SlashNext has revealed that AI and automation are driving a huge increase in credential compromise attacks, with the threat accelerating at a shocking pace.
How shocking? Well, according to the report, credential theft attacks surged by 703% in the second half of 2024, with a sharp escalation in the use of sophisticated phishing kits and social engineering tactics.
The numbers get more concerning, if thatโs possible, when you realise that 80% of embedded malicious links in emails were zero-day threats.
Letโs stick with those numbers. After all, what are threat intelligence reports for if not to appeal to statistic nerds such as myself?
During peak periods, users faced an average of 3-6 threats per week, up to 600 mobile threats per user on average. Oh, and social engineering-based attacks rose by 141% in the last six months.
High figures, no surprises
None of this surprises me, and it shouldn’t surprise you either. Just keep reading the cybsersecurity news and analysis here at TechFinitive, and youโll be well aware of the threat posed by both AI and automation in todayโs threat landscape.
โThe 703% increase in credential phishing and 141% rise in social engineering attacks align with the expanded use of generative AI,โ said Callie Guenther, Senior Manager of the Cyber Threat Research Team at managed detection and response provider Critical Start.
She added this this “enables attackers to produce natural-language phishing content at scale, localise campaigns across languages, and automate deep personalisation”.
When it comes to attack automation, Guenther warned, the zero-day links statistic reflect its use within phishing infrastructures. โAttackers are using tools that dynamically generate unique phishing URLs and evade static detection methods,โ she said.
โThese evade-and-adapt phishing kits modify their behavior in real-time, depending on environmental signals such as IP addresses and user agents, complicating traditional takedown efforts.โ
Fighting AI credential attacks with AI
Nicole Carignan, Vice President of Strategic Cyber AI at Darktrace, said that we should be fighting AI with AI.ย
โAs sophistication of phishing attacks continue to grow,โ she said, โorganisations cannot rely on employees to be the last line of defence against these attacks.โ
Instead, they must โuse machine learning-powered tools that can understand how their employees interact with their inboxes and build a profile of what activity is normal for users, including their relationships, tone and sentiment, content, when and how they follow or share links.โ
With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.