The Number of Phishing Sites in March Was Twice That of the Previous Year

Stu Sjouwerman | Jun 22, 2021

Number of Phishing Sites DoubledWith the number of phishing sites in Q1 overall up 47%, according to new data from Phishlabs, the bad guys are starting their year off letting you know… they mean business.

Nobody wants to hear that the bad guys appear to be ramping up even more than they already have. But that’s pretty much what it sounds like, according to Phishlabs Q1 2021 Threat Trends & Intelligence Report. “Growth” was a recurring theme… after all, isn’t that what most “businesses” are striving for? More “customers”? Greater market penetration? Etc. This report shows how organized the bad guys are striving to be, and that they’re actually behaving like "professional companies", nefarious as they may be.

According to the report:

  • 62% of all phishing sites abused free web services and tools to stage a site
  • 66% of all phishing site domains were free domain registrations
  • SSL use has leveled out in Q1 with 83% of sites using SSL for legitimacy
  • The ZLoader banking trojan was used when targeting corporate users 62% of the time

The last interesting stat is that 94% of phishing emails did not contain a malicious attachment or link. According to the report, it’s the social engineering-based attacks that are the most damaging and “remain highly likely to reach user inboxes undetected.”

The only way to get out ahead of the problems, Phishlabs are pointing out, is to engage your user as a line of defense, empowering them with continual Security Awareness Training that educates them not just on the basics of good cyber hygiene, but about the latest scams, social engineering tactics and campaign themes, so they can be aware and vigilant.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.