Interisle Consulting Group has collected data and published measurements on phishing since May 2020. Annually, we’ve published phishing landscape studies on the scope and distribution of phishing and we’ve collected the same data sources at our Cybercrime Information Center so that our analyses would be longitudinally consistent.
In this series of posts, we will share some of the measurements, observations and findings as we prepare our fifth study.
We begin by looking at phishing attacks and how phishers acquired name resources since May 2020.
700% increase in phishing attacks
Phishing attacks reported by our contributing feeds increased steadily from May 2020 through May 2022. A dramatic increase persisted until November 2022, when a key supply chain for phishers was disrupted.
The number of domain names reported for phishing tracked closely with phishing attacks until February 2023, when litigation forced Freenom to cease operations. Freenom, a commercial ccTLD operator, had been a major resource for free domain names in five TLDs: .CF, .GA, .GQ, .ML, and .TK.
Litigation proved more effective than operational mitigation efforts, and phishers had to scramble to find alternative name resources for their attacks.
Phishers found ample naming alternatives at free web hosting providers. Many of these offer free web site hosting and a free name: a subdomain in a legitimately registered domain, for example, ph1betaphishy911.blogspot.com or 1800w3arephishing4free.vercel.app.
It’s no coincidence that phishing attacks hosted on free web sites swelled in 2024. Note how phishing attacks that used (subdomains) of free web hosting nearly compensated fully for the loss of phish friendly Freenom in between February 2023 and October 2023.
Phishing declined generally in the August – October 2023 period. Much of this is attributed to a significant decline in phishing activity hosted on free web sites (especially Google’s blogspot).
In our next posts, we’ll look at how phishing activity soared in ’24, and where phishers flocked to acquire name resources.