Phishing is one of the most flexible types of ‘social engineering’ attack, as it can be disguised in many ways.
Kaspersky Lab’s anti-phishing system prevented more than 482 million attempts to visit fraudulent web pages during 2018, a two-fold increase in 2017 when 236 million such attempts were blocked. Annual rises in the number of phishing attacks have been observed for the last few years, yet the figure for 2018 indicates a significant surge in the use and popularity of such attacks. These and other findings are documented in Kaspersky Lab’s new report, Spam and phishing in 2018.
Phishing is one of the most flexible types of ‘social engineering’ attack, as it can be disguised in many ways and used for different purposes. To create a phishing page, all one needs to do is create a replica of a popular or trusted website, lure unwary users to the site and trick them into entering personal information. Such information often includes financial credentials such as bank account passwords or payment card details, or access credentials for social media accounts. It could also be a case of getting someone to open an attachment or click on a link that then downloads malware onto their computer. The consequences of such attacks may range from a loss of money to the compromise of an entire corporate network. Phishing attacks, especially of the malicious link or attachment variety are a popular initial infection vector for targeted attacks on organizations.
The rapid growth of phishing attacks in 2018 is part of a long-running trend, with both 2017 and 2016 experiencing increases of 15% on the previous year. However, the 2018 figure marks a new peak.
The financial sector was hit especially hard: Over 44% of all phishing attacks detected by Kaspersky Lab technologies were aimed at banks, payment systems and online shops. This means that there were almost as many financial phishing attacks in 2018 as there were phishing attacks overall in 2017.
The country with the highest percentage of users attacked by phishing remained Brazil with 28% of all attacked users. Portugal, which was in 7th place a year ago, is now ranked second with 23% of users, while Australia moved from second to third, with 21% of those affected.
Other findings of the spam and phishing in 2018 report include:
Kaspersky Lab experts advise users to take the following measures to protect themselves from phishing: