Full Report
Netskope observed a 190% growth in enterprise users clicking phishing links as attackers become more creative in delivering effective lures
Analysis Summary
# Incident Report: Significant Rise in Enterprise Phishing Click Rates (2024)
## Executive Summary
Research conducted by Netskope in 2024 revealed that enterprise users' click rates on phishing lures nearly tripled compared to the previous year, indicating a severe degradation in human-factor defense effectiveness. The rise is attributed to user cognitive fatigue and increasingly sophisticated attack designs. Cloud applications, particularly Microsoft services, were the primary targets for these credential-harvesting activities.
## Incident Details
- **Discovery Date:** Research findings released in January 2025, reflecting 2024 data.
- **Incident Date:** Throughout 2024 (continuous trend).
- **Affected Organization:** General enterprise population targeted by phishing campaigns.
- **Sector:** Not explicitly stated, but research impacts all sectors using cloud services.
- **Geography:** Global (implied by the nature of cloud/internet research).
## Timeline of Events
*The reported information is trend analysis based on monitoring research, not a single isolated incident timeline.*
### Initial Access
- **Date/Time:** Ongoing throughout 2024.
- **Vector:** Social engineering delivered via phishing emails/messages.
- **Details:** Attackers increased the volume of phishing attempts, leading to user cognitive fatigue, and simultaneously improved lure creativity, resulting in a 190% increase in clicks compared to 2023 (over eight clicks per 1000 users monthly).
### Lateral Movement
- *Not detailed for this trend report, but implied goal is account compromise.*
### Data Exfiltration/Impact
- **What was stolen or damaged:** Compromised credentials for cloud applications. The primary goal is selling access on illicit marketplaces, which then leads to Business Email Compromise (BEC) or data theft for pivoting to other high-value victims. Cloud apps accounted for 27% of all click targets.
### Detection & Response
- **How it was discovered:** Analysis of phishing campaign telemetry data collected by Netskope throughout 2024.
- **Response actions taken:** (Implicitly) Monitoring and reporting the trend increase. Specific organizational response actions are not detailed as this is industry-wide reporting.
## Attack Methodology
Based on the description of the observed malicious activity:
- **Initial Access:** Phishing Lures (High volume + creative/harder-to-detect lures).
- **Persistence:** Not detailed, but the objective implies establishing persistence via compromised cloud accounts.
- **Privilege Escalation:** Not detailed, but achieving access to high-value targets is the likely subsequent goal.
- **Defense Evasion:** Attackers used more creative lures to evade human detection mechanisms (i.e., user scrutiny).
- **Credential Access:** Directly achieved via users clicking malicious links designed to capture cloud application credentials.
- **Discovery:** Not detailed.
- **Lateral Movement:** Likely achieved by leveraging compromised cloud credentials to pivot to related systems or conduct BEC.
- **Collection:** Cloud application data.
- **Exfiltration:** Selling compromised access on illicit marketplaces.
- **Impact:** Account takeover, potential data theft, and pivot points for further attacks (BEC scenarios).
## Impact Assessment
- **Financial:** Unknown (implied significant cost due to increased BEC risk and remediation efforts across enterprises).
- **Data Breach:** Credentials for cloud applications (Microsoft being the most targeted brand at 42% of related clicks).
- **Operational:** Increased risk of operational disruption due to account compromise and BEC activities.
- **Reputational:** Increased risk for organizations suffering successful breaches stemming from these high click rates.
## Indicators of Compromise
*Since this involves a general trend of phishing campaigns, specific IOCs are illustrative, focusing on the targeted application:*
- **Network indicators (Defanged):** URLs leading to credential harvesting pages (Requires dynamic monitoring).
- **File indicators:** None specified, relying on link clicking.
- **Behavioral indicators:** Users interacting with suspicious links leading to cloud service login pages that deviate slightly from the legitimate site. Excessive failed login attempts post-click.
## Response Actions
*Based on the threat identified (high click rate on cloud application phishing):*
- **Containment measures:** Immediate revocation of access tokens/credentials associated with compromised cloud accounts. Blocking connections to known malicious domains used in phishing campaigns.
- **Eradication steps:** Thoroughly auditing affected cloud environments for persistence mechanisms installed by the threat actors.
- **Recovery actions:** Resetting passwords for potentially compromised users; restoring any services affected by BEC.
## Lessons Learned
- **Key takeaways:** Human susceptibility to phishing significantly worsened in 2024 due to fatigue and improved lure quality. Cloud applications represent the number one asset targeted via these social engineering attacks.
- **What could have been done better:** Increased emphasis on security awareness training that adapts to modern, sophisticated lures rather than basic pattern recognition. Stronger authentication controls are needed beyond simple credentials (e.g., MFA enforcement and monitoring MFA fatigue attacks).
## Recommendations
- **Prevention measures for similar incidents:**
1. **Enhance Multi-Factor Authentication (MFA):** Implement phishing-resistant MFA (e.g., FIDO2/WebAuthn tokens) for high-value accounts and cloud administrative access.
2. **Improve Phishing Simulation:** Update security awareness programs to frequently test users against modern, context-aware phishing lures targeting cloud sign-ins.
3. **Cloud Access Security Broker (CASB) Monitoring:** Deploy CASB tools to actively monitor traffic to legitimate cloud services for anomalous login behavior or session hijacking attempts following a credential capture.
4. **Filter Sophisticated Email Lures:** Deploy advanced email gateway security capable of identifying visual anomalies in login pages or suspicious link redirection chains.