Cyberattacks targeting user logins have surged by 156 percent due to advanced phishing kits and info-stealing malware, according to research. Identity-based attacks now account for 59 percent of all investigations by eSentire. The rise of phishing-as-a-service platforms like Tycoon 2FA, which costs between $200-300 per month, democratizes these attacks with tailored phishing pages for major platforms. Business email compromise (BEC) schemes pose a heightened risk, often resulting in significant financial losses, although they are less notorious than ransomware attacks. Tycoon 2FA has become a leading tool since its launch in 2023, boasting over 2,000 monthly subscribers.
Researchers report a 156 percent increase in cyberattacks targeting user logins, primarily driven by advanced phishing kits and info-stealing malware. Identity-based attacks now constitute 59 percent of all investigations.
Phishing-as-a-service platforms like Tycoon 2FA are providing sophisticated toolkits for identity-based attacks, with pre-made phishing pages for platforms like Microsoft 365 and Google Workspace, which cost $200-300 per month.
Collection
[
|
...
]