ChannelLife UK - Industry insider news for technology resellers
Story image

UK organisations face significant rise in phishing threats

Mon, 24th Mar 2025

The latest Phishing Threat Trend Report from KnowBe4 reveals a significant rise in phishing threats targeting organisations as 2025 commences.

The report, based on data from KnowBe4 Defend, highlights a 17.3% increase in phishing emails between September 15, 2024, and February 14, 2025, compared to the previous six months. It also notes a 22.6% rise in ransomware payloads and a surge in phishing hyperlinks, malware, and social engineering payloads getting through traditional detection systems.

The report sheds light on the proliferation of AI-powered polymorphic phishing campaigns, with 76.4% of phishing campaigns exhibiting these tactics. Such campaigns involve creating variations that bypass traditional security measures, exemplifying the sophistication of contemporary cyber threats.

Additionally, compromised accounts being used for attacks have seen a 57.9% increase, presenting a major challenge for security systems. The top five platforms used to send phishing emails are DocuSign, PayPal, Microsoft, Google Drive, and Salesforce, with brands like Microsoft, DocuSign, Adobe, PayPal, and LinkedIn being the most impersonated.

The report also focuses on cybercriminals exploiting the hiring process, particularly targeting engineering roles to access systems and data, with 64% of attacks aimed at this sector. The significance of this trend points towards a growing sophistication in targeting specific organisational vulnerabilities.

Jack Chapman, Senior Vice President of Threat Intelligence at KnowBe4, commented, "As ever, innovation in phishing threats and defenses is accelerating rapidly. In this report, we have observed cybercriminals evolving their tactics, leveraging ransomware and polymorphic campaigns with new strategies to evade detection by both traditional and advanced technologies. As we move through 2025, both phishing threats and defenses will continue to evolve, emphasizing a holistic approach that integrates technical defenses with human risk management. A strong security culture starts with detection but is reinforced by awareness, continuous education, and adaptive technology."

As the report details, ransomware payloads have increased sharply by 57.5% in just three months, further illustrating the growing threat landscape. The report highlights an INC Ransom payload as a particular example detected by KnowBe4 Defend, underscoring the need for vigilant monitoring of cyber threats.

Overall, the Phishing Threat Trend Report suggests a pressing need for organisations to prioritise a combination of technical security measures and cultivating a strong security culture among employees to mitigate human risk factors in cybersecurity.

Follow us on:
Follow us on LinkedIn Follow us on X
Share on:
Share on LinkedIn Share on X