A new report from SlashNext showed a sharp increase in phishing attacks during the second half of 2024.

According to the “2024 Phishing Intelligence Report”, there was a 202% increase in total phishing emails and a 703% increase in credential phishing attacks.
Key findings from the study reveal that users face an average of one advanced phishing attack every week. Mobile are also targeted by hackers, facing up to 600 threats per year. This shows that phishing is not only done through the traditional email method, but in a variety of ways.
The analysis shows that phishing is expanding to platforms such as SMS, LinkedIn and Microsoft Teams. Mobile threats, such as smishing and malicious links in messaging apps, remain a significant concern.
See also: Hackers exploit Google Calendar for phishing attacks
Popular phishing tactics
The researchers analyzed phishing tactics into three main categories:
- Link-based threats
- Text-based threats
- File-based threats
Link-based phishing remains the most prevalent, with 80% of malicious links categorized as zero-day threats, i.e. URLs created shortly before they are used. These bypass conventional signature-based defenses. Organizations are urged to develop real-time threat analysis tools.
See also: Phishing scammers forge Ledger emails for fake breach notification
Phishing and new threats
As attackers increasingly use artificial intelligence to create sophisticated phishing campaigns, organizations must rethink their security frameworks. Additionally, SlashNext predicts an increase in threats to messaging platforms. This evolution requires a comprehensive, automated approach to threat detection and mitigation.

Phishing Protection
“A critical addition to these strategies should be the adoption of passwordless authentication,” commented Keeper Security CEO Darren Guccione.
«These technologies complement existing security measures by reducing reliance on traditional passwords, which remain a prime target for phishing and other credential-based attacks. Passkeys add a layer of security through biometric or device-based authorization, making it more difficult for attackers to exploit stolen credentials.».
See also: Securonix discovered new phishing campaign, known as “FLUX#CONSOLE
Also, users and organizations should take measures, such as:
- Use of email spam filters
- Protecting devices with antivirus
- Regular software updates
- Using a unique password for each of your online accounts (if a passkey is not used)
- Multi-factor authentication application
- Backup
- Informing staff about new threats and training with test phishing attacks
- Monitoring and protecting endpoints
- Restricting access to important systems
- Network segmentation
Source: www.infosecurity-magazine.com
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
