Social Media Platforms Become Half of all Phishing Attack Targets

Stu Sjouwerman | Aug 16, 2023

Social Media Half of Phishing Attack TargetsSocial platforms are the current favorite target of cybercriminals, displacing financial institutions, providing cybercriminals with credentials to be used as launch points for further phishing campaigns.

Most cyber attacks we read about seem to involve an organization that was attacked because it was perceived to have a lot of money that could be parted with via ransomware, extortion, digital fraud, etc. But then we have initial access brokers that focus solely on obtaining valid credentials which can then be sold to a cybercriminal intent on attacking an organization.

And then there’s those cybercriminals that focus on targeting social media in an effort to compromise accounts that can be used in scams or to propagate social engineering attacks. According to PhishLabs, the focus on social media sites as attack targets jumped nearly 25% last quarter, making it not only the number one industry targeted, but single-handedly representing just shy of half of all phishing attacks last quarter.

q2-2023-phish-top-targeted-industries_71b8d76df8bb8dab5091c12c80ce3bdc_800

Source: PhishLabs

The real risk in social media being compromised is that the accounts that are misused can have a wide reach that includes mobile and desktop devices, individuals and corporate users, and have more than just a credit card or digital currency scam in mind. So, users within organizations should be very familiar with the latest social engineering techniques used in social media, as well as taught to remain constantly vigilant – something provided through continual Security Awareness Training.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.