Phishing Exposure Surges Across Key U.S. Industries: Analysis from ANY.RUN
Recent research from ANY.RUN reveals a staggering phishing exposure rate of 69.9% across five critical sectors: finance, banking, manufacturing, technology, and government. This alarming statistic raises pressing questions about the underlying threats targeting these industries and the evolving tactics, techniques, and procedures (TTPs) employed by cyber adversaries.
The reality behind this statistic reflects the sophisticated nature of contemporary phishing campaigns. Increasingly, these attacks leverage advanced social engineering tactics combined with legitimate services and stealthy delivery methods. With the rise of adversary-in-the-middle (AiTM) phishing and session hijacking, credential theft has become a primary focus, posing significant challenges to organizations striving to protect sensitive data.
ANY.RUN’s analysis indicates that the finance sector exhibits the highest exposure to phishing, standing at 73.4%, closely followed by manufacturing at 72.2%. This highlights how threats impact a diverse range of industries, each with unique operational dynamics and security frameworks. Such high levels of exposure spotlight the pervasive nature of phishing threats and emphasize the need for proactive defense strategies.
The leading phishing threats identified in ANY.RUN’s submissions for 2026 include Tycoon, Sneaky2FA, ClickFix, EvilProxy, and EvilTokens, outlining a shift in the threat landscape that increasingly targets credential acquisition and user-driven execution. These threats extend beyond traditional malware delivery, making it imperative for organizations to adapt their cybersecurity strategies to counteract these evolving tactics.
Further examination of file types reveals that emails account for a significant portion of phishing threats, with finance reporting 58.7% of analyzed files and government and administration at 67.9%. The presence of malicious attachments, links, and post-click activities complicates detection efforts, necessitating a more nuanced approach beyond mere inbox controls.
To combat the rising tide of phishing, organizations can benefit from enhanced threat intelligence. This strategic resource can illuminate current TTPs, indicators of compromise (IOCs), and emergent threats specific to their operational context.
Effective threat intelligence can support organizations in three critical areas. First, by utilizing tools such as Threat Intelligence Lookups, security teams can investigate threats pertinent to their industry and geographic location, streamlining the process of threat recognition. This tool allows for deep dives into relationships between threats, enabling analysts to pivot to related sandbox investigations and tap into a wealth of data from other security professionals.
Second, continually updated threat research provides insights into evolving phishing tactics. By leveraging this information, organizations can refine their cybersecurity priorities, ensuring they remain aligned with the latest attack trends and risks pertinent to their respective industries.
Finally, integrating threat intelligence into detection workflows ensures that security teams have access to real-time IOCs enriched with relevant context. This capability not only enhances detection accuracy but also minimizes the manual research burden on security analysts, empowering them to respond more effectively to phishing incidents.
In conclusion, as phishing continues to pose a significant risk across various U.S. industries, it remains crucial for security leaders to prioritize understanding the threats most relevant to their operational environments. By leveraging threat intelligence effectively, they can transform raw data into actionable insights, ultimately enhancing their defense strategies against potential cyber-attacks.