Phishing's New Playbook: Why Email-Only Defenses Are Failing

Phishing remains the root cause of more than 90% of cybersecurity incidents, and mid-August brought a stark reminder of its reach. Attacks targeted the U.S. election cycle, escalated geopolitical tensions between the U.S., Israel, and Iran, and drove $60M in corporate losses. After three decades of email as the dominant attack vector, it's tempting to assume defenders are powerless. That's a miscalculation.

Phishing is not tied to email alone or any single protocol. At its core, it's an attempt to trick a person into taking an action that leads to damage. Attacks succeed because they look authentic — visually or organizationally — such as impersonating a CEO or CFO. Cloudflare's analysis of blocked malicious emails identifies three primary vectors:

  • Deceptive links, representing 35.6% of threat indicators
  • Malicious attachments, at 1.9% of threat indicators
  • Business email compromise (BEC), which elicits money or intellectual property without links or files, at 0.5% of threat indicators

Beyond the Inbox: Multi-Channel Attacks

Cloudflare is seeing growth in what it terms "multi-channel phishing." Attackers now push links, files, and BEC tactics through SMS and messaging apps, taking advantage of how people consume information and work. Cloud collaboration tools like Google Workspace, Atlassian, and Microsoft Office 365 are frequent targets, as are social platforms like LinkedIn and X. Any effective phishing defense must span these channels, not just email.

A Real-World Scenario

Consider how a sophisticated multi-channel attack unfolds. An executive finds an email in their junk folder — flagged by Cloudflare's Email Security for being suspicious, but relevant enough to their current project that they open it. The message requests a company org chart and includes a link to a legitimate Google form, knowing that continuing over email would likely be caught.

The executive clicks the link and the form displays an upload request. They drag the file in, but the upload fails. The document contains an "internal only" watermark that Cloudflare's Gateway and data loss prevention (DLP) engine detected and blocked. Attackers use urgency to drive better outcomes — in this case, the executive has a deadline for a consultant to report to the CEO. Unable to upload, they reply to the attacker, who suggests trying another method or sending the document via WhatsApp. Each subsequent attempt — uploading to a provided website that would have loaded malware, or sharing via WhatsApp — is blocked. The website is rendered in Cloudflare's Browser Isolation, protecting the device, and the file transfer is stopped by policy.

Protection Without the Administrative Burden

Security solutions require maintenance, but constant IT tweaking creates overhead and risk. Protecting the executive in the scenario above required just four configuration steps, each integrated into the Cloudflare One suite:

  1. Install the device agent. A few clicks protects users against multi-channel phish. Agentless deployment is available for organizations that cannot install clients.
  2. Configure gateway policies. Route all user traffic through the secure web gateway to block high-risk sites outright. Suspicious sites, such as newly registered domains, can open in isolated browser sessions, limiting interaction.
  3. Set DLP policies. Define what cannot be uploaded, typed, or copied and pasted. In the example, uploading to a free cloud storage service was prevented, and copy-paste was disabled in the remote browser session. WhatsApp uploads and downloads were also blocked via gateway configuration.
  4. Deploy Email Security with auto-move rules. The executive never received the multiple malicious emails sent to them. Those that got through were routed to the Junk folder because the sender impersonated someone whose signature didn't match, and a one-click configuration automatically moved them there.

Robust detections should also include visibility into individual users affected by ongoing attacks. An improved email security monitoring dashboard is planned to provide that drill-down capability.

Why Email Security Alone Isn't Enough

Phishing remains a clear and present danger, and email-only security is fundamentally insufficient. Work and data extend beyond email to every channel and device, so protection must follow. Stitching together multiple vendors increases cost and adds overhead for investigation, maintenance, and uniformity — a burden for already stretched IT teams. Comprehensive, integrated protection is the practical path forward, whether you're starting fresh or already using Cloudflare's suite. For Office 365 users, a Retro Scan can identify threats that current providers missed.