Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireSecurity Leadership and ManagementCybersecurity News

The last six months shows a 341% increase in malicious emails

By Security Staff
Email app with many unread messages

Image via Unsplash

May 22, 2024

A report by SlashNext reveals an increase in malicious emails by 341% in the past six months. This includes a rise in BEC, phishing and other message-based attacks driven by generative AI. 

Notable findings from the report include: 

  • Since November 2022 (the launching of ChatGPT) malicious emails have increased by 4,151%. 
  • Credential harvesting phishing attacks have increased by 217% in the last six months. 
  • BEC attacks have increased by 29% in the last six months. 
  • 45% mobile threats are SMS smishing attacks. 

Security leaders weigh in 

Mika Aalto, Co-Founder and CEO at Hoxhunt:

“If you look closely, there’s some bad-news-good-news happening with this surge in phishing attack volume. The generative AI-enabled flood of sophisticated phishing emails is bad. But the fact that email filters still catch most of them is good. Most importantly, a well-trained workforce will spot and report the AI-boosted phishing emails as well as human-originated attacks, according to our own original research. 

“The bad news is that most companies are still relying on old-school SAT tools. These compliance-based exercises are based on yesterday’s threats and are proven to be ineffective. This SlashNext report brings into focus the need for targeted security training that keeps pace with the rapidly evolving threat landscape. BEC continues to be the top form of cybercrime, and AI is particularly concerning in a BEC attack because it can make the spoofed executive email seem more convincing via tone and deep fake technology. 

“Fluctuations in the threats hitting the technical perimeter are important, but it’s most crucial to know what attacks are bypassing technical protections, and how people are responding to attacks that land in their inboxes. For instance, we saw a 22x rise in QR phishing attacks that slipped past email filters, most of which redirected users to credential harvesters, which SlashNext reported had risen by over 200%. 

“The rise in mobile attacks such as SMS is a growing problem that can be addressed with targeted training. People click on malicious links more often on their phones, so security awareness training should help people stay alert against smishing attacks.”

Krishna Vishnubhotla, Vice President of Product Strategy at Zimperium:

“Organizations must protect their employees from phishing links, malicious QR codes and malicious attachments found in emails across all legacy and mobile endpoints. Bad actors are getting creative in designing email campaigns that bypass traditional detection mechanisms. Email attachments and links should be scrutinized by enterprises; adopting a zero-trust security model and using encrypted communication for sensitive exchanges will further guard against malicious emails. The best way to fight cybercriminals is to combine technological defenses with vigilant practices. 

“Today, we are exposed to an overwhelming number of scams. There are phishing scams, malware, lottery scams, tax scams, charity scams, fake invoices, package delivery scams, etc. And they don’t have the luxury of enterprise email filters of any sort, so they are really exposed. But even for consumers, the overall approach is the same. For protection, they should download tools to their laptops, desktops and mobile devices to help identify malicious emails. This is a good starting point. Once that’s done, the real work begins, which includes developing better cyber hygiene. We need to be watchful for destination URLs, spelling mistakes, sender emails, etc.” 

Darren Guccione, CEO and Co-Founder at Keeper Security:

“Over the past year, we have seen AI applications, like ChatGPT, gain remarkable ground in practical utilization. Cybersecurity is an arms race and bad actors are constantly evolving their tools to circumvent detection, while defenders are trying to adapt. ChatGPT or other popular artificial intelligence tools can be used on both sides of the cybersecurity landscape. For cybersecurity professionals, AI’s natural language processing capabilities enable it to streamline threat intelligence analysis, extracting valuable insights from vast datasets to stay abreast of emerging threats. ChatGPT can assist in real-time incident response by providing quick insights and suggestions during security incidents. Cybersecurity professionals can use these capabilities to analyze logs, identify potential attack vectors and recommend mitigation strategies.

“Meanwhile, a bad actor can utilize ChatGPT a number of ways, including to create convincing phishing emails. By leveraging ChatGPT or the natural language processing capabilities of other generative AI tools, bad actors can quickly and easily craft sophisticated messages tailored to specific individuals or organizations, making it more likely for recipients to fall victim to them. These emails can contain malicious links or attachments, leading to unauthorized access, data breaches or the deployment of malware. ChatGPT can also be utilized to generate deceptive content for social engineering, creating fake profiles or messages to manipulate individuals into disclosing sensitive information. 

“Not only can the tools help bad actors create content such as a believable phishing email or malicious code for a ransomware attack, but they can do so quickly and easily. The least-defended organizations will be particularly vulnerable, as the volume of attacks will likely continue to increase.

“AI in the hands of adversaries has the potential to ramp up social engineering exponentially, which is currently one of the most successful scamming tactics available. Cybercriminals can use AI for password cracking, phishing emails, deep fakes, impersonation and malware attacks. Phishing emails used to be easy to spot because they had frequent grammatical errors and spelling mistakes, but AI is now making it easy for cybercriminals to generate well-written, convincing content for phishing scams. Instead of writing their own phishing emails or text messages, cybercriminals are leveraging AI to write the scams for them. Because AI algorithms can analyze large amounts of data, they can also create fake personas, such as impersonating someone’s voice or creating a deep fake video.”

KEYWORDS: artificial intelligence (AI) email security phishing security leaders smishing social engineering

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Cybersecurity
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Columns
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Cybersecurity Education & Training
    By: Charles Denyer
Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Half open laptop

“Luigi Was Right”: A Look at the Website Sharing Data on More Than 1,000 Executives

Person working on laptop

Governance in the Age of Citizen Developers and AI

Shopping mall

Victoria’s Secret Security Incident Shuts Down Website

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

August 27, 2025

Risk Mitigation as a Competitive Edge

In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Paper airplane image against brick wall

    Research shows that 15% of emails were malicious in 2023

    See More
  • ChatGPT on computer

    Report shows 1265% increase in phishing emails since ChatGPT launched

    See More
  • Blue ceiling lights in dark room

    72% of cybersecurity leaders faced a cyberattack in last 18 months

    See More

Related Products

See More Products
  • databasehacker

    The Database Hacker's Handboo

See More Products

Events

View AllSubmit An Event
  • August 27, 2025

    Risk Mitigation as a Competitive Edge

    In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing