Report | Five Attacks That Gmail is Missing and What You Can Do About It
This report highlights five common attacks that Gmail misses, putting businesses at risk. With Gmail and Google Workspace becoming prime targets for cybercriminals, the need for enhanced security is critical. Discover how Avanan’s solution can address these gaps, ensuring comprehensive protection for your email and cloud collaboration tools. Don't let your business fall victim—download the report to learn more.

THE 5 ATTACKS THAT GMAIL IS MISSING AND WHAT YOU CAN DO ABOUT IT
Y O U D E S E R V E T H E B E S T S E C U R I T Y
2THE 5 ATTACKS THAT GMAIL IS MISSING
Executive Summary • Gmail remains an incredibly popular email service, especially for small businesses • Attackers are not only targeting email, but the entire Google Workspace, such as Docs and Slides • Without full-suite security, your Google Workspace is at risk • With the joint Avanan and Check Point solution, you can effectively defend yourself against these attacks
Introduction When we think of business email, we tend to think of Microsoft Office 365. In general, they are the dominant provider, as 1 in 5 corporate employees use Office 365. However, in terms of total email, Gmail is the king. Gmail has over 1.8 billion users, accounting for 18% of the email market share. This includes individuals, and indeed 53% of Americans use Gmail. This extends to businesses as well, as 60% of mid-sized US companies use Gmail and 92% of US startups use the service. In all, we’re talking about six million paying customers. That’s a nearly 250% increase in the last decade.
Given that rapid growth, it’s unsurprising that attackers target their attacks on Gmail.
As a base layer, Google does a good job. They cite an astonishing stat, whereby their machine learning protects over 1.4 billion accounts from 10 million spam and malicious emails each minute.
That’s undoubtedly saving countless users from devastating effects. And yet, it’s not enough. Both Gmail as an email provider and the larger Google Workspace are consistently targeted.
As Gartner writes: “The controls in G Suite Basic are insufficient for most large enterprise with extensive governance mandates or enterprises of any size with certain regulatory requirements.” From: What You Need to Know About Security in G Suite
3THE 5 ATTACKS THAT GMAIL IS MISSING
Content collaboration has become a key method for hackers. According to recent data, Google Drive has become a top vector for malicious files and downloads. In fact, Google Drive accounted for 37% of malicious downloads in 2021, a 28% increase over 2020. Further, G-Drive accounts for 50% of malicious Office document downloads, a 42% increase over 2020.
And since so many attacks are getting through, security admins are looking to find additional help.
“ Security pros supplement [Google’s] native capabilities with third-party solutions like cloud- native API-enabled email security solutions… so that their customers can fully protect their inboxes.” From: The Forrester Wave: Enterprise Email Security, Q2 2021
4THE 5 ATTACKS THAT GMAIL IS MISSING
These are not just words on a page. We have the numbers to back it up.
Avanan researchers analyzed over 300 million emails to understand how other security solutions perform against phishing emails. We measured the number of phishing emails reaching the inbox per 100,000 emails. Google is in the middle of the road.
Though some are worse than Google, 626 phishing emails are still a lot.
And using our threat miss calculator, you can see how it gets worse when the companies are larger.
Take a 50,000 seat organization. Using an estimated emails per user per day of 20, this is what pops out:
Email User / Month 600
Total Emails Organization / Month 30,000,000
Estimated Missed Attacks / Month 189,000
0
300
600
900
1200
1500
Avanan Mimecast Google Proofpoint Microsoft Barracuda
Phishing Emails / 100K in User Inbox
5THE 5 ATTACKS THAT GMAIL IS MISSING
That’s nearly four missed attacks per user per month. Successful phishing campaigns can cost $17,7000 per minute. This is particularly concerning for the majority of small and medium-sized businesses that use Gmail. One study found that 60% of small and medium-sized businesses that get hacked go out of business after just six months. Just one phishing attack can prove devastating.
