Skip to content

Email Attacks Follow Multi-Stage Patterns from Phishing to Financial Fraud

Key Takeaway: Email attacks follow a systematic multi-stage attack chain from phishing through account compromise to financial fraud; traditional filters are insufficient.

Cybercriminals do not execute email attacks as isolated incidents, but as coordinated attack chains building on one another: phishing leads to compromised accounts, which are then used for business email compromise attacks and ultimately result in financial fraud. According to the damage report from cyber insurance company Stoïk, 98 percent of all fraud cases are associated with emails.

The Stoïk damage report from spring documents the extent: approximately 60 percent of reported damages stem from email incidents. Wire transfer fraud is particularly costly, with average damage amounts in the five-figure range. This makes email-based cybercrime the leading attack vector across all damage statistics.

Attackers today systematically combine multiple techniques: the scenario typically starts with phishing emails that appear to come from known business partners or suppliers. Once attackers have gained access to their email accounts, they send messages with deceptively authentic links to fake login pages — such as for Microsoft 365. When an employee enters their credentials there, attackers obtain access to the real account. Because the messages come from legitimate senders, traditional spam and security filters regularly fail.

With stolen credentials, attackers then carry out business email compromise (BEC) attacks. They send emails directly from compromised corporate accounts and access existing communication histories. Payment requests or other business messages appear particularly credible — they follow familiar writing styles and contain correct information. Such account compromises are more readily detected through unusual account activity than through the sender itself: suspicious logins, newly created forwarding rules, or changes to two-factor authentication are warning signs.

At the end of the attack chain lies financial damage. Criminals alter banking details in ongoing email conversations or send fraudulent payment instructions with high urgency. Because they use existing communication histories and operate through compromised accounts, the messages appear authentic — companies then transfer money to accounts controlled by the perpetrators.

Traditional phishing protection is insufficient against this multi-stage pattern. Stoïk therefore relies on a combination of rule-based checks, machine learning procedures, and manual assessment by its own Security Operations Center (SOC). Suspicious emails are analyzed automatically and evaluated by security experts before countermeasures are initiated. This multi-stage approach is designed to detect phishing, business email compromise, and financial fraud as an interconnected chain.


Source: www.it-daily.net · Published July 23, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: