PHISHING ATTACKS 2020–2025: TRENDS, TACTICS, AND DEFENSE STRATEGIES

Автор: Julia Iarajuli, Sandra Mkheidze, Elene Mchedlidze, Anastasia Kundukhashvili, Maksim Iavich
Организация: University of Young Penetration Testers, Caucasus University

Категория:

Ключевые слова: Phishing attacks, AI, Zero Trust architecture
Аннотация. Between 2020 and 2025, phishing attacks have evolved significantly in both technical and strategic dimensions. This study analyzes global trends using open cybersecurity sources and highlights the increasing sophistication of phishing techniques, including BEC, vishing, smishing, whaling, and search engine phishing. The research identifies the most affected sectors — finance, healthcare, and education — and evaluates modern defense mechanisms such as AI-powered filters, behavioral biometrics, and Zero Trust architectures. Findings indicate that attacks have become increasingly realistic and difficult to detect. Based on the results, the study recommends adopting integrated, multi-layered defense strategies and emphasizes the importance of AI technologies in phishing prevention.

Библиография:

Verizon. 2024 Data Breach Investigations Report. Verizon, 2024
Anti-Phishing Working Group (APWG). Phishing Activity Trends Report. APWG, 2023
IBM X-Force. Threat Intelligence Index 2025. IBM Security, 2025
Kaspersky Labs. The Rise of Deepfake Phishing. Kaspersky, 2023
European Union Agency for Cybersecurity (ENISA). Threat Landscape Report 2024. ENISA, 2024