2 Sources
[1]
Zscaler ThreatLabz Uncovers Surge in AI-Driven Cyberattacks Targeting Critical Business Operations - Zscaler (NASDAQ:ZS)
Key Findings: Global phishing is down 20%, but attackers are striking deeper, not wider -- targeting IT, HR, finance, and payroll teams with high-impact campaigns.Telegram, Steam, and Facebook are top platforms for phishing - used for both impersonation and malware delivery.Tech support and job scams increase with 159M+ hits in 2024, preying on users across social platforms. SAN JOSE, Calif., April 24, 2025 (GLOBE NEWSWIRE) -- Zscaler, Inc. ZS, the leader in cloud security, today published its Zscaler ThreatLabz 2025 Phishing Report, analyzing over two billion blocked phishing attempts between January and December 2024 captured by the Zscaler Zero Trust Exchangeâ„¢, the world's largest cloud security platform. The annual report exposes how cybercriminals are using Generative AI to launch surgical, targeted attacks against high-impact business functions - and why a Zero Trust + AI defense strategy is mission critical. The report uncovers a shift from high-volume email blasts to targeted, AI-fueled attacks designed to evade defenses and exploit human behavior. It also offers actionable insight to help organizations defend against this evolving threat landscape. "The phishing game has changed. Attackers are using GenAI to create near-flawless lures and even outsmart AI-based defenses," said Deepen Desai, CSO and Head of Security Research, Zscaler. "Cybercriminals are weaponizing AI to evade detection and manipulate victims, which means organizations must leverage equally advanced AI-powered defenses to outpace these emerging threats. Our research reinforces the importance of adopting a proactive, multi-layered approach -- combining robust zero trust architecture with advanced AI-driven phishing prevention -- to effectively combat the rapidly evolving threat landscape." Emerging markets see a surge in phishing activity While phishing dropped overall by 20% globally and by nearly 32% in the U.S., due in part to rising email authentication standards, attackers transitioned just as fast, launching more attacks on emerging markets like Brazil, Hong Kong, and the Netherlands, often where digital adoption outpaces security investment. Established targets like India, Germany, and the UK remain under sustained pressure, as threat actors adapt to local patterns and seasonal trends. Community platforms fuel phishing growth Phishing campaigns are increasingly abusing community-based platforms like Facebook, Telegram, Steam, and Instagram - not only spoofing their brands, but using them to distribute malware, mask C2 communications, gather target intel, and carry out social engineering attacks. Meanwhile, tech support scams, where attackers pose as IT support teams to exploit urgency and safety concerns of victims, remain widespread with 159,148,766 hits in 2024. Threat actors capitalize on AI: Phishing-as-a-Service and AI deception on the rise Cybercriminals are using GenAI to scale attacks, generate fake websites, and craft deepfake voice, video, and text for social engineering. New scams mimic AI tools - such as resume generators and design platforms - tricking users into handing over credentials or payment data. Critical departments like payroll, finance, and HR are prime targets, along with executives - as they hold the keys to sensitive systems, information, and processes, and can more easily approve fraudulent payments. Cybercriminals are also creating fake "AI assistant" or "AI agent" websites, falsely offering services such as resume generation, graphic design, workflow automation, and more. As AI tools become increasingly integrated into daily life, attackers are capitalizing on the ease of use and trust around AI to drive unsuspecting users to fraudulent sites. Zscaler can help: Defending against AI threats with Zero Trust everywhere + AI As cybercriminals continue to use GenAI to develop new tactics and deliver more sophisticated attacks, enterprises need to strengthen their defenses against every type of compromise. The Zscaler Zero Trust Exchange protects users, applications, and data across all phases of the attack chain by: Minimizing the attack surfacePreventing initial compromiseEliminating lateral movementShutting down insider threatsStopping data loss Zscaler AI-powered offerings add advanced protection by securing public AI use, shielding private AI models, and detecting AI-generated threats. Download the Report Get the full ThreatLabz 2025 Phishing Report to explore emerging trends and attack vectors. Learn why a Zero Trust + AI approach is critical to staying ahead of today's phishing threats. Download today. Research Methodology Zscaler ThreatLabz analyzed 2 billion blocked phishing transactions between January-December 2024, exploring various aspects including the top phishing attacks, targeted countries, hosting countries for phishing content, distribution of company types based on server IP addresses, and the top referrers linked to these phishing attacks. Additionally, ThreatLabz tracked and examined notable phishing trends and use cases observed throughout 2024. About ThreatLabz ThreatLabz