Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Phishing Via Social Media Up 100 Percent, Now A Preferred Vector
Articles

Phishing Via Social Media Up 100 Percent, Now A Preferred Vector

ISBuzz TeamBy ISBuzz TeamMarch 6, 2018Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Social Media Meets Customer Care
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The most interesting trend to surface in Q4 of RiskIQ’s phishing report was a 100 percent increase in phishing campaigns leveraging social media platforms, accounting for 20 percent of the top 10 most phished brands.

Phishing actors are always innovating and creating new methods to lure victims into gaining access to their financial information, PII, and user accounts. Understanding the latest phishing techniques and threat actor tendencies can help organizations to stay one step ahead of phishing threats targeting them.

For the uninitiated, phishing is a form of fraud where the malicious actor impersonates or compromises the account of a reputable organisation to con unsuspecting users into parting with their login credentials, personal information and in some cases, financial assets. Users can also unwittingly divulge information about their employer that can be used by the attacker to gain access to corporate networks.

RiskIQ processes huge volumes of web-related threat data, including data on phishing incidents. From these various sources, it receives URLs which might be indicative of phishing. The URLs are processed through crawling infrastructure and fed through machine-learning technology to classify each detected phishing page appropriately. Within this group of phishing pages, there are those used for highly targeted phishing attacks, also known as ‘spear phishing,’ as well as phishing pages used for widespread ‘generic’ phishing.

Regarding infrastructure, there are two distinctions: self-maintained custom infrastructure and abused or compromised infrastructure belonging to someone else.

This information is summarized by RiskIQ every quarter to create a quarterly phishing roundup, tracking the evolving tactics of phishing campaigns. Looking at activity that took place in Q4 2017 while drawing upon data used in the Q3 Report we can make comparisons and recap trends seen over the entirety of 2017.

Overall 27,285 uniquely blacklisted phishing—domains were observed, down two percent from Q3, targeting a total of 259 unique brands, down seven percent from Q3. A slight decline quarter over quarter isn’t unusual as phishing tends to be very cyclical.  Looking at the most phished brands by vertical industry there was a 40 percent of phish leveraging the brands of financial institutions, 20 percent impersonating large tech companies and 20 percent impersonating digital transaction providers. All three of those stats are in line with the Q3 findings. However, the most interesting trend to surface in Q4 was a 100 percent increase in phishing campaigns leveraging social media platforms, a trend that accounted for 20 percent of the top-ten most phished brands including the overall most-phished brand.

This new focus on social media by threat actors is significant because it represents a pivot in tactics between Q3 and Q4 towards social media platforms and away from cloud service providers, which represented 10 percent of targets in the previous report. Financial institutions are almost always the target of the highest volume of attacks, but social media is an interesting new addition to the top-target list.

Fake social media profiles have been a problem for some time. Back in November, Facebook admitted that up to 270 million accounts on the social network are illegitimate and in January Twitter disclosed to investors that up to 60 million accounts are not what they seem.  But why the rise in fake accounts associated with phishing activity?

There are several potential reasons why social media is drawing more attention from threat actors. For one, the growth in popularity of financial integrations within social media platforms that, for example, give users the ability to send and receive money, can make for an easy payday. There’s also the possibility of using sensitive information from posts, messages, and profiles that can be used as lures in social engineering attacks.

For organizations that leverage social media to engage with customers and prospects, these figures should act as a wake-up call; advanced social threat detection is now a critical capability and no longer a nice to have. The low barriers to entry and high visibility of social media make it a fast and powerful tool for threat actors to commit fraud by impersonating your brand. Users who are taken in are likely to place some of the blame on the impersonated organisation for not better protecting its brand, and those same social media platforms can be used to amplify their sentiment, further tarnishing the brand.

Knowing your phishing risk is only half the battle; real-time monitoring and web enforcement should be deployed to help you protect your organization’s assets.

[su_box title=”About Fabian Libeau” style=”noise” box_color=”#336588″][short_info id=’104597′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}