The biggest threat to your online security
Summary
This blueAPACHE post reports: A recent study by Google has found phishing to be the biggest threat to your online security. As the digital footprint of internet users expands to encompass social networks, financial records and data stored in the cloud, account takeover, or hijacking, is a widespread problem that’s not just limited to high-profile accounts. It concerns Human Risk Management, emPOWER Security, Managed Detection & Response. It names Google in connection with the announcement. Published in 2017. Figures, product names and event details reflect that time; for current information see the linked service pages.
Key facts
| Label | Value |
|---|---|
| Publication year | 2017 |
| Services referenced | Human Risk Management, emPOWER Security, Managed Detection & Response |
| Named products or vendors |
Article
A recent study by Google has found phishing to be the biggest threat to your online security. As the digital footprint of internet users expands to encompass social networks, financial records and data stored in the cloud, account takeover, or hijacking, is a widespread problem that’s not just limited to high-profile accounts. Often, a single account or email address underpins a user’s entire online identity. Once this is compromised, a hijacker can reset a victim’s passwords to other services as a stepping stone attack, download all of the victim’s private data, remotely wipe the victim’s data and backups or impersonate the victim to launch further attacks. In order to better understand how hijackers attempt to take over accounts in the wild, Google teamed up with the University of California, Berkeley, and using Google accounts as a case-study, analysed several black markets to see how hijackers steal passwords and other sensitive data. The study captured three market segments – 1) Credentials leaks via third party data braches 2) Phishing kits that deceive users into submitting their credentials and 3) Keyloggers the harvest passwords from infected machines. To conduct the study, black market actors and stolen credentials were monitored using a custom developed automated framework, from March 2016 to March 2017. The result? Phishing posed the greatest threat, followed by keyloggers and finally third-party breaches. The study found that 25 percent of phishing victims have their current Google password exposed, compared to 12 percent of keylogger victims and 7 percent of victims in third party data breaches. While this is a global phenomenon, phishing largely affected victims in the United States, South Africa and Canada. Victims of phishing are also 400 times more likely to be successfully hijacked compared to a random Google user.
Phishing kits
The deadly threat stemmed from the ease of deploying phishing kits – “ready-to-deploy” packages for creating and configuring phishing content that deceive users into submitting their credentials to fake login pages – that can harvest a victim’s username, password, and geolocation information among other sensitive data.
The yearlong study identified 4,069 distinct phishing kits, many of which use email as a mechanism to forward stolen credentials to operators concentrated in Nigeria, the United States and other African countries.
Yahoo, Hotmail, Gmail and other mail providers were the most frequently spoofed brands generating almost 1.5 million reports of stolen credentials. Other brands spoofed by the top phishing kits include file storage services like Dropbox and Office 365.
What can you do?
Google has reported it is using insights from the study to improve login defences for all users. It has launched new security features, including safe browsing and the Advanced Protection program to prevent attacks.
Ultimately, cybersecurity is a collective responsibility and the importance of good cybersecurity hygiene cannot be overlooked. This means avoiding unfamiliar websites, never clicking on links or downloading attachments from unknown email senders, enabling multi-factor authentication (MFA), keeping systems updated with the latest security patches and using reputable security products.
blueAPACHE’s phishing exploit testing Software-as-a-Service (SaaS) platform, PhishTrain, is an easy way to test your employees’ ability to resist such attacks. It can help you assess your staff’s current security awareness level and train them to differentiate between a legitimate email and a targeted phishing email from a malicious attacker. To know more, contact the blueAPACHE security team.
The original research paper can be viewed here.
Related
Frequently asked questions
What organisations conducted the phishing study cited in this article, and over what period?
The article cites a study conducted by Google in partnership with the University of California, Berkeley, using Google accounts as a case study and monitoring black-market actors and stolen credentials from March 2016 to March 2017.
What percentage of phishing victims had their current Google password exposed, compared to other attack types?
The article says 25 percent of phishing victims had their current Google password exposed, compared to 12 percent of keylogger victims and 7 percent of victims of third-party data breaches.
How many distinct phishing kits did the study identify, and where were operators concentrated?
The study identified 4,069 distinct phishing kits, many using email to forward stolen credentials to operators concentrated in Nigeria, the United States and other African countries.
What blueAPACHE product does the article recommend for testing staff resistance to phishing?
The article recommends blueAPACHE's PhishTrain, a phishing exploit testing Software-as-a-Service platform, to assess staff security awareness and train them to differentiate legitimate emails from targeted phishing attempts.
Is the information in this post still current?
No. It reports a 2017 Google/UC Berkeley phishing study; for blueAPACHE's current phishing and security awareness services, see the emPOWER Security pillar page rather than this post.
Source
https://www.blueapache.com/blog/the-biggest-threat-to-your-online-security/
Knowledge Base
According to the Google study discussed in the blueAPACHE article, what is the biggest threat to online security?
Phishing is the biggest threat to online security, according to a study by Google, followed by keyloggers and then third-party data breaches.
Who conducted the study on account hijacking referenced in the article, and how was it conducted?
Google teamed up with the University of California, Berkeley, using Google accounts as a case study. They analysed several black markets to understand how hijackers steal passwords and sensitive data, monitoring black market actors and stolen credentials with a custom-developed automated framework from March 2016 to March 2017.
What three market segments did the Google/UC Berkeley study capture regarding account hijacking?
The study captured three market segments: 1) credential leaks via third-party data breaches, 2) phishing kits that deceive users into submitting their credentials, and 3) keyloggers that harvest passwords from infected machines.
What percentage of phishing victims had their current Google password exposed, compared to keylogger and data breach victims?
25 percent of phishing victims had their current Google password exposed, compared to 12 percent of keylogger victims and 7 percent of victims in third-party data breaches.
How much more likely are phishing victims to be successfully hijacked compared to a random Google user?
Victims of phishing are 400 times more likely to be successfully hijacked compared to a random Google user.
Which countries were most affected by phishing according to the study?
Phishing largely affected victims in the United States, South Africa and Canada.
How many distinct phishing kits did the yearlong study identify, and where were operators concentrated?
The study identified 4,069 distinct phishing kits. Many of these kits use email to forward stolen credentials to operators concentrated in Nigeria, the United States, and other African countries.
Which brands were most frequently spoofed by phishing kits, and how many stolen credential reports did they generate?
Yahoo, Hotmail, Gmail and other mail providers were the most frequently spoofed brands, generating almost 1.5 million reports of stolen credentials. Other spoofed brands included file storage services like Dropbox and Office 365.
What security features has Google launched in response to insights from this phishing study?
Google has launched new security features, including Safe Browsing and the Advanced Protection program, to prevent attacks, using insights gained from the study to improve login defences for all users.
What cybersecurity hygiene practices does the article recommend to protect against phishing?
The article recommends avoiding unfamiliar websites, never clicking on links or downloading attachments from unknown email senders, enabling multi-factor authentication (MFA), keeping systems updated with the latest security patches, and using reputable security products.
What is PhishTrain and how does it help organizations?
PhishTrain is blueAPACHE's phishing exploit testing Software-as-a-Service (SaaS) platform. It provides an easy way to test employees' ability to resist phishing attacks, assess staff's current security awareness level, and train them to differentiate between a legitimate email and a targeted phishing email from a malicious attacker.
When was 'The biggest threat to your online security' article published and who wrote it?
The article was written by blueAPACHE and published on December 13, 2017.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bdfb153d68a8eeb6acc_Google-Phishing-Study.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701be1b153d68a8eeb6b53_Phish-table.png
Phishing table
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.
-
https://www.facebook.com/tr?id=541021476571056&ev=PageView&noscript=1
(no alt text)