Cofense: Fraudsters use trusted services and a well-designed social engineering scheme to trick users into enabling malware to bypass an end point’s security protocols. The attack profile centers on using legitimate file-sharing websites and invoice-themed phishing attacks to steal credentials and spread malware. The social engineering aspect of the attack is that the sender’s email address relates in some way to the business being attacked to help lower the recipient’s suspicion. The report recommends all email recipients consider two questions: Was I expecting this transfer? and Am I expecting to receive a purchase order from this sender?””]
Source: https://www.databreachtoday.com/phishing-attacks-dodge-email-security-a-14681