Q1 2022 Phishing Threat Trends and Intelligence Report (2024)

Image

Q1 2022 Phishing Threat Trends and Intelligence Report (1)

In 2022, phishing attacks have not only increased substantially, but they have also taken a new turn of events. According to the Agari and PhishLabs Quarterly Threat Trends & Intelligence report, phishing attacks are gradually being delivered through a wide range of online platforms. The classic email phishing attack technique has increased slightly, while other significant phishing trends include:

  • Impersonation scams through social media.
  • Dark web threats, such as credit card fraud.
  • Business Email Compromise (BEC) attacks.
  • Hybrid Vishing attacks.

Some detail about how enterprises and consumers are targeted by phishing attacks on these diverse platforms is worthy of deeper exploration.

Phishing Threat Trends

As compared to Q1 2021 this year's volume of total phishing sites showed a steady growth of 4.4% from January to March. Furthermore, it is anticipated that these numbers would increase throughout 2022. Financial businesses were the top targets, affected mostly by credential theft phishing. While the incidence of this method declined by 7.4% from Q4 2021, it was still a remarkable 53.8% out of all attacks. The entire technology sector was targeted more in Q1, notably social media (21.5%), webmail/online services (5.5%), ecommerce (1.9%), and cloud storage/hosting. The largest increase of attack volume of credential theft (+9.6%) was reported in the social media industry.

Paid domain registrations or compromised sites were primarily used to stage the majority of phishing sites. This staging method is the first instance in five consecutive quarters, representing the highest of 52% of abused paid services from all incidences. The most common staging method was through compromising existing websites 35.1%.

66% of phishing sites were staged on legacy generic Top-Level Domains (gTLDs), which contributed to almost half of all domain abuse phishing activity. Of course, these dizzying numbers are more easily understood in the chart from the report.

Credential theft still reigned supreme in all of the threats in corporate email systems. What is interesting to note is that employees are treating many messages with high caution. However, 82% of the reported emails were identified as “No Threat Detected”. While this heightened sensitivity could generate some cynicism about the value of security awareness training, the report notes that:

“While the majority of employee-reported emails are not classified
as malicious, the identification and reporting of suspicious activity
by a trained workforce is needed to prevent attacks that increasingly
make it past email filters.”

In 2022, it is somewhat unbelievable that 419 “Nigerian Prince” response-based attacks have increased by 3.3%. The fact that this decades-old scam still exists is almost breath-taking. Prior to the internet, these scams were transmitted via fax machines. Unfortunately, the report does not indicate the success rate of these scams, but their continued existence would suggest that they are still effective.

The volume of threats from social media channels has advanced 27% from Q4 to Q1 single-handedly. This is a 107% increase targeting enterprises. Impersonation scams are the most frequent method of social media attacks, followed by fraud, and traditional account compromise techniques. Financial institutions still remain the primary target of social media attacks.

Dark Web Threat Trends

The top dark web threat cited in the PhishLabs report is credit card fraud. The dark web is highly famous for publishing stolen card data, which has contributed 53.7% from the total share of dark web threats, despite a 20% decline in Q1. The second most common dark web threat is the sale of corporate credentials. 64% of the stolen data was primarily marketed on carding marketplaces and forums. Forums gained a large 9.3% increase of activity from all dark web marketplaces.

Similar to social media attacks, financial institutions are the most targeted industries for dark web attacks. Credit unions, and Financial Services companies round out the list.

Conclusion

The report indicates technological and strategical improvements in phishing tactics, and enterprises are targeted more than private consumers. Phishing attacks have leveraged various media to execute malicious activity. Apart from the traditional email delivery mechanism, social media is the highest trending platform. Organizations need to be vigilant against these scams and carefully maintain a presence on these platforms to confirm their authenticity and validity to avoid phishing activity, and to secure the name of the company.

One way for organizations to protect against phishing attacks is to enforce email filters, and apply security protocols in their systems to reduce the impact of credential theft attacks. While it is true that some staff members will become overly cautious, security awareness training is still a valid and valuable defence.

Organizations should pay close attention to the diverse platforms that are available today which allow threat actors to easily perform many fraudulent activities. Phishing attacks are being executed in various forms, using myriad tactics. It is the responsibility of each organization to address any phishing related activities for the awareness of consumers and even employees. Proper monitoring of these platforms, and the application of appropriate security protocols and mechanisms to deter phishing threats is a valuable security approach.

About the Author: Dilki Rathnayake is a Cybersecurity student studying for her BSc (Hons) in Cybersecurity and Digital Forensics at Kingston University. She is also skilled in Computer Network Security and Linux System Administration. She has conducted awareness programs and volunteered for communities that advocate best practices for online safety. In the meantime, she enjoys writing blog articles for Bora and exploring more about IT Security.

Editor’s Note:The opinions expressed in this guest author article are solely those of the contributor, and do not necessarily reflect those of Tripwire, Inc.