is the security research arm of Zscaler. This world-class team is responsible for hunting new threats and ensuring that the thousands of organizations using the global Zscaler platform are always protected. In addition to malware research and behavioral analysis, team members are involved in the research and development of new prototype modules for advanced threat protection on the Zscaler platform, and regularly conduct internal security audits to ensure that Zscaler products and infrastructure meet security compliance standards. ThreatLabz regularly publishes in-depth analyses of new and emerging threats on its portal, research.zscaler.com. About Zscaler Zscaler ZS accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchangeâ„¢ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across more than 150 data centers globally, the SASE-based Zero Trust Exchange is the world's largest in-line cloud security platform. Media Contacts Nick Gonzalez Sr. Manager, Media Relations [email protected] A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/6b96dd38-9f87-4353-85b3-13a0086fc129 ZSZscaler Inc$200.59-%Stock Score Locked: Want to See it? Benzinga Rankings give you vital metrics on any stock - anytime. Reveal Full ScoreEdge RankingsMomentum80.96Growth83.30Quality-Value1.56Price TrendShortMediumLongOverviewMarket News and Data brought to you by Benzinga APIs
[2]
Zscaler ThreatLabz Uncovers Surge in AI-Driven Cyberattacks Targeting Critical Business Operations
, (GLOBE NEWSWIRE) -- (NASDAQ: ZS), the leader in cloud security, today published its Zscaler ThreatLabz 2025 Phishing Report, analyzing over two billion blocked phishing attempts between January and captured by the Zscaler Zero Trust Exchangeâ„¢, the world's largest cloud security platform. The annual report exposes how cybercriminals are using Generative AI to launch surgical, targeted attacks against high-impact business functions - and why a + AI defense strategy is mission critical. The report uncovers a shift from high-volume email blasts to targeted, AI-fueled attacks designed to evade defenses and exploit human behavior. It also offers actionable insight to help organizations defend against this evolving threat landscape. "The phishing game has changed. Attackers are using GenAI to create near-flawless lures and even outsmart AI-based defenses," said Deepen Desai, CSO and Head of , . "Cybercriminals are weaponizing AI to evade detection and manipulate victims, which means organizations must leverage equally advanced AI-powered defenses to outpace these emerging threats. Our research reinforces the importance of adopting a proactive, multi-layered approach -- combining robust zero trust architecture with advanced AI-driven phishing prevention -- to effectively combat the rapidly evolving threat landscape." Emerging markets see a surge in phishing activity While phishing dropped overall by 20% globally and by nearly 32% in the , due in part to rising email authentication standards, attackers transitioned just as fast, launching more attacks on emerging markets like , , and , often where digital adoption outpaces security investment. Established targets like , , and the remain under sustained pressure, as threat actors adapt to local patterns and seasonal trends. Community platforms fuel phishing growth Phishing campaigns are increasingly abusing community-based platforms like Facebook, Telegram, Steam, and Instagram - not only spoofing their brands, but using them to distribute malware, mask C2 communications, gather target intel, and carry out social engineering attacks. Meanwhile, tech support scams, where attackers pose as IT support teams to exploit urgency and safety concerns of victims, remain widespread with 159,148,766 hits in 2024. Threat actors capitalize on AI: Phishing-as-a-Service and AI deception on the rise Cybercriminals are using GenAI to scale attacks, generate fake websites, and craft deepfake voice, video, and text for social engineering. New scams mimic AI tools - such as resume generators and design platforms - tricking users into handing over credentials or payment data. Critical departments like payroll, finance, and HR are prime targets, along with executives - as they hold the keys to sensitive systems, information, and processes, and can more easily approve fraudulent payments. Cybercriminals are also creating fake "AI assistant" or "AI agent" websites, falsely offering services such as resume generation, graphic design, workflow automation, and more. As AI tools become increasingly integrated into daily life, attackers are capitalizing on the ease of use and trust around AI to drive unsuspecting users to fraudulent sites. can help: Defending against AI threats with everywhere + AI As cybercriminals continue to use GenAI to develop new tactics and deliver more sophisticated attacks, enterprises need to strengthen their defenses against every type of compromise. The Zscaler Zero Trust Exchange protects users, applications, and data across all phases of the attack chain by: Zscaler AI-powered offerings add advanced protection by securing public AI use, shielding private AI models, and detecting AI-generated threats. Download the Report Get the full