Evolution of phishing threats in 2025
Source: Promo
Wednesday, 22.10.2025.
11:00
Wednesday, 22.10.2025.
11:00
(Photo: Shutterstock)
The report reveals how cybercriminals are reviving and refining phishing techniques targeting individuals and businesses in 2025.
The report highlights calendar attacks, voicemail scams, and sophisticated multifactor authentication (MFA) bypass schemes.
Calendar phishing targeting office workers
(Photo: Unsplash/Icons8 Team)
A technique that dates back to the late 2010s has resurfaced, now focused on the B2B environment.
Attackers send emails with invitations to calendar events, often without any text in the body of the message, while malicious links are hidden in the event description.
When the event is opened, it is automatically added to the user’s calendar, with reminders encouraging them to click on links that lead to fake login pages, such as those impersonating Microsoft.
While previous campaigns have targeted private Google Calendar users in mass attacks, this method now targets office workers.
Organizations should regularly conduct phishing awareness training, such as mock attack workshops, to teach employees how to check for unexpected calendar invitations.
Phishing with voicemails and CAPTCHA evasion
Phishing attackers use minimalist emails that pretend to be voicemail notifications, with very little text and a link to a simple page.
Clicking on the link triggers a series of CAPTCHA verifications to bypass security bots, and the user is ultimately redirected to a fake Google login page that validates email addresses and collects login credentials.
This multi-layered scam highlights the need for employee training programs, such as interactive modules for recognizing suspicious links, as well as advanced email server protection solutions like KasperskySecureMail, which detect and block these covert tactics.
Bypassing multifactor authentication via fake logins to cloud services
(Photo: ShutterPNPhotography/shutterstock.com)
These sophisticated phishing campaigns target multifactor authentication (MFA) by impersonating services such as pCloud (a cloud storage provider that offers encrypted file storage, sharing, and backup).
These emails, disguised as neutral support in the form of previous contact tracing, lead to fake login pages on domains that resemble the real ones (e.g. pcloud.online).
The pages communicate with the real pCloud service via APIs, validating email addresses and requesting one-time passwords (OTPs) and passwords, granting attackers access to the account after a successful login.
To counter this, organizations should introduce mandatory cybersecurity training and implement email protection solutions such as Kaspersky Security for Mail Servers, which detects fake domains and attacks launched via APIs.
“As phishing schemes become increasingly insidious, Kaspersky advises users to be especially cautious with unusual email attachments, such as password-protected PDF files or QR codes, and to always check website URLs before entering any login details. Organizations should adopt comprehensive training programs, including real-world simulations and best practices for recognizing phishing attempts. In addition, implementing robust email server protection solutions enables real-time detection and blocking of advanced phishing tactics,” said Roman Dedenok, Anti-Spam Expert at Kaspersky.
Companies:
Kaspersky
Tags:
Kaspersky
KasperskySecureMail
Kaspersky Security for Mail Servers
Roman Dedenok
cyber crime
phishing threats
email
protection
simulated attack workshops
cyber security
Comments
Your comment
Most Important News
Full information is available only to commercial users-subscribers and it is necessary to log in.
Pratite na našem portalu vesti, tendere, investicione projekte, grantove i pravnu regulativu.
Registracija na eKapiji vam omogućava pristup potpunim informacijama i dnevnom biltenu
Naš dnevni ekonomski bilten će stizati na vašu mejl adresu krajem svakog radnog dana. Bilteni su personalizovani prema interesovanjima svakog korisnika zasebno,
uz konsultacije sa našim ekspertima.

Izdanje Srbija
Serbische Ausgabe
Izdanje BiH
Izdanje Crna Gora