Phishing Attacks are the Most Prevalent Source of Identity-Related Breaches

Stu Sjouwerman | Jul 14, 2022

Phishing Attacks Source of Identity-Related BreachesCybercriminals almost always need to leverage credentials as part of just about any kind of cyberattack. To no surprise, phishing and social engineering play a dominant role.

Usually when we’re talking about cyberattacks, it’s a conversation that starts with an endpoint, a malware infection, and then a succession of malicious actions intent on gathering internal credentials to move laterally, access resources, and eventually the desired data and applications to carry out the final step in the attack – be it ransomware, exfiltration, or fraud.

But, new data found in the Identity Defined Security Alliance’s latest report 2022 Trends in Securing Digital Identities, identity is a target much earlier in an attack and is very often the focus. According to the report, a majority (84%) of organizations have experienced an identity-related breach in the last 12 months. Of these orgs, 78% of them dealt with “direct business impacts” including recovery costs and reputational damage.

Digging a bit deeper, the data begins to reveal the why behind that 84% number. According to the report:

  • 59% of organizations have experienced phishing-based campaigns focused on stealing credentials
  • 27% experienced social engineered password scams
  • 23% experienced brute force password attacks

Each of these experienced relate to one simple factor within an organization’s security strategy – the educating of its’ users. Those organizations that undergo continual Security Awareness Training have a userbase more apt to utilize secure passwords (working to thwart the brute force attacks), and are vigilant enough to spot phishing and social engineering attacks a mile away, stopping cyberattacks – whether focused on identity or not – dead in their tracks.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.