ThreatLabz 2025 Phishing Report to explore emerging trends and attack vectors. Learn why a + AI approach is critical to staying ahead of today's phishing threats. Download today. Research Methodology Zscaler ThreatLabz analyzed 2 billion blocked phishing transactions between January-December 2024, exploring various aspects including the top phishing attacks, targeted countries, hosting countries for phishing content, distribution of company types based on server IP addresses, and the top referrers linked to these phishing attacks. Additionally, ThreatLabz tracked and examined notable phishing trends and use cases observed throughout 2024. About ThreatLabz ThreatLabz is the security research arm of . This world-class team is responsible for hunting new threats and ensuring that the thousands of organizations using the global platform are always protected. In addition to malware research and behavioral analysis, team members are involved in the research and development of new prototype modules for advanced threat protection on the platform, and regularly conduct internal security audits to ensure that products and infrastructure meet security compliance standards. ThreatLabz regularly publishes in-depth analyses of new and emerging threats on its portal, research.zscaler.com. About (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchangeâ„¢ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across more than 150 data centers globally, the SASE-based Zero Trust Exchange is the world's largest in-line cloud security platform. Media Contacts Sr. Manager, Media Relations [email protected] A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/6b96dd38-9f87-4353-85b3-13a0086fc129
Share
Copy Link
Zscaler's 2025 Phishing Report uncovers a shift in cybercriminal tactics, with AI-powered attacks targeting high-impact business functions. The report highlights the need for advanced AI-driven defenses and zero trust architecture to combat evolving threats.
Zscaler, Inc., a leader in cloud security, has released its ThreatLabz 2025 Phishing Report, revealing a significant shift in cybercriminal tactics. The report, which analyzed over two billion blocked phishing attempts in 2024, highlights the increasing use of Generative AI (GenAI) by attackers to launch sophisticated, targeted attacks against critical business operations 12.
The report uncovered several important trends:
Cybercriminals are leveraging GenAI to enhance their attack capabilities:
Deepen Desai, CSO and Head of Security Research at Zscaler, noted, "The phishing game has changed. Attackers are using GenAI to create near-flawless lures and even outsmart AI-based defenses" 1. This shift represents a move from high-volume email blasts to more targeted, AI-fueled attacks designed to exploit human behavior and evade traditional security measures.
A new trend identified in the report is the creation of fake "AI assistant" or "AI agent" websites. These fraudulent sites offer services like resume generation, graphic design, and workflow automation, capitalizing on the growing trust and integration of AI tools in daily life 12.
To combat these evolving threats, Zscaler recommends a multi-layered approach:
While overall phishing attempts decreased globally, the report highlights a geographical shift in attack focus:
The Zscaler ThreatLabz 2025 Phishing Report underscores the critical need for organizations to adapt their cybersecurity strategies in the face of AI-driven threats. As cybercriminals continue to leverage advanced technologies, businesses must invest in equally sophisticated defense mechanisms to protect their critical operations and sensitive data.
NVIDIA announces significant upgrades to its GeForce NOW cloud gaming service, including RTX 5080-class performance, improved streaming quality, and an expanded game library, set to launch in September 2025.
10 Sources
Technology
19 hrs ago
10 Sources
Technology
19 hrs ago
Nvidia is reportedly developing a new AI chip, the B30A, based on its latest Blackwell architecture for the Chinese market. This chip is expected to outperform the currently allowed H20 model, raising questions about U.S. regulatory approval and the ongoing tech trade tensions between the U.S. and China.
11 Sources
Technology
19 hrs ago
11 Sources
Technology
19 hrs ago
SoftBank Group has agreed to invest $2 billion in Intel, buying common stock at $23 per share. This strategic investment comes as Intel undergoes a major restructuring under new CEO Lip-Bu Tan, aiming to regain its competitive edge in the semiconductor industry, particularly in AI chips.
18 Sources
Business
11 hrs ago
18 Sources
Business
11 hrs ago
Databricks, a data analytics firm, is set to raise its valuation to over $100 billion in a new funding round, showcasing the strong investor interest in AI startups. The company plans to use the funds for AI acquisitions and product development.
7 Sources
Business
3 hrs ago
7 Sources
Business
3 hrs ago
OpenAI introduces ChatGPT Go, a new subscription plan priced at ₹399 ($4.60) per month exclusively for Indian users, offering enhanced features and affordability to capture a larger market share.
15 Sources
Technology
11 hrs ago
15 Sources
Technology
11 hrs ago