Phishing Exposure Nears 70% Across Finance, Manufacturing and Other U.S. Industries
What Happened — ANY.RUN’s recent telemetry shows that 69.9 % of organizations in five key U.S. sectors experienced at least one phishing attempt over the last reporting period. Finance and manufacturing recorded the highest exposure rates, with the remaining sectors (healthcare, retail, technology) also showing significant activity.
Why It Matters for Trust & Control Assurance —
- Continuous monitoring of phishing activity is a core evidence source for the security‑awareness control objective that spans NIST CSF, ISO 27001 and other frameworks.
- Documented training, simulated phishing tests, and response metrics provide a defensible audit trail that demonstrates due‑diligence.
- Without a measurable awareness program, organizations struggle to prove they have mitigated credential‑theft risk, a frequent trigger for data‑exfiltration incidents.
Who Is Affected — Finance, manufacturing, healthcare, retail, and technology firms operating in the United States.
Recommended Actions —
- Deploy a regular, automated phishing‑simulation campaign and capture completion / click‑through rates.
- Align training records with the control objective for credential protection and map them to your audit framework of record.
- Strengthen email‑gateway filtering and enforce DMARC/DKIM/SPF policies to reduce inbound phishing volume.
Source: HackRead article
Technical Notes — The exposure is driven by credential‑phishing emails that embed malicious links or attachments; no specific vulnerability or CVE is involved. Attack vector: phishing (social engineering). Source: ANY.RUN telemetry cited in the article.