Proofpoint’s 2024 State of the Phish Report: 68% of Employees Willingly Gamble with Organizational Security
Proofpoint, Inc.
Proofpoint, Inc.

Human-centric threats continue to impact organizations with reports of direct financial penalties due to phishing up 144% and reports of reputational damage up 50%

SUNNYVALE, Calif., Feb. 27, 2024 (GLOBE NEWSWIRE) -- Proofpoint, Inc., a leading cybersecurity and compliance company, today released its tenth annual State of the Phish report, revealing that more than two-thirds (68%) of employees knowingly put their organizations at risk, potentially leading to ransomware or malware infections, data breaches, or financial loss. And while the incidence of successful phishing attacks has slightly declined (71% of surveyed organizations experienced at least one successful attack in 2023 versus 84% the previous year), the negative consequences have soared: a 144% increase in reports of financial penalties, such as regulatory fines, and a 50% increase in reports of reputational damage.

The findings from this year’s report notably challenge the traditional belief that people take risky actions due to a lack of cybersecurity knowledge and that security awareness training alone can fully prevent unsafe behaviors. The conundrum extends to security professionals’ belief that most employees know they are responsible for protecting the organization, signaling a gap between the limitations of individual security technology and user education.

“Cybercriminals know that humans can be easily exploited, either through negligence, compromised identity—or in some instances—malicious intent,” said Ryan Kalember, chief strategy officer, Proofpoint. “Individuals play a central role in an organization’s security posture, with 74% of breaches still centering on the human element. While fostering security culture is important, training alone is not a silver bullet. Knowing what to do and doing it are two different things. The challenge is now not just awareness, but behavior change.”

This year’s State of the Phish report provides an in-depth overview of the current threat landscape where generative AI, QR codes, and multifactor authentication (MFA) are abused by malicious actors, as sourced by Proofpoint’s telemetry of more than 2.8 trillion scanned emails across 230,000 organizations worldwide, as well as findings from 183 million simulated phishing attacks sent over a twelve-month period. The report also examines the perceptions of 7,500 employees and 1,050 security professionals across 15 countries, showing how attitudes towards security manifest in real-world behavior and how threat actors are finding new ways to take advantage of our preference for speed and expedience, as well as the current state of security awareness initiatives.