This week's SEG miss of the week follows a targeted social engineering attack. Proofpoint missed this attack.
It works like this:
The subject line is: Handle this
This Proofpoint customer was susceptible to this targeted social engineering attack from an attacker using a freemail account. Avanan was also able to detect that this attacker was impersonating an important person in the company—the Treasurer. Finally, with Avanan’s cutting-edge natural language processing, Avanan’s AI was able to detect the urgency and purchase of gift cards which is a growing trend among phishing attacks.
The email looks like this:
Proofpoint failed to detect this same attack against 17 other users in the same company. See below screenshot from Avanan’s dashboard: