Cyber Security News

Top Five Industries Aggressively Targeted By Phishing Attacks

Phishing attacks continue to pose a significant threat to various industries, with cybercriminals employing sophisticated tactics to deceive recipients.

A recent analysis by Cofense Intelligence, covering data from Q3 2023 to Q3 2024, has identified the top five industries most targeted by phishing attacks using customized subject lines.

The top Targeted Industries that are aggressively targeted by attackers via Phishing attacks are:-

  1. Finance and Insurance: This sector tops the list, accounting for 15.5% of all credential phishing emails with customized subjects. Attackers often mimic business communications such as invoices and forms requiring attention.
  2. Manufacturing: Representing 11.3% of emails with subject redaction, this industry is particularly vulnerable due to its reliance on order and contract-based communications.
  3. Mining, Quarrying, and Oil and Gas Extraction: This sector accounts for 10.3% of emails with customized subjects, often featuring proposals, invoices, and shared document notifications.
  4. Health Care and Social Assistance: 8.2% of emails with subject redaction targeted this industry, typically using notification-based or document-related subjects.
  5. Retail Trade: Comprising 7.4% of emails requiring subject redaction, this industry often receives phishing attempts related to sales, contracts, and urgent shipments.
Top five industries targeted by emails with customized subjects requiring redaction (Source – Cofense)

While the common tactics and trends observed by the security analysts at Cofense Intelligence are:-

Subject Customization: Threat actors frequently incorporate the recipient’s name, email address, phone number, or company name in the subject line to increase legitimacy.

Quarterly Fluctuations: Most industries experienced peak volumes of customized phishing emails in Q3 2023, with varying trends in subsequent quarters.

Attachment Types: The most common malicious file types attached to these emails are .HTM(L) (90.3%) and .DOC(X) (9.4%).

Free Webinar on Best Practices for API vulnerability & Penetration Testing:  Free Registration

Technical Analysis

Here below we have mentioned the industry-specific examples:-

Finance and Insurance

  • ” shared ‘Invoice20248904.pdf’ with you”
  • “Invoice from “
  • “ACH on 2024-06-28 For “

Manufacturing

  • “Proposals from “
  • “File Shared By “
  • “NEW P.O. # 94153 from “

Mining, Quarrying, and Oil and Gas Extraction

  • “Contract Proposal for service – “
  • “Document shared with you: #_Financ…..#88456.docx”
  • “FW: New Invoice Acknowledgement 6472749IK From “

Implementation of sophisticated techniques to safeguard customers’ personally identifiable information (PII) and proprietary company data while providing actionable intelligence is must.

As this approach allows for accurate threat analysis without compromising sensitive information.

Besides this, researchers urged organizations across these industries must remain vigilant and implement robust security measures to protect against these targeted attacks.

Analyse Real-World Malware & Phishing Attacks With ANY.RUN - Get up to 3 Free Licenses

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Critical Apache Struts Vulnerabilities Enables Remote Code Execution Attacks

Four security flaws described in the supplied Apache Struts advisories could expose affected applications to…

58 minutes ago

Former Infrastructure Engineer Sentenced for Sabotaging Employer’s Windows Network

A former infrastructure engineer has been sentenced to 32 months in federal prison for sabotaging…

1 hour ago

GitHub Copilot CLI Vulnerability Lets Attackers Steal Developer Secrets Using Encrypted Prompt Injection

A new GitHub Copilot CLI finding that could allow an attacker-controlled web page to guide…

1 hour ago

From Telemetry to Defense: How SOC and MSSP Leaders Can Build Intelligence-Led Threat Monitoring

Every function in a security operations center, from alert triage to incident response, depends on…

1 hour ago

ASOS Hacked – App Users Receive Notifications Sent by Hackers

ASOS is investigating a cyber incident after customers received an unauthorized app notification claiming hackers…

2 hours ago

Aembit Extends Access Controls to Personal AI Agents

Silver Springs, United States / Maryland, October 6th, 2026, CyberNewswire Aembit, the identity control plane…

2 hours ago