New Data Reveals Phishing Attacks Are Bigger Than Reported, Exact Size of Problem Unknown

Read the original article: New Data Reveals Phishing Attacks Are Bigger Than Reported, Exact Size of Problem Unknown


Attack Activity by Day – Phishing is lowest on the weekends when potential victims are away from their email. Phishing then ramps up early in the week as phishers send email lures, when the attention of potential victims is highest. (Phishing Landscape 2020 / Interisle)

A group of experts from Interisle Consulting Group released a paper today, reporting a comprehensive study of the phishing landscape in 2020. The study’s goal was to capture and analyze a large set of information about phishing attacks to better understand how much phishing is taking place, where it is taking place, and better ways to fight them.

Major findings: After a three-month data collection period, the group learned about more than 100,000 newly discovered phishing sites. Here are the major findings — full details on the study can be obtained here.

  • Most phishing is concentrated at small numbers of domain registrars, domain registries, and hosting providers.
  • Phishers themselves register more than half of the domain names on which phishing occurs.
  • Domain name registrars and registry operators can prevent and mitigate large amounts of phishing by finding and suspending maliciously registered domains.
  • Registries, registrars, and hosting providers should focus on both mitigation and prevention.
  • The problem of phishing is bigger than is reported, and the exact size of the problem is unknown.
  • Sixty-five percent of maliciously registered domain names are used for phishing within five days of registration.
  • New top-level domains introduced since 2014 account for 9% of all registered domain names, but 18% of the domain names used for phishing.
  • About 9% of phishing occurs at a small set of providers that offer subdomain services.

Also noteworthy: The group analyzed 65,255 gTLD domains to determine how much time elapsed between when a domain name was registered and when that domain was first flagged for phishing by one of the phishing data feeds. 45% of the domains (31,610 out of 65,255) were used for phishing within 14 days of registration, reinforces the conventional wisdom that when phishers register domains, they tend to use them quickly to avoid detection.

gTLD Domains User for Phishing: days from domain registration to phishing (Phishing Landscape 2020 / Interisle)


Read the original article: New Data Reveals Phishing Attacks Are Bigger Than Reported, Exact Size of Problem Unknown