Previously, we talked about phishing and its four common types: spear phishing, whaling, clone/deceptive phishing, and CEO fraud. In this blog, we’ll tackle 10 phishing emails that cybercriminals commonly use to trick users. While SMS, voice calls, and websites can also be used for phishing, we’ll focus on email since 96% of phishing attacks arrive by email.Did you know that?
Guest blog courtesy of Graphus, a Kaseya company. Read more guest blogs from Kaseya here.
- The 2020 Verizon Data Breach Investigations (DBIR) Report shows that if an attacker sends out 10 phishing emails, there is a 90% chance that one person will fall for it.
- The same report reveals that 22% of data breaches in 2019 involved phishing.
- The 2020 Proofpoint State of the Phish report indicates that 65% of organizations in the United States suffered a successful phishing attack, which is above the global average of 55%.
1. Government pretense
This type of phishing email appears to come from a federal, state, or local government body, such as the Federal Bureau of Investigation and National Security Agency. The messages used greatly vary depending on the function of the agency. Some examples include:- “Your request for a loan has been denied due to incomplete information. Click here to provide your information.”
- “We detected that you illegally downloaded files, therefore we will revoke your internet access unless you enter the requested information in the form below.”
- “You are eligible to receive a tax refund. Click on the link below to submit your tax refund request.”
- “We created a website for citizens to verify their personal information. Please use the following link.”
