impostor email threats - proofpoint, inc. · proofpoint imposter infographic author: proofpoint...

1
To learn more about the threat of impostor emails, download our white paper www…. Wire Transfer Urgent Greeting Confidential Acquisition 21% 21% 19% 7% 2% 30% Tax Information Tax Information Tax Information ! 25% HR 13% Finance 8% Payroll 5% COO 1% Specialist impostor EMAIL Topics 47% CFO Reply-to spoofing The “From” name, address field, and reply-to name are the real ones of the executive being impersonated. But the “Reply-to” address is the impostor’s. Spoofed name The name of the spoofed executive in the “From” field. But the email address is an outside email account (such as Gmail) that belongs to the attacker. Lookalike domain The attacker’s “From” address is close enough in appearance to the impersonated executive’s to fool busy recipients. Spoofed Sender (With no reply-to address) The impostor email uses the name and email address of the spoofed executive. But the email does not contain a “Reply-to” address. 75% 21% 2% 2% impostor EMAIL Targets impostor Email ThreatS Impostor email threats (also called business email compromise and CEO fraud) have hit more than 17,000 companies since the FBI’s Internet Crime Complaint Center (IC3) began tracking this type of scam in late 2013. These attacks have collectively scammed victims out of more than $2.3 billion globally. Many messages will be quickly recognized by recipients as phishing and discarded. But the small few that succeed can yield millions of dollars in fraudulent transfers. Here are some facts about impostor emails from Proofpoint research. 4 Types of Impostor Emails What You Need to Know to Recognize and Stop Them

Upload: others

Post on 30-Sep-2020

5 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: impostor Email ThreatS - Proofpoint, Inc. · Proofpoint Imposter Infographic Author: Proofpoint Subject: Imposter Emails: What You Need to Know to Recognize and Stop Them Keywords:

To learn more about the threat of impostor emails, download our white paper www….

Wire Transfer Urgent Greeting Confidential Acquisition

21% 21% 19% 7% 2%30%

Tax Information

Tax Information

Tax Information !

25%

HR

13%

Finance

8%

Payroll

5%

COO

1%

Specialist

4 Types of impostor Emails

impostor EMAIL Topics

47%

CFO

Reply-to spoofingThe “From” name, address field, and reply-to name are the real ones of the executive being impersonated. But the “Reply-to” address is the impostor’s.

Spoofed nameThe name of the spoofed

executive in the “From” field. But the email address is an outside email account (such as Gmail)

that belongs to the attacker.

Lookalike domainThe attacker’s “From”

address is close enough in appearance to the

impersonated executive’s to fool busy recipients.

Spoofed Sender(With no reply-to address)The impostor email uses the name and email address of the spoofed executive. But the email does not contain a “Reply-to” address.

75%

21%

2%

2%

impostor EMAIL Targets

impostor Email ThreatSImpostor email threats (also called business email compromise and CEO fraud) have hit more than 17,000 companies since the FBI’s Internet Crime Complaint Center (IC3) began tracking this type of scam in late 2013. These attacks have

collectively scammed victims out of more than $2.3 billion globally. Many messages will be quickly recognized by recipients as phishing and discarded. But the small

few that succeed can yield millions of dollars in fraudulent transfers.

Here are some facts about impostor emails from Proofpoint research.

4 Types of Impostor Emails

What You Need to Know to Recognize and Stop Them