Most phishing emails (malspam) sent in the first half of the year contained links to malicious files, rather than file attachments, according to statistics from Proofpoint.
More specifically, 85% of all malspam sent in Q2 2019 (April, May, and June) contained a link to a malicious file download instead of a malicious file attached to the email message.

Q2 continues the trend seen in Q1, where malicious URLs also dominated as the favorite way to distribute malware via spam email.
If the majority of malspam content sent these days exploits malicious links, this means that hackers are getting higher clicks compared to the classic technique of attaching files to emails.
"While the reason for the continued dominance of URLs may be due to a number of factors, the most important one is that users are more suspicious of file attachments," Proofpoint said.

URLs, on the other hand, are increasingly common in business emails as we regularly receive notifications about shared files and collaboration updates via email as organizations move to the cloud.
Proofpoint's findings should have implications for the entire cybersecurity market. Companies that provide anti-phishing training should follow the hackers' tactics.

Employee training is important
A previous Proofpoint study found that 99% of all phishing emails require human interaction, such as opening files, clicking links, or taking any other careless action. With a little training, employees can recognize and avoid phishing attacks.
