Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Corporate Users 3x More Likely Targeted by Phishing Than Malware – SpyCloud Report

Corporate Users 3x More Likely Targeted by Phishing Than Malware – SpyCloud Report

Posted on December 4, 2025December 4, 2025 By CWS

Austin, TX, USA, December 4th, 2025, CyberNewsWire

Phishing has surged 400% year-over-year, highlighting want for real-time visibility into identification exposures.

SpyCloud, the chief in identification risk safety, right this moment launched new knowledge exhibiting a pointy rise in phishing assaults that disproportionately goal company customers.

The corporate tracked a 400% year-over-year enhance in efficiently phished identities, with practically 40% of the 28+ million recaptured phished information containing a enterprise electronic mail handle – in comparison with simply 11.5% in recaptured malware knowledge.

The result’s a warning to enterprises that their workforce is thrice extra prone to be focused with phishing assaults than infostealer malware. 

The findings reinforce a rising shift in cybercriminals’ technique: phishing is now the popular gateway into enterprise environments, and SpyCloud sees this pattern persevering with in 2026.

Menace actors are utilizing this entry as a launchpad for follow-on assaults, with SpyCloud reporting in its 2025 Id Menace Report that phishing is now the main entry level for ransomware, accounting for 35% of all ransomware infections. 

“Phishing is now one of the scalable instruments cybercriminals use to breach enterprise environments,” mentioned Trevor Hilligoss, SpyCloud’s Head of Safety Analysis.

“Cybercrime enablement providers, like phishing-as-a-service kits that automate convincing lures and adversary-in-the-middle techniques that seize MFA tokens and session cookies, put superior techniques into the arms of low-skilled actors, making it simpler than ever to compromise customers at scale. SpyCloud’s visibility into these campaigns provides organizations a crucial edge, serving to them detect who’s been focused and what knowledge has been uncovered, and remediate these credentials earlier than they are often weaponized.”

SpyCloud is the one supplier recapturing and routinely remediating efficiently phished identification knowledge and focusing on lists at scale earlier than follow-on assaults like ransomware, fraud, and account takeover can happen.

“Many organizations depend on conventional defenses like electronic mail filtering, endpoint safety, and worker training to cease phishing and malware makes an attempt, however these instruments solely go to date,” mentioned Damon Fleury, SpyCloud’s Chief Product Officer.

“Attackers are nonetheless getting by means of – and after they do, it’s the uncovered identification knowledge that allows additional hurt. Safety groups should be vigilant about what’s already been compromised and circulating within the prison underground. Prevention is vital, however with out real-time visibility and post-compromise remediation, it’s not sufficient.”

Whereas phishing has develop into a dominant entry level, malware stays a crucial risk vector. Within the age of distant work and bring-your-own-device insurance policies, private exposures are more and more used to compromise enterprise environments.

A latest instance is the 2025 Nikkei breach, the place malware on a private system led to the compromise of delicate company knowledge.

Regardless of solely 11.5% of recaptured malware infections exfiltrating enterprise electronic mail addresses immediately, SpyCloud knowledge exhibits that just about 1 in 2 company customers have been the sufferer of an infostealer malware an infection of their digital historical past, whether or not that be on a managed or unmanaged system – a powerful indicator that risk actors are transferring laterally from private to company accounts.

“Defending the enterprise means trying past company accounts,” Fleury added.

“Because of the steady reuse of passwords and shared identification knowledge throughout work and private accounts like cell numbers, the road between a consumer’s private digital historical past and their skilled entry successfully not exists. That’s why it’s important to observe and remediate exposures throughout the complete spectrum of a person’s digital identification – private {and professional}.”

SpyCloud is the chief in holistic identification safety, detecting and defending organizations from the phishing, malware, and breach exposures of staff, contractors, and distributors throughout private {and professional} identities.

Customers can click on right here to study extra.

About SpyCloud:

SpyCloud transforms recaptured darknet knowledge to disrupt cybercrime.

Its automated identification risk safety options leverage superior analytics and AI to proactively forestall ransomware and account takeover, detect insider threats, safeguard worker and shopper identities, and speed up cybercrime investigations.

SpyCloud’s knowledge from breaches, malware-infected units, and profitable phishes additionally powers many standard darkish net monitoring and identification theft safety choices.

Prospects embody seven of the Fortune 10, together with tons of of worldwide enterprises, mid-sized corporations, and authorities businesses worldwide.

Headquartered in Austin, TX, SpyCloud is dwelling to greater than 200 cybersecurity specialists whose mission is to guard companies and shoppers from the stolen identification knowledge criminals are utilizing to focus on them now.

To study extra and see insights on their firm’s uncovered knowledge, customers can go to spycloud.com.

Contact

Sr. Account Director

Emily Brown

REQ on behalf of SpyCloud

[email protected]

Cyber Security News Tags:Corporate, Malware, Phishing, Report, SpyCloud, Targeted, Users

Post navigation

Previous Post: New SVG Clickjacking Attack Let Attackers Create Interactive Clickjacking Attacks
Next Post: Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China

Related Posts

Cybersecurity Newsletter Weekly Recap – UK Hacker Bust to BMW Data Leak Cybersecurity Newsletter Weekly Recap – UK Hacker Bust to BMW Data Leak Cyber Security News
Hackers Leveraging LLM Shared Chats to Steal Your Passwords and Crypto Hackers Leveraging LLM Shared Chats to Steal Your Passwords and Crypto Cyber Security News
CISA Warns of Iranian Cyber Actors May Attack U.S. Critical Infrastructure CISA Warns of Iranian Cyber Actors May Attack U.S. Critical Infrastructure Cyber Security News
MongoDB Servers at Critical Risk MongoDB Servers at Critical Risk Cyber Security News
Cl0p Ransomware Actively Exploiting Oracle E-Business Suite 0-Day Vulnerability in the Wild Cl0p Ransomware Actively Exploiting Oracle E-Business Suite 0-Day Vulnerability in the Wild Cyber Security News
WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide
  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide
  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark