Report: Malicious Phishing Takes Hold Globally

By Pete Rizzo (@pete_rizzo_)  

Released on September 18, a new report from the Anti-Phishing Working Group (APWG) has found that the volume of phishing attacks around the globe decreased markedly during the first half of 2013, falling from 123,486 unique events in the second half of 2012 to the 72,758 observed from January to June.

There was, however, one alarming statistic that indicated phishing will remain a problem for businesses and consumers – the number of domain names that the APWG believes were registered maliciously by phishers with the intent to commit fraud rose to 12,173. This figure was up from the 5,835 observed during the previous study period.

To illustrate how common malicious websites are globally, the APWG analyzed the metric ‘Phishing Domains per 10,000 domains.’ Top-level domains are the common website suffixes – such as .com, .uk and .me – that can correspond to specific countries.

“Phishing Domains per 10,000 is a ratio of the number of domain names used for phishing in a [top-level domain] TLD to the number of registered domain names in that TLD,” the report authors wrote. “This metric is a way of revealing whether a TLD has a higher or lower incidence of phishing relative to others.”

The result is a detailed estimate of how many top-level domains in countries around the world were either started maliciously or hacked by phishers during the six-month study period.

Phishing Domains Per 10,000 Websites – Global 

From the chart, you can see that while websites in the developed world have remained insulated from harmful phishing domains, phishing websites are common in South America, Asia and Africa.

Phishing Domains Per 10,000 Websites – South America

Top-level domains in South American countries were revealed to have high levels of fraudulent domains related to phishing. The problem was most pronounced in Ecuador, Peru and Paraguay, each of which were found to have more than 12 phishing websites per 10,000 domains.

However, these figures pale to the nations that were found to be the biggest offenders.*

Phishing Domains Per 10,000 Websites – Worst Offenders

By comparison, the researchers observed only 1.4 phishing domains per 10,000 domains originating in the United States.

For more insights and analysis, and a host of additional statistics about the phishing epidemic, click here for the full report.

To take a look at which industries are most affected by phishing, view a suplemental infographic here.
 
*These nations were removed from the world map to allow us to better illustrate the findings.