PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Phishing Attacks Shift to More Subtle Enticements

By Tom Nawrocki
March 31, 2025
in Analysts Coverage, Fraud & Security
0
0
SHARES
0
VIEWS
Share on LinkedIn
Strong MFA and Safe Authentication are the Real Holiday Must-Haves This Holiday Season

Strong MFA and Safe Authentication are the Real Holiday Must-Haves This Holiday Season

The days of receiving phishing emails with subject lines like “Payment Overdue!” may be coming to an end. As users grow desensitized to alarmist messages, malicious actors have shifted to more subtle approaches.

“Request” was the most common word in phishing subject lines in 2024, according to research from Cisco. Threat actors have largely abandoned urgent or time-sensitive language, instead opting for ordinary terms that blend seamlessly into a user’s daily inbox.

Microsoft Outlook was the most commonly spoofed brand, appearing as the sender in 25% of suspicious emails, followed by Amazon and LinkedIn. Other frequently impersonated names  include PayPay, a Japanese payment service, and Chinese e-commerce giant Shein.

A Hot Market for Credentials

One reason phishing remains so prevalent is that adversaries find it easier to compromise networks and accounts by obtaining credentials for illegal log ins rather than using more complex methods like deploying malware.

According to a report from Javelin Strategy & Research, 2025 Identity Fraud Study: Breaking Barriers to Innovation, identity fraud incidents and financial losses skyrocketed over the past year. The survey found that over half of consumers surveyed experienced an increase in unusual text messages, while slightly fewer noticed a rise in emails with suspicious links. In total, consumers lost $27.2 billion to identity theft in 2024—a 19% increase from the prior year, according to Jennifer Pitt, Senior Analyst of Fraud and Security and author of the study.

A thriving market for stolen credentials further fuels this trend, with valid username and password combinations frequently bought and sold on the dark web. According to Cisco, bulk lists of credentials commonly sell for as little as $10 on dark web marketplaces.

System Vulnerabilities

One of the most common organizational vulnerabilities leading to successful phishing attacks is weak multi-factor authentication. Pitt recommends that organizations implement MFA protocols incorporating behavioral and device analytics, as well as biometric authentication methods such as fingerprint and voice recognition. These password-free methods can also prevent criminals from using stolen credentials to create fraudulent new accounts. 

Another critical security weakness stems from unpatched and vulnerable systems. Many widely used systems are several years old, and patch management remains a continuing challenge for many organizations. 

0
SHARES
0
VIEWS
Share on LinkedIn
Tags: CiscoIdentity TheftMulti-Factor AuthenticationPasswordsPhishingPhishing Attacks

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    complex debit

    Regulation, Economics, and Technology: The Complex World of Debit

    September 8, 2026
    agentic commerce

    Biometrics Are Here. Agentic Payments Aren’t—Yet.

    September 4, 2026
    swift cross-border

    P2P Payments Have Changed How Consumers Move Money. What’s Next?

    September 3, 2026
    holiday prepaid

    The Holiday Gift Card Outlook: Why Repeat Buyers Matter Most

    September 2, 2026
    co-branded debit cards

    A New Generation of Consumers Is Changing the Role of Debit Cards

    September 1, 2026
    BNPL for credit unions

    How BNPL Is Helping Credit Unions Strengthen Member Relationships

    August 31, 2026
    cross-border tokenized deposits

    Project Agorá Is Showing Banks Why Tokenized Deposits Matter

    August 28, 2026
    prepaid speed

    How Jumpstarting Gift Card Redemption Can Mitigate Breakage

    August 27, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result