TL;DR: Nearly 77% of all email attacks contain a phishing link, according to Abnormal AI, underscoring why phishing remains the primary delivery path for account compromise and downstream fraud. The real control gap is not awareness alone but whether email, identity, and response workflows can stop bait before users act.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Gone Phishing? Catching the Phish Before Your Employees Bite”.
By the numbers:
- Nearly 77% of all email attacks contain a phishing link.
Key questions
Q: How should security teams reduce the risk of phishing links in email attacks?
A: Combine email filtering with identity controls that limit damage after a click.
Q: Why do traditional email security tools still miss modern phishing campaigns?
A: Traditional email security relies heavily on reputation checks, URL scanning, and automated detonation, but attackers now design phishing infrastructure to frustrate those methods.
Practitioner guidance
- Tighten link inspection and URL rewriting Inspect destination reputation, redirect chains, and impersonation cues before the user reaches a login page or credential prompt.
- Connect email alerts to identity response Trigger account review, token revocation, or session invalidation when a phishing message is reported or a suspicious click is detected.
- Make reporting the fastest path Give users a single, low-friction way to report suspicious email and ensure the SOC can triage those reports in real time.
Bottom line: Phishing remains a delivery mechanism that turns email into an identity problem once a user engages with a malicious link.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Phishing is now an identity control failure as much as an email problem. Email filtering can reduce exposure, but the decisive failure occurs when a message is able to induce authentication, authorisation, or trust transfer from the user. That shifts phishing out of the narrow inbox category and into IAM governance, where identity assurance and response speed become part of the same control surface.
A few things that frame the scale:
- Roughly 1 in 3 phishing payloads are delivered outside email, through channels such as social media, search ads and messaging apps.
A question worth separating out:
Q: What should security teams do when a phishing link has already been clicked?
A: Act immediately. Disconnect the device from the internet if possible, avoid entering any further information, and change affected passwords from a separate trusted device. Run a malware scan and report the incident to the IT or security team so they can monitor for compromise, contain any spread, and review whether other accounts were exposed.
👉 Read our full editorial: Phishing remains the primary email attack vector for enterprises