PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Phishing Attacks Shift to More Subtle Enticements

By Tom Nawrocki
March 31, 2025
in Analysts Coverage, Fraud & Security
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Strong MFA and Safe Authentication are the Real Holiday Must-Haves This Holiday Season

Strong MFA and Safe Authentication are the Real Holiday Must-Haves This Holiday Season

The days of receiving phishing emails with subject lines like “Payment Overdue!” may be coming to an end. As users grow desensitized to alarmist messages, malicious actors have shifted to more subtle approaches.

“Request” was the most common word in phishing subject lines in 2024, according to research from Cisco. Threat actors have largely abandoned urgent or time-sensitive language, instead opting for ordinary terms that blend seamlessly into a user’s daily inbox.

Microsoft Outlook was the most commonly spoofed brand, appearing as the sender in 25% of suspicious emails, followed by Amazon and LinkedIn. Other frequently impersonated names  include PayPay, a Japanese payment service, and Chinese e-commerce giant Shein.

A Hot Market for Credentials

One reason phishing remains so prevalent is that adversaries find it easier to compromise networks and accounts by obtaining credentials for illegal log ins rather than using more complex methods like deploying malware.

According to a report from Javelin Strategy & Research, 2025 Identity Fraud Study: Breaking Barriers to Innovation, identity fraud incidents and financial losses skyrocketed over the past year. The survey found that over half of consumers surveyed experienced an increase in unusual text messages, while slightly fewer noticed a rise in emails with suspicious links. In total, consumers lost $27.2 billion to identity theft in 2024—a 19% increase from the prior year, according to Jennifer Pitt, Senior Analyst of Fraud and Security and author of the study.

A thriving market for stolen credentials further fuels this trend, with valid username and password combinations frequently bought and sold on the dark web. According to Cisco, bulk lists of credentials commonly sell for as little as $10 on dark web marketplaces.

System Vulnerabilities

One of the most common organizational vulnerabilities leading to successful phishing attacks is weak multi-factor authentication. Pitt recommends that organizations implement MFA protocols incorporating behavioral and device analytics, as well as biometric authentication methods such as fingerprint and voice recognition. These password-free methods can also prevent criminals from using stolen credentials to create fraudulent new accounts. 

Another critical security weakness stems from unpatched and vulnerable systems. Many widely used systems are several years old, and patch management remains a continuing challenge for many organizations. 

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Tags: Ciscoidentity theftMulti-Factor AuthenticationPasswordsphishingPhishing Attacks

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    metal credit card

    Defying Expectations: How a Metal Credit Card Found Its Market

    January 12, 2026
    swift digital assets, banks leveraging geography, PhotoPay stablecoin

    PhotonPay Raises Tens of Millions in Series B to Pioneer Stablecoin-Centric Financial Infrastructure

    January 9, 2026
    payments innovation

    The $7 Trillion Bottleneck: Why Banks Are Paralyzed by Payments Innovation

    January 8, 2026
    Amazon

    Is There a Future for Unattended Retail?

    January 7, 2026
    Walmart Delivers Groceries Direct To Your Fridge

    How the Principles of the Planogram Can Apply to Payments

    January 6, 2026
    merchant security customer engagement AI, IoT impact on retail, machine learning small business loans

    How Bank Websites Can Build Customer Relationships

    January 5, 2026
    What Is the "Dark Web" and Why Should Fraud Analysts Be Paying Attention?, Dark web bank account value

    To Track Down Stolen Data, Dark Web Threat Intelligence Is Key

    December 30, 2025
    tokenization

    The Trends That Will Modernize Payments Technology in 2026

    December 29, 2025

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2024 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result