news.mlab.sh
Back to the feed
threat-intel

Phishing Attack Volume Down 20%, but Risk Still Rising

High
Summary

The volume of phishing attacks has decreased by 20% across multiple industries, despite a shift towards more sophisticated attacks utilizing AI. Threat actors are prioritizing targeted campaigns with higher conversion rates, moving away from mass-spray approaches. This shift is evidenced by a tripling of losses attributed to phishing attacks, alongside a decline in overall complaint volume, and a significant reliance on cloud hosting, particularly Amazon Web Services (AWS), for malicious infrastructure.

Phishing attacks are experiencing a notable shift in strategy, moving away from high-volume, low-conversion tactics. According to Zscaler research, the decline in phishing volume – a 20% drop in 2024 and another 20% in 2025 – isn't solely attributable to AI, but rather a deliberate move by threat actors towards more targeted and resource-intensive operations. This trend is driven by the desire for higher payouts, as exemplified by the shift in ransomware tactics from targeting individual users to focusing on larger businesses seeking multi-million dollar ransom payments. The FBI’s Internet Crime Report reflects this change, showing consistent complaint numbers alongside a dramatic increase in total losses, highlighting the effectiveness of this new approach.

The industry landscape is also seeing significant variations. Sectors like the services and government sectors experienced substantial increases in phishing attacks, while education saw a decline. Globally, countries like Canada, Spain, and Australia experienced significant drops in phishing activity, while the US saw a more modest reduction. Notably, phishers are increasingly leveraging cloud hosting services, with Amazon Web Services (AWS) emerging as a dominant platform, accounting for 76% of attacker IPs targeting Zscaler decoys. This shift is driven by factors like cost and the difficulty of blocking AWS infrastructure.

This trend underscores the evolving threat landscape and the need for organizations to adapt their security strategies. The reliance on cloud services presents new challenges for security teams, requiring a deeper understanding of how attackers are utilizing these platforms and implementing robust monitoring and detection capabilities.

Read the full article at Dark Reading