, as they target the very foundation of organizational trust,” said Stu Sjouwerman, CEO at KnowBe4, in a press release on Aug. 7. “Moreover, the increase of QR codes in phishing attempts adds another layer of complexity to these threats.”

The health care and pharmaceuticals industries were most susceptible to phishing attacks, KnowBe4 found, followed by hospitality, education, and insurance — with some variance for different sizes of organizations.

How does KnowBe4’s phishing report work?

KnowBe4 gathers the information for its quarterly Industry Benchmarking Report from its customers and from its phishing report portal, which any business can use.

KnowBe4, which sells a simulated phishing platform, launches fake phishing attacks against businesses to test their resilience. Specifically, KnowBe4 assessed the types of attacks people are falling for and how training like theirs keeps businesses safer from cyberattacks.

The data came from 54 million simulated phishing tests, which impacted more than 11.9 million users from 55,675 organizations around the world.

“A lot of times we actually take the real ones [phishing attacks] that are out there and turn them into simulated ones,” said Kron. “So we do what we call defanging them, because we know that’s really what’s going on out there.”

The report measured “Phish-prone Percentage,” a proprietary assessment of the percentage of “employees likely to fall for social engineering or phishing scams.” The average PPP fell from 34.3% to just 4.6% after a year of ongoing training and phishing tests.

SEE: The difference between phishing and spear phishing is whether the attack is widespread or crafted for a specific person.

How businesses can reduce vulnerability to phishing attacks

Organizations should make it clear to employees that phishing emails may not be as filled with typos or blatant pleas for money as they used to be.

“Generative AI has really helped with the translations and cleaning up things,” said Kron, “and allowed them [attackers] to scale a whole lot more without all of those errors that we would normally see.”

Employees should remember to look closely at URLs and email addresses. They should consider whether an email with a subject line including the word “urgent” really is what it seems.

For example, “Did it actually come from my boss, or does it just say their name?” Kron said.

Anti-spam or anti-virus filters can catch some social engineering and phishing attacks, while multifactor authentication can limit attackers’ reach even if the victim clicks a link or scans a QR code. Along with KnowBe4, companies such as Sophos, Proofpoint, Ninjio Hoxhunt, Cofense, and others offer security training through simulated attacks.

Overall, make sure employees are vigilant, whether or not that vigilance is tested with a regular phishing test.

“Be a little bit on edge about it,” Kron said.

Subscribe to the Cybersecurity Insider Newsletter

Strengthen your organization's IT security defenses by keeping abreast of the latest cybersecurity news, solutions, and best practices. Delivered every Monday, Tuesday and Thursday

Subscribe to the Cybersecurity Insider Newsletter

Strengthen your organization's IT security defenses by keeping abreast of the latest cybersecurity news, solutions, and best practices. Delivered every Monday, Tuesday and Thursday

Common Business-Related Phishing Scams Include Fake HR and IT Subject Lines (2024)

References

Top Articles
Corpus Christi Airport (CRP) Info
LatinVFR Airbus A318 for Microsoft Flight Simulator | MSFS | Flightsim.to
Obituary for Mark E. Rimer at Hudson-Rimer Funeral Chapel
Why Does It Say I Have 0 Followers on TikTok?
Growing At 495%, Saviynt Says It Prevails Over SailPoint In $20B Market
Stolen Touches Neva Altaj Read Online Free
Ann Taylor Assembly Row
50 Cent – Baby By Me (feat. Ne-Yo) ఆంగ్ల లిరిక్స్ & రంగుల అనేక. అనువాదాలు - lyrics | çevirce
Optum Primary Care - Winter Park Aloma
Missed Connections Dayton Ohio
Nsu Kpcom Student Handbook
Bank Of America Operating Hours Today
Busted Newspaper Randolph County
Varsity Competition Results 2022
Blind Guardian - The God Machine Review • metal.de
Grizzly Expiration Date 2023
Premier Auto Works-- The House Of Cash Car Deals
Nsu Occupational Therapy Prerequisites
Nutrislice White Bear Lake
Hotfixes: September 13, 2024
12 Week Glute Program to Transform Your Booty with Free PDF - The Fitness Phantom
Dominion Post Obituaries Morgantown
3 30 Mountain Time
Redgifs.comn
Madison Legistar
Baddiehub Cover
David Goggins Is A Fraud
Arsenal news LIVE: Latest updates from the Emirates
Pella Culver's Flavor Of The Day
Kaelis Dahlias
Worldfree4U In
My Les Paul Forum
4201 Crossroads Wy, Rancho Cordova, CA 95742 - MLS 224103058 - Coldwell Banker
Matrix Skilled Nursing Login
Hyvee.com Login
Panama City News Herald Obituary
Basis Independent Brooklyn
Www.publicsurplus.com Motor Pool
Carlynchristy
Dyi Urban Dictionary
How to paint a brick fireplace (the right way)
I Heard The Bells Film Showtimes Near Newport Cinema Center
NUROFEN Junior Fieber-u.Schmerzsaft Oran.40 mg/ml - Beipackzettel
Busted Bell County
American Idol Winners Wiki
Old Navy Student Discount Unidays
Hkx File Compatibility Check Skyrim/Sse
1Wangrui4
Craigslist West Valley
Larry's Country Diner LIVE! - 2024 Tickets - Branson Travel Office
Creed 3 Showtimes Near Island 16 Cinema De Lux
Imagetrend Elite Delaware
Latest Posts
Article information

Author: Duncan Muller

Last Updated:

Views: 6300

Rating: 4.9 / 5 (79 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Duncan Muller

Birthday: 1997-01-13

Address: Apt. 505 914 Phillip Crossroad, O'Konborough, NV 62411

Phone: +8555305800947

Job: Construction Agent

Hobby: Shopping, Table tennis, Snowboarding, Rafting, Motor sports, Homebrewing, Taxidermy

Introduction: My name is Duncan Muller, I am a enchanting, good, gentle, modern, tasty, nice, elegant person who loves writing and wants to share my knowledge and understanding with you.