Why we need a layered approach to email security

Why-we-need-a-layered-approach-to-email-security

Digital Content Editor, Eve Goode speaks exclusively to Steven Peake, Director, Solutions Architects, Northern Europe at Barracuda about the findings from Barracuda’s recent research and what this tells us about modern email defence strategies.

How are email attacks evolving beyond traditional phishing?

Phishing has evolved into a highly sophisticated, automated threat. It’s no longer just an entry point to users’ inboxes, but also a tool for identity theft, data exfiltration, persistence and lateral movement across systems.

Malicious payloads are now activated days after they reached the inbox, and conversations can be hijacked mid-thread.

Identities are quietly compromised and used to spread attacks further.

All while traditional security, built for when static attacks happened at a single point in time, assumes that bad emails will be caught at the point of delivery.

Over the last few months, we’ve seen genuine Microsoft login pages being used to harvest session tokens, as well as legitimate device code flows being hijacked to capture credentials and calendar invites being turned into delivery mechanisms.

We’ve seen phishing kits that build a unique, personalised fake page for every victim and hidden text designed to confuse spam filters that can also fool AI-powered detection. Little of this resembles the phishing tactics users have been trained to spot.

How are attackers bypassing traditional security controls?

Phishing-as-a-service (PhaaS) is evolving fast.

LogoKit, for example, builds a unique, personalised page for each victim in real time, pulling their company logo and a live screenshot of their website using legitimate services such as Clearbit and Google Favicon.

This marks a shift from simple brand impersonation to something closer to environment impersonation, where the fake page mirrors the real one closely enough that generic indicators of compromise stop being useful.

Text salting, the technique of hiding large amounts of harmless-looking text inside phishing emails, was created to confuse spam filters into misreading the message as legitimate. It can fool modern, AI-powered ones the same way.

We’ve also seen a genuine Microsoft login page routed through the Tycoon 2FA PhaaS.

The victim received a calendar invite warning that their inbox was nearly full, with a button linking to what looked like a standard Microsoft sign-in.

The attackers had registered their own Microsoft account and were asking victims to authenticate into it.

Once someone entered their details, the attackers captured the session token and OAuth permissions – which gave them immediate, persistent access to email, files and linked Microsoft 365 services.

As the domain is genuine, it slips past checks built to catch spoofed URLs and it fools employees who’ve been trained to look for exactly that.

We’ve seen similar abuse of device code authentication, where attackers generate fake device codes locally in the browser to mimic the flow people recognise from linking apps to their Microsoft account.

Some of these campaigns even include a kill switch, with phishing pages set to expire automatically to limit forensic analysis afterwards.

What is driving the shift from traditional phishing to more sophisticated email attacks?

A few things are converging.

AI has made it easier to produce and tailor convincing content at scale, further industrialising the cyber-threat.

Even in 2025, 90% of high-volume phishing campaigns used phishing-as-a-service kits.

This means attackers no longer need deep technical skills and resources to run a sophisticated operation.

As we’ve seen with Logokit, PhaaS platforms are maturing fast, becoming dynamic, automated, personalised and cloud-based.

That evolution lowers the cost and effort for attackers while making each individual attack harder to detect.

How fast can these attacks move once someone clicks?

Fast enough that manual response often can’t keep pace.

We created a simulation of a real world attack in which a single click progressed to full compromise, including identity theft, MFA bypass and endpoint compromise, within about five minutes.

Once an account is compromised, attackers can move laterally from that one account into identity systems and other applications.

Crucially, by the time a security team starts investigating, the attack may already have spread well beyond the original inbox.

Why are traditional email security tools struggling to keep up?

Native email security will typically scan a message when it arrives and then stop watching it.

That doesn’t work when a link can sit dormant for days before it weaponises; or when an account starts sending phishing emails internally after being compromised.

It also doesn’t account for phishing pages that look different every time.

What should a modern, layered email security strategy look like?

The threats we detect highlight why traditional email security is no longer enough.

Staying safe against attacks like these comes down to building real resilience through multiple layers of protection, rather than leaning on any single control.

That means advanced email filtering, identity protection and continuous monitoring working together, alongside phishing-resistant multifactor authentication and defences against account takeover.

AI-assisted anomaly detection and incident response tools matter just as much here as user awareness does.

Detection needs to extend beyond the inbox to calendar invites, attachments and login flows, with strong attachment and endpoint protection in place to catch fileless and embedded threats.

Organisations also need the ability to respond quickly and automatically, given how fast these attacks move, supported by ongoing user training and awareness of the latest threats.

Share this content

Latest Issue

Connect with us

Free digital subscription

Receive the latest breaking news straight to your inbox