Top 10 Email Phishing Scam Subjects: Q3 2022
Each quarter, KnowBe4 - the world’s largest security awareness training and simulated phishing platform - publishes the top-clicked phishing emails by subject lines. The results come from their millions of users reporting real phishing emails. The subjects are categorized into two different categories: those related to social media, general subjects, and 'In the Wild'.
The first category contains email subjects created by KnowBe4 to test their clients’ security posture. ‘In the Wild’ attacks refer to those email subjects that were real phishing emails and not KnowBe4 templates. Vectors are the methods used in the phishing attack.
Top Clicked Email Subjects
Top Clicked General Email Subjects Globally in Q3 2022:
Wells Fargo: Transfer Completed
DocuSign: Please review and sign your document
IT: IT Satisfaction Survey
Zoom: [[manager_name]] has sent you a message via Zoom Message Portal
Microsoft: Microsoft account security code
Most Common 'In the Wild' Emails in Q3 2022:
LinkedIn: Who's searching for you online?
IT: Internet Report
HR: Please update W4 for file
Acknowledge Your Appraisal
Employee Expense Reimbursement for [[email]]
Top Attack Vectors in Q3 2022:
Link - Phishing Hyperlink in the Email
Spoofs Domain - Appears to Come From the User's Domain
PDF Attachment - Email Contains a PDF Attachment
Branded - Phishing Test Link Has User's Organizational Logo and Name
Credentials Landing Page - Phishing Link Directs User to Data Entry or Login Landing Page
Key Takeaways
Most emails are related to business or mention HR in the title.
Recently, there have been an increasing number of business-related scams being sent from HR/IT/Managers. These scams are successful because they play on users' emotions and initial reactions before the person has time to think logically about whether or not the email is legitimate.
According to phishing tests and observations, the number one vector for cyberattacks is clicking on links in email bodies. These often lead to horrendous attacks such as ransomware and business email compromise.
Emails pretending to be from businesses were the most clicked subject category worldwide. They can come as messages supposedly from internal departments of an organization or external requests that seem urgent and entice users into taking some kind of action.
See KnowBe4’s original post.
Ozark Technology is a Business Technology Provider that helps organizations across the country rethink the value technology brings to their business. Want to partner with us? Let’s chat.