Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Phishing - Phishing Report Findings Call for a Fundamental Shift in Organizational Approaches to Defense
Phishing Attacks Latest News News & Analysis Study & Research

Phishing Report Findings Call for a Fundamental Shift in Organizational Approaches to Defense

Adam ParlettBy Adam ParlettDecember 23, 2024Updated:January 2, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Phishing
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

SlashNext has released its 2024 Phishing Intelligence Report, a comprehensive study identifying and analyzing the vectors most exploited by cybercriminals in the past year. The findings and how the data is trending form recommendations for organizations on the best areas to strengthen their security defenses against attacks in 2025. Their message to organizations for 2025 is clear: Phishing isn’t an email-only problem anymore; instead, it is a multi-faceted message security problem that necessitates a change in how organizations tackle threat detection and prevention.

Key Findings from the 2024 Report

Without wishing to sound hyperbolic, the findings revealed huge increases across multiple areas. These include:

Drastic increase in Credential Phishing

Credential phishing is an online scam where cybercriminals seek to obtain usernames and passwords to access victims’ bank accounts and personal information, leading to potential identity theft. Two standard methods used to extract information are Phishing attempts and Fake Login Pages.

Credential theft attacks surged by 703% in the latter half of 2024, reflecting the increased use of sophisticated phishing kits and social engineering tactics.

Rise in Email-Based Attacks

Email phishing can be understood as ‘the quintessential model of phishing attacks.’ The attack method involves sending out fraudulent emails containing malicious links in vast numbers.

Overall, email-based threats rose by 202% in the latter half of the year, with users receiving at least one advanced phishing link weekly that could bypass standard security measures.

Zero-Day Threats on the Rise

A zero-day threat is a cyberattack that exploits a previously unknown vulnerability present in a computer or mobile device’s software or hardware. The “zero-day” aspect references how the targeted organization has essentially a period of “zero days” to resolve the issue once the flaw has been identified.

Among all embedded malicious links observed, 80% were previously unknown zero-day threats. This highlights the limitations of relying solely on static threat intelligence and signature-based detection methods.

Alarmingly Frequent User Exposure

Phishing is one of the most common forms of social engineering that users are exposed to and another area that attackers deployed substantially more of in 2024. Social engineering is a manipulative tactic cybercriminals use to deceive individuals into divulging confidential information or performing actions that compromise security.

The report found that in 2024, users faced 3 to 6 threats weekly, representing up to 600 mobile threats annually. Social engineering attacks rose by 141%, underscoring the need for adaptive security measures.

Expert Analysis

Cybersecurity experts have been reacting to the report. Nicole Carignan, Vice President of Strategic Cyber AI at Darktrace, identified how organizations still face phishing attacks despite improved email security. She spoke about how many tools rely on outdated data, making them ineffective against new threats, and how employees alone can’t defend against evolving tactics; machine learning is needed to identify suspicious behaviours. Speaking on the expanded threat landscape (noting how threats now extend to platforms like Microsoft Teams and Dropbox), she called for the adaption of proactive security strategies and better governance to combat cross-domain attacks.

James Scobey, Chief Information Security Officer at Keeper Security, believes that ‘As attackers grow more sophisticated, the need for stronger, more dynamic identity verification methods – such as MFA and biometrics – will be critical to defend against these increasingly nuanced threats.’

Conclusion

The report’s takeaway message is that Phishing is now a broader messaging security problem and should act as a wake-up call to organizations of all sizes. By recognizing phishing as a multi-faceted and pervasive threat, businesses can better position themselves to protect critical assets and maintain trust in an increasingly hostile digital environment.

Adam Parlett
Adam Parlett

Adam Parlett is a cybersecurity marketing professional who has been working as a project manager at Bora for over two years. A Sociology graduate from the University of York, Adam enjoys the challenge of finding new and interesting ways to engage audiences with complex Cybersecurity ideas and products.

  • Adam Parlett
    Apache Tomcat Under Siege 2: Well-Hidden Payload
  • Adam Parlett
    NIST Adds SandboxAQ’s HQC as Their Newest PQC Standard
  • Adam Parlett
    Policy Statement Sheds Light on Upcoming UK Cybersecurity Bill
  • Adam Parlett
    New Lazarus Group Scam Targets Crypto Jobseekers

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}