Phishing clicks nearly tripled in 2024 as criminals aim for smarter attacks

Fraude en ligne phishing
Image Credit: Shutterstock (Image credit: wk1003mike / Shutterstock)

  • The number of people clicking on links in phishing attacks increased three times in a year
  • Netskope's new report argues this is because threat actors have evolved their tactics
  • Cloud apps remain the number one target

The number of workers clicking on phishing links saw a major increase in 2024, putting businesses of all sizes at risk of compromise, new research has claimed.

A report from Netskope based on anonymized usage data collected by its Netskope One platform, found during the year, for every 1,000 workers, there were 8.4 who clicked on a link in a phishing email.

This represents a threefold increase from the year before, when just 2.9 people did the same.

Netskope says the significant increase in successful phishing attempts was particularly down to two things: people suffering from cognitive fatigue (there are simply too many phishing attacks and people eventually drop their guard), and threat actors being super creative and adaptable, thus creating harder-to-detect campaigns.

This being said, threat actors were most interested in access to cloud apps. These took up more than a quarter of all the clicks, with Microsoft’s Live and 365 credentials being of particular interest.

Pages targeting Yahoo and AOL were also quite widespread, while those for Adobe and DocuSign were used as stepping stones towards other credentials.

“Microsoft’s popularity as a phishing target is unsurprising because Microsoft 365 is the most popular productivity suite by a large margin,” the report stated.

Phishing awareness training will also need to be revamped this year, Netskope suggested, since it was too focused on email, and not enough on other channels.

Email was not the number one attack vector distributing these phishing links. Netskope thinks this is mostly because people have learned to pay attention to incoming emails, forcing threat actors to get creative. “They know their victims may be wary of inbound emails (where they are repeatedly taught not to click on links) but will much more freely click on links in search engine results,” the report says.

So, instead of through emails, users were tricked on search engines (through SEO poisoning), as well as shopping, technology, and entertainment sites running referrals in comments, malicious ads, and infected sites.

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Everything you need to know about phishing
Phishing
Corporate executives are being increasingly targeted by AI phishing scams
Hacker Typing
This devious two-step phishing campaign uses Microsoft tools to bypass email security
mobile phone
Forget phishing, now "mishing" is the new security threat to worry about
Russian flag on a laptop
Hackers are using Russian domains to launch complex document-based phishing attacks
Fraude en ligne phishing
What is phishing and how dangerous is it?
Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
MacBook Air mute key
The new M4 MacBook Air finally fixes an Apple keyboard annoyance that's been around for decades
A collage of Ellie and Joel in The Last of Us season 2
The Last of Us season 2's new trailer teases a huge showdown between Bella Ramsey's Ellie and Pedro Pascal's Joel, but the big moment I'm waiting for is still being held back
Apple iPhone 16 Pro Max REVIEW
New iPhone 17 Air leak may have revealed some key specs – and how it compares to the iPhone 17 Pro Max
Gaming with AI
I asked Gemini to play a text-based adventure game with me and the AI whisked me away to a word-based fantasy
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price