SpyCloud Data Shows Corporate Users 3x More Likely to Be Targeted by Phishing Than by Malware
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。用户已经提供了文章的详细内容,我需要先快速浏览一下,抓住主要信息。 首先,文章提到钓鱼攻击激增了400%,主要针对企业用户。然后,SpyCloud的数据指出,40%的钓鱼记录包含企业邮箱,而恶意软件只有11.5%。这说明钓鱼攻击比恶意软件更受网络犯罪分子青睐。 接下来,文章提到钓鱼攻击是勒索软件的主要入口,占35%。专家Trevor Hilligoss指出,钓鱼攻击成为犯罪分子进入企业环境的主要手段,并且他们利用犯罪服务套件来扩大攻击规模。 最后,Damon Fleury强调传统防御措施有限,需要实时监控和补救措施。同时,文章也提到恶意软件仍然是威胁,并举例说明个人设备被感染如何影响企业安全。 综合以上信息,我需要将这些要点浓缩到100字以内。确保涵盖钓鱼攻击的增长、对企业的影响、其作为勒索软件入口的重要性以及传统防御措施的不足。 </think> 钓鱼攻击激增400%,企业用户成主要目标。SpyCloud数据显示,40%的钓鱼记录涉及企业邮箱,远超恶意软件的11.5%。网络犯罪分子偏好通过钓鱼进入企业环境,其已成为勒索软件的主要入口(占35%)。专家指出,钓鱼攻击现为犯罪分子进入企业环境的主要手段,并借助自动化工具扩大规模。传统防御措施有限,需加强实时监控和补救以应对威胁。 2025-12-4 14:1:25 Author: securityboulevard.com(查看原文) 阅读量:3 收藏

Austin, TX, USA, December 4th, 2025, CyberNewsWire

Phishing has surged 400% year-over-year, highlighting need for real-time visibility into identity exposures.

SpyCloud, the leader in identity threat protection, today released new data showing a sharp rise in phishing attacks that disproportionately target corporate users. The company tracked a 400% year-over-year increase in successfully phished identities, with nearly 40% of the 28+ million recaptured phished records containing a business email address – compared to just 11.5% in recaptured malware data. The result is a warning to enterprises that their workforce is three times more likely to be targeted with phishing attacks than infostealer malware. 

The findings reinforce a growing shift in cybercriminals’ strategy: phishing is now the preferred gateway into enterprise environments, and SpyCloud sees this trend continuing in 2026. Threat actors are using this access as a launchpad for follow-on attacks, with SpyCloud reporting in its 2025 Identity Threat Report that phishing is now the leading entry point for ransomware, accounting for 35% of all ransomware infections. 

“Phishing is now one of the most scalable tools cybercriminals use to breach enterprise environments,” said Trevor Hilligoss, SpyCloud’s Head of Security Research. “Cybercrime enablement services, like phishing-as-a-service kits that automate convincing lures and adversary-in-the-middle tactics that capture MFA tokens and session cookies, put advanced tactics into the hands of low-skilled actors, making it easier than ever to compromise users at scale. SpyCloud’s visibility into these campaigns gives organizations a critical edge, helping them detect who’s been targeted and what data has been exposed, and remediate those credentials before they can be weaponized.”

SpyCloud is the only provider recapturing and automatically remediating successfully phished identity data and targeting lists at scale before follow-on attacks like ransomware, fraud, and account takeover can occur.

“Many organizations rely on traditional defenses like email filtering, endpoint protection, and employee education to stop phishing and malware attempts, but those tools only go so far,” said Damon Fleury, SpyCloud’s Chief Product Officer. “Attackers are still getting through – and when they do, it’s the exposed identity data that enables further harm. Security teams need to be vigilant about what’s already been compromised and circulating in the criminal underground. Prevention is important, but without real-time visibility and post-compromise remediation, it’s not enough.”

While phishing has become a dominant entry point, malware remains a critical threat vector. In the age of remote work and bring-your-own-device policies, personal exposures are increasingly used to compromise enterprise environments. A recent example is the 2025 Nikkei breach, where malware on a personal device led to the compromise of sensitive corporate data. Despite only 11.5% of recaptured malware infections exfiltrating business email addresses directly, SpyCloud data shows that nearly 1 in 2 corporate users have been the victim of an infostealer malware infection in their digital history, whether that be on a managed or unmanaged device – a strong indicator that threat actors are moving laterally from personal to corporate accounts.

“Protecting the enterprise means looking beyond corporate accounts,” Fleury added. “Due to the continuous reuse of passwords and shared identity data across work and personal accounts like mobile numbers, the line between a user’s personal digital history and their professional access effectively no longer exists. That’s why it’s essential to monitor and remediate exposures across the full spectrum of an individual’s digital identity – personal and professional.”

SpyCloud is the leader in holistic identity protection, detecting and protecting organizations from the phishing, malware, and breach exposures of employees, contractors, and vendors across personal and professional identities. Users can click here to learn more.

About SpyCloud:

SpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions leverage advanced analytics and AI to proactively prevent ransomware and account takeover, detect insider threats, safeguard employee and consumer identities, and accelerate cybercrime investigations. SpyCloud’s data from breaches, malware-infected devices, and successful phishes also powers many popular dark web monitoring and identity theft protection offerings. Customers include seven of the Fortune 10, along with hundreds of global enterprises, mid-sized companies, and government agencies worldwide. Headquartered in Austin, TX, SpyCloud is home to more than 200 cybersecurity experts whose mission is to protect businesses and consumers from the stolen identity data criminals are using to target them now.

To learn more and see insights on their company’s exposed data, users can visit spycloud.com.

Contact

Sr. Account Director
Emily Brown
REQ on behalf of SpyCloud
[email protected]


文章来源: https://securityboulevard.com/2025/12/spycloud-data-shows-corporate-users-3x-more-likely-to-be-targeted-by-phishing-than-by-malware/
如有侵权请联系:admin#unsafe.sh