Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Sunday, 21 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

New KnowBe4 Report Reveals a Spike in Phishing Campaigns

KnowBe4’s fifth edition of the Phishing Threat Trends Report explores key phishing threats for 2025

by The Gurus
March 20, 2025
in News
Share on FacebookShare on Twitter

KnowBe4, Security Awareness Training leader, today launched its Phishing Threat Trend Report, detailing key trends, new data, and threat intelligence insights surrounding phishing threats targeting organisations at the start of 2025.

Based on data generated by KnowBe4 Defend, this edition highlights the growing threat of ransomware and explores how cybercriminals are using sophisticated tactics to bypass native security and secure email gateways (SEGs). It also examines how AI is being leveraged to create polymorphic phishing campaigns, how attackers are infiltrating the hiring process to access systems and data, and the increasing success of attacks evading traditional defences.

Key Findings From the Report:

  • Between September 15, 2024 and February 14, 2025 there was a 17.3% increase in phishing emails compared to the previous six months.
  • 82.6% of all phishing emails analysed exhibited some use of AI.
  • The report observes a 22.6% increase in ransomware payloads.
  • The phishing hyperlink, malware, and social engineering payloads getting through traditional detection have surged, with phishing hyperlinks increasing by 36.8%, malware by 20%, and social engineering tactics by 14.2% compared to the previous six months.
  • Additionally, there has been a 57.9% increase in attacks being sent from compromised accounts getting through traditional detection.
  • The top five legitimate platforms used to send phishing emails include DocuSign, Paypal, Microsoft, Google Drive, and Salesforce.
  • Currently the most impersonated brands include Microsoft, Docusign, Adobe, Paypal, and LinkedIn.

The report examines the unprecedented scale of polymorphic phishing tactics, now present in 76.4% of all phishing campaigns, which use AI-generated variations to bypass traditional security measures. Meanwhile, ransomware payloads in phishing attacks have risen by 22.6% over six months, with a sharp 57.5% increase in just three months—exemplified by a sophisticated INC Ransom payload detected by KnowBe4 Defend. The research also highlights how cybercriminals are increasingly targeting the hiring process, with 64% of attacks focused on engineering roles, exploiting their access to critical systems and data.

“As ever, innovation in phishing threats and defences is accelerating rapidly,” said Jack Chapman, SVP of threat intelligence at KnowBe4. “In this report, we have observed cybercriminals evolving their tactics, leveraging ransomware and polymorphic campaigns with new strategies to evade detection by both traditional and advanced technologies. As we move through 2025, both phishing threats and defences will continue to evolve, emphasising a holistic approach that integrates technical defences with human risk management. A strong security culture starts with detection but is reinforced by awareness, continuous education, and adaptive technology.”

The Phishing Threat Trends Report, Vol 5 is available for download here.

This follows a report from KnowBe4 revealing how underprepared the education sector is for escalating cyberattacks.

Tags: cybersecurityPhishingsecurityTechnology
ShareTweet
Previous Post

Nominations Open for 2025 European Cybersecurity Blogger Awards

Next Post

One-third of CNI organisations admit to paying ransomware according to new report from Bridewell

Recent News

AI Needs Human Expertise: How Securonix and Acora Are Transforming Security Operations

AI Needs Human Expertise: How Securonix and Acora Are Transforming Security Operations

June 19, 2026
75% of Organisations Have Gaps in Core Security Controls, Research Finds

More than 60% of Organisations Report Cyberattacks Spreading Beyond Email Into Teams, Slack and SMS, Finds New Research From KnowBe4

June 19, 2026
Frontline Workers Twice as Likely to Use Unapproved AI

VerifyLabs.AI Brings Deepfake Detection to Android After a recent IOS release

June 19, 2026
Proton removes the last barrier to leaving Google Workspace

Proton removes the last barrier to leaving Google Workspace

June 17, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol