New Report Shows Phishing Links and Malicious Attachments Are The Top Entry Points of Cyber Attacks

Stu Sjouwerman | Apr 3, 2024

Phishing StudentNew TTP attack data covering 2023 sheds much needed light on the threat actor and user actions that are putting organizations at the most risk.

In cybersecurity vendor ReliaQuest’s Annual Cyber-Threat Report: 2024, there is a ton of great detail mapped to the MITRE ATT&CK Framework outlining which threat actions are used and how organizations are most effectively fighting back and stopping attacks.

According to the report:

  • Phishing links or attachments were involved in 71% of all initial access phases of cyber attacks
  • The top three MITRE ATT&CK techniques in attacks involved phishing or spear phishing
  • Drive-by-compromise was used in 29% of attack
  • QR code phishing saw a 51% increase in just one month – September – over the previous 8 months combined

It appears that there’s a ton of effort around attacks that involve targeting the user. So, just how well are your users responding?

According to ReliaQuest, sadly, in 29% of incidents, users helped to facilitate initial access. In other words, users aren’t exactly helping.

ReliaQuest has some recommendations to better secure users:

  • Require employees verify transaction requests through an alternate means of communication
  • Block newly-registered domains
  • Monitor high-risk roles
  • And educate employees through continual security awareness training

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.