White Paper | Phishing Threats Delivered Via Email
Discover how email phishing drives 63-68% of global malicious file distribution, targeting sectors like finance and government. Learn about top attack methods, regional insights, and strategies to strengthen email security. Download now to stay protected!

PHISHING THREATS DELIVERED VIA EMAIL
2PHISHING THRE ATS DEL I VERED V I A EMA IL
Executive Summary Email-based phishing remains a critical security threat, with 63-68% of malicious files distributed via email. Key findings from September-November 2024:
Overview Email phishing remains one of the most significant cybersecurity challenges, serving as the primary vector for the distribution of malicious files worldwide. The latest data from Check Point Research reveals that phishing attacks delivered via email have targeted various sectors and regions, with executable files (EXE), PDFs, spreadsheets (XLS) and JS files being the most common file types used in these attacks.
This report focuses mainly on threats delivered via files, which remain a popular vector. The overall phishing landscape includes file-less, text-based threats, as well as zero-click attacks that execute upon delivery.
In general, the threat landscape is vast, and this data shows the incredible importance of file scanning, anti-virus and malware protection.
This analysis was run multiple times; first, during the week of September 16th and then during the week November 4th. All data reflects the previous 30 days from the day of analysis.
Critical Sectors Finance/Banking
remains most targeted (89-93% of attacks)
Regional Impact Africa experiences
highest attack rates
Attack Methods EXE files dominate (54-55%), with emerging prominence
of JS files (15% in November)
SEPTEMBER
16
SEPTEMBER
16
NOVEMBER
4
NOVEMBER
4
3PHISHING THRE ATS DEL I VERED V I A EMA IL
Global Email Phishing Statistics • 68% of malicious files were distributed via email in the last 30 days. • 1 out of every 983 email attachments are malicious. • 1 out of every 482 email links is malicious. • 1 out of every 56 malicious emails involves sextortion.
• 63% of malicious files distributed via email in the last 30 days. • 1 out of every 1069 email attachments are malicious. • 1 out of every 764 links in emails is malicious. • 1 out of every 66 malicious emails is sextortion.
Malicious File Types in Email Phishing The most commonly used file types in phishing emails over the last 30 days were:
• EXE (55.5%) • PDF (20.4%) • XLS (6.7%) • DOCX (5.1%)
The most commonly used file types in phishing emails over the last 30 days were:
• EXE (54.3%) • js (15%) • PDF (10%) • DOCX (5.6%)
These file types are frequently employed to deliver malware, ransomware, and other forms of cyberattacks, often with the intent of exploiting vulnerabilities within organizations.
4PHISHING THRE ATS DEL I VERED V I A EMA IL
Sector-Specific Phishing Vulnerabilities • Finance & Banking was the most heavily targeted sector, with 93% of malicious files
delivered via email. This highlights the sensitive nature of financial information and the appeal for cybercriminals.
• Communications (96%) and Leisure & Hospitality (92%) also saw high levels of email phishing activity via file, largely due to the heavy flow of personal and transactional data in these industries.
• Government & Military worldwide experienced 82% of their malicious files via email, with EXE files accounting for 52% of threats, making it a critical sector for national security.
• Manufacturing (85%) also faced significant threats, with EXE files representing 72% of the total malicious files.
• Finance & Banking remains the most highly targeted sector, with 89% of malicious files delivered via email.
• Government/military worldwide experienced 83% of malicious files delivered via email, with EXE files accounting for 65%.
• Leisure & Hospitality and Communications both received high amount of phishing via files, with 83 and 82% respectively.
• Manufacturing saw a decrease from September, down to 63%.
Regional Breakdown of Phishing Threats • Africa had the highest percentage of malicious files delivered via email,
at 89%, with EXE files (76%) being the dominant attack vector. • In North America, 64% of malicious files were delivered through email,
with 61% of these being EXE files and 20% PDFs. • Latin America saw 58% of malicious files arrive via email, where PDFs almost
equaled EXE files in prevalence (42% vs. 44%). • Europe experienced 74% of malicious files arriving by email, while EXE files (61%)
and PDF files (16%) led the list. • Asia had 60% of malicious files delivered by email, with EXE files (62%) dominating
the threats.
SEPTEMBER
16
NOVEMBER
4
SEPTEMBER
16
5PHISHING THRE ATS DEL I VERED V I A EMA IL
• Though Africa saw a decrease from September, it remained at the top of malicious files delivered via email, at 69%. EXE (77%) remain the dominant attack vector.
