🚨 2025 Phishing Threat Trends Report: AI, Ransomware & Hiring Exploit by Knowbe4
🚨 2025 Phishing Threat Trends Report: AI, Ransomware & Hiring Exploits
By Admin | Sourced from KnowBe4 Threat Intelligence – March 2025
📈 17.3% rise in phishing emails in just six months
🔐 57.9% of phishing attacks used compromised accounts
🤖 82.6% of phishing emails were powered by AI
🔐 57.9% of phishing attacks used compromised accounts
🤖 82.6% of phishing emails were powered by AI
1. AI-Powered Polymorphic Phishing
Attackers now use AI to create near-unique phishing messages that evade filters. These emails alter sender names, metadata, subjects, and logos to trick both systems and humans.
| Month (2024) | % Emails with Polymorphic Features |
|---|---|
| March | 42.2% |
| July | 56.8% |
| October | 65.5% |
| December | 74.3% |
2. Ransomware Surge via Obfuscated Payloads
Ransomware-as-a-service and HTML smuggling lead to more encrypted payloads slipping past detection.
| Obfuscation Method | Impact |
|---|---|
| HTML Smuggling | 85.6% ↑ (Q4 2024 – Q1 2025) |
| Password-Protected ZIPs | Bypass traditional scanning |
| AI-generated filler text | Breaks signature detection |
| Base64 URL Encoding | Hides links from blocklists |
3. Phishing via Job Applications
Cybercriminals target HR and IT workflows with fake CVs and job offers. Shared inboxes are especially at risk.
| Target Role | % of Phishing Attempts | Common Entry Point |
|---|---|---|
| Engineering | 64% | Shared mailboxes (33.4%) |
| Finance | 12% | Shared inboxes |
| HR | 10% | Delegate accounts |
| IT | 10% | User accounts (spear phishing) |
4. What’s Getting Past Email Security?
Attackers now bypass Microsoft and SEGs with increasing success using trusted platforms and creative obfuscation.
| Payload Method | Bypass Rate |
|---|---|
| Compromised Accounts | 57.9% |
| Phishing Links (redirected) | 36.8% |
| Social Engineering Only | 21.2% |
| Image-Based Emails | Used to bypass NLP/AI detection |
📊 Summary & Recommendation
- ✅ Train employees to recognize AI-driven, highly personalized phishing attempts.
- ✅ Use advanced anti-phishing tools that don’t rely on signatures or static rules.
- ✅ Segment inbox access, especially for shared or delegated accounts.
- ✅ Prepare for phishing threats in HR, Finance, and Engineering—beyond just IT.
Source: KnowBe4 (2025). Phishing Threat Trends Report. www.knowbe4.com
Stay alert. Stay informed. Train your people—because AI is training the attackers.
Comments
Post a Comment