Messaging Fraud Surge: Phishing‑Driven Spam Up 94% in 2025, Blocking ↑ 77%
What Happened — Fraudsters amplified SMS, voice and chat attacks in 2025, pushing phishing‑laden traffic that grew 94% year‑over‑year. Infobip, a global communications‑platform provider, reported a 77% rise in blocked messages between 2024‑2025 as its detection stack caught more malicious content, including a six‑fold increase in image‑based scams.
Why It Matters for Compliance & Audit Readiness
- The spike in credential‑theft (phishing, smishing) tests the effectiveness of your SOC 2 Security controls around access management and incident detection.
- Real‑time classification and continuous monitoring, as demonstrated by Infobip, provide the audit evidence needed to prove that anti‑fraud controls are operating as designed.
- A robust Security Awareness Training program is a core SOC 2 control (CC6.1) that mitigates the human‑factor risk highlighted by the surge in phishing attempts.
Who Is Affected
- SaaS communications platforms (e.g., API providers, CPaaS)
- Enterprises that rely on SMS, voice or chat for authentication, order notifications and customer outreach (retail, fintech, travel).
Recommended Actions
- Map phishing‑related incidents to SOC 2 CC6.1 (Security Awareness) and CC7.1 (Incident Management) controls; capture training completion and detection logs as audit evidence.
- Deploy real‑time content‑analysis (including OCR for image‑based scams) and integrate alerts into a centralized SIEM for continuous monitoring.
- Refresh employee phishing simulations quarterly and track remediation metrics to demonstrate ongoing diligence.
Source: Help Net Security – Messaging fraud trends point to smarter attacks, stronger blocking
Technical Notes
- Attack vectors: phishing (SMS “smishing”), credential‑theft campaigns, image‑embedded malicious text.
- No specific CVE; the threat is driven by social‑engineering tactics rather than software flaws.
- Data types targeted: authentication codes, payment confirmations, account‑recovery messages.