Adaptivesecurity Phishing and BEC Incidents Surge: Email Security Practices Essential
Article Content
- •Phishing and BEC incidents led to over $3 billion in losses in 2025.
- •Organizations without structured incident response plans face higher recovery costs and longer timelines.
- •Effective email incident response teams are essential for mitigating risks associated with email threats.
In 2025, phishing and business email compromise (BEC) incidents surged, with the FBI reporting over 191,561 complaints and $3.04 billion in BEC losses. Email remains the primary vector for social engineering attacks, leading to significant financial and reputational damage for organizations. The average cost of a data breach reached $4.8 million, with containment timelines averaging 254 days. Security teams lacking structured incident response plans face longer recovery times and increased regulatory exposure. Effective email incident response teams are crucial for mitigating these risks, emphasizing the need for defined roles and best practices. Organizations must prioritize training and simulations to prepare for potential email threats. The current status indicates a pressing need for improved email security measures across various sectors.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…