Contents

Email fraud, a form of cybercrime that uses email to obtain sensitive information, is now one of the most powerful weapons cyberattackers use to take over people’s entire digital identities. Statistics show that around 60% of all data breaches involve a human element, with phishing and social engineering among the most commonly employed tactics. Stolen credentials are among the leading initial access methods, accounting for approximately 22% of confirmed breaches. These breaches show that attackers are no longer content with receiving a single illicit payment or stealing a single dataset. Instead, their goal is to wreak as much havoc as possible by maintaining long-term attacks that continue to impact their victims for weeks, months, or even years.

Traditional Email Fraud

In the past, traditional email fraud involved actions such as mass phishing campaigns, fake parcel delivery or banking emails, executive impersonation schemes, and business email compromise. The latter typically followed this scenario: the attacker would gain access to a company email account via phishing or a stolen password. They would then review email content for a few days, observing how employees communicated and identifying upcoming payments. The next step was to impersonate a manager, colleague, or supplier, sending employees or colleagues an email requesting an urgent transfer, a change to bank account details, or the purchase of gift cards. The goal was typically to trick recipients into transferring money or disclosing sensitive information.

Current Email Fraud: Obtaining Initial Access

Today, attackers take a different approach to email fraud, with a view to abusing cloud identity at scale. Attacks are carried out in multiple stages, as part of schemes that exploit cloud authentication protocols, SaaS trust relationships, and native Google Workspace features, often without triggering traditional security alerts. The modern playbook involves obtaining initial access through phishing, session hijacking, or OAuth abuse, in which attackers trick users into granting malicious applications access to their data. For instance, attackers may create a fake app with a familiar name like ‘Dropbox’, which users may think is safe. When they click “Allow”, the fake app receives a token—a kind of digital key that attackers can use to steal files or send spam. They can use real, trusted login pages (like Google) to trick users by creating a custom URL that uses the legitimate login page, then manipulating the final redirect so users are taken to a malicious website.

The Discovery and Stealth Stages

Once cyberattackers gain access to their victims’ systems, they begin the discovery phase, looking for information such as contacts, address books, and emails. They then manipulate inboxes stealthily. For instance, they may move emails from their victims’ inboxes to the trash can or file them away in other folders so these communications are never read. They may also suppress evidence of compromise by creating filters that automatically delete security alerts, password reset confirmations, multifactor authentication notifications, and victim replies to phishing emails. This enables them to adopt the identities of their victims without being noticed for days or even weeks. During this time, they can send phishing emails to the victims’ colleagues, target external partners, request sensitive information, authorize payments, or transfer funds.

 Attacks Persist

The aim of modern email fraudsters is often to carry out sustained attacks. They achieve persistence by creating forwarding rules to exfiltrate all inbound mail, maintaining OAuth tokens that survive password resets, and leveraging alternate access channels. Their goal is to find additional ways to access accounts so they don’t have to rely on a single stolen password. For instance, if they steal a user’s email password, they may also add their own recovery email address. They may steal browser session cookies to remain logged in even after users change their passwords. Another tactic is to compromise a linked social media account that can later be used to reset an email password. For this reason, security-conscious companies are adopting measures such as Identity Threat Detection and Response (ITDR), in which detection focuses on identity behavior rather than on email content alone.

Modern email fraud involves sophisticated methods designed not only to conduct a single attack but also to persist in systems over the long term. This goal is achieved through initial access, discovery, stealth tactics, and persistence. Companies wishing to protect their employees, customers, suppliers, and business partners can benefit from taking identity theft seriously and adopting measures that address identity-related behaviors, such as OAuth theft, unusual authentication behavior, and mailbox configuration abuse.

 

 

Share This Story