Internet scams - Microsoft and American Express most frequently counterfeited brands

A new Trustwave SpiderLabs study reveals "interesting changes" in delivery methods, techniques, themes, and target brands of email phishing directed against financial services.

Internet scams - Microsoft and American Express most frequently counterfeited brands
00:00 00:00

Summary

  • Fraudsters often impersonate Microsoft and American Express in phishing attacks targeting financial services, according to the 2023 Financial Services Sector Threat Landscape report by Trustwave SpiderLabs.
  • Phishing and malicious software transmitted by email are the most common methods of gaining access to organizations.
  • Changes in delivery methods, techniques, themes, and targeted brands have increased the effectiveness of these attacks.
  • Financial services are increasingly targeted by cybercriminals, with a 65% increase in attacks on web applications and APIs in the second quarter of 2023 compared to the same period in 2022.
  • The financial services sector is the main target of DDoS attacks, with the EMEA region accounting for 63.5% of global DDoS events.
  • HTML files are the most common malicious attachments in emails, accounting for 78% of all assessed malicious attachments, and are mainly used for phishing authentication data, redirects, and smuggling HTML.
  • Attackers rarely used PDF files (3%), Excel (2%), and Word documents (1%) for malicious attachments.
  • The most common themes of malicious email attachments were voice notifications, payment receipts, purchase orders, money transfers, bank deposits, and quote requests.
  • American Express (24%), DHL (21%), and Microsoft (15%) were the most frequently counterfeited brands in these attacks.

Fraudsters using phishing messages in their attacks targeted at financial services most often impersonate the technology giant Microsoft and the international banking company American Express. This is according to the 2023 Financial Services Sector Threat Landscape report prepared by Trustwave SpiderLabs, which analyzes the threats faced by the financial services industry.

The report lists phishing and malicious software transmitted by email as the two most commonly used methods of gaining access to organizations, with Trustwave SpiderLabs observing "interesting changes" in delivery methods, techniques, themes, and targeted brands of attacks on financial services in the past year. According to the report, such changes have contributed to the further significance and effectiveness of these types of attacks.

Finance in the crosshairs of cybercriminals

Financial services are increasingly in the crosshairs of cybercriminals. Recent research conducted by Akamai showed an increase in the number of attacks on web applications and application programming interfaces (APIs) aimed at the global financial services industry. These attacks increased by 65% in the second quarter of 2023 compared to the second quarter of 2022. The study also showed that the financial services sector is currently the main target of DDoS attacks, with the EMEA region accounting for 63.5% of global DDoS events.

Data from Trustwave SpiderLabs' financial services client base also indicate that HTML files are the most common malicious attachments in emails and account for 78% of all assessed malicious attachments. They are mainly used for phishing authentication data, redirects, and smuggling HTML, with 33% of such files using obfuscation as a way to avoid defense. According to the report, attackers rarely used PDF files (3%), Excel (2%), and Word documents (1%).

Voice notifications, payment receipts, purchase orders, money transfers, bank deposits, and quote requests were the most common themes of malicious email attachments, with American Express (24%), DHL (21%), and Microsoft (15%) being the most frequently counterfeited brands.