Nine in 10 enterprises fell victim to successful phishing in 2022

Egress annual email security risk report breaks down impacts of email-based phishing attacks and data loss, and the effect these can have on organisations in terms of staff retention and morale

Sebastian Klovig Skelton

By

Published: 07 Mar 2023 15:00

Email security company Egress finds that 92% of organisations have fallen victim to a successful phishing attack in their Microsoft 365 environments over the past year, with a further 98% of cyber security managers expressing frustration with secure email gateway (SEG) technologies.

According to Egress’ Email security risks report 2023 – which investigated both inbound phishing attacks and outbound data loss and exfiltration – 58% of cyber security managers said traditional SEG technologies were not effective in stopping employees from accidentally emailing the wrong person or with the wrong attachment, while 53% conceded that too many phishing attacks bypass their gateway.    

Egress’ data shows that almost half (44%) of phishing emails are classed as “technical”, meaning they were specifically engineered to bypass signature-based defences, while over a quarter (28%) were sent from compromised legitimate domains. Out of all account takeover attacks, Egress notes 85% start with a phishing email.

A further 91% of cyber security managers also noted that data has been leaked by outbound emails, although this was due to mistakes or taking risks as opposed to malicious insiders.

Egress said the top three causes for these incidents is risky employee behaviour (i.e. transferring data to personal accounts for remote work), human error (emailing confidential information to incorrect recipients), and self-serving data exfiltration (such as taking data to a new job).

Overall, Egress found that 86% of organisations surveyed were negatively impacted by phishing emails, 54% suffered financial losses from customer churn following a successful phishing attack, and 40% of successful phishing incidents resulted in employees leaving the company. Nearly all cyber security managers (99%) said they were stressed about email security.

“The growing sophistication of phishing emails is a major threat to organisations and needs to be urgently addressed,” said Jack Chapman, vice-president of threat intelligence at Egress.

“The signature-based detection used by Microsoft 365 and secure email gateways can filter out many phishing emails with known malicious attachments and links, but cyber criminals want to stay one step ahead.

“They are evolving their payloads and increasingly turning to text-based attacks that utilise social engineering tactics and attacks from a known or trusted source, such as a compromised supply chain email address.”

He further warned that phishing attacks will only become more advanced as cyber criminals turn to AI-powered technologies such as chatbots to automate and refine their attacks.

Egress noted that the top three types of phishing attacks that people fell victim to were those involving malicious URL or malware attachments, social engineering, and supply chain compromises.

Aside from the SEG issues, managers also expressed concern about their security awareness and training (SA&T) programmes, as while 98% carry out some kind of SA&T, 96% aired a concern or limitation with it.

For example, 46% said employees skip through it as fast as possible, 29% said employees find the training annoying, and a further 37% admitted they are not confident people remember what they are taught.

Egress concluded in its report that, despite investments in traditional email security and SA&T, enterprises remain highly vulnerable to phishing attacks, human error and data exfiltration.

It recommends using intelligent email security solutions to augment traditional SEGs and Microsoft 365, such as integrated cloud email security (ICES) solutions that use behaviour-based security to detect anomalies in peoples actions to detect and stop advanced phishing threats.

Read more on IT education and training

Read More
Luz Volkman

Latest

Moore Park South Unveils New Park, 12-Hole Golf Course | Mirage News

NSW Gov Mums, dads and young people from across Sydney are a step closer to being able to enjoy a brand-new park with sports fields, courts, outdoor fitness equipment, a nature playground, shaded picnic spaces with barbecues and more. The Minns Labor Government has today released the final plan for the new 20-hectare park and

HDB resale prices and transactions ease slightly in April 2026, Money News

April 2026 brings a clearer view of how the HDB resale market is evolving. While headline figures show slight changes in both prices and activity, the underlying trends point to a shift in buyer behaviour and market dynamics. HDB resale prices ease slightly in April 2026 In April 2026, the HDB resale market showed signs

