Categories

No categories

Phishing — key trends in 2025

June 26, 2025
Eye23
Book11 min
Background

Phishing is plague of the 21st century! Does it sound loud? But it is reality. Today, almost everyone has encountered this fraudulent tool, and most of these people have fallen victim to phishing. How do scammers work? What are the most effective techniques? And most importantly – how to fight it?

Some statistics

And so, 2022 was the year of beginning of the AI revolution in the world, which became even stronger with appearance of GPTChat from OpenAI. Fraudsters were quick to recognise that they had an almost limitless tool for analysing and filtering information. This has resulted in phishing attacks that are more sophisticated and targeted than ever before. Artificial intelligence algorithms are used to analyse, target data, identify and exploit vulnerabilities and analyse evasion techniques.

Since 2020, there has been a nearly 95% increase in phishing and fraud activity, with security systems identifying nearly 2 million fraudulent sites per month. AI has contributed to much of this growth. There has been a record increase in phishing activity in nearly 20 countries. Registration of new phishing domains is booming here, and more often than not, this trend coincides with general pattern of growth of this type of fraud in a country.

The top 10 countries with the most phishing domains are the United States (4.89 million registrations), Germany (1.153 million registrations), Canada (0.498 million registrations), Russia (0.414 million registrations) and the United Kingdom (0.3 million registrations). The Netherlands, France, Australia, China, Singapore and the Netherlands rank 6th-10th respectively.

Key phishing trends in 2025

Targeted attacks of institutions with large amounts of sensitive information (banks, finance, startups, technology companies, business representatives).

Spoofing phishing sites to look like well-known brands. Over 6,000 such cases have been reported in 2023 and more than 100 brands have been affected by this activity.

Holidays are favourite time for phishing scams. People are active spenders, focused on pleasure and relaxed, which affects their attentiveness.

Hackers research social and economic crises and create their strategies with these burning topics in mind.

While in 2023, attackers mainly used GPT models to generate malware, phishing email, and deceive users, by 2025, scale and the level of attack automation has increased markedly.

In 2024-2025, specialised tools based on various LLMs (large language models), including GPT-4/4.5, Anthropic's Claude, Google's Gemini and Mistral — for spyware creation, social engineering scenario generation and API attack automation — began to proliferate in shadow forums. Some models are adapted to bypass antifraud, generate realistic dialogues, forge documents and gather information from public sources.

Separate tools allow hackers to "train" models on stolen correspondence or corporate data, making attacks even more targeted and dangerous.

By 2025, AI is becoming a key element in the arsenal of cybercriminals, not just an ancillary element. Countering such threats requires the development of specialised solutions to track and block AI-generated malicious content, as well as tighter controls on access to advanced language models.

According to 2024-2025 data, Cloudflare, Amazon Web Services (AWS), Google Cloud, Microsoft Azure, as well as SEDO GmbH, Namecheap, Unified Layer, DDOS-GUARD, etc. are actively used. The number of malicious resources hosted through these services is in millions. Criminals take advantage of ease of registration, high reliability and trust in these brands, which makes it difficult to identify threats.

Attackers continue to use popular and trusted domain zones such as com, .org, .net, as well as national and quasi-Cyrillic variants such as .ru, .ру, .рф. The u.se of new TLDs such as .app, .xyz, .online and .zip is also on the rise, especially in phishing and malvertising campaigns.

Experts emphasise that the mere fact that a website belongs to a well-known domain or hosting does not guarantee its security anymore. Phishing and malicious links are increasingly disguised as legitimate resources, including subdomains and mirrors of real brands. Even if the link looks familiar, don't let your guard down. The use of extensions to check reputation of a site and antivirus solutions with function of analysing URLs remains a relevant protection measure.

Impersonation attacks have been on the rise in recent years, where cybercriminals use trust and authority of individuals to fraudulently gain access to sensitive information or funds. This can range from using well-known personalities (Elon Musk, for example) to targeted phishing on companies (impersonating communications with executives, top managers and analysts, impersonating regulators, and so on):

  • ill be more targeted, meeting the personal needs of each victim thanks to ability to assess your digital footprint on the web with help of artificial intelligence. You will have a feeling of exclusivity of the offer, moreover, thanks to targeted pressure and emphasis of the pain, you will be in more of hurry and reduce attention, which works in hands of fraudsters;

  • deepfake. Many people have seen videos of colossal quality and veracity that are made with deepfake technology. This technology is already being used by phishing companies to make them as realistic and deep as possible. You can fake a voice, a video, and gain trust of a potential victim;

  • supply chain attacks. Attackers are increasingly targeting third-party suppliers and partners to gain access to an organisation's network. It is therefore critical for businesses to secure entire supply chain and verify even long-standing contacts;

  • smishing and vishing. New types of phishing: smishing and vishing. Scammers are no longer limited to standard mailings. They are now making phone calls (vishing) and SMS (smishing). You've probably received these calls before, as this is the hottest trend in the world;

  • use of popular social networks. A frequent source of threat is social networks. Telegram, WhatsApp and Snapchat are especially popular because many official companies communicate with customers there.

What are the basic rules of phishing protection to follow?

There are basic rules of digital security that work for phishing as well. To avoid becoming victim of scammers you need to:

  • check URLs of sites you visit. Even a 1 letter difference is a reason to avoid visiting. This is exactly how phishing works – by focusing on your inattention;

  • do not click on suspicious e-mail attachments, even if e-mail came from your contact. If in doubt, it's better to double-check alternatively whether it really came from a familiar number. After all, the account could simply have been hacked.

Log out of all devices in the app if you detect suspicious activity in your account. Update your security settings.

Don't ignore recommended software updates, because they also work against cyber threats.

Do not use public Wi-Fi networks, especially when connecting to applications with sensitive information (online banking, crypto wallet, payment service).

Protect your accounts with two-factor authentication. This is the easiest and most effective anti-phishing tool available.

Anexet warns: the problem of phishing is not as ephemeral and easy as you might think at first glance. It is a real klondike for scammers, which they take advantage of. Be vigilant and secure your data as much as possible.

Advertisement

Explore the power of Anexet right now!

Start Free Trial