Incidents According to Entities: Growing Frequency and Higher
Sophistication of Phishing Attacks
The most common types of cyberattacks experienced by surveyed organisations during
2022 were phishing, external network scanning, and fraudulent emails (see Graph 4). These
types of attacks are less technically demanding and easy to detect; they appear regularly in
our statistics. A key difference compared to the previous year has been the entities´ perception
of spear-phishing, which has been declared the most serious type of attack according to the
surveyed organizations (see Graph 5). This is probably (55-70 %) due to growing sophistication
and persistence of attackers carrying out such attacks. Various forms of phishing and fraudulent
e-mails also continue to represent one of the most common vectors of cyberattacks globally.3
Overall, 68% of surveyed organizations experienced an attempted cyberattack during 2022;
however, only 24% experienced a breach of confidentiality, integrity, or availability of information
or services (see Graph 6).
50%
40%
40
37 39
30%
27
20%
26
16
21
17
14
15
14
10%
7
6
3
0%
Phishing
Scanning
Scam e-mail
Harmful content
2
6
4
Spear-phishing
2020
6
Other
2021
2022
Graph 4: Most Frequent Types of Cyberattacks in 2020 - 2022 (in % of Respondents)
50%
44
40%
32
30%
21
20%
10%
13 11
15
9
17
12
11
19
18
9
6
2
0%
Spear-phishing
Phishing
Scam e-mail
9
0
Vulnerability
exploitation attempt
2
Scanning
Other
2020
2021
2022
Graph 5: Most Severe Types of Cyberattacks in 2020 - 2022 (in % of Respondents)
Microsoft. 2022. Microsoft Digital Defense Report 2022. https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/
RE5bUvv?culture=en-us&country=us
3
10