Report: Phishing Attacks on the Upswing

Phishing attacks have increased 13 percent and spear phishing attacks are up 22 percent from 2014, according to new research from Wombat Security Technologies. The "State of the Phish" report, based on data from millions of simulated phishing attacks as well as several hundred survey responses from security professionals, found that "phishing attacks continue to grow in volume and complexity, supported by more aggressive social engineering practices that make phishing more difficult to prevent."

Survey respondents reported that they have experienced malware infections (42 percent), compromised accounts (22 percent) and loss of data (4 percent) due to successful phishing attacks. The resulting loss of employee productivity and uncontained credential compromise can cost an average size organization $3.77 million per year, according to Wombat.

The Wombat research found that "the most popular phishing attack templates with the highest click rates included items employees expected to see in their work e-mail, such as an HR document or a shipping confirmation." While users were more cautious when receiving "consumer" e-mails such as gift card notifications or social network notifications, an "urgent e-mail password change request" had a 28 percent average click rate.

Other findings from the report include:

  • E-mails personalized with a first name (spear phishing) had click rates 19 percent higher than those with no personalization;
  • Click rates vary per industry, with telecommunications and professional services clicking phishing e-mails more than other industries;
  • Organizations use a variety of security technologies, including e-mail spam filters (99 percent), outbound proxy protection (56 percent), advanced malware analysis (50 percent) and URL wrapping (24 percent);
  • The plugins most likely to be out of date and susceptible to an attack are Adobe (61 percent), Adobe Flash (46 percent), Microsoft Silverlight (27 percent) and Java (25 percent); and
  • The most suspicious attachments include pdf (29 percent), doc (22 percent), html (13 percent) and xls (12 percent).

"Phishing continues to be a highly effective attack vector that is increasingly responsible for a significant percentage of data breaches in the market today," said Trevor Hawthorn, CTO of Wombat, in a press release. "In spite of continued investments in a number of popular security technologies, phishing messages continue to reach end users and can result in serious damages to a company's critical data and reputation."

The full report can be downloaded free from the Wombat site (registration required).

About the Author

Rhea Kelly is editor in chief for Campus Technology, THE Journal, and Spaces4Learning. She can be reached at [email protected].

Featured

  • digital graph

    Building Genuinely Data-Informed School Districts

    Schools today generate enormous amounts of data. The difference between collecting it and using it effectively often comes down to quality, access, and context.

  • abstract electronic circuit board 3d rendering

    Content Infrastructure, Governance Lag Behind Agentic AI Adoption

    AI agents have moved into mainstream enterprise use, but the content infrastructure needed to support them has struggled to keep up, according to a new report from cloud content management company Box.

  • abstract spiral of multi colored lights

    OpenAI's New Astra Model Reaches Critical Cyber Threshold

    OpenAI has introduced GPT-6 Astra, its most capable broadly deployed model and the first system the company says has reached the "Critical" cybersecurity capability threshold under its Preparedness Framework.

  • circuit patterns

    Anthropic Intros Lower-Cost Claude Sonnet 5

    Anthropic has launched Claude Sonnet 5, positioning the model as its most autonomous mid-tier offering to date and a lower-cost alternative to its flagship Opus 4.8 system. The company said the model can plan multi-step tasks, operate tools such as browsers and terminals, and complete agentic work at a level that previously required larger and more expensive models.