Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Vishing, platform abuse and SEG bypass: what security teams need to know


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Vishing attacks rose 449%, phishing sent from legitimate platforms increased 70%, and attacks bypassing secure email gateways climbed 38%, according to KnowBe4’s 2025 Phishing Threat Trends Report, Vol. 6, highlighting how social engineering now blends voice, brand abuse, and trusted delivery paths. That combination weakens traditional email-only defences and raises the value of identity-aware controls.

NHIMG editorial — based on content published by KnowBe4: 2025 Phishing Threat Trends Report, Vol. 6

By the numbers:

Questions worth separating out

Q: How should security teams reduce vishing success against privileged users?

A: Security teams should harden the workflows that vishing targets first: password resets, MFA resets, help desk overrides, and privileged support requests.

Q: Why do legitimate-platform phishing campaigns bypass traditional controls so often?

A: They bypass traditional controls because many defences assume malicious delivery comes from suspicious infrastructure.

Q: What do organisations get wrong about secure email gateways and phishing defence?

A: The main mistake is treating the secure email gateway as the primary trust boundary.

Practitioner guidance

  • Harden reset and recovery workflows Require stronger verification for password resets, MFA resets, and help desk account recovery, especially for privileged users and support staff.
  • Review trusted-platform abuse detection Add detections for suspicious use of legitimate platforms, unusual tenant behaviour, and anomalous sending patterns.
  • Tie phishing response to identity telemetry Correlate email, identity provider, and help desk activity so that a suspicious message is not treated as an isolated mail event.

What's in the full report

KnowBe4's full report covers the operational detail this post intentionally leaves for the source:

  • The report's scenario discussion of what happens after a user responds to vishing.
  • The broader breakdown of Scattered Spider's campaign methods against global retail giants.
  • The report's full stat set on legitimate-platform abuse and secure email gateway bypass.
  • The original research context behind the 2025 phishing trend data and how it was compiled.

👉 Read KnowBe4's 2025 Phishing Threat Trends Report on vishing, platform abuse, and SEG bypass →

Vishing, platform abuse and SEG bypass: what security teams need to know?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Trusted-channel abuse is now a core phishing governance problem. The report shows that attackers are no longer relying only on malicious links and spoofed domains. They are leveraging voice, legitimate platforms, and brand trust to bypass the first line of defence. For practitioners, that means phishing defence has become an identity assurance problem as much as a mail security problem.

A question worth separating out:

Q: What should organisations do when helpdesk password recovery is a phishing target?

A: Organisations should unify helpdesk and self-service recovery under one verification standard, then require all exceptions to be logged and reviewed. The aim is to remove split trust models, because attackers often target the channel with the weakest identity proofing and the most pressure-driven operators.

👉 Read our full editorial: Phishing threat trends show vishing and platform abuse rising fast



   
ReplyQuote
Share: