Phishing Dominates US Cyberattacks, Costing Billions Annually
Phishing remains the primary vector for cyberattacks against US companies, responsible for 80% of incidents and contributing to over $20 billion in losses since 2013, according to FBI data.

Phishing continues to be the most prevalent and effective method for cybercriminals to breach corporate defenses, with the FBI reporting that 80% of attacks on US companies originate from this vector. Between 2013 and 2023, the FBI recorded over 158,000 victims of Business Email Compromise (BEC) alone, resulting in staggering losses exceeding $20 billion. These attacks primarily aim to steal corporate credentials, granting attackers access to sensitive networks and data.
Despite significant investments in traditional security measures such as email gateways, endpoint protection, and employee awareness training, attackers consistently find novel ways to circumvent these defenses. Modern phishing campaigns are highly sophisticated, leveraging compromised infrastructure, legitimate cloud services, intricate redirect chains, dynamic web pages, and advanced social engineering tactics. The increasing accessibility of AI tools further lowers the barrier for creating convincing and large-scale phishing operations, making it harder for organizations to stay ahead.
For Security Operations Centers (SOCs) and Chief Information Security Officers (CISOs), the challenge lies in detecting these evolving threats early enough to prevent a full-blown incident. A single successful phishing attempt can initiate a cascade of malicious activities, including credential theft, account compromise, lateral movement within the network, financial fraud, and further phishing attacks. The earlier the malicious infrastructure or intent is identified, the greater the opportunity to disrupt this attack chain.
Traditional security controls often rely on reputation-based blocking, known indicators of compromise (IOCs), and static analysis. While these methods offer a baseline level of protection, they frequently fall short against sophisticated phishing campaigns that utilize newly registered domains, legitimate redirect services, and conditional logic to evade detection. By the time indicators are incorporated into conventional threat intelligence feeds, they may already be outdated or lack the crucial context that security analysts need for effective assessment.
To combat this persistent threat, SOCs must prioritize the integration of fresh, high-confidence threat intelligence. This intelligence should focus on recently observed malicious infrastructure and campaigns, providing actionable insights that enable proactive disruption rather than reactive cleanup. By combining up-to-date threat indicators with analyst-curated intelligence on active campaigns, security teams can significantly enhance their detection capabilities, accelerate incident triage, and shift their posture from responding to phishing incidents to actively preventing them.
Tools like ANY.RUN's Threat Intelligence (TI) Feeds offer a solution by providing SOC teams with visibility into emerging threats through interactive sandbox investigations. These feeds deliver a high volume of unique IOCs, including malicious IP addresses, domains, and URLs, enriched with contextual data from thousands of real-world malware and phishing analyses. This approach aims to deliver high-confidence intelligence with near-zero false positives, allowing for earlier detection of malicious infrastructure before it can be exploited.
The practical advantages of using such fresh intelligence include earlier detection of threats, higher fidelity in alerts due to enriched data, and the potential for automation. By integrating TI Feeds into existing security infrastructure via APIs or standards like STIX/TAXII, organizations can automate detection, correlation, alerting, and threat hunting. This operationalization of threat intelligence can lead to a significant increase in identified threats, faster Mean Time to Respond (MTTR), and a reduction in escalations, transforming threat intelligence from a manual research task into a continuous, automated defense mechanism.
Beyond raw indicators, threat intelligence reports provide crucial context that aids analysts in faster triage. These expert-curated research pieces offer overviews of recent cyber threats, including detailed information on targeted industries, TTPs, IOCs, and indicators of behavior (IOBs) and attack (IOAs). This comprehensive context allows SOC teams to quickly assess the nature and scope of a potential threat, identify related indicators, and strengthen their existing detection rules, ultimately improving their ability to defend against sophisticated and rapidly evolving phishing attacks.