Site navigation

Report: Phishing Clicks Surged 190% in 2024

Tom Quinn

,

phishing
 “The common thread for organisations working to safely enable the use of apps in the enterprise, and mitigate the challenges across the threat landscape, is the need for modern data security,” said Ray Canzanese, Netskope Threat Labs.

Phishing clicks nearly tripled in 2024, according to new research from cybersecurity firm Netskope.

More than eight out of every 1,000 users clicked on a phishing link each month last year – up 190% from 2023 when fewer than three per thousand users fell prey to phishing attempts.

The findings, published as part of Netskope’s annual Cloud & Threat Report, reveal growing security risks related to the use of personal cloud apps, with popular services such as GitHub, Microsoft OneDrive, and Google Drive being targeted.

Cloud applications accounted for more than a quarter of all phishing clicks last year (27%), with Microsoft by far the most targeted brand at 42%, as attackers increasingly target Microsoft Live and Microsoft 365 credentials, followed by Adobe (18%), and DocuSign (15%).

In 2024, Netskope found that downloads of malicious content from cloud apps occurred in 88% of organisations at least once per month. 

Last year, 88% of all employees used personal cloud apps each month, with more than one out of every four users (26%) uploading, posting, or otherwise sending data to personal apps, leading to loss of organisational control over data and potential breaches.

Among the top personal apps that users send data to are cloud storage, webmail, genAI, social media, and personal calendar apps.

Sensitive data being leaked through personal apps is top of mind for most enterprises, with the most common type of data policy violation being for regulated data (60%), including personal, financial, or healthcare data uploaded to personal apps. 

The other types of data involved in policy violations include intellectual property (16%), source code (13%), passwords and keys (11%), and encrypted data (1%).

Netskope’s report also shows where victims are now most likely to encounter phishing links. Interestingly, the top source of clicks last year came from search engines (19%), where attackers run malicious ads or use SEO poisoning techniques to get phishing pages listed among the top results.

Other referrers include shopping (10%), technology (8.8%), business (7.4%), and entertainment (5.7%) websites, with the researchers noting that the results highlight a shift away from the use of email links by threat actors.


Recommended reading


According to the researchers, this could be because victims are more aware of the risks associated with inbound emails, but are much more likely to freely click on search engine results, leading to more creative social engineering by attackers.

“The common thread for organisations working to safely enable the use of apps in the enterprise, and mitigate the challenges across the threat landscape, is the need for modern data security,” said Ray Canzanese, director of Netskope Threat Labs.

“Gone are the days when data security was an afterthought. It must be seamlessly integrated into every aspect of an organisation’s operations.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data