Every day, Avanan sees–and stops–scores of attacks that Gmail misses. They run the gamut from simple credential harvesting attacks to complex attacks incorporating malicious attachments.
We will run through a sampling of the attacks that Gmail misses. Then, we’ll focus on how Avanan stops these attacks, so your business remains safe.
6THE 5 ATTACKS THAT GMAIL IS MISSING
The Google Docs Comment Exploit Starting in December 2021, Avanan observed a new, massive wave of hackers
leveraging the comment feature in Google Docs. In this attack, hackers are adding a comment to a Google Doc. The comment mentions the target with an @. By doing so, an email is automatically sent to that person’s inbox. In that email, which comes from Google, the full comment, including the bad links and text, is included. Further, the email address isn’t shown, just the attackers’ name, making this ripe for impersonators.
This works whether the attacker uses Google Slides or Google Docs. There are several ways that make this email difficult for scanners to stop and for end-users to spot. For one, the notification comes directly from Google. Google is on most Allow Lists and is trusted by users. Secondly, the email doesn’t contain the attacker’s email address, just the display name.
This makes it harder for anti- spam filters to judge, and even harder for the end-user to recognize. For example, a hacker can create a free Gmail account, such as <bad.actor@gmail.com>. They can then create a Google Doc, insert a comment and send it to their intended target. For this example, let’s say the intended target has a work address of <vic.tim@company.com>. The end- user will have no idea whether the comment came from <bad.actor@gmail.com> or <bad.actor@company.com>. It will just say “Bad Actor” mentioned you in a comment in the following document. If Bad Actor is a colleague, it will appear trusted. Further, the email contains the full comment, along with links and text. The victim never has to go to the document, as the payload is in the email itself. Finally, the attacker doesn’t even have to share the document--just mentioning the person in the comment is enough.
Since Google Docs and Slides and the entire Google Workspace is a huge repository for information, there is a wealth of data for hackers to take advantage of. Without proper protection, these attacks will continue to propagate.
MISS 1
7THE 5 ATTACKS THAT GMAIL IS MISSING
Using Google Docs to Host Phishing Sites
This Google Docs page may look familiar to those who share Google Docs outside of their organization. This, however, isn’t that page. It’s a custom HTML page made to look like that familiar Google Docs share page.
The attacker wants the victim to “Click here to download the document” and once the victim clicks on that link, they will be redirected to the actual malicious phishing website where their credentials will be stolen through another webpage made to look like the Google Login portal.
By creating a simple HTML page and uploading it to Google, the hacker, with Google’s help, will have a full HTML page with a redirect hyperlink to a malicious website.
Attackers are using Google Docs to deliver malicious phishing websites to victims. It starts with a simple email:
That link leads to the following Google Docs page.
MISS 2
8THE 5 ATTACKS THAT GMAIL IS MISSING
The Undelivered Message In this attack, hackers are spoofing failed delivery messages to send credential
harvesting pages.
In this email attack, hackers found a way to take advantage of missed delivery messages to send phishing. When a message is missed delivered, IT staff will send a list of the emails, which can then be released. Clicking on the subject line should lead to the email itself. In this attack, the link goes to a credential harvesting page.
Since the email's subject lines use classic social engineering tactics such as urgency. Seeing a subject line of “invoice” or “Shipping document” will entice the user to click.
This email failed SPF checks, and there was also an insignificant historical reputation with the sender.
MISS 3
9THE 5 ATTACKS THAT GMAIL IS MISSING
The BEC Attack As we reported in our 1H 2021 Global Phish Cyber Attack Report, BEC accounts for
20.7% of all phishing attacks.
BEC can be incredibly difficult to stop. It's no surprise, then, that the Internet Crime Complaint Center (IC3) reported that, in 2020, they received 19,369 BEC complaints. The total losses? $1.8 billion.
This attack is seemingly simle, but it could have devastating consequences.
