Proofpoint’s 2024 State of the Phish Report: 68% of Employees Willingly Gamble with Organizational Security
ID: fb50a15e-3ec5-5554-852b-cf86939a16e8
STIX ID: report--fb50a15e-3ec5-5554-852b-cf86939a16e8
Feed Name: Proofpoint Blog
Proofpoint’s 2024 State of the Phish report finds that while successful phishing incidents slightly declined year-over-year, the consequences worsened, with reports of financial penalties up 144% and reputational damage up 50%. The report emphasizes that risky user behavior is often deliberate (68% knowingly undermined security) and that awareness alone doesn’t ensure behavior change; usability and simplified controls are key. Threat trends include widespread MFA bypass using EvilProxy (over 1M attacks monthly), AI-fueled growth in BEC, persistent ransomware (69% victimization; 54% paid; only 41% recovered data after one payment), and rising TOAD activity (10M incidents monthly), while few organizations train users on TOAD or genAI safety (23% each).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
