Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

3 January 2026

What happens to data stolen from phishing

Source: Kaspersky. An example of an administration panel through which stolen data is managed. Screen shot.
Source: Kaspersky. An example of an administration panel through which stolen data is managed.

Over 117 M phishing links were clicked in the Asia Pacific region from November 2024 to October 2025.

According to Kaspersky's research, 88.5% of phishing attacks targeted online account credentials, while 9.5% were focused on personal data such as names, addresses, and dates of birth. Just 2% were aimed at bank card information. 

Once captured, these personal details are funnelled through specialised automated systems which help to manage large amounts of data. These systems are offered as a platform-as-a-service (PaaS) and are either created by the attackers themselves or based on legitimate frameworks for creating websites or apps. 

Kaspersky Digital Footprint Intelligence stated that attackers consolidate stolen data into "dumps" – large batches of verified information – often priced on dark web forums at US$50 or less for bulk sales. Higher-value accounts fetch premium prices: cryptocurrency platforms average US$105, banking accounts – US$350, e-government portals – US$82.50, and personal documents – US$15.  

Data is meticulously verified using scripts to check its validity across services and is then combined into comprehensive "digital dossiers" that enhance its worth for targeted attacks, such as whaling schemes against high-profile individuals. 

"Stolen data evolves into a persistent weapon for cybercriminals. By leveraging open-source intelligence and old breach data, attackers can craft highly personalised scams, turning one-time victims into long-term targets for identity theft, blackmail, or financial fraud," said Olga Altukhova, Security Expert at Kaspersky.

To mitigate these risks, Kaspersky recommends users: 

  • Block compromised bank cards by contacting your financial institution
  • Change passwords across accounts that are suspected of compromise using unique combinations and enable multifactor authentication (MFA) wherever possible
  • Review active sessions in messaging apps, online banking, and other services
  • Utilise trusted security solutions to protect your devices and monitor for data leaks

23 May 2024

Your next phishing email could be about taxes, healthcare or ApplePay: KnowBe4

Source: KnowBe4 Top-Clicked Phishing Tests infographic. List of Q124 'in the wild' attacks.
Source: KnowBe4 Top-Clicked Phishing Tests infographic. Q124 'in the wild' attacks.

KnowBe4, the provider of the security awareness training and simulated phishing platform, has found that HR or IT-related business email messages are the most common email subjects clicked on in phishing tests.

Phishing emails continue to be one of the most common methods for executing cyberattacks on organisations worldwide, the company said. KnowBe4’s 2023 Phishing by Industry Benchmarking Report, published in Q124, reveals that nearly one third of users are susceptible to clicking on malicious links or complying with fraudulent requests. 

Cybercriminals are further leveraging tools now available to them, such as AI, to come up with increasingly sophisticated messages to outsmart users, KnowBe4 said. Phishing emails can now be tailored to appear even more legitimate, or trick employees by inciting an emotional response and urgency to click on a malicious link or download an infected attachment.

HR-related phishing attacks take the top spot at 42%, a trend that has persisted for the last three quarters, followed by IT-related phishing emails at 30%. Phishing emails from HR or IT departments that prompt dress code changes, tax and healthcare updates, training notifications and other similar actions are effective in deceiving employees as they can affect a user’s work, evoke an immediate response and can cause a person to react before thinking about the validity of the email.

The KnowBe4 phishing report this quarter also noted more personal phishing email attacks, using pretexts such as tax, healthcare and ApplePay, that could affect users' sensitive information. These types of attacks are effective because they cause a person to react to a potentially alarming topic and engage to protect their private information before thinking logically about the credibility of the email.

“KnowBe4’s report shows that cybercriminals are becoming increasingly tactical in exploiting employee trust by using HR-related phishing emails due to their seemingly legitimate source,” said Stu Sjouwerman, CEO of KnowBe4.

“Emails coming from an internal department such as HR or IT are especially harmful to organisations since they appear to be coming from a trusted source and can convince employees to engage quickly before confirming their legitimacy, exposing the company to security vulnerabilities. 

