UK under persistent email attack, researchers say

happygeek 1 Tallied Votes 351 Views Share

Some interesting research from security outfit Proofpoint was published this morning which reveals that unsolicited email heading towards users in the UK is three times more likely to contain malicious URLs than that destined for users in the United States, or Germany, or France for that matter.

It's not, as you may think at first glance, just a matter of the UK getting more spam. The research conducted over the summer, using the US as a baseline, shows Germany getting more spam as a percentage than the UK, US and France. The prevalence of spam and malicious URLs in the total email traffic are not, Proofpoint conclude, therefore correlated. Instead, UK users are being targeted with less spam but with a higher volume of infected spam. Compared to Germany, as much as five times as high in fact. Which begs the question 'why are cybercriminals targeting the UK so relentlessly when compared to other nations?'

Kevin Epstein, VP of Advanced Security & Governance at Proofpoint, doesn't think the answer is all that difficult. If the evidence points, relative to other countries in the report, that there are a startlingly high number of targeted attacks against the UK then given the almost universal financial motivation behind them "this strongly suggests cybercriminals have found UK organizations to be an unusually lucrative target" he insists.

Not that Epstein thinks non-UK email users should be complacent about the level of risk as he says that lower phishing volumes do not appear to have translated into lower criminal impact. "Over 29 million Germans have fallen victim to cybercrime" Epstein says "that's almost 40% of the population." Indeed, Epstein reckons that, historically and taking into account a summer lull in criminal activity, the German economy is the most targeted and most affected by cybercrime worldwide when measured against gross national product. Summing up, he concludes that "the results from France, Germany and the US are not particularly low; rather, the UK is unusually high."

Dani AI

Generated

A compact, practical addendum to 's post: the observation that UK inboxes were receiving a high share of malicious-URL mail is most useful as an operational signal rather than an academic one. Treat those messages as targeted phishing campaigns that demand prioritized blocking, detection and reporting—phishing and malicious links remain a primary initial-access vector for fraud and account takeover. ()

Possible contributors (not proven causes, but worth checking in any post-incident review): a high concentration of financial and high-value business targets in the UK; English-language reach for global campaigns; business workflows that include high-value payment approvals; and gaps or complexity in senders' email authentication that let spoofing through. Where domain-based authentication is incomplete, attackers can impersonate brands and run convincing URL-based lures—so authentication visibility is essential. (DMARC overview)

Immediate checklist for defenders (priorities first):

  • Enforce SPF + DKIM and deploy DMARC with monitoring (start p=none + rua reports, fix streams, then move to quarantine/reject). (DMARC overview)
  • Enable URL rewriting / time-of-click scanning on inbound mail (reduces successful malicious-URL clicks). Example: Microsoft Safe Links provides time-of-click checks and URL rewriting. (Safe Links documentation)
  • Require phishing-resistant MFA (FIDO2/passkeys or equivalent) for admins and all financial approval roles; this cuts account-takeover risk dramatically. (Phishing-resistant MFA guidance)
  • Sandbox attachments, block macros by default, flag/inspect archive files, and detect unusual mailbox rules or external auto-forwarding.
  • Run focused phishing simulations for finance and execs, hunt for domain lookalikes, and register common impersonation variants.

If an incident looks targeted or results in loss, report it and forward suspicious emails to the UK Suspicious Email Reporting Service (SERS) / Action Fraud so URLs can be taken down and intelligence shared. (Action Fraud SERS guidance)

Start with DMARC visibility + time-of-click URL scanning + phishing-resistant MFA—those three changes raise the cost for attackers and reduce successful compromise quickly.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.