• In North America, just 29% of malicious files were delivered via email. 54% were delivered via EXE.
• In Europe, 67% of malicious files were delivered via email, with 54% being EXE. • In Latin America, 41% of malicious files were delivered via email. 73% were EXE. • In Asia, 50% of malicious files were delivered via email. 67% of these were EXE.
Mobile Phishing Insights The data also highlights the growing threat of phishing over mobile devices:
• 1 out of every 12 visits to a malicious website is to a phishing site. • 1 out of every 4 phishing attacks over mobile networks occurs over SSL
(Secure Sockets Layer), making it harder for victims to detect malicious activity.
• 1 out of every 12 entrances to a malicious website is to a phishing site. • 1 out of ever 3 phishing attacks over mobile networks occurs over SSL.
NOVEMBER
4
SEPTEMBER
16
NOVEMBER
4
6PHISHING THRE ATS DEL I VERED V I A EMA IL
1. Percentage of Malicious Files Delivered via Email Across Regions
The bar chart below shows the percentage of malicious files delivered via email in different regions, with Africa leading at 89% and Latin America having the lowest percentage at 58%.
SEPTEMBER
16
NOVEMBER
4
100
80
60
40
20
0
PE RC
EN TA
GE (%
)
North America Latin America Africa Asia Europe Middle East
REGIONS
Percentage of Malicious Files Delivered via Email Across Regions
50
70
60
40
30
20
10
0
PE RC
EN TA
GE O
F M AL
IC IO
US FI
LE S
(% )
North America Africa AsiaEurope Latin America
REGIONS
Percentage of Malicious Files Delivered via Email Across Regions
7PHISHING THRE ATS DEL I VERED V I A EMA IL
2. Email Phishing Vulnerabilities by Sector
This horizontal bar chart highlights the vulnerability of different sectors to email phishing attacks. Finance & Banking and Communications are the most targeted sectors.
60 80 10040200
Leisure and Hospitality
Communications
Healthcare
Retail and Wholesale
Education and Research
Finance and Banking
Government and Military
Manufacturing
PERCENTAGE (%)
Percentage of Malicious Files Delivered via Email Across Sectors
60 80 10040200
Finance and Banking
Manufacturing
Government and Military
Communications
Leisure and Hospitality
Education and Research
Healthcare
Retail and Wholesale
PERCENTAGE (%)
Malicious Files Delivered via Email by Industry
SEPTEMBER
16
NOVEMBER
4
8PHISHING THRE ATS DEL I VERED V I A EMA IL
3. Top Malicious File Types Distribution by Region
This clustered bar chart compares the distribution of malicious file types (EXE, PDF, XLS, DOCX, ZIP, RTF) across regions. EXE files dominate in most regions, but there are some variations, such as Latin America's high use of PDFs.
SEPTEMBER
16
NOVEMBER
4
50
40
70
60
30
20
10
0
PE RC
EN TA
GE (%
)
EXE PDF RTFXLS DOCX ZIP
File Types
Top Malicious File Types Distribution by Region
North America Latin America Africa Asia Europe Middle East
50
40
70
80
60
30
20
10
0
PE RC
EN TA
GE (%
)
EXE PDF RTF XLSDOCX ZIPPPT CMD JS
File Types
Top Malicious File Types Distribution by Region
North America Latin America Africa Asia Europe Middle East
9PHISHING THRE ATS DEL I VERED V I A EMA IL
Recommended Mitigation Strategies Organizations are encouraged to implement mitigation strategies to ensure protection against email-based threats. These include:
• Deploy AI-powered email filtering that can block malicious emails before reaching the inbox
• Implement DMARC, SPF, and DKIM
• Block executable attachments by default
• Sandbox attachments before delivery
Conclusion Phishing threats delivered via email continue to be a dominant attack vector, particularly in critical industries like finance, government, and communications. Executable files (EXE) are the most commonly used malicious file type across all sectors and regions, although PDFs and XLS files also feature prominently in phishing campaigns.
The regional and sector-specific insights from Check Point Research suggest that organizations need to prioritize email security to mitigate the ever-growing risk of phishing attacks. Robust email filtering, user awareness training, and multi-factor authentication can significantly reduce the success of phishing campaigns.
Worldwide Headquarters 5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599
U.S. Headquarters 100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel: 1-800-429-4391
www.checkpoint.com
© 2024 Check Point Software Technologies Ltd. All rights reserved.
Bookmark 1 Zero Trust and Why You Should Embrace It