"A well-trained workforce is therefore crucial in building a strong security culture and serves as the best defence in safeguarding organisations against preventable cyberattacks.”

Explore

Download the Q124 KnowBe4 Phishing Report Top-Clicked Phishing Tests infographic at https://www.knowbe4.com/hubfs/Quarterly-Phishing/Q12024.pdf (PDF), and 

Get the 2023 Phishing by Industry Benchmarking Report at https://info.knowbe4.com/en-us/phishing-by-industry-benchmarking-report.

8 April 2021

Cybercriminals find phishing easier than ever

Consumers beware. Group-IB, a global threat hunting and adversary-centric cyberintelligence company, has found that it is increasingly easy for cybercriminals to obtain user data stolen through phishing, or fake websites which look like genuine ones requesting consumer data.

Source: Group-IB. Chart showing the brands most frequently targeted in phishing kits: online services, followed by email clients and then financial organisations.
Source: Group-IB. Types of brands most frequently targeted in phishing kits.

Legitimate services such as Google Forms and Telegram bots are helping help cybercriminals keep data safe and enable them to start using the information immediately. Ready-to-go platforms that automate phishing are distributed under the cybercrime-as-a-service model, which allows more groups to conduct attacks, and widen the scope of cybercriminal activity, Group-IB said. 

According to Group-IB, phishing kits give cybercriminals who do not have strong coding skills a way to effortlessly build infrastructure for large-scale phishing campaigns and quickly resume an operation if it’s blocked.

Group-IB’s Computer Emergency Response Team (CERT-GIB) analysed the tools used to create phishing web pages (phishing kits) and discovered that in the past year, they were most often used to generate web pages mimicking online services (online tools to view documents, online shopping, streaming services, etc.), email clients, and — traditionally — financial organisations. Last year, Group-IB identified phishing kits targeting over 260 unique brands.

In 2020, as in the previous year, the main target for cybercriminals were online services (30.7%). By stealing user account credentials, hackers gain access to the data of linked bank cards. Email services became less appealing last year, with the share of phishing kits targeting them dropping to 22.8%. 

Financial institutions turned out to be the third favourite among scammers, with their share totalling above 20%. In 2020, the brands most often exploited in phishing kits were Microsoft, PayPal, Google, and Yahoo.

The analysts further found that phishing kits can do more than generating fake web pages to steal user data. Some upload malicious files to the victim's device. Sellers of phishing kits can deceive their buyers. Apart from selling the malicious tool they created, they may also direct stolen user data to themselves.

“Phishing kits have changed the rules of the game in this segment of the fight against cybercrime. In the past, cybercriminals stopped their campaigns after the fraudulent resources had been blocked and quickly switched to other brands. Today, they automate their attacks and instantly replace the blocked phishing websites with new web pages,” commented CERT-GIB Deputy Head Yaroslav Kargalev.

“In turn, automating such attacks leads to the spread of more complex social engineering used in large-scale attacks rather than separate incidents, as used to be the case. This keeps one of the oldest cybercriminal professions afloat.”

5 May 2014

HSBC Hong Kong warns customers against phishing emails

The Hongkong and Shanghai Banking Corporation (HSBC) has alerted its Hong Kong customers that it has no connection to phishing e-mails which link to fraudulent HSBC websites. The websites feature links such as http://mercipapa.com.br/files/.files/HK/ and http://www.birth.hk/bb3/ol.php.
 

Source: HSBC. Sample phishing email.

"HSBC would like to remind its customers that the Bank's internet banking site does not carry a web page such as the one hyperlinked in the fraudulent e-mails, and has not sent these e-mails to its customers," the bank said in a statement on its website. "The bank has no connection with the fraudulent sites involved."
 
Source: HSBC. Another sample phishing email.

HSBC asked customers to type in the website address directly into the address bar of their browsers, and asked customers who suspect that they have been duped to call the HSBC customer service hotline at +852 2748 8288 for business
Internet banking users or +852 2233 3000 for personal Internet banking customers.