What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Proofpoint’s 2024 State of the Phish report found that risky security behavior was not simply a matter of people failing to recognize danger: among surveyed working adults who took at least one risky action, 96% said they knew it carried risk. The report, released February 27, 2024, examines 2023 activity and survey responses—not current 2026 prevalence.

What the 2024 State of the Phish report found

The report’s central lesson is that awareness alone does not guarantee safer choices. Proofpoint said 71% of surveyed working adults took at least one risky action, and 96% of that group said