Researchers from Google, Samsung, PayPal, and Arizona State University spent a year examining and analyzing the threat landscape associated with phishing attacks, as well as how users interact with phishing pages. By analyzing 22,553,707 user visits to 404,628 phishing pages, the researchers gathered a wealth of information about how phishing campaigns operate.
Specifically, from their findings, the researchers found that a phishing attack lasts, on average, 21 hours, from the first to the last victim visiting a page, while the detection of each phishing attack by entities occurs on average 9 hours after the first victim visits. The researchers will present their findings in more detail at the USENIX to be held August 12-14.

After detection, there were another 7 hours before maximum mitigation by browser-based warnings. The researchers characterize the period between the start of the campaign and the deployment of phishing warnings in browsers as the “golden hours” of a phishing attack – during which attackers attract the most victims. However, once the “golden hours” are over, the attacks continue to increase their victim count, even after the browser is warned through systems such as API . Worryingly, 37.73% of the total victim traffic in the researchers’ dataset occurred after the attack was detected.

Additionally, the researchers analyzed user interactions with phishing pages and reported that 7.42% of victims entered credentials into phishing forms and eventually experienced a breach or noticed a “fraudulent” transaction being made to their account. On average, fraudsters attempted to compromise user accounts and make “fraudulent” transactions 5.19 days after the user visited the phishing site, while credentials ended up in public dumps or on criminal portals 6.92 days after the user visited the phishing page.
The findings align with what Sherrod DeGrippo, Sr. Director, Threat Research and Detection at Proofpoint, told ZDNet. Specifically, DeGrippo said that Proofpoint detects about 12 million phishing attacks each month, and the best cybercriminals focus on evasion tactics to avoid detection, knowing that this will allow them to keep their campaigns “active” for longer and extend the “golden hours.”

The Arizona State University research team said that the success of these attacks is largely due to their slow detection by defense mechanisms. In addition, the researchers added that the lack of cooperation between industry partners is another factor contributing to the success of the attacks. For this reason, they urge the various entities to cooperate more in defending and dealing with phishing attacks. They also emphasized that cooperation makes all entities stronger against phishing and other types of attacks. According to Proofpoint, domain, encryption certificate providers and hosting companies, among others, must assist in this effort. Finally, the researchers emphasized that stopping phishing attacks is vital to protecting organizations worldwide, while it is equally important to properly and promptly inform employees so that they are suspicious of such attacks.
The full academic research is titled “Sunrise to Sunset: Analysis of the End-to-end Life Cycle and Effectiveness of Phishing Attacks at Scale”.
