Two-Thirds of Phishing Emails in Ed Use 'Attached Invoice' Ploy

The most common form of phishing email in education tends to include an attached invoice; 66 percent of hacker attempts use the attached invoice ploy to get unwary recipients to click on an infected link; another 28 percent use a payment notification scheme; and 6 percent try online order tricks.

The findings were shared by digital security vendor Cofense, in its "State of Phishing Defense 2018" report. The company provides online services to organizations that automates response to suspicious emails and also helps them condition their employees to recognize and report phishing. (In other words, the company facilitates employers sending fake emails to test how savvy their workforce is.) For the report, Cofense used data gathered through the experiences of 1,400 clients in 23 industries around the world covering real attack attempts correlated with customer simulation data.

The same analysis found that 11 percent of malicious emails in education reported turned out to be actual phishing attempts, slightly higher than the cross-industry rate of 10 percent. The others were ordinary emails that users just thought were fake. Of course, as the report's authors pointed out, "It takes just one successful phish to inflict a costly toll."

The top phishing campaigns tended to use "invoice" in the subject header. That word appeared in seven of the top 10 headers for actual phishes. Also highly popular: "payment remittance," "statement" and "payment."

More than half of reported phishes across all segments (53 percent) were sent to collect user logins, according to Cofense. This "credential phishing" typically includes a link to a malicious landing page, enabling criminals to gain access to internal data or "establish a network foothold." To protect against this delivery mechanism for malware, the company recommended that organizations use a "steady diet of credential phishing" in their simulation programs., particularly if the operation uses a lot of cloud services.

The report, which called Microsoft Office macros "the Domino's of malware delivery," said that nearly half of all malware analyzed (45 percent) currently "lurks" in Office macros. One option is for schools to disable macros in emails, forcing users to "enable" content before they work with it. Another approach is to block or "gray-list" documents from both known malware sources and unknown sites and balance that with user education.

The security firm recommended that organizations train users "to view attachments suspiciously," especially if they include invoices, online orders or anything that might contain a macro. Also, users need to be on the watch especially during intense periods of financial processing, such as end-of-month, end-of-quarter and end-of-year periods.

Cofense also suggested that organizations run phishing simulations based on real threats and the newest subjects or themes that have been circulating.

"We see phishing emails bypass technology controls every day and more and more end-users recognizing and reporting these threats that slipped past million-dollar defenses," said Aaron Higbee, co-founder and chief technology officer of Cofense, in a statement. "The results of our research...shows that resiliency is building across key industries thanks to those same people that were once deemed as the weakest-links in an organization. These trends are powerful and reinforce that humans are a key element to a successful security program."

The full report, with additional recommendations, is available with registration on the Cofense website.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • The AI Show

    Register for Free to Attend the World's Greatest Show for All Things AI in EDU

    The AI Show @ ASU+GSV, held April 5–7, 2025, at the San Diego Convention Center, is a free event designed to help educators, students, and parents navigate AI's role in education. Featuring hands-on workshops, AI-powered networking, live demos from 125+ EdTech exhibitors, and keynote speakers like Colin Kaepernick and Stevie Van Zandt, the event offers practical insights into AI-driven teaching, learning, and career opportunities. Attendees will gain actionable strategies to integrate AI into classrooms while exploring innovations that promote equity, accessibility, and student success.

  • laptop displaying a red padlock icon sits on a wooden desk with a digital network interface background

    Reports Point to Domain Controllers as Prime Ransomware Targets

    A recent report from Microsoft reinforces warns of the critical role Active Directory (AD) domain controllers play in large-scale ransomware attacks, aligning with U.S. government advisories on the persistent threat of AD compromise.

  • laptop displaying a glowing digital brain and data charts sits on a metal shelf in a well-lit server room with organized network cables and active servers

    Cisco Unveils AI-First Approach to IT Operations

    At its recent Cisco Live 2025 event, Cisco introduced AgenticOps, a transformative approach to IT operations that integrates advanced AI capabilities to enhance efficiency and collaboration across network, security, and application domains.

  • educators seated at a table with a laptop and tablet, against a backdrop of muted geometric shapes

    HMH Forms Educator Council to Inform AI Tool Development

    Adaptive learning company HMH has established an AI Educator Council that brings together teachers, instructional coaches and leaders from school district across the country to help shape its AI solutions.