Phishing attacks remain a prominent cause of security incidents and data breaches. According to security software firm Egress, impersonation is the most prolific phishing tactic occurring in 2024.
Among the phishing emails detected by Egress, 26% appeared to be sent from brands that had no business relationship with the recipient.
Egress reports that the top-five words used in phishing include “urgent,” “sign,” ”password,” “document,” and “delivery.”
Egress has found that employees in their initial 2-7 weeks on the job were the most targeted.
The report states that employees are only “accurately reporting” 29% of phishing emails received.
The most impersonated brands are Adobe, Microsoft, Chase, and Meta. Two most impersonated internal systems were e-signatures and employee feedback surveys.
Hackers are also impersonating celebrities like Warren Buffet or Mackenzie Scott along with CEO, HR, IT, and Finance departments to increase threat outreach.
There was a 28% increase in phishing emails sent in the second quarter of 2024 over the previous quarter, with 44% of phishing emails originating from already compromised accounts.
Phishing emails containing QR codes are rising. Educating teams is critical to avoid these attacks.
Appropriate cybersecurity training should be conducted to help employees identify malicious activity and potential attacks through the analysis of such phishing techniques.