HomeSecurityPhishing or malware: What is the biggest threat to corporate users?

Phishing or malware: Which is the bigger threat to corporate users?

Phishing attacks have increased 400% year-over-year , highlighting the need for immediate visibility into identity exposures . SpyCloud , a leader in identity threat protection, has released new data showing a sharp increase in phishing attacks that disproportionately target corporate users .

Phishing malware

The company observed a 400% year-over-year increase in successfully phished identities, with nearly 40% of the more than 28 million recovered phished records containing a business email address – compared to just 11.5% in recovered malware data. The result is a warning to businesses that their workforce is three times more likely to be targeted by phishing attacks than by infostealer malware.

These findings reinforce a growing shift in cybercriminal strategy: phishing is now the preferred gateway into corporate environments, and SpyCloud sees this trend continuing in 2026. Threat actors are using this access as a springboard for subsequent attacks, with SpyCloud reporting in its 2025 Identity Threat Report that phishing is now the primary entry point for ransomware (representing 35% of all ransomware infections).

See also: Intellexa: Predator network survives despite sanctions – New evidence

“Phishing is now one of the most scalable tools cybercriminals use to compromise corporate environments,” said Trevor Hilligoss, Head of Security Research at SpyCloud. “Cybercrime enablers, such as phishing-as-a-service kits and adversary-in-the-middle tacticsthat capture MFA tokens and session cookies, put advanced tactics in the hands of less skilled actors, making it easier than ever to compromise users on a large scale. SpyCloud’s visibility into these campaigns gives organizations a critical advantage, helping them detect who has been targeted and what data has been exposed, and restore those credentials before they can be weaponized.”

Phishing or malware: Which is the bigger threat to corporate users?

SpyCloud is the only provider that successfully recovers and automatically restores phished identity data and target lists at scale, before subsequent attacks such as ransomware, fraud, and account takeover occur.

“Many organizations rely on traditional defenses like email filtering, endpoint protection, and employee training to stop phishing and malware attempts, but these tools have limited effectiveness,” said Damon Fleury, Chief Product Officer at SpyCloud. “Attackers still get into systems – and when they do, it’s the exposed identity data that allows for further damage. Security teams need to be vigilant about what has already been compromised. Prevention is important, but without immediate visibility and remediation after a breach, it’s not enough.”

See also: “Sryxen” malware manages to bypass Chrome encryption

Phishing and malware: Two major threats

While phishing has become a dominant entry point, malware remains a critical threat actor. In the era of remote work and “bring your own device” policies, personal exposures are increasingly being used to compromise corporate environments. A recent example is the breach Nikkei, where malware on a personal device led to the compromise of sensitive corporate data.

Phishing or malware: Which is the bigger threat to corporate users?

Despite the fact that only 11.5% of recovered malware infections directly extract business email addresses, SpyCloud data shows that nearly 1 in 2 corporate users have been infected with infostealer, either on a managed or unmanaged device – a strong indicator that threat actors are moving from personal to corporate accounts.

See also: SEEDSNATCHER: Android malware steals data and crypto wallets

“Protecting the enterprise means looking beyond corporate accounts,” Fleury added. “With the constant reuse of passwords and shared credentials across work and personal accounts like mobile phone numbers, the line between a user’s personal digital history and their work access is essentially blurred. That’s why it’s essential to monitor and remediate exposures across the entire spectrum of an individual’s digital identity – personal and work.”

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS