KnowBe4 Q4 2025 Phishing Trends Report Reveals Surge in Personalized, Domain-Spoofed Attacks

KnowBe4 Q4 2025 Phishing Trends Report Reveals Surge in Personalized, Domain-Spoofed Attacks

Personalized phishing emails referencing company names record the highest click rates, while nearly 90% of top-clicked attacks rely on domain spoofing

KnowBe4, a global platform focused on human and agentic AI risk management, has released its Q4 2025 Phishing Simulation Roundup, highlighting how personalized messaging and internal workplace themes continue to drive the most successful phishing attacks.

The report analyzes simulated phishing tests conducted between October and December 2025, revealing that emails containing recipients’ company names generated the highest engagement. Internal workplace topics appeared in 100% of the top 10 most-clicked phishing subject lines, with HR-related themes referenced in 46% of cases. Messages impersonating IT notifications, training updates, and routine HR communications consistently ranked among the most effective phishing lures.

These findings reinforce insights from KnowBe4’s State of Human Risk Report 2025: The New Paradigm of Securing People in the AI Era, which emphasizes the growing need for comprehensive human risk management as cybercriminals increasingly rely on AI-enhanced social engineering techniques.

Cyber Technology Insights: Netmore Group Acquires Actility to Expand Global LPWAN and Massive IoT Leadership

The analysis also highlights the prevalence of domain spoofing. Among the top 20 most-clicked phishing links, approximately 87% referenced internal topics, while 90% involved spoofed domains, demonstrating how attackers closely mimic legitimate corporate infrastructure to build trust and prompt rapid action.

In addition to simulated tests, KnowBe4 examined real-world phishing threats reported through its Phish Alert Button. The top 10 most-reported attacks frequently impersonated trusted brands such as Microsoft, ShareFile, Google, Zoom, Adobe, Coinbase, and DHL, alongside internal IT and HR departments. Overall, 62% of phishing landing pages interacted with by users were branded, with Microsoft accounting for 22.9% of impersonated brands. Social media platforms collectively represented 14.5%.

“The fact that nearly 90% of top-clicked phishing attempts involved domain spoofing shows how effectively attackers are creating convincing illusions of legitimacy,” said Erich Kron, CISO Advisor at KnowBe4. “When employees see their company name, a manager’s name, or familiar internal systems referenced in an email, their instinct is to trust and act quickly. Technology alone isn’t enough—organizations must build a security-conscious culture that empowers employees to pause, question, and verify.”

Cyber Technology Insights: IQM Quantum Computers Appoints Jan Goetz as Sole CEO in Leadership Restructure

To participate in our interviews, please write to our CyberTech Media Room at info@intentamplify.com

Picture of CyberTech Media Room

CyberTech Media Room

CyberTech Media Room is the editorial intelligence arm of CyberTech Insights, focused on delivering high-impact narratives at the intersection of cybersecurity, data infrastructure, AI systems, and enterprise risk. Built for decision-makers, analysts, and technology leaders, the CyberTech Media Room translates complex security developments into structured, actionable intelligence. Its coverage spans threat landscapes, regulatory shifts, cyber resilience frameworks, and emerging technologies shaping modern enterprise defense. The editorial approach is grounded in three principles: Signal over noise — prioritizing relevance, depth, and strategic clarity over volume Intelligence-led storytelling — combining data, expert perspectives, and market context Decision utility — ensuring every piece contributes to informed business or technology outcomes CyberTech Media Room collaborates with industry practitioners, researchers, and enterprise leaders to surface insights that matter—from boardroom-level risk considerations to operational security strategies. Positioned beyond traditional media, it operates as a strategic intelligence layer for organizations navigating an increasingly complex and adversarial digital environment.

See Your Target Accounts Already in Market

We identify companies actively researching cybersecurity, CX, and enterprise tech solutions.

Includes sample accounts, intent signals, and activation strategy.

Access Real Buyer Intent Data for Cybersecurity & B2B Tech

Get a sample of verified in-market accounts, campaign benchmarks, and audience insights.

No spam. Only relevant insights and campaign data.

Get Verified B2B Buyers from Your Target Accounts

See how CyberTech Insights identifies in-market buyers, activates demand, and converts pipeline across cybersecurity and enterprise tech.

What are you looking to achieve?

Get Your Custom Audience & Pipeline Plan

We’ll share a sample audience, campaign benchmarks, and how we generate pipeline for companies like yours.