Vishing Attacks Increase 550% Over Last Year as the Financial Sector Continues to be a Primary Target

Stu Sjouwerman | Jun 20, 2022

Vishing Attacks Increase 550% Over Last YearCybercriminals are continuing to bypass the use of malware in favor of response-based and credential-centric social engineering attacks, according to new data from Agari and PhishLabs.

Malware-based attacks certainly are not dead, as threat actors need to gain control over endpoints, and ransomware continues to thrive. But new data from PhishLabs’ Quarterly Threat Trends & Intelligence Report shows that cybercriminals are favoring attacks that are less likely to be detected by security solutions – the greatest, of which, is vishing.

According to the report, hybrid vishing now leads over business email compromise (BEC) as the second most reported response-based threat, with one in four reported response-based attacks being a vishing attack.

Response-based threat – those attacks that rely on social engineering and requiring the interaction of a corporate user – represented 37.5% of email-based threats as well, with credential theft used in nearly 59% of attacks, and malware delivery only occurring in less than 4% of attacks.

This breakdown demonstrates the power and effectiveness of the use of social engineering tactics and the longer-term play by threat actors to gradually gain the access needed to compromise networks and breach data.

It also makes the case for the need for Security Awareness Training to counteract such tactics – whether the medium is email, web, voice, or text. If users are not fully-prepared for social engineering attacks, the trends outlined by the PhishLabs report indicate that cybercriminals will continue to win the battle, seeing more successful attacks via social engineering.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.