chat
expand_more

New Research Shows Phone Fraud Targets 89% of Companies

Today, Abnormal released our H1 2022 Email Threat Report, focused on data from July to December 2021. Over the course of those six months, we tracked a relatively new form of cyber attack—phone fraud that starts via email.
March 22, 2022

Modern threats continue to increase in volume and severity, as cybercriminals turn from low-value attacks to more sophisticated, high-value strategies that rely on social engineering to trick recipients into sending money or leaking sensitive information. And because these threats contain few indicators of compromise, they evade secure email gateways and other traditional systems, landing in employee inboxes where they can cause significant damage.

Today, Abnormal released our H1 2022 Email Threat Report, focused on data from July to December 2021. Over the course of those six months, we tracked a relatively new form of cyber attack—phone fraud that starts via email.

New Malware Tactic Involves Phone Fraud

Starting in the spring of 2021, Abnormal noticed an increase in scams that encouraged recipients to do something fairly unexpected—pick up their phone and call the scammers. These emails use a variety of scare tactics, often involving a pending charge, to prompt their targets to call the phone number provided within the email.

Example of a fraud email prompting victims to call a phone number

Once they do so, they are directed to a website to download some type of file that then installs a form of malware, typically BazarLoader, on their computer. This initial installation allows attackers to then install additional malware that can be used for ransomware attacks.

An Emerging (and Growing) Trend

Vishing, or voice phishing, has become an increasingly popular tactic in recent years, but these phone fraud attacks are different in that they start with a phishing email. They then direct users to call them, versus directly calling the target as part of the vishing scam. These phone

fraud attacks are likely geared toward consumers, but it is clear that threat actors were willing to scam organizations as well—and may even prefer them. In cases uncovered by Abnormal, impersonated brands included PayPal, Microsoft, Amazon, Norton AntiVirus, and Best Buy, all of which could be used for both personal and business transactions.

These phone scams were first detected in the first part of the year, but started increasing in the third quarter and picked up significantly in December—right before the holidays, perhaps when the scammers knew that people would be more concerned about money being unexpectedly deducted from their bank accounts.

Probability of receiving a phone fraud attack by week

The likelihood of receiving these attacks increased dramatically throughout the last half of the year, with 31.4% of organizations receiving at least one attack in the third quarter, and over half in the fourth quarter. But that number jumped even more in December, with organizations reaching a 59.2% likelihood of attack in the last month of the year. The highest week ​​saw a 89% chance of attack, before dropping back to average levels closer to the holidays.

Largest Organizations at Largest Risk for Phone Fraud

Perhaps unsurprisingly, those organizations with the most employees had the largest probability of receiving an attack. Small businesses under 500 employees were fortunate to experience only an average 12% probability of attack throughout the half, but large organizations comprised of more than 50,000 employees received an attack nearly three weeks out of each month.

Phone fraud probability by organization size

While business email compromise attacks mainly target executives or those in the finance department, these phone fraud attacks could be relevant to almost anyone. As such, it makes sense that the chance of receiving an attack simply grows alongside the number of people within the organization.

No matter the size, one thing is for sure—threat actors saw success with phone fraud attacks in 2021 and doubled down on this attack type in the last quarter of the year. It remains to be seen if this trend will continue into 2022, particularly as end users become more aware of the tactic.

To learn more about how phone fraud is impacting your industry, as well as additional data on supply chain compromise and business email compromise, download the email threat report.

New Research Shows Phone Fraud Targets 89% of Companies

See Abnormal in Action

Get a Demo

Get the Latest Email Security Insights

Subscribe to our newsletter to receive updates on the latest attacks and new trends in the email threat landscape.

Get AI Protection for Your Human Interactions

Protect your organization from socially-engineered email attacks that target human behavior.
Request a Demo
Request a Demo

Related Posts

B Proofpoint Customer Story Blog 8
A Fortune 500 transportation and logistics leader blocked more than 6,700 attacks missed by Proofpoint and reclaimed 350 SOC hours per month by adding Abnormal to its security stack.
Read More
B Gartner MQ 2024 Announcement Blog
Abnormal Security was named a Leader in the 2024 Gartner Magic Quadrant for Email Security Platforms and positioned furthest for Completeness of Vision.
Read More
B Gift Card Scams Tricker to Spot Blog
Learn why gift card scams are becoming more difficult to identify, how cybercriminals evolve their tactics, and strategies to protect your organization.
Read More
B Offensive AI 12 16 24
Learn how AI is used in cybersecurity, what defensive AI vs. offensive AI means, and how to use defensive AI to combat offensive AI.
Read More
B Proofpoint Customer Story Blog 7
See how Abnormal's AI helped a Fortune 500 insurance provider detect 27,847 threats missed by Proofpoint and save 6,600+ hours in employee productivity.
Read More
B Cyberattack Forecast Emerging Threats Blog
Uncover the latest email threats and strategies to strengthen your cybersecurity and prepare for 2025.
Read More