As a cybersecurity enthusiast with a deep understanding of the evolving landscape of online threats, I find the information presented in the provided article to be both insightful and reflective of the current phishing landscape. My expertise in this field stems from an academic background in Cybersecurity and Digital Forensics, where I am currently pursuing a BSc (Hons) at Kingston University. Additionally, my practical skills in Computer Network Security and Linux System Administration contribute to a comprehensive understanding of the technical aspects involved in combating cyber threats.

The data from the Agari and PhishLabs Quarterly Threat Trends & Intelligence report aligns with my knowledge of the phishing landscape up to my last training cut-off in January 2022. The report highlights a concerning increase in phishing attacks across diverse online platforms, showcasing a departure from the traditional email-centric approach. This aligns with the evolving tactics employed by cybercriminals to exploit a wider range of vectors and increase their chances of success.

One notable trend mentioned is the rise of impersonation scams through social media, indicating a shift towards exploiting trust relationships established on these platforms. This tactic requires organizations and individuals to adapt their cybersecurity measures to safeguard against social engineering attacks originating from platforms like Facebook and Twitter.

The mention of Dark Web threats, particularly the prevalence of credit card fraud and the sale of corporate credentials, underscores the multifaceted nature of cyber threats. This aligns with my understanding of the Dark Web's role as a marketplace for various cybercriminal activities, with financial institutions being a prime target.

The statistics on the growth of phishing sites and the specific industries targeted resonate with my knowledge of the persistence and adaptability of cyber threats. The emphasis on credential theft, especially in corporate email systems, underscores the ongoing relevance of this technique for attackers. The report rightly highlights the importance of a trained workforce in identifying and reporting suspicious activity to complement email filters.

The article also touches upon the surprising persistence of certain phishing techniques, such as the "Nigerian Prince" scam, indicating that even with advancements in technology, some classic tactics continue to be effective. This aligns with the notion that cybercriminals often leverage both sophisticated and time-tested methods to achieve their objectives.

The recommendations provided in the conclusion, such as the enforcement of email filters, the application of security protocols, and the importance of security awareness training, are in line with established best practices in cybersecurity. These measures, coupled with continuous monitoring of diverse platforms, are crucial for organizations to stay ahead of the evolving threat landscape.

In conclusion, the insights presented in the article align with my in-depth knowledge of cybersecurity trends and practices. The ever-changing nature of cyber threats necessitates a proactive and multifaceted approach to cybersecurity, involving both technical measures and user awareness initiatives.

Q1 2022 Phishing Threat Trends and Intelligence Report (2024)

FAQs

Q1 2022 Phishing Threat Trends and Intelligence Report? ›

As compared to Q1 2021 this year's volume of total phishing sites showed a steady growth of 4.4% from January to March. Furthermore, it is anticipated that these numbers would increase throughout 2022. Financial businesses were the top targets, affected mostly by credential theft phishing.

What is the phishing activity trends report 1st quarter 2022? ›

Most concerning is that APWG reported 1,025,968 phishing attacks in Q1 2022; the highest quarterly number in their reporting history and the first time they have seen phishing attacks exceed one million! It is also notable that this number is 67% higher than the same period in 2021 (611,877).

What are the phishing trends in 2022? ›

During Q3 2022, gift card requests were the most popular cash-out method, making up 38.5 percent of the total. This was followed by advance fee fraud (30.9%), payroll diversion attempts (12.5%), and wire transfers (4.9%), with miscellaneous cash-out methods accounting for the balance.

What is the phishing activity trends report 4th quarter 2022? ›

In the fourth quarter of 2022, APWG observed 1,350,037 total phishing attacks. This is more than in the third quarter of 2022 when APWG recorded 1,270,883 total phishing attacks, which was a new record at the time and the worst quarter for phishing that APWG has ever observed.

How to respond to phishing emails? ›

Do not click on any links, open attachments, or reply to suspicious emails. Instead, verify the sender through trusted means, such as contacting them directly using a known, legitimate phone number or email address.

What is the phishing activity trend report for the second quarter of 2022? ›

In Q2 2022, gift card requests were the most popular cash-out method used by criminals, making up 39.9 percent of the total, followed by payroll diversion attempts (25.9%), advanced fee fraud (15.5%), and wire transfers (9.6%).

What are the number one target for phishing attacks? ›

These attacks often have one of two targets: individuals or employers. Individuals: Cyber criminals target individuals because they are the easiest to compromise and the most susceptible to phishing attacks. This is because many people aren't tech-savvy or educated on how to spot phishing emails.

What is the most common cyber threat in 2022? ›

Malware
  • Botnet software. Botnet software is a type of malware that allows attackers to control a network of infected computers, or 'bots'. ...
  • Ransomware attack. ...
  • RATs. ...
  • Rootkits and bootkits. ...
  • Spyware. ...
  • Trojan. ...
  • Viruses and worms.

Who is most vulnerable to phishing? ›

Although young adults are incredibly tech-savvy, they are the most susceptible to falling victim to cyber crimes. Young adults and adults over 75 are the most vulnerable to fraud attacks.

