🚨 2025 Phishing Threat Trends Report: AI, Ransomware & Hiring Exploit by Knowbe4
🚨 2025 Phishing Threat Trends Report: AI, Ransomware & Hiring Exploits
By Admin | Sourced from KnowBe4 Threat Intelligence – March 2025

📈 17.3% rise in phishing emails in just six months
🔐 57.9% of phishing attacks used compromised accounts
🤖 82.6% of phishing emails were powered by AI
🔐 57.9% of phishing attacks used compromised accounts
🤖 82.6% of phishing emails were powered by AI
1. AI-Powered Polymorphic Phishing
Attackers now use AI to create near-unique phishing messages that evade filters. These emails alter sender names, metadata, subjects, and logos to trick both systems and humans.
Month (2024) | % Emails with Polymorphic Features |
---|---|
March | 42.2% |
July | 56.8% |
October | 65.5% |
December | 74.3% |
2. Ransomware Surge via Obfuscated Payloads
Ransomware-as-a-service and HTML smuggling lead to more encrypted payloads slipping past detection.
Obfuscation Method | Impact |
---|---|
HTML Smuggling | 85.6% ↑ (Q4 2024 – Q1 2025) |
Password-Protected ZIPs | Bypass traditional scanning |
AI-generated filler text | Breaks signature detection |
Base64 URL Encoding | Hides links from blocklists |
3. Phishing via Job Applications
Cybercriminals target HR and IT workflows with fake CVs and job offers. Shared inboxes are especially at risk.
Target Role | % of Phishing Attempts | Common Entry Point |
---|---|---|
Engineering | 64% | Shared mailboxes (33.4%) |
Finance | 12% | Shared inboxes |
HR | 10% | Delegate accounts |
IT | 10% | User accounts (spear phishing) |
4. What’s Getting Past Email Security?
Attackers now bypass Microsoft and SEGs with increasing success using trusted platforms and creative obfuscation.
Payload Method | Bypass Rate |
---|---|
Compromised Accounts | 57.9% |
Phishing Links (redirected) | 36.8% |
Social Engineering Only | 21.2% |
Image-Based Emails | Used to bypass NLP/AI detection |
📊 Summary & Recommendation
- ✅ Train employees to recognize AI-driven, highly personalized phishing attempts.
- ✅ Use advanced anti-phishing tools that don’t rely on signatures or static rules.
- ✅ Segment inbox access, especially for shared or delegated accounts.
- ✅ Prepare for phishing threats in HR, Finance, and Engineering—beyond just IT.
Source: KnowBe4 (2025). Phishing Threat Trends Report. www.knowbe4.com
Stay alert. Stay informed. Train your people—because AI is training the attackers.
Comments
Post a Comment