Report: Phishing Has Surged 400% Year-Over-Year
Researchers at SpyCloud have observed a 400% year-over-year increase in successful phishing attacks, with a disproportionate number of attacks targeting corporate accounts.
Researchers at SpyCloud have observed a 400% year-over-year increase in successful phishing attacks, with a disproportionate number of attacks targeting corporate accounts.
Threat actors are using the open-source phishing framework Evilginx to target universities across the United States, according to researchers at Infoblox. The attackers have targeted at least 18 universities and educational entities since April 2025, using phishing pages that spoofed student single sign-on (SSO) portals.
ReliaQuest warns that the cybercriminal collective โScattered Lapsus$ Huntersโ appears to be using social engineering attacks to target organizationsโ Zendesk instances.
Researchers at Palo Alto Networksโ Unit 42 are tracking two new malicious AI tools, WormGPT 4 and KawaiiGPT, that allow threat actors to craft phishing lures and generate ransomware code.
KnowBe4 is proud to announce that three of its leading security products โ Security Awareness Training, PhishER/PhishER Plus and Compliance Plus โ have been recognized as 2026 Buyer's Choice award winners by TrustRadius, a HG Insights company and buyer intelligence platform for business technology.
Since November 3, 2025, KnowBe4 Threat Labs has been monitoring a highly sophisticated, multi-stage phishing operation that is actively targeting organizations to steal employeesโ Microsoft 365 credentials. The campaign has been engineered to bypass traditional email security defenses, such as secure email gateways (SEGs),ย and multi-factor authentication (MFA) tools.
Following its launch in 2024, Gartnerยฎ has now published the second Magic Quadrantโข for Email Security โand KnowBe4 is delighted to once again be named a Leader!
Users should be particularly wary of holiday-themed scams over the next few weeks, according to researchers at Malwarebytes.
โMobile-first shopping has become second nature, and during the holidays, itโs faster and more frantic than ever,โ Malwarebytes says. โFifty-five percent of people get a scam text message weekly, while 27% are targeted daily.
Think about your digital spaces. Youโve got your corporate email, which we all treat a bit like a high-security bank vault. We approach it with caution, we're suspicious of unfamiliar senders, and weโre primed to spot a dodgy attachment. Then, you have WhatsApp. Thatโs the digital equivalent of your living room. Itโs comfy, familiar, and filled with people you (mostly) trust. Our guard is down.
The finance and banking sector across Europe, the Middle East, and Africa (EMEA) faces extraordinary cybersecurity challenges, according to KnowBe4โs Cyber Risk in Finance and Banking Across EMEA report. While digital transformation has revolutionized operations and customer engagement, it has also created vulnerabilities that threaten the stability of the entire financial system.
In recent weeks, the UK government has announced the introduction of its new Cyber Security and Resilience Bill.
Lead analysts: Louis Tiley, Lucy Gee and James Dyer
Between 1:48pm ET on October 29 and 6:53pm ET on October 30, 2025, KnowBe4 threat analysts observed a high volume of phishing emails detected by KnowBe4 Defend that were sent from the legitimate domain of one of the worldโs largest sportswear brands.