A recent report from the software firm Egress has revealed significant insights into the current landscape of phishing attacks, a prevalent cybersecurity threat. Titled the "Phishing Threat Trends Report," this comprehensive document highlights the increase in phishing toolkits available on the dark web, thus enabling individuals with minimal technical expertise to launch sophisticated phishing campaigns. The report also outlines the challenges faced by security teams due to the high volume of these attacks and the emerging trend of AI-assisted phishing techniques.
The report identifies June 10th, 2024 as the busiest day for phishing incidents thus far, with a peak in phishing emails being sent around 12:37 p.m., coinciding with lunch hours. This period has seen a 28% rise in phishing emails from the first to the second quarter of 2024. Notably, 44% of these emails originated from already compromised accounts, circumventing traditional authentication processes. Furthermore, the report details that 23% of phishing attempts involved malicious attachments, 20% relied purely on social engineering tactics, and 12% included QR codes, a tactic known as "QRishing".
A key finding from the report is the identification of the most common words used in phishing emails. Words such as "urgent," "sign," "password," "document," and "delivery" frequently appear, signalling potential phishing content. The most impersonated companies include major brands like Adobe, Microsoft, Chase, and Meta, further underscoring the sophistication of these attacks.
The report pinpoints impersonation as the leading phishing tactic of 2024. Between January and August 2024, 26% of detected phishing emails claimed to be from brands unassociated with the recipient’s work or personal circles. More concerning is that 16% of phishing emails attempt to impersonate the recipient's own company, with the HR department being a frequent target through emails that mimic employee benefit packages and other HR-related communications.
In addition, phishing emails often feign correspondence from internal departments such as IT and Finance, leveraging familiar requests for information or participation in surveys. The Microsoft logo is notably prevalent in these deceptions, as attackers exploit shared platforms such as SharePoint to evade security checks.
New employees, particularly those within their first two to seven weeks in a company, are also targeted, with phishing emails often impersonating high-ranking company executives like the CEO or CFO. This tactic exploits the authority bias and the likelihood of newer employees responding to emails that appear to be from senior figures.
Further diversifying their approach, cybercriminals also impersonate well-known celebrities. Figures like Jeff Bezos, Elon Musk, Warren Buffet, and Mackenzie Scott are often used in phishing schemes, banking on their authority and public recognition to trick recipients into engaging with malicious content.
The Egress report provides crucial data that cybersecurity professionals can integrate into employee training programmes, emphasising the importance of vigilance and authentication in mitigating phishing risks. Understanding these tactics helps individuals and organisations better protect themselves against the ongoing threat landscape characterised by increasingly sophisticated phishing methods.
Source: Noah Wire Services