Phishing Attacks Increased by Nearly 200% in H2 2024

Phishing and malicious emails remained the primary vectors of infection during the second half of 2024, according to a new report from Acronis.
“The number of email-based attacks detected in the second half of 2024 increased 197% compared to the second half of 2023, while the number of attacks per organization within the same time frame increased by 21%,” the report says.
“Almost 50% of users were attacked at least once, 29% of users experienced at least one phishing attack via URL, and 14% of users experienced at least one malware detection.”
The researchers also observed an increase in ransomware attacks, which often begin with a phishing attack.
“Ransomware attacks saw a noticeable increase in sophistication, often combining social engineering with technical exploits to infiltrate organizations,” the researchers write. “When compared to breaches from 2023, a clear shift in attack vectors is evident, with ransomware groups increasingly targeting third-party service providers and cloud-based systems.”
The report adds that organized ransomware gangs are increasingly targeting managed service providers (MSPs) to maximize disruption.
“In 2024, ransomware increasingly targeted critical industries, including transportation, healthcare, and manufacturing, with attackers using personalized tactics and AI-driven strategies to exploit vulnerabilities and demand higher ransoms,” Acronis says.
“This trend reflects a shift towards more sophisticated, large-scale attacks aimed at maximizing disruption and financial gain, highlighting the critical role MSPs play in protecting organizations with advanced security measures and incident response strategies.”
The researchers note that employee awareness is an important layer of defense against social engineering attacks.
“Human error is often the weakest link in security,” the report says. “Regularly train employees on recognizing phishing attempts, creating strong passwords, and following company policies on data protection to reduce the risk of breaches caused by negligence or lack of awareness.”
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
Acronis has the story.
Free Phish Alert Button
Do your users know what to do when they receive a phishing email? KnowBe4’s Phish Alert Button gives your users a safe way to forward email threats to the security team for analysis and deletes the email from the user’s inbox to prevent future exposure. All with just one click! Phish Alert benefits:

Here’s how it works:
- Reinforces your organization’s security culture
- Users can report suspicious emails with just one click
- Incident Response gets early phishing alerts from users, creating a network of “sensors”
- Email is deleted from the user’s inbox to prevent future exposure
- Easy deployment via MSI file for Outlook, Google Workspace deployment for Gmail (Chrome) and manifest install for Microsoft 365
PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/free-phish-alert-partner?partnerid=001a000001lWEoJAAW