The Public PurviewThe Public Purview
Font ResizerAa
  • Home
  • Top Stories
  • Pakistan
    • Regional
  • World
    • China Insights
    • Saudi Arabia Insights
    • Qatar Insights
    • UAE Insights
    • Ethiopia Insights
  • Business
  • Education
  • Health
  • Sports
  • Showbiz
  • Tech
  • Tourism
  • Blog
    • Opinion
    • Editorial
  • Interviews
    • Ambassador
  • Epaper Archive
Font ResizerAa
The Public PurviewThe Public Purview
Search
  • Home
  • Top Stories
  • Pakistan
    • Regional
  • World
    • China Insights
    • Saudi Arabia Insights
    • Qatar Insights
    • UAE Insights
    • Ethiopia Insights
  • Business
  • Education
  • Health
  • Sports
  • Showbiz
  • Tech
  • Tourism
  • Blog
    • Opinion
    • Editorial
  • Interviews
    • Ambassador
  • Epaper Archive
Follow US
The Public Purview > Home News > Business > Nearly 90% of phishing attacks aim to steal online account credentials, Kaspersky finds
Business

Nearly 90% of phishing attacks aim to steal online account credentials, Kaspersky finds

Last updated: January 21, 2026 2:44 pm
Abid Saeed
Share
3 Min Read
Nearly 90% of phishing attacks aim to steal online account credentials, Kaspersky finds
SHARE

Nearly 90% of phishing attacks worldwide are designed to steal login credentials for digital accounts, according to new research by Kaspersky, highlighting how cybercriminals increasingly focus on long-term access rather than immediate financial theft.

Contents
Phishing remains one of the most widespread cyber threatsStolen credentials resold on underground marketsLong-term risks from reused and enriched dataSecurity recommendations

Kaspersky’s analysis of phishing and scam campaigns observed between January and September 2025 found that 88.5% of attacks targeted credentials for online accounts, while 9.5% focused on personal data such as names, addresses, and dates of birth. Only 2% of phishing campaigns targeted bank card details, the report said.

Phishing remains one of the most widespread cyber threats

According to Kaspersky, millions of phishing links were clicked during the previous year, all of which were detected and blocked by the company’s security solutions. However, the firm noted that many users still lack adequate protection, allowing phishing attacks to remain one of the most common and effective cyber threats.

Also Read: QR phishing attacks surge fivefold in late 2025: Kaspersky

Attackers typically lure users to fake websites that closely resemble legitimate services, tricking them into entering usernames, passwords, personal information, or payment details. Stolen data is then transmitted through email, messaging platforms such as Telegram, or attacker-controlled dashboards before being prepared for resale.

Stolen credentials resold on underground markets

Kaspersky’s research shows that data obtained through phishing is rarely used only once. Credentials collected from multiple campaigns are often combined into large datasets and sold on underground marketplaces, sometimes for as little as $50 per bundle.

According to Kaspersky Digital Footprint Intelligence, average prices in 2025 ranged from about $0.90 for access to global internet portals, $105 for cryptocurrency platform accounts, and up to $350 for online banking access. Personal documents, including passports and ID cards, sold for an average of $15, with prices influenced by factors such as account age, balances, linked payment methods, and security settings.

Long-term risks from reused and enriched data

As stolen datasets are enriched and merged, attackers can build detailed digital profiles of individuals. These profiles may later be used in targeted attacks against executives, finance staff, IT administrators, or individuals with valuable assets or sensitive documents.

“Our analysis shows that credentials account for nearly 90% of phishing attempts,” said Olga Altukhova, senior web content analyst at Kaspersky. She noted that even older credentials can remain valuable when combined with new data, enabling account takeovers, identity theft, blackmail, or financial fraud years after the initial compromise.

Security recommendations

To reduce phishing risks, Kaspersky advises users to avoid clicking on links or opening attachments from unknown or suspicious sources, carefully verify senders, and double-check website addresses before entering personal or financial information.

The company also recommends enabling multi-factor authentication wherever available, regularly reviewing account login activity, and closing any suspicious sessions to limit potential damage from compromised credentials.

You Might Also Like

Five-Day Project Management Training for PESCO Employees Concludes

Blockchain Bonds Could Help Pakistan Broaden Investor Base, Experts Say

Islamabad Industrial Association Says Budget Falls Short of Industry Expectations

Gold Prices Rise in Global and Local Markets

Gold rate in Pakistan surges above Rs440,000 per tola on June 12

Share This Article
Facebook Twitter Copy Link Print

Follow US

Find US on Social Medias
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
Popular News
AI System Transforms Public Bidding Regulation in China’s Anhui Province

AI System Transforms Public Bidding Regulation in China’s Anhui Province

June 14, 2026
Chinese Vice Premier Calls for Stronger Salt Lake Industries, Disaster Response in Qinghai

Chinese Vice Premier Calls for Stronger Salt Lake Industries, Disaster Response in Qinghai

June 14, 2026
China Launches $11.3bn Waterway Project to Ease Yangtze River Shipping Bottleneck

China Launches $11.3bn Waterway Project to Ease Yangtze River Shipping Bottleneck

June 14, 2026
Ensuring Muharram peace

Ensuring Muharram peace

June 14, 2026
BLA: Is it an Insurgent Movement or Terrorist Organization?

BLA: Is it an Insurgent Movement or Terrorist Organization?

June 14, 2026
Today's E-Paper

You Might Also Like

Wafi Energy, NHMP and Rescue Agencies Conduct Emergency Response Drill on Lahore–Sialkot Motorway
Business

Wafi Energy, NHMP and Rescue Agencies Conduct Emergency Response Drill on Lahore–Sialkot Motorway

June 12, 2026
Gold Prices Fall Below Rs433,000 Per Tola After Sharp Rs9,720 Drop
Business

Gold Prices Fall Below Rs433,000 Per Tola After Sharp Rs9,720 Drop

June 11, 2026
Mari Energies Says No Spinwam Gas Sale Will Proceed Without OGRA Approval
Business

Mari Energies Says No Spinwam Gas Sale Will Proceed Without OGRA Approval

June 11, 2026
Digital Economy Projects Retain Priority Status Despite PSDP Funding Pressures
Business

Digital Economy Projects Retain Priority Status Despite PSDP Funding Pressures

June 11, 2026
  • Epaper Archive
  • Disclaimer | The Public Purview – Accuracy, Transparency, and Responsibility
  • Terms of Service
  • About Us | The Public Purview
  • Contact Us
Welcome Back!

Sign in to your account

Lost your password?