Sentry CTO - Cybersecurity
Email Is Still How Businesses Get Breached: The Threats That Matter and the Defenses That Work
Ask anyone what a cyberattack looks like and they describe something cinematic: code scrolling, systems seizing up, a ransom note on every screen. The attacks that actually cost businesses money are quieter than that, and most of them start in an inbox.
Email is the one system where outsiders get to put content directly in front of your least suspicious employee, all day, every day. That is why it remains the front door for most incidents we see in Arizona businesses, and why the FBI’s fraud numbers put email-based payment scams north of two and a half billion dollars a year in reported losses, more than ransomware.
The Attack That Costs the Most Money Involves No Malware at All
Business email compromise works like this. An attacker gets into one mailbox, usually with a password stolen or phished weeks earlier. They do not announce themselves. They read. They learn who pays invoices, who approves wires, which vendors bill you, and what the invoices look like.
Then one day your bookkeeper receives a message from a vendor they know, in a thread that already exists, saying the bank account for payments has changed. Every detail checks out, because the attacker is writing from inside a real relationship. The money leaves, and it does not come back.
Any request to change payment details, no matter how legitimate it looks, gets verified by phone, using a number you already had, not one from the email. This one habit defeats the single most expensive attack in the FBI's statistics. It costs nothing.
The Other Patterns Worth Knowing
- Phishing and spear phishing. Mass phishing casts a wide net. Spear phishing is written for one person, using details from LinkedIn, your website, or a previously compromised mailbox. The tell is rarely spelling anymore; modern phishing is well written. The tell is urgency plus a request involving credentials, gift cards, or money.
- Ransomware delivered by attachment. Still common, and increasingly aimed at cloud data as well as local files. The defense is layered: filtering that strips the attachment, endpoint control that stops the payload executing, and backups that are tested and kept beyond the attacker’s reach.
- Internal phishing. Once one mailbox is compromised, the next wave of phishing comes from a colleague’s real address. Perimeter filters never see it, because it never crosses the perimeter. This is why filtering that only inspects mail at the boundary is a decade out of date.
- Password reuse. One employee, one password, used for both a shopping site and their work account. The shopping site gets breached, and attackers try the same credentials against your Microsoft 365 within hours. This is how “sophisticated” attacks usually actually start.
The Defenses That Actually Work, in Order
- Multi-factor authentication, enforced everywhere. Not encouraged. Enforced. A stolen password should get an attacker nothing. Most of the incidents that reach us would have been stopped here.
- Filtering inside the mailbox, not just at the perimeter. Modern email security examines messages after delivery too, including internal mail, so a compromised account inside your business cannot phish its colleagues unnoticed.
- Machine-learning detection. Legitimately useful here, and this is one of the few places the AI label is more than marketing: pattern analysis catches the “vendor” who writes at 3am from a new device with subtly changed reply-to routing, details no busy human checks.
- A payment verification rule. The callout above. No technology can approve a wire transfer. That decision belongs to your process, so make the process strong.
- Trained, tested people. Awareness training plus simulated phishing, tracked over time so you can see who improves. Not to shame anyone, but because the person who fails three simulations is the person the real thing will reach.
- Encryption for sensitive content. For anything regulated (client records, financial data, health information), encryption keeps an intercepted message unreadable, and increasingly your insurer and your compliance framework both expect it.
Is MFA enforced on every mailbox, including the owner's? Would an email from a compromised coworker account pass your filtering untouched? And does the person who pays your invoices know the phone-verification rule for banking changes? If any answer is "not sure," that is your starting point.
Where This Fits for Your Business
Every layer above is part of the email security stack we run for Sentry Protect clients, and the questions in that last callout are among the first we ask in an assessment. If you cannot answer them confidently today, the three-minute self-assessment will show you where email fits among your other gaps, no email address required, which we recognize is a small irony given the topic.