Cybercriminals seem to be honing their craft, picking specific attack types, victim demographics, and methods, according to new data from the latest PhishLab’s report.
Like any business, you should see what does and doesn’t work, and double down on that which is working. Cybercriminals are no exception – they see their operations as a business in the very same way your organization does.
According to PhishLabs’ 2019 Phishing Trends and Intelligence Report, the bad guys focused much of their efforts using very specific execution over all of 2018:
- Phishing attacks stand out as the attack of choice, growing by 40.9% in 2018
- 98% of attacks in user inboxes contained no malware, making proactive detection of malicious content that much more difficult
- 83.9% of attacks targeted just five industries, showing observed opportunities and successes with specific vertical-specific campaigns
The industries included Payment Services, E-commerce, Financial Institutions, Email/Online Services, and Cloud/File Storage. All but one (payment services) saw a decline in phishing volume (a minuscule -0.1%), with the others seeing increases as much as 48%.
This data makes the case that phishing is here to stay – it’s a viable, effective, and lucrative means to get direct access to individuals within your organization. What’s needed is to make everyone with access to email and the web within the organization a difficult target to turn into a victim. By leveraging Security Awareness Training, you can turn users into security sentries, aware of the danger that exists, looking for suspicious content, and avoiding becoming the next cyber-casualty.
Free Phishing Security Test
Find out what percentage of your employees are Phish-prone™
Would your users fall for CEO Fraud and other social engineering attacks? Take the first step now and find out before the bad guys do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.
Here's how it works:
- Immediately start your test for up to 100 users (no need to talk to anyone)
- Customize the phishing test template based on your environment
- Choose the landing page your users see after they click
- Show users which red flags they missed, or a 404 page
- Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
- See how your organization compares to others in your industry
PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser: