Why Does Phishing Remain the Biggest Cyberattack Threat?

Phishing creates a sense of urgency and emergency in employees. As a result, it has become
a very common occurrence in companies, even among higher-ranking
positions

Moreover, phishing remains the main entry point for intrusions. Back in 2022, it already accounted for 41% of incidents, according to IBM’s X-Force Threat Intelligence Index. Since then, the pattern has not changed. What did change is the quality of the lures. After all, generative AI now writes flawless messages.

But why is phishing so dangerous for companies? The reason is simple. It is an attack aimed at people. Therefore, it sometimes bypasses the cybersecurity investments companies have made, including those focused on identifying vulnerabilities.

In practice, its purpose is to deceive the victim and obtain data or access. That data may include banking and credit information. Moreover, the most valuable prize today is the session token. With it, the criminal enters the cloud without typing any password.

Similarly, the channels have multiplied. Links and attachments still show up, of course. However, SMS and messaging app phishing, malicious QR codes, and cloned-voice calls have grown. Therefore, training people only for “suspicious email” no longer works.

Guard down, risk up

Therefore, the purpose behind phishing is to create a sense of urgency or trust. The message can arrive by email, SMS, chat app, or phone call.

Similarly, over time these attacks became far more targeted. That led the market to adopt the concept of “spear phishing.” In this case, the attacker researches the target beforehand. As a result, the chance of success rises considerably.

As an example, consider the executive who receives an apparently trustworthy message. It seems to come from a familiar supplier. In addition, approval requests now arrive with voice and video deepfakes. In general, spear phishing targets senior roles, since that widens the access obtained.

Meanwhile, regardless of hierarchy, a successful attack is always a danger. It can be the green light for access to systems and confidential data.

In this way, the whole planned security structure falls behind because of one human slip. In the 2023 “State of the Phish” report, developed by Proofpoint, the 5 main consequences were:

Phishing: the damage in numbers

– 44% of successful attacks led to a customer data breach. Today, in fact, that scenario triggers notification duties under privacy laws;

– 43% resulted in data hijacking, that is, ransomware. Currently, with double extortion, an updated backup helps but does not close the case;

– 36% had employee credentials compromised;

– 33% turned into loss of data or intellectual property;

– 30% resulted in financial losses.

In short, it is no accident that two areas stand out within IT support. They are cybersecurity and backup and restore. Moreover, both reduce the damage when phishing succeeds.

After all, this care matters even more in businesses that face periodic instability. That is the case, for example, of e-commerce during peak dates such as Black Friday and Christmas.

The importance of awareness

Moreover, one of the main paths to avoid phishing scams lies in training. It applies to the whole team, including the Information Technology staff. That weighs even more now that this type of behavior has become more common.

In practice, the Proofpoint report showed a worrying figure. It concerns how well employees understand the risks involved.

According to the document, one third of people could not define “malware,” “phishing,” or “ransomware.” In other words, they did not understand what these attacks are. Consequently, they did not know how to prevent them either.

Therefore, among the facts unknown in that survey were the following:

– 21% did not know an email can appear to come from someone else;

– 44% believed that knowing the brand makes the email safe. No wonder criminals imitate well-known brands. Among the most used are Microsoft, Google, Apple, and Adobe;

– 63% did not know that a link in an email may not lead to the site it displays.

Similarly, part of these numbers has an explanation. After all, few companies run periodic phishing simulations. As a result, the team only discovers the gap during a real incident.

The risks of hybrid work

As a result, another point deserves attention. It concerns the boundary between personal and corporate devices. Today hybrid work is routine, and that boundary is often minimal. Consequently, risk grows on familiar fronts:

– Most employees use corporate devices for personal activities;

– Many also use personal devices for company tasks;

– Moreover, plenty of them let family and friends use company equipment.

Meanwhile, this mix shows up across several activities. Some examples: reading email, browsing social networks, and shopping online. Therefore, it pays to separate profiles and apply conditional access per device.

The need to report

One of the essential ways to prevent phishing attacks is guidance. After all, employees need to know what to do with a suspicious message.

In short, a few measures greatly reduce the risk. Among them are simple precautions, such as:

– Stay skeptical toward messages demanding urgency or confidential data. In addition, distrust approval requests made by audio or video;

– Check the sender carefully. Sometimes the criminal changes a single letter in the domain;

– Avoid entering confidential data on unknown sites. Likewise, do not scan QR codes received by message;

– Adopt phishing-resistant MFA, with FIDO2 keys or passkeys. In this way, stolen passwords and codes stop working.

After all, the employee’s duty is to report such messages to IT. The goal is to tune filtering tools and block the campaign. As a result, the risks the organization faces go down.

Moreover, talk to one of our specialists. Find out how Inove Solutions works to guarantee your business security!