Phishing Email Volume Doubles in Q1 as the use of Malware in Attacks Slightly Declines

Stu Sjouwerman | Apr 20, 2023

Phishing Email Volume DoublesNew data shows that cybercriminals started this year off with a massive effort using new techniques and increased levels of attack sophistication.

According to cybersecurity vendor Vade’s Q1 2023 Phishing and Malware Report, the number of phishing attacks in Q1 this year reached the highest total since 2018. While January represented the lion’s share of Q1 phishing volume (approximately 87%), Vade detected over 562 million phishing emails.

This substantial push in January was not without its own trends. According to Vade, the use of malware declined by 13% from the same period last year, representing around 52 million detected instances.

What is not surprising is the focus on targeting credential theft of productivity suites, including Microsoft 365. Vade did note the creative use of YouTube attribution links being used as redirects, CAPTCHA to avoid being detected by security solutions, and obfuscated IPFS Decentralized Networks addresses (via Google Translate) all to ensure engaged victims make their way to the spoofed productivity suite login page to steal their credentials.

With phishing continuing to grow in frequency, sophistication and focused targeting of simple credentials, it’s necessary for your organization to ensure its’ users recognize these attacks the moment they see them – something taught through continual new school Security Awareness Training.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.