Cybersecurity5 min read

The Growing Threat of Phishing in 2024: A Gateway Crime

Nearly 1.9 million phishing attacks in a single year, $4.5M average breach recovery cost, and seniors losing $3.4B. The data on phishing in 2024 is staggering. Here's what organisations must do.

Marco Cavani

Marco Cavani

Cybersecurity Analyst

|
The Growing Threat of Phishing in 2024: A Gateway Crime

Phishing continues to be one of the most insidious and widespread forms of cybercrime. Despite significant efforts to combat it, phishing attacks have only increased over time. Recent data shows a continued rise in phishing activity, underscoring its role as a gateway crime to more damaging cyberattacks.


The Rise in Phishing Attacks

In 2023, the world saw an increase of 47,560 phishing attacks over the previous year. While this is the smallest increase since monitoring began in May 2020, the sheer scale is staggering: 1,897,952 phishing attacks reported between May 2023 and April 2024 (Aaron et al., 2024).

More than 90% of all cyberattacks begin with phishing, making it the gateway to larger, more damaging attacks such as data breaches and financial fraud (CISA, n.d.).


The Financial and Social Cost

The cost of phishing attacks is enormous:

  • $4.5 million: average recovery cost of a single phishing-related data breach (IBM, 2024)
  • $3 billion: losses from Business Email Compromise (BEC) in the U.S. alone in 2022 (FBI, 2022)
  • $3.4 billion: losses suffered by U.S. seniors aged 60+ in 2023, three times higher than losses by adults aged 30 to 39 (Aaron et al., 2024)

The elderly are increasingly targeted due to limited online security knowledge, which is a growing public concern.


Despite growing security measures, phishing remains highly effective:

  • Google Safe Browsing flags more than 1.8 million phishing sites and issues over 3 million warnings daily
  • Many warnings are ignored or misunderstood by users
  • Phishers use subdomains and URL tricks to make fake websites appear legitimate

Phishing attacks target human behaviour and psychological weaknesses, often bypassing traditional technical security measures.


Conclusion: The Path Forward

The data is clear: this problem is only growing, and its impact is far-reaching. Phishers are becoming more sophisticated, and the cost of recovery continues to rise.

To protect themselves, businesses and individuals must:

  1. Remain vigilant: question unexpected emails, links, and requests
  2. Implement MFA: reduce the impact of credential theft
  3. Train employees: human awareness is the most effective control
  4. Use email filtering: block phishing attempts before they reach inboxes
  5. Monitor and respond: detect phishing campaigns early

References

  • Aaron, G., et al. (2024). Phishing Landscape 2024. Interisle Consulting Group.
  • APWG. (2024). Phishing Trends Report Q3 2024.
  • CISA. (n.d.). 4 Things You Can Do To Keep Yourself Cyber Safe. https://www.cisa.gov/
  • FBI. (2022). 2022 Internet Crime Report.
  • Google. (2024). The Browser is the New Frontline Defense for Endpoint Security.
  • IBM. (2024). Cost of a Data Breach 2024. https://www.ibm.com/reports/data-breach
#Phishing#Cybercrime#BEC#Social Engineering#Cyber Awareness#Data Breach#2024
Marco Cavani

Written by

Marco Cavani

Cybersecurity analyst and IT governance professional. Author of digital reports on threat intelligence, critical infrastructure security, and IT audit frameworks.

Related articles

Understanding the Cost of Data Breaches
Cybersecurity6 min read

Understanding the Cost of Data Breaches

Key insights from IBM's Cost of a Data Breach report: healthcare leads at $10.1M per breach, while AI platforms, DevSecOps, and incident response teams can significantly cut costs.

Read more →
Data BreachIBMCost Analysis

Stay ahead of cyber threats

Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.

No spam. Unsubscribe at any time.

ITGC Audit Tool

Streamline Your IT General Controls Audits

The RACM ITGC SaaS platform helps audit professionals manage IT General Controls assessments, from risk and control mapping to workpaper generation and evidence tracking.