Business Email Compromise stories
The update gives Microsoft 365, Google Workspace and Cisco Duo users faster containment and clearer evidence as identity attacks rise.
Targeted phishing and payment fraud are getting harder to spot as attackers mimic routine business workflows and trusted contacts.
Businesses risk being misled into revealing information unless phone systems can verify caller identity across increasingly complex cloud-linked networks.
Criminal access to thousands of Microsoft accounts was cut off after the companies shared threat data through the Global Signal Exchange.
The deal gives finance teams a single platform to check supplier records and bank details as fraud risks rise across payment systems.
Trusted employees and AI agents are now seen as prime insider risks, with deepfake fraud and hidden access gaps worsening the threat.
For Google Workspace users, the new Defend release adds phishing detection, AI verdicts and employee coaching against business email compromise.
More than 12,000 inboxes were exposed as the kit used to bypass multi-factor authentication and sustain account access was taken offline.
Irish SMEs will get support to tackle weak website, email and domain settings as cyber risk erodes trust and productivity.
Nearly three-quarters of medium-sized firms have faced a cyber threat in six months, as AI scams and weak staff training heighten risk.
Traditional email filters are failing as AI-crafted scams now look legitimate enough to fool staff and drive up fraud losses.
Businesses have almost no time to patch flaws now, as ESET says the median gap between disclosure and exploitation fell to zero days in 2026.
Phishing emails can still slip into Microsoft 365 mailboxes when attackers leave the SMTP envelope sender blank, ReliaQuest has found.
New Zealand users risk fake login pages and scam sites after ChatGPT search results were found pointing to unsafe links and downloads.
Microsoft security teams can now ingest email authentication signals in one place, helping spot phishing and spoofing sooner during investigations.
Spoofed emails could still reach public servants and citizens, as 50% of more than 200 New Zealand agencies have not met the DMARC standard.
Most of Southeast Asia's biggest firms still leave customers exposed to spoofed emails, with only 17% enforcing the strictest DMARC setting.
The fake acquisition pitch pushed an Avast employee towards a EUR €626,735.45 wire, exposing a broader impersonation scam across several industries.
Australian firms are being urged to tighten payment checks as email impersonation scams drive AUD $166.8 million in losses.
Australian firms still face email compromise and poor security hygiene, even as AI helps criminals move faster and hide harder.