Ninety-Four Percent of Organizations Sustained Phishing Attacks Last Year

31 January 2024

A survey by Egress has found that 94% of organizations were hit by phishing attacks in 2023.

Additionally, 91% of firms experienced data loss and exfiltration. The three most common causes of data loss were reckless behaviour, human error and malicious exfiltration.

“The negative effects of a data loss incident are varied,” Egress says. “Businesses can suffer a loss of clients, reputation damage, litigation, and in more serious cases, have to cease operations altogether. In fact, according to our survey, 58% of organizations had to cease operations following breaches of internal information barriers by email. More organizations are being negatively impacted by security incidents caused by data loss and exfiltration this year than last year. 94% of the organizations surveyed reported being adversely affected, which is an increase of 8% from last year’s report.”

The researchers found that 79% of account takeovers were due to phishing attacks.

“Phishing is the most common tactic for credential harvesting and account takeover,” Egress writes. “These emails will often contain a link to a credential-harvesting site, like this Netflix impersonation campaign we highlighted last year. Account takeover is understandably one of the top stressors for Cybersecurity leaders. Once threat actors have access to an employee’s account, they use it to move laterally, sell credentials to other cybercriminals, and send phishing emails that are difficult for traditional security to detect, as the threat is coming from a trusted domain.”

Jack Chapman, VP of threat intelligence at Egress, stated, “Organizations continue to face vulnerabilities when it comes to advanced phishing attacks, human error, and data exfiltration, and analysing emerging trends will be key to bolstering defences.”

KnowBe4 enables your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk. 

Related News

New HardBit Ransomware 4.0 Uses Passphrase Protection to Evade Detection

17 Jul 2024

Cybersecurity researchers have shed light on a new version of a ransomware strain called HardBit that comes packaged with new obfuscation techniques to deter analysis efforts.

Read More

Indonesia tightens cybersecurity after ransomware attack

15 Jul 2024

The recent cyberattack in Indonesia, which massively disrupted its national data system, has urged the country to strengthen its cyber resilience and evaluate its digital technology policy, reported Xinhua.

Read More

New “Paste and Run” Phishing Technique Makes CTRL-V A Cyber Attack Accomplice

09 Jul 2024

A new phishing campaign tries to trick email recipients into pasting and executing malicious commands on their system that installs DarkGate malware.

Read More