Add Think Technology as a trusted source What Is Lateral Phishing and How to Stop It | TTA

What is lateral phishing and why is it so hard to spot

email phishing

An email lands in your inbox from a colleague you trust. The address is real. The name is correct. The tone sounds familiar. You click the link. That is lateral phishing, and it is one of the most effective attack methods targeting Australian businesses right now.

Unlike a standard phishing email that arrives from a suspicious external address, a lateral phishing attack starts from inside your own organisation. Attackers compromise one email account, then use that account to send phishing emails to contacts across the business and beyond. Because the sender is a real, known person, the usual warning signs disappear.

At TTA, we work with businesses across Brisbane and South-East Queensland on email security and phishing response. Lateral phishing comes up often. The businesses affected are rarely negligent. They are simply caught by a technique designed to exploit trust rather than bypass technology.

How lateral phishing works

The attack follows a clear sequence. First, an attacker gains access to a legitimate email account, usually through a phishing email of their own, a stolen password, or a session token stolen by malware. Once inside, they have full access to the inbox, the contact list, and the sending history of that account.

They then send phishing emails outward, targeting close contacts within the business, clients, suppliers and other outside organisations. The emails appear to come from a trusted source. Recipients are far more likely to click a link or open an attachment when they recognise the sender’s name and address.

Once the first click happens, the attacker may compromise a second account, and then a third. The original breach spreads like a chain reaction. Early research into this attack type found that over 60% of targeted organisations ended up with multiple compromised accounts, with some organisations seeing dozens of hijacked accounts sending lateral phishing emails to more than 100,000 different recipients in a single campaign.

Why lateral phishing is growing in 2025 and 2026

Two factors have made lateral phishing more common. The first is the rise of phishing-as-a-service (PhaaS). Attackers can now purchase ready-made kits that handle the entire compromise process, from stealing credentials to automating follow-up attacks. The 2026 Email Threats Report, based on analysis of more than 3.1 billion emails globally, found that 90% of high-volume phishing campaigns now rely on these PhaaS kits.

The second factor is AI. Phishing emails used to be easy to spot because they were poorly written. AI has changed that. Analysis of phishing emails detected between late 2024 and early 2025 found that over 80% used AI to generate content, a 53% increase year on year. AI-drafted lateral phishing emails carry the natural tone of internal business communication, which makes them far harder for staff to identify.

The Australian Cyber Security Centre (ACSC) has warned that AI advances are “amplifying the effectiveness of social engineering by weaponising trust, urgency and familiarity.” In its 2024-25 Annual Cyber Threat Report, the ACSC logged over 84,700 cybercrime reports, roughly one every six minutes, with average self-reported business costs up 50% year on year.

The reputational damage goes beyond the original victim

One aspect of lateral phishing that businesses underestimate is the reputational impact. When a compromised account sends phishing emails to clients and suppliers, those recipients associate the attack with your business. Even if you were the victim, the experience from the outside looks like a security failure on your part.

If one of your client contacts clicks a malicious link sent from your account and suffers a data breach as a result, your business may also face notification obligations under the Notifiable Data Breaches scheme administered by the Office of the Australian Information Commissioner (OAIC). A compromised email account that causes harm to contacts can trigger mandatory reporting to both the OAIC and the affected individuals.

The ACSC guidance on business email compromise recommends alerting all contacts, including customers, colleagues and suppliers, as soon as you discover an account has been compromised. That conversation is difficult. It is far better to avoid it altogether.

What we see at TTA: how these attacks play out for Brisbane SMEs

The pattern we see most often is this: a staff member receives a phishing email outside business hours, enters their credentials on a convincing fake login page, and the attacker uses those credentials before the business day starts. By the time someone notices something is wrong, the compromised account has already sent dozens of emails to the contact list.

Professional services firms are a common target. A law firm or accounting practice has a long list of trusted contacts, clients who expect to receive documents and requests from known senders. That contact list is exactly what an attacker wants. The damage spreads to clients before the firm has any idea the account was touched.

The good news is that these attacks follow a predictable structure. Modern email security tools can detect behavioural anomalies, such as an account suddenly sending emails at 2am, messaging contacts it has never emailed before, or sending links to file-sharing services from unusual locations. That pattern stands out even when the email content looks normal.

Three layers of defence that actually reduce the risk

No single control stops lateral phishing on its own. The businesses that contain these attacks quickly tend to have three things in place.

  • Phishing-resistant multi-factor authentication (MFA). Standard SMS or app-based MFA still adds real protection, but modern attackers increasingly use adversary-in-the-middle (AiTM) phishing kits that intercept one-time codes in real time. Phishing-resistant MFA, such as FIDO2 passkeys or hardware security keys, binds authentication to the legitimate domain and cannot be intercepted in the same way. As of 2026, attackers have pivoted specifically to session-token theft to get around conventional MFA, so upgrading to phishing-resistant methods matters.
  • Advanced email security with behavioural detection. Traditional filters check whether a sender is on a blocklist. Behavioural tools look at whether the account is acting normally. An account that suddenly emails 200 people it has never contacted before is flagged, even if the address is legitimate. This is the layer that catches lateral phishing before it spreads far.
  • Regular, practical security awareness training. Staff do not need to become security experts. They need to know that a familiar sender address is not proof that an email is safe, and that unusual requests, even from known senders, are worth a quick phone call to verify. Training that includes realistic phishing simulations is measurably more effective than annual compliance presentations.

You can read more about building effective security habits in our post on security training that sticks.

A quick check for your business

These five questions are worth asking now, before an incident forces the conversation:

  • Do all email accounts, including shared and service accounts, have MFA turned on?
  • Does your email security tool detect unusual sending behaviour, not just known bad senders?
  • Do your staff know how to verify an unusual request from a known sender?
  • Do you have a process for quickly revoking access if an account is compromised?
  • Do you know your notification obligations under the Notifiable Data Breaches scheme if a compromised account affects your clients?

If any of these has an uncertain answer, that is a reasonable place to start. Our IT security assessments give businesses a clear view of where their current controls sit and what to address first. For businesses already on Microsoft 365, a review of conditional access and email security policies can close several of the most common gaps without significant cost.

The ACSC’s Small Business Cyber Security Guide is also a useful free reference for the basics.

Where to from here

Lateral phishing works because it exploits the trust your contacts already have in you. The defences are practical and achievable for businesses of any size. If you would like a straightforward conversation about where your email security stands, get in touch with the TTA team. We work with businesses across Queensland and are happy to start with a no-pressure review.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.