61% of Successful Phishing Attacks Against Government Organizations Result in Full Compromise of Credentials

Stu Sjouwerman | Oct 9, 2020

phishing attack government organizationsPhishing remains the top primary attack vector that keeps on giving to cybercriminals, as new data highlights the victories cybercriminals are enjoying at your organization’s expense.

The old adage “if it works, work it” seems to be applicable to phishing scams targeting credentials. Cybercriminals have long been looking for a way to easily monetize phishing attacks – and they seem to have found the holy grail in the form of obtaining victim credentials to online services.

And so, they continue to “work it” – using phishing attack after phishing attack to steal credentials to assist in either network infiltration, business email compromise, a ransomware attack, or data theft.

According to new data from Coalfire’s 3rd Annual Penetration Risk Report shows phishing also is the top attack vector leading to the compromise of government organizations subject to FedRAMP compliance. According to the report, a lack of training against social engineering tactics used in phishing also tops the list of vulnerabilities in these organizations.

The combination of these two pieces of information points directly at an inability for users to determine when email is malicious in intent, and that the malicious outcomes of such attacks are significant in nature.

Organizations subject to FedRAMP are required to perform phishing testing, which is only useful as a feedback loop within a Security Awareness Training initiative, where additional training can be assigned to those that fail the phishing tests.

Phishing attacks are at their historical peak in effectiveness and there’s no indication that this is going to change. It’s time to provide your users with tools in the form of new school Security Awareness Training to prepare them for when the next phishing attack occurs.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.