Menlo Security
Reports
All Statistics
One in three highly evasive threats originated from sites classified as 'safe'.
52,185 threats were hosted on domains that enterprise security stacks are configured to trust, including Google Drive, Dropbox, and SharePoint.
One in five phishing links clicked by users went completely undetected by legacy URL filtering.
57% of employees input sensitive data into free-tier AI tools.
73% of organisations in India reported implementing GenAI.
A staggering 155,005 copy attempts and 313,120 paste attempts were logged in a single month, demonstrating potential data exposure.
Four of the top five hosting providers used by bad actors to host phishing attacks were based in the U.S. in 2024.
One in five attacks in 2024 displayed some form of evasive technique designed to evade traditional network and endpoint-based security controls
Nearly 51% of browser-based phishing attempts involved some form of brand impersonation in 2024.
There were 10.53 billion visits to AI sites recorded in January 2025.
Web traffic to GenAI sites increased by 50%, from 7 billion visits in February 2024 to 10.53 billion in January 2025.
75% of organisations in China reported implementing GenAI.
68% of employees use free-tier AI tools like ChatGPT via personal accounts.
80% of AI access happens via browsers.
75% of phishing links are hosted on good, trusted websites.
Cybercriminals created nearly 1 million new phishing sites each month in 2024. This represents a 700% increase since 2020.
There is up to six days as the average window of exposure before legacy security tools begin blocking pages from zero-hour phishing attacks.
Menlo Security identified nearly 600 incidents of GenAI fraud in 2024.
There has been a 130% increase in zero-hour phishing attacks in 2024.
AWS and CloudFlare accounted for nearly 50% of all instances of abused cloud hosting instances in 2024.
Phishing attacks hosted on subdomain providers increased by 51% in 2024, representing 24% of all phishing attacks.
There has been a 140% increase in browser-based phishing attacks in 2024 compared to 2023.