Phishing, Spear-Phishing, and Vishing: Growing Sophistication and Persistence Similar to 2021, phishing, spear-phishing, and fraudulent emails comprised the most common vectors of cyberattack. The trend of increasing sophistication continued also into the last year. The NÚKIB also registered more vishing cases, i.e. fraudulent phone calls in which attackers attempt to gain access to the victim’s systems, along with extorting login credentials, particularly online banking information. During 2022, an attempted or successful phishing attack was experienced by 92% of respondents, spear-phishing emails by 49%, fraudulent emails by 89%, and vishing by 20%. Compared to the previous year, the data show a slight increase. The NÚKIB warned about these types of attacks several times during the past year in the form of warnings (see the Box). In reaction to phishing campaigns, the NÚKIB issued three alerts in 2022. Two of them were published in response to a vishing campaign in February and April. The perpetrators of this campaign aimed to persuade victims that their system had been compromised, which would then need to be resolved by a pretend Microsoft staff. However, the operator would instead attempt to access the victim‘s system through a remote access tool, used to obtain payment card details. He would also instruct the victim to confirm the two-step verification of sent payments or install a so-called keylogger on the victim‘s system. Alert to new wave of fraudulent vishing calls Alert to still continuing wave of fraudulent vishing calls In August, the NÚKIB issued an alert related to a phishing campaign using the subject of social housing allowances. Fraudulent messages were spread via email and SMS messages, attempting to trick victims into sharing their banking identities with the attackers. The campaign was active for several weeks. Alert to phishing campaign with aim to exploit bank identity The best defence against these attempts is the education of society, i.e. increasing people‘s awareness and caution and improving their ability to recognize these attempts. 92 % 89 % surveyed organizations stated they were targeted by a phishing attack or a phishing attempt in 2022 surveyed organizations stated that they were targeted by an attack or attempted attack in form of a fraudulent e-mail in 2022 (+2 % compared to 2021) (+5 % compared to 2021) 49 % 20 % surveyed organizations stated they were targeted by a spear-phishing attack or spearphishing attempt in 2022 surveyed organizations stated they were targeted by a vishing attack or vishing attempt in 2022 (+2 % compared to 2021) (+9 % compared to 2021) 18

Select target paragraph3