{"id":4583,"date":"2023-11-15T17:10:42","date_gmt":"2023-11-15T04:10:42","guid":{"rendered":"https:\/\/ostermanresearch.com\/2023\/11\/15\/slashnext-phishing\/"},"modified":"2025-03-11T06:36:15","modified_gmt":"2025-03-10T17:36:15","slug":"slashnext-phishing","status":"publish","type":"post","link":"https:\/\/ostermanresearch.com\/2023\/11\/15\/slashnext-phishing\/","title":{"rendered":"Some thoughts on SlashNext&#8217;s 2023 report on phishing"},"content":{"rendered":"\n<p>SlashNext recently published its 2023 report on the <a href=\"https:\/\/www.prnewswire.com\/news-releases\/slashnexts-2023-state-of-phishing-report-reveals-a-1-265-increase-in-phishing-emails-since-the-launch-of-chatgpt-in-november-2022--signaling-a-new-era-of-cybercrime-fueled-by-generative-ai-301971557.html\" target=\"_blank\" rel=\"noreferrer noopener\">State of Phishing<\/a>. The data is from SlashNext&#8217;s optics into email traffic around the world, along with a survey of 300 cybersecurity professionals and getting hands-on in the Dark Web.<\/p>\n\n\n\n<p>Headline findings:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Malicious phishing messages have increased 1,265% in the 12 months from Q4 2022 to Q3 2023, with ChatGPT and malicious generative AI services a significant contributing factor.<\/li>\n\n\n\n<li>SlashNext detected an average of 31,000 phishing attacks each day. This is an average number across the 12 months under investigation. What&#8217;s not disclosed is the baseline number of email messages sent each day that were subjected to SlashNext&#8217;s analysis. Globally, the number is around <a href=\"https:\/\/www.demandsage.com\/how-many-emails-are-sent-per-day\/#:~:text=How%20Many%20E%2Dmails%20Are,to%20392.5%20billion%20by%202026.\">350 billion emails<\/a> sent each day, which makes 31,000 a mere 0.00000886% of the global total. But that&#8217;s an unfair calculation, because SlashNext doesn&#8217;t see all of those. If we assume that SlashNext has the optics to assess 1% of the total email traffic volume (3.5 billion emails), then it&#8217;s 0.000886%. However you cut it, phishing is a dangerous needle in a very, very, very, very large haystack, and the high percentage of phishing messages being BEC threats (68%) in that needle is very, very, very expensive to get wrong.<\/li>\n\n\n\n<li>Key point &#8211; &#8220;AI chatbots (like ChatGPT) lowered the barriers to creating sophisticated BEC attacks and improved malware.&#8221; Be warned.<\/li>\n\n\n\n<li>SlashNext explores the rise of multi-stage attacks, cross-channel attacks, the use of trusted services to host malicious content (e.g., SharePoint &#8211; and why that&#8217;s a problem), and dark web hi jinx with jailbreak prompts and anonymizing wrappers for generative AI services.<\/li>\n<\/ul>\n\n\n\n<p>Request the <a href=\"https:\/\/slashnext.com\/state-of-phishing-2023\/\" target=\"_blank\" rel=\"noreferrer noopener\">full report from SlashNext<\/a> (25 content pages). Registration is required.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>SlashNext recently published its 2023 report on the State of Phishing. The data is from SlashNext&#8217;s optics into email traffic around the world, along with a survey of 300 cybersecurity professionals and getting hands-on in the Dark Web. Headline findings: Request the full report from SlashNext (25 content pages). Registration is required.<\/p>\n","protected":false},"author":384585,"featured_media":4484,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[712027491,712027195],"tags":[712027511,712027521],"class_list":["post-4583","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-reports","category-email-security","tag-cybersecurity","tag-research-reports-we-didnt-write"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2021\/08\/grammatech2021.jpg?fit=1160%2C350&ssl=1","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pcHAk4-1bV","_links":{"self":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4583","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/users\/384585"}],"replies":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/comments?post=4583"}],"version-history":[{"count":1,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4583\/revisions"}],"predecessor-version":[{"id":4678,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4583\/revisions\/4678"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media\/4484"}],"wp:attachment":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media?parent=4583"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/categories?post=4583"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/tags?post=4583"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}