Cyber Attackers are Adopting a “Mobile First” Attack Strategy

Stu Sjouwerman | Oct 21, 2024

Mobile is a Security ProblemWith 16+ billion mobile devices in use worldwide, new data sheds light on how bad actors are shifting focus and tactics to put attacks into the victim’s hands.

There’s an interesting story woven throughout mobile security provider Zimperium’s 2024 Global Mobile Threat Report that demands the attention of organizations intent on securing every attack vector – which includes personal mobile devices.

According to the report:

  • 82% of organizations allow BYOD
  • The average smartphone has 80 apps installed, with 5-11 being work-related
  • 85% of the apps on the device are personal apps that all have some potential impact to the organization’s risk exposure
  • 71% of employees leverage smartphones for work tasks
  • 60% of employees use their smartphones for work-related communication
  • 48% of employees use their smartphones for accessing work-related information

While Zimperium goes into more about the insecurity of the apps on devices, let’s stick with the fact that employees are using their mobile devices for work to a material degree.

According to the report, there’s a huge shift towards attacking via mobile devices. Take the following additional stats:

  • 83% of phishing sites being designed to specifically target mobile devices
  • Mobile malware instances have increased 13% in the last year
  • 80% of all malware observed by Zimperium were riskware and trojans deployed as “sideloaded apps” on mobile devices

In other words, the data points to two things: first, mobile presents a real risk to organizations, and second, cyber attacks are shifting toward mobile.

And since most organizations have limited ability to secure an employee’s personal devices, it’s necessary to leverage the employee themselves as part of the organization’s security strategy through new-school security awareness training to elevate their continual sense of vigilance when interacting with email and the web on a mobile device.

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.