KnowBe4's latest reports on top-clicked phishing email subjects have been released for Q1 2023. We analyze 'in the wild' attacks reported via our Phish Alert Button, top subjects globally clicked on in phishing tests, top attack vector types, and holiday email phishing subjects.
This last quarter's results reflect the shift to IT and online service notifications such as laptop refresh or account suspension notifications that can affect end users’ daily work.
“Cybercriminals are constantly increasing the damage they cause to organizations by luring unsuspecting employees into clicking on malicious links or downloading fake attachments that seem realistic,” said Stu Sjouwerman, CEO, KnowBe4. “Emails that are disguised as coming from an internal source, such as the IT department, are especially dangerous because they appear to come from a trusted place where an employee would not necessarily question it or be as skeptical. Building up an organization’s human firewall by fostering a strong security culture is essential to outsmart bad actors.”
Click here to download the full infographic (PDF). Great to share with your users!
Each quarter, we examine ‘in-the-wild’ email subject lines that show emails that users received and reported to their IT departments as suspicious. In 2023, we've seen mostly IT and online service notifications that could potentially affect users' daily work:
We have seen a lot more business related subjects coming from HR/IT/Managers in the past year. Others involve logins on new devices and password resets. Tax-related email subjects became more popular as the U.S. prepared for tax season in Q1. These attacks are effective because they cause a person to react before thinking logically about the legitimacy of the email:
Unsurprisingly, the #1 attack vector we've seen each quarter was phishing links in the email body. When these links are clicked they often lead to disastrous cyberattacks such as ransomware and business email compromise. Other top attack vectors are as follows:
Holiday phishing email subjects for the beginning of the year largely such as a change in schedule, gift card and spa package giveaway are used as bait for unsuspecting users.
*Capitalization and spelling are as they were in the phishing test subject line.
**Email subject lines are a combination of both simulated phishing templates created by KnowBe4 for clients, and custom tests designed by KnowBe4 customers.
See results from all previous quarters in our Top Clicked Phishing Email Subjects topic.