Cyber Criminals Don’t Take a Summer Holiday: How To Stay Safe on Email

Email Security >

Cyber Criminals Don’t Take a Summer Holiday: How To Stay Safe on Email

By Cian Fitzpatrick | 27th July 2026

Table des matières

Summer is in full-swing. Yet while most of us are getting ready for our time off, cyber criminals are sharpening their tools and tactics to get into our inboxes. That’s why email security needs to be top of mind all 12 months of the year. 

We like to think Summer should be about fun and relaxation, instead of fraud alerts. However, the truth is that Summer is a prime season for phishing, business email compromise and account takeover.

Phishing is still the number one email threat

There are plenty of new attack techniques, but phishing remains the number one way attackers access an organisation. Microsoft’s email threat landscape report shows the increase in Summer-specific scams rely heavily on phishing for the initial contact. 

Once a user clicks a link or opens a bad attachment, malicious actors aim to:

  • Steal login credentials for email, cloud services or banking portals.
  • Install malware to capture keystrokes or sensitive data.
  • Redirect payments inside a compromised inbox by changing invoice or supplier details. 

Cyber criminals are playing a numbers game. They only need a tiny fraction of users to respond to their campaign to be profitable. This makes sending the copious amount of emails they send worth it. Summer, with all the excitement of holidays and great weather, comes with a lot of distraction. This distraction is the reason why cyber criminals ramp up their efforts during the warmer months.

Business Email Compromise are on the rise too

Business Email Compromise (BEC) is on the rise too.

The Association for Financial Professionals’ 2026 Payments Fraud and Control Survey reports that 74% of organisations experienced BEC attempts in 2025.  This figure is an increase from 63% the year before. 

BEC is just as big a threat in the UK, Ireland and across Europe as it is in the US.

The European Central Bank states that a record €4.2 billion in payment fraud took place in the European Economic Area in 2024. This figure is an increase from €3.5 billion in 2023. Approximately €2.2 billion of that sum is estimated to come from BEC scams. And industry analyses indicate that social engineering and BEC-type incidents represent the biggest drivers of cyber-insurance claims in Europe

With people going on leave, workflows can change during the Summer. This makes BEC so much easier. Approvers are on holiday, but staff are still under pressure to keep  things moving. This creates the perfect condition for an email like “Can you process this urgent payment before my flight?” to slip through.

Cyber criminals don’t take a holiday

If we look at Summer from the cyber criminal’s perspective we can see why it’s such a lucrative time. People travel more, spend more and rely heavily on digital communications. This combination of factors makes for fertile ground for believable scams. 

Generative AI also has no off switch. Malicious actors can automate campaigns to keep running around the clock. AI has given cyber criminals the means to clone voice for phone-based scams, build realistic lookalike websites that give the appearance of hosting valid payment portals or login links. 

Five practical steps to keep your email security safe this season

As much as cyber criminals are ready to strike during Summer, it’s not a foregone conclusion that they’ll succeed. There is a lot you can do to keep your organisation safe.

  • Tighten out of office and escalation rules
      1. Set clear guidelines on the information staff can include in their out of office replies. Travel dates and mobile numbers give cyber criminals valuable data!
      2. Instead of naming individuals, direct external senders to generic mailboxes, such as accounts@… or support@… The less intelligence an attacker can get hold of the better.

  • Review BEC protocols before people go on holiday
      1. Always require secondary verification via phone call or secure chat for new or changed payment details.
      2. Make it non-negotiable that “urgent” payment requests that come in via email are checked through a second channel.
      3. Ensure finance, procurement and HR teams know how to escalate suspicious messages quickly.

  • Reinforce phishing awareness with specific Summer examples
      1. Show examples of scams that are based on travel confirmations, ticket purchases, delivery notes and subscription alerts.
      2. Teach users to hover over links they’re emailed instead of clicking straight away. 
      3. Highlight how important it is to check sender domains carefully.
      4. Be wary of emails that play on urgency and want the receiver to take immediate action.
      5. Provide a simple way for staff to report suspicious emails.
      6. Give feedback when staff do the right thing.

  • Make sure access is locked down
      1. Ensure multi-factor authentication (MFA) is on all email and collaboration platforms.
      2. Double-check all devices with corporate email access have full-disk encryption, screen-lock and automatic lock enabled.
      3. Request staff to use mobile data instead of public Wi-Fi where possible. 
      4. Provide VPN access for cases where public networks are unavoidable.

  • Prepare your teams for Summer workloads
    1. Plan for incident response and monitoring during peak holidays periods.
    2. Ensure there is always someone to review email-security alerts, even when core staff are away.
    3. Set clear response targets that are time-bound for suspected BEC cases.
    4. Partner with a managed email security service who can watch your environment 24/7 no matter what time of the year it is.

How Topsec can help you have a scam-free Summer

There’s no question email is the mail communication tool for nearly every organisation on  earth. This is also what makes it a primary target for fraud.

At Topsec, we are in the business of giving our clients peace of mind.Our Managed Email Security Platform eliminates spam, viruses, malware, phishing and all types of security threats. You can see what this looks like in the real world in our case studies

So if you’d like to make this Summer your safest one yet, contact us. We will protect your organisation while you and your team take a well-earned break!

 

Book a call to find out more

Contactez-nous