What are the results of Meta Reports 4th quarter 2022? ›

Meta Reports Fourth Quarter and Full Year 2022 Results
Three Months Ended December 31,% Change
In millions, except percentages and per share amounts2022
Revenue$ 32,165(4) %
Costs and expenses25,76622 %
Income from operations$ 6,399(49) %
5 more rows
Feb 1, 2023

What is a common indicator of a phishing attempt cyber Awareness 2022? ›

A common indicator of a phishing attempt is a deceptive and suspicious email often disguised as a legitimate one. Such emails are meant for stealing information and malicious actions.

How many spoofing attacks in 2022? ›

Phishing Attack Trends
YearNumber of attacks observed
2019779,200
20201,845,814
20212,847,773
20224,744,699
Apr 10, 2024

Which of the following emails is most likely a phishing attempt? ›

In fact, an email that includes both a zip attachment and a password to open the attachment is almost always a phishing email.

What if I accidentally replied to a phishing email? ›

Contact the company or organization. If you responded to a phishing email that appeared to be from a trusted source, contact the company or organization to alert them. They may be able to take steps to prevent other customers or employees from falling victim to the same scam.

How do I know if I got phished? ›

Here are some ways to recognize a phishing email: Urgent call to action or threats - Be suspicious of emails and Teams messages that claim you must click, call, or open an attachment immediately. Often, they'll claim you have to act now to claim a reward or avoid a penalty.

What are the cybersecurity trends report 2022? ›

According to Gartner, “Acceleration of credential misuse continues, leading to a tragic increase in security incidents.” Gartner also shares, “The more-sophisticated attackers are now actively targeting the IAM infrastructure itself.” We believe this aligns with the findings of the CrowdStrike 2022 Global Threat Report ...

What is the industry phishing click rate 2022? ›

10.4% click-through rate on phishing simulation emails, marking a 3.4 percentage point increase from the previous year. (Note: the 2022 simulation template used a different context but targeted the same behaviors with its tactics).

What is the Cyberattack October 2022? ›

In October of this year, a pro-Russian hacker group claimed responsibility for hacking several US airport websites. Although this was widely reported in our cyber circles, it was just another DDoS attack on US airport websites by the notorious “Killnet” hacking group.

Top Articles
Climate Resilience Portal
https://www.hulu.com/series/who-wants-to-be-a-millionaire-19ae44d5-5331-4cfc-8b9e-f50845869b3f
Express Pay Cspire
Canya 7 Drawer Dresser
Angela Babicz Leak
Farepay Login
Rainbird Wiring Diagram
Fusion
Bluegabe Girlfriend
Craigslist In Fredericksburg
Simple Steamed Purple Sweet Potatoes
Caroline Cps.powerschool.com
Little Rock Arkansas Craigslist
Amelia Bissoon Wedding
Nj State Police Private Detective Unit
Suffix With Pent Crossword Clue
Truth Of God Schedule 2023
Dr Adj Redist Cadv Prin Amex Charge
Echat Fr Review Pc Retailer In Qatar Prestige Pc Providers – Alpha Marine Group
Powerball winning numbers for Saturday, Sept. 14. Check tickets for $152 million drawing
Walmart Car Department Phone Number
Xsensual Portland
Jc Green Obits
Xfinity Cup Race Today
Prey For The Devil Showtimes Near Ontario Luxe Reel Theatre
Cona Physical Therapy
Nearest Ups Ground Drop Off
Waters Funeral Home Vandalia Obituaries
Wolfwalkers 123Movies
Bend Missed Connections
Darknet Opsec Bible 2022
Hotel Denizen Mckinney
Www Craigslist Com Shreveport Louisiana
Σινεμά - Τι Ταινίες Παίζουν οι Κινηματογράφοι Σήμερα - Πρόγραμμα 2024 | iathens.gr
Skroch Funeral Home
Junee Warehouse | Imamother
Leatherwall Ll Classifieds
Die Filmstarts-Kritik zu The Boogeyman
Aliciabibs
Claim loopt uit op pr-drama voor Hohenzollern
Tiny Pains When Giving Blood Nyt Crossword
Legit Ticket Sites - Seatgeek vs Stubhub [Fees, Customer Service, Security]
Home Auctions - Real Estate Auctions
Sand Castle Parents Guide
Dickdrainersx Jessica Marie
Menu Forest Lake – The Grillium Restaurant
Bellelement.com Review: Real Store or A Scam? Read This
All Buttons In Blox Fruits
Blippi Park Carlsbad
Craigslist Anc Ak
Is TinyZone TV Safe?
Latest Posts
Article information

Author: Rev. Porsche Oberbrunner

Last Updated:

Views: 5795

Rating: 4.2 / 5 (73 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Rev. Porsche Oberbrunner

Birthday: 1994-06-25

Address: Suite 153 582 Lubowitz Walks, Port Alfredoborough, IN 72879-2838

Phone: +128413562823324

Job: IT Strategist

Hobby: Video gaming, Basketball, Web surfing, Book restoration, Jogging, Shooting, Fishing

Introduction: My name is Rev. Porsche Oberbrunner, I am a zany, graceful, talented, witty, determined, shiny, enchanting person who loves writing and wants to share my knowledge and understanding with you.