Even though Google has the internal access needed to prevent BEC attacks, their infrastructure can’t perform the per-customer contextual analysis required to stop these. Far too many companies and customers work with Gmail, making it impossible for them to properly monitor all internal accounts and understand an organization's relationships and reputation patterns.It's worth noting that, even if a BEC is detected by Google, the common action taken is a warning banner injection into the email message, which in turn still gets delivered to the recipient.
That means that one of the most pernicious attacks is prime to soar right by Google. Avanan does things a bit differently. Within hours of first deployment, the Avanan AI scans a year's worth of email conversations to build a reputation network that not only provides superior BEC protection, it reduces the number of false positives that plague most other email solutions. The 'tuning' that typically takes months with other security solutions is done automatically using millions of real email conversations.
MISS 4
10THE 5 ATTACKS THAT GMAIL IS MISSING
The .ppam Attack A .ppam file is a rarely used add-on file in Powerpoint.
In this attack, that file is attached to an email that otherwise looks like a purchase order:
When opening the file, it will start a process that overwrites the registry settings in Windows, allowing the attacker to take control over the computer. This extension has further application, as it can effectively wrap executable files from malware to ransomware.
Because Avanan uses multiple real-time malware, sandboxing and AI active content analysis tools that work in parallel to identify malicious content, we can check every file for malicious content and quarantine threats before your users download them.
MISS 5
11THE 5 ATTACKS THAT GMAIL IS MISSING
How Avanan Protects Google Avanan uses machine learning and Artificial Intelligence trained on attacks that get past the Google Workspace, analyzing over 300 indicators per message. If you have Google Workspace, Avanan will stop the threats they miss. Further, with full-suite security, whenever a user downloads a file to Google Drive, Avanan scans the file via API and picks up on weaponized payloads and malicious links.
Further, Avanan leverages ThreatCloud, Check Point’s threat intelligence database. The largest database of its kind in the world, it takes 42 separate machine learning and AI engines that run in concert to detect the most advanced malware. It does 86 billion transactions a day and finds over 6,000 previous unknown malware and zero-day malware daily.
It takes 150,000 connected networks, millions of endpoint devices and dozens of external feeds crawling the web, as well as exclusive intelligence discovered by Check Point Research. It aggregates and analyzes this big data telemetry to prevent attacks before they reach your organization. It blocks attacks faster than anyone else and has the best catch rate of both known and unknown threats. In fact, ThreatCloud caught TrickBot 12 days faster than anyone else, and ZLoader 15 days faster.
Further, this advanced telemetry works at lightning speed. Take this example: A malicious link is detected and blocked in a zero-day attack in the US. The threat data is then immediately shared across all attack vectors with protections for this attack updated in real-time. This same zero-day malicious link is then blocked less than 2 seconds later in a similar attack in Australia.
12THE 5 ATTACKS THAT GMAIL IS MISSING
Worldwide Headquarters 5 Ha’Solelim Street, Tel Aviv 67897, Israel | Tel: 972-3-753-4555 | Fax: 972-3-624-1100 | Email: info@checkpoint.com
U.S. Headquarters 959 Skyway Road, Suite 300, San Carlos, CA 94070 | Tel: 800-429-4391; 650-628-2000 | Fax: 650-654-4233
www.checkpoint.com
© 2022 Check Point Software Technologies Ltd. All rights reserved.
Avanan is the only email security solution on the market that can leverage this data.
When customers deploy this solution, they see a 99.2% reduction in phishing attacks and a 71% reduction in end-user requests to the SOC.
As one IT admin in the enterprise space said, “Avanan has provided a truly integrated way to do G-Suite email security. Avanan is able to deploy as an app, which allows it to natively supply better security without spending too much time on set up.”
Takeaways Google is rapidly gaining market share as an email provider, particularly among SMBs and tech companies. Attacks are just as prevalent in Google as they are anywhere else, yet native Google security isn’t enough. A security solution that protects the entire Google Suite is necessary to stay safe.
WIth Avanan, staying safe in Google is simple.