Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Mimecast’s Global Threat Intelligence Report for January–June 2024 highlighted rising malicious-link activity, heavier threat exposure per user at small and midsize businesses (SMBs), and several targeted uses of generative AI. The findings describe activity observed by Mimecast during the first half of 2024—not threat rates for 2026 or a census of all businesses.

What the H1 2024 report measured

Mimecast said the report drew on analysis of more than 1.7 billion messages per day across more than 42,000 customers, alongside its analysts’ findings and open-source intelligence. Those figures describe the company’s telemetry context, not the number of attacks. Its counts reflect threats observed or blocked by its systems and can depend on its customer base, products, and classification methods; they do not establish the chance that a particular SMB will be attacked. See Mimecast’s Global Threat Intelligence Report 2024 H1 (January–June 2024) and official report announcement, August 20, 2024.

Malicious links and trusted services were a major concern

Mimecast reported that malicious links increased 133% in Q1 2024 compared with Q1 2023, and 53% in Q2 2024 compared with Q2 2023. The company described attackers moving away from malware attachments toward links that use familiar cloud file-sharing and collaboration services, including SharePoint and Google Drive, as part of multi-step campaigns.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In the report’s examples, a link could lead through an intermediary document or collaboration platform before reaching a fake sign-in page. Other campaigns used confusing URLs, CAPTCHAs, or false requests for multifactor authentication (MFA) to make victims more likely to proceed. Mimecast cited cases involving Australian law firms in which collaboration-platform links led to fake Microsoft login pages. These examples do not mean the named services themselves were compromised or inherently malicious. The reported figures and examples appear in Mimecast’s August 20, 2024 announcement.

SMBs faced higher threat counts per user in Mimecast’s data

Mimecast reported the highest threat volume per user for small businesses, peaking at 40 threats per user in Q1 2024. It also said employees at small and medium businesses saw more than twice as many threats per user as users at large enterprises. These are Mimecast’s observed threat counts for the stated periods and groups—not estimates of an individual company’s likelihood of attack.

The overall average across businesses of all sizes did not rise throughout the period: Mimecast reported 19 threats per user in Q4 2023 and 14 in Q2 2024. This helps put the malicious-link increases in context: the report identified a rise in that category, not a universal increase across every threat measure. Mimecast’s announcement provides the SMB and overall-average figures.

AI appeared in specific campaigns, not as a proven cause of a general surge

Mimecast described phishing templates reportedly created with generative AI and a consumer scam that used an AI- or large-language-model-operated call center. The company said it detected more than 1.6 million messages connected with that campaign in May 2024. That is a campaign-specific message count, not a count of successful attacks or victims.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Mimecast also characterized AI’s overall impact on attackers and defenders as limited so far. The report’s examples show ways AI was being used in particular campaigns; they do not establish that AI caused a general increase in successful attacks. Read the company’s August 20, 2024 report announcement for its account of these examples.

How SMBs can respond to the risks described

Mimecast’s recommendations span identity, email, networks, staff practices, suppliers, and external infrastructure. They are risk-reduction measures, not guarantees that an incident will be prevented.

Protect accounts and credentials

  • Require MFA, especially for accounts with privileged access, and use strong passwords.
  • Remove default administrator passwords. Review who has privileged access and keep those accounts protected.
  • Where an account supports it, a FIDO2 security key is one possible hardware-based MFA method. Mimecast does not name or test a particular key, and compatibility depends on the services and identity systems an organization uses.

Reduce exposure to suspicious email

  • Configure email images not to load automatically, and isolate images that users flag as suspicious.
  • Train employees to scrutinize unexpected links, unfamiliar sign-in pages, CAPTCHAs, and unsolicited MFA prompts—particularly when a message routes through a familiar sharing service.

Limit internal and supplier risk

  • Segment internal networks and monitor traffic so a compromised account or device has less opportunity to reach unrelated systems.
  • Review suppliers’ security obligations and monitoring arrangements; a trusted supplier relationship does not make every link or request safe.

Check internet-facing systems and cloud settings

  • Regularly scan external infrastructure for exposed ports and cloud misconfigurations, then prioritize remediation according to the organization’s risk and capacity.

These controls differ in coverage and operational effort: MFA and password changes focus on identity, image and link handling on email, segmentation on internal networks, and supplier reviews on third-party exposure. Their fit depends on existing systems, available staff, visibility, and response capability; Mimecast’s report does not rank security vendors or score products against these factors.

Rank #4
Advanced Persistent Threat Cybersecurity Humor Text Tank Top
  • Distressed block lettering featuring the classic APT term minimal, gritty, and instantly recognizable to InfoSec teams, SOC analysts, and threat hunters who live in alerts, logs, and adversary tracking.
  • Clean monochrome text design that sparks conversation at meetups, conferences, and on-call nights. Perfect for blue team, red team, DFIR, threat intel, and security engineers who appreciate subtle cyber humor.
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the report does—and does not—show

Mimecast’s August 20, 2024 announcement quotes Mick Paisley, then the company’s Chief Security & Resilience Officer: “Email and collaboration tools are often seen merely as cost centers, but this overlooks their essential role in cybersecurity.” This is a vendor executive’s view of the importance of those systems, not an independent assessment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The report offers a snapshot of Mimecast’s January–June 2024 observations. It documents category-specific link increases, higher per-user threat counts for SMBs in its telemetry, and examples of AI use. It does not provide a population-wide estimate of SMB attack probability, establish that AI generally increased successful attacks, or independently validate the telemetry figures.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.