Business Email Compromise stories
Average losses from successful attacks have fallen sharply, but one in three German SMEs says a major breach could still threaten its existence.
Reduced staffing and delegated approvals during annual leave are giving fraudsters more chances to slip through corporate checks, Everywhen says.
Rising deadline pressure is leaving finance and payroll teams more exposed to sophisticated scams that can disrupt payments and damage trust.
Attackers are increasingly using genuine Microsoft pages and browser tricks to steal session tokens, passwords and spread malware, Barracuda says.
Criminals are using AI to scale phishing and hunt flaws faster, forcing firms to harden defences as alert volumes and risks rise.
Half of organisations in Australia and New Zealand say AI use is ungoverned, heightening fears of deepfake scams and prompt-injection attacks.
Existing phishing and fraud tactics are becoming faster, cheaper and harder to detect, raising the risk for large organisations, ReliaQuest said.
AI-driven phishing is forcing buyers to favour platforms that cut false positives and blend email defence with user training, Frost & Sullivan said.
Fraudsters are using AI to forge invoices and supplier messages, prompting finance leaders to warn that traditional AP controls are no longer enough.
A single phishing email can now compromise identities, bypass multifactor authentication and hit endpoints within five minutes, Barracuda said.
BlueVoyant says a ClickFix malware campaign using fake browser updates is linked to the Rapid Brigantine ransomware ecosystem.
Thousands of corporate devices may be exposed because many remain unpatched, unseen or missing endpoint protection, Arctic Wolf found.
Recent breaches have exposed how weak vendor oversight is leaving schools and businesses more vulnerable to supply chain attacks.
Australian firms are using AI at scale, but many lack the visibility to stop shadow tools, agentic access and rising incidents.
Most customers still face avoidable phishing risk, as 59% of Australian banks lack the strict DMARC setting that blocks spoofed emails.
More than half of Singapore respondents lacked full visibility of employee AI use, heightening fears over shadow tools, data leaks and breaches.
Human error and ungoverned AI are heightening cyber risk in Singapore, where most workers say deepfakes are hard to spot and scams could succeed.
Australian businesses face renewed ransomware pressure as INC expands quickly after LockBit and BlackCat were disrupted, researchers say.
Industry experts warn that reimbursement is masking the scale of scams, as APP losses climbed 19% to GBP £576.4 million last year.
Phishing is becoming harder to spot as attackers use encryption and AI-generated sites to target organisations more effectively.