Site navigation

Report: Phishing Beats Ransomware as Top Security Concern in 2025

Tom Quinn

,

phishing 2025
New research shows phishing has become the top attack vector this year, and has become the primary launchpad for major breaches.

Phishing has overtaken all other vectors as the leading cause of ransomware attacks, according to new research from SpyCloud, fuelled by the growing sophistication of phishing-as-a-service and the use of adversary-in-the-middle techniques to bypass MFA and hijack active sessions. 

The cyber firm’s latest Identity Threat Report found a 10% year-on-year spike in phishing attacks, now impacting 35% of organisations, with 75% of firms worried that phishing incidents will trigger more damaging cyber-attacks.

Overall, 40% of the more than 500 security leaders polled by SpyCloud said they were extremely concerned about the impact of phishing attacks, more even than ransomware (37%), nation-state threat actors (36%), or the use of unmanaged and unauthorised devices (36%).

These worries are being exacerbated by cybercriminals’ use of AI to enhance their phishing capabilities, an anxiety shared by 92% of security leaders.

The report notes that genAI tools are being used to scale precision attacks, for example, by crafting highly personalised lures in seconds and generating high-quality phishing pages with minimal effort.

Such techniques allowed the notorious phishing-as-a-service operation Darcula to claim hundreds of thousands of victims, with SpyCloud highlighting that less technically able criminals were able to use it to impersonate brands with considerable ease.

Other phishing-as-a-service (PhaaS) platforms such as Tycoon 2FA and FlowerStorm have become adept at using adversary-in-the-middle (AitM) techniques to steal MFA tokens and session cookies, targeting highly used platforms like Microsoft 365 and Gmail accounts.  

According to the report, the widespread availability of phishing tools and services has resulted in 85% of organisations experiencing at least one ransomware attack in the past year, with 31% facing up to ten incidents.

Meanwhile, infostealer malware continues to slip past traditional EDR and antivirus defences, with SpyCloud finding that nearly half of all corporate users have had their credentials compromised, opening the door to further downstream attacks.

SpyCloud has found that nearly 1 in 2 corporate users were victims of an infostealer infection on either a personal or corporate device at some point in their digital history, with 66% of malware infections occurring on devices that had antivirus or EDR tools installed.


Recommended reading


However, though two-thirds of organisations saying they are extremely concerned about the impact of identity-based attacks, the study found that just 41% routinely revoke or reset compromised access, while fewer than 20% have automated identity threat response.

Despite growing awareness of ransomware and other infostealer-driven threats, many still struggle to respond effectively. The study found that just 35% of firms have workflows in place to remediate identity exposures, and only a third (33%) have protocols in place for investigating identity-related incidents.

“Phishing can no longer be seen as just a nuisance; it’s a primary launching point for ransomware and other identity-based attacks,” said Trevor Hilligoss, SpyCloud’s head of security research.

“Attackers are using phishing kits to steal session cookies, bypass MFA, and impersonate users with alarming accuracy. What’s especially concerning is how quickly these tools evolve.

“Adversaries are refining distribution, evasion, and targeting faster than most defenders can respond. The growth of commoditised tactics like PhaaS has made these capabilities available to even low-skill threat actors, which is why we’re seeing such a sharp spike in ransomware incidents tied directly to phishing. 

“Organisations need real-time insight into the identity data these actors are harvesting – and they need the ability to act on it.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data