Phishing attacks surge in 2024 as cybercriminals adopt AI tools and multi-channel tactics

Phishing
(Image credit: Vektor Illustration/Shutterstock)
  • Phishing attacks are becoming more complex and harder to detect
  • Attackers are using new techniques such as QR codes and deepfakes
  • Some businesses are receiving 36 phishing emails per day

Phishing attacks are consistently on the rise and becoming more sophisticated, as cybercriminals no longer rely solely on basic email schemes, instead incorporating new tactics such as QR code phishing (quishing), AI-powered attacks, and multi-channel phishing to enhance their effectiveness.

A new Egress report has revealed phishing attacks spiked in the second quarter of 2024, with a 28% rise in the number of phishing emails compared to the first quarter.

Phishing attacks are also becoming more sophisticated. Cybercriminals now use a variety of new tactics to bypass secure email gateways (SEGs) and native defenses like Microsoft 365’s security features. In Q2 2024 alone, there was a 52.2% increase in phishing attacks that successfully bypassed SEG detection.

Commodity attacks - a mass-produced threat

One type of phishing that has seen a notable increase in 2024 is commodity attacks. These are mass-produced, malicious campaigns that impersonate well-known brands on a large scale to trick users into clicking on fake promotions, images, or hyperlinks.

The report reveals that during these attacks, organizations experience a staggering 2,700% increase in phishing attempts, with organizations over the 2,000 employee mark would have to deal with over 1,128 phishing emails over 31 days, which is about 36 phishing emails per day. The sheer volume of these attacks can overwhelm many companies' security systems, making it increasingly difficult to prevent every malicious email from reaching an employee's inbox.

One of the methods used to bypass SEG is HTML smuggling, where attackers hide malicious scripts inside HTML attachments. Once opened by the user, the script assembles itself on the victim’s device, bypassing traditional signature-based detection. Another tactic involves embedding phishing links within seemingly legitimate documents or exploiting vulnerabilities in trusted websites to host malware.

Businesses must now implement advanced security measures and foster a culture of awareness to better protect themselves against the growing threat of phishing.

Phishing attacks are increasingly using AI-powered tools to scale their operations. AI allows cybercriminals to automate and personalize phishing campaigns, making them more convincing and harder to detect. Deepfakes and AI-generated chatbots are now major tools of choice for cybercriminals.

These technologies allow attackers to impersonate trusted individuals or organizations, further increasing the likelihood of success. This year, there has been a significant rise in "payloadless" attacks which rely solely on social engineering rather than traditional malicious attachments or links, accounting for nearly 19% of phishing attempts in 2024, up from 5.4% in 2021.

Cybercriminals are also using multi-channel phishing tactics, allowing hackers to target victims across multiple platforms such as email, SMS, and even collaboration platforms like Microsoft Teams. This multi-channel approach has become more common in 2024, exploiting the relative lack of security on non-email platforms.

You might also like

Efosa Udinmwen
Freelance Journalist

Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master's and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity. Upon joining TechRadar Pro, in addition to privacy and technology policy, he is also focused on B2B security products. Efosa can be contacted at this email: udinmwenefosa@gmail.com

Read more
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Everything you need to know about phishing
Phishing
Corporate executives are being increasingly targeted by AI phishing scams
Fraude en ligne phishing
Phishing clicks nearly tripled in 2024 as criminals aim for smarter attacks
mobile phone
Forget phishing, now "mishing" is the new security threat to worry about
Hacker Typing
This devious two-step phishing campaign uses Microsoft tools to bypass email security
Fraud
Hackers are tricking victims into scam-yourself attacks with fake tutorials, CAPTCHAs, and updates
Latest in Security
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
A hacker wearing a hoodie sitting at a computer, his face hidden.
Experts warn this critical PHP vulnerability could be set to become a global problem
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
botnet
Another top security camera maker is seeing devices hijacked into botnet
Bluetooth
Top Bluetooth chip security flaw could put a billion devices at risk worldwide
Latest in News
Apple's Craig Federighi demonstrates the iPhone Mirroring feature of macOS Sequoia at the Worldwide Developers Conference (WWDC) 2024.
Report: iOS 19 and macOS 16 could mark their biggest design overhaul in years – and we have one request
Google Gemini Calendar
Gemini is coming to Google Calendar, here’s how it will work and how to try it now
Lego Mario Kart – Mario & Standard Kart set on a shelf.
Lego just celebrated Mario Day in the best way possible, with an incredible Mario Kart set that's up for preorder now
TCL QM7K TV on orange background
TCL’s big, bright new mid-range mini-LED TVs have built-in Bang & Olufsen sound
Apple iPhone 16e
Which affordable phone wins the mid-range race: the iPhone 16e, Nothing 3a, or Samsung Galaxy A56? Our latest podcast tells all
An image of a Jackbox Games Party Pack
Jackbox games is coming to smart TVs in mid-2025, and I can’t wait to be reunited with one of my favorite party video games