A new survey has found that 91% of UK organisations were hit by bulk phishing email attacks in 2021.
The new State of the Phish report from Proofpoint explored the vulnerability of businesses to modern cyber threats. It surveyed 600 participants in IT and security roles across seven countries, including the UK.
The group identified around 5,500 phishing campaigns deploying commonly used tactics, along with about 15 million messages that aimed to deploy malware onto victims’ systems that took place last year.
Compared to 2020, 2021 saw the volume of email phishing attacks grow.
This breaks down to 86% of groups suffered bulk phishing attacks, up from 77% in 2020. Another 79% were hit by spear phishing attacks, compared to 66% in 2020 and 77% saw suffered from business email compromise (BEC) attacks, which generally involve attempts to redirect payroll or invoice fraud, compared to 65% in 2020.
In addition, hackers have not just been using email as a vector for cyberattacks. The use of smishing, social media attacks, vishing and USB-based attacks all increased in 2021 compared to 2020.
In total, 74% of organisations were hit by smishing, 74% by social media attacks, 69% by vishing and 64% with USB drops.
The study found that, out of all the countries surveyed, UK groups were most likely to be hit by multiple attacks – over 20% reported being hit by at least 50 smishing, social media, and vishing attacks. An additional 18% said they had been hit by more than 50 USB drop attacks.
Another issue that the report warned of was that more phishing attacks are succeeding. It found 83% of respondents said their organisation had been hit with a successful email phishing attack, growing from 57% in 2020.
In addition, 54% said they had dealt with more than three successful attacks, and 11% said they had been hit by ten or more successful attacks.
Recommended
- CAN DO Innovation Summit | Reshaping our food landscape
- How cybercriminals exploit trust between organisations
- IoT security adoption will reach a “turning point” in 2022, research finds
Successful attacks can have serious consequences for an organisation. The most common repercussions found in the report were breaches of customer or client data (54%), credential or account compromise (48%) and ransomware infection (46%).
In total, 68% of organisations said they had been hit by ransomware in 2021, a small increase compared to 2020’s 66%.
The UK had the highest number of organisations that opted to pay ransoms to get back their back or access their systems – 82%. This is 41% more than the global average.
After paying a ransom, more than half or respondents were able to regain access to their data and systems after a payment, while 32% had to pay additional ransoms to get their data back. 4% never got access to their data, even after paying the ransom.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





