Credential Harvesting Attacks Targeting the U.S. Federal Government Nearly Double as Malware Declines

Stu Sjouwerman | Mar 11, 2021

Credential Harvesting Attacks Targeting Federal GovernmentShifts to a remote workforce in 2020 gave cybercriminals an opportunity to change tactics, focusing on credentialed access to systems accessed from outside government networks.

New data from mobile security vendor, Lookout highlights new problems arising from increased mobile use by government employees in their new U.S. Government Threat Report. The change to using a mobile device has implications on how security-aware employees are when accessing systems, applications, and data that may be cloud-based and not necessarily secured within a government-hardened network environment.

According to the report:

  • In 2020, 71.5% of phishing attacks were focused on credential harvesting, a 67% increase over 2019
  • In the same timeframe, only 28.5% of phishing attacks delivered malware, a decrease of 50% over 2019

The problem seems to be from the rise in use of personal devices. According to Lookout, 91% of mobile devices used by federal employees are unmanaged, and the exposure to mobile phishing attacks on unmanaged devices is nearly 8 times greater than managed devices! And with just under 72% of federal employees clicking on phishing links, the use of unmanaged mobile devices smells like trouble for the U.S. government and any other business that uses personal mobile devices.

Employees need to be taught via Security Awareness Training to keep their cyber defenses up, remaining vigilant when interacting with email and the web by being mindful that links and attachments can be malicious in nature.

Topics: Phishing Malware

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.