Big Breakthrough In Suvendu Aide Chandrakanth’s Murder Probe: Fake Number Plate, Live Rounds, Fired Cartridges Recovered; Vehicle Seized

Updated 7 May 2026 at 10:30 IST On Wednesday, Suvendu Adhikari's PA was allegedly shot at and succumbed to his injuries at a hospital near Madhyamgram. Big Breakthrough In Suvendu Aide Chandranath’s Murder Probe: Fake Number Plate, Live Rounds, Fired Cartridges Recovered; Vehicle Seized | Image: Republic Madhyamgram: West Bengal Police on Thursday seized a

Berkshire-owned distribution giant to deploy driverless big rigs across U.S. Sun Belt

Berkshire Hathaway's McLane, with autonomous trucking company Aurora Innovation, is planning new autonomous freight routes between its distribution centers and restaurants across the U.S. Sun Belt by year-end. Aurora Innovation Berkshire Hathaway subsidiary McLane is planning to deploy self-driving trucking technology from Aurora Innovation on routes in Texas and across the U.S. Sun Belt by

Newsletter

Don't miss

Moore Park South Unveils New Park, 12-Hole Golf Course | Mirage News

NSW Gov Mums, dads and young people from across Sydney are a step closer to being able to enjoy a brand-new park with sports fields, courts, outdoor fitness equipment, a nature playground, shaded picnic spaces with barbecues and more. The Minns Labor Government has today released the final plan for the new 20-hectare park and

HDB resale prices and transactions ease slightly in April 2026, Money News

April 2026 brings a clearer view of how the HDB resale market is evolving. While headline figures show slight changes in both prices and activity, the underlying trends point to a shift in buyer behaviour and market dynamics. HDB resale prices ease slightly in April 2026 In April 2026, the HDB resale market showed signs

Big Breakthrough In Suvendu Aide Chandrakanth’s Murder Probe: Fake Number Plate, Live Rounds, Fired Cartridges Recovered; Vehicle Seized

Updated 7 May 2026 at 10:30 IST On Wednesday, Suvendu Adhikari's PA was allegedly shot at and succumbed to his injuries at a hospital near Madhyamgram. Big Breakthrough In Suvendu Aide Chandranath’s Murder Probe: Fake Number Plate, Live Rounds, Fired Cartridges Recovered; Vehicle Seized | Image: Republic Madhyamgram: West Bengal Police on Thursday seized a

Berkshire-owned distribution giant to deploy driverless big rigs across U.S. Sun Belt

Berkshire Hathaway's McLane, with autonomous trucking company Aurora Innovation, is planning new autonomous freight routes between its distribution centers and restaurants across the U.S. Sun Belt by year-end. Aurora Innovation Berkshire Hathaway subsidiary McLane is planning to deploy self-driving trucking technology from Aurora Innovation on routes in Texas and across the U.S. Sun Belt by

New members for Registration Board | Local Business | trinidadexpress.com

THE Government has appointed new members to the Registration, Recognition and Certification Board (RRCB). The appointments were formalised during a ceremony hosted by the Ministry of Labour on April 10 at the ministry’s head office, International Waterfront Centre, Port of Spain. In a release from the ministry, Labour Minister Leroy Baptiste said the RRCB plays

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID

Business groups are fighting Labor’s CGT changes. Here is where SMEs stand

Labor’s most contested tax reform in a generation cleared its first formal hurdle on Thursday and immediately ran into organised resistance. Treasurer Jim Chalmers introduced the government’s tax reform legislation to the House of Representatives on 28 May, bundling together four budget measures: the capital gains tax overhaul, new limits on negative gearing, a $250

Meet the most influential business owners from Southwest Nigeria

This article spotlights the most influential business owners from Southwest Nigeria, adjudged by their dominance in their respective sectors of the economy where they operate. The post Meet the most influential business owners from Southwest Nigeria appeared first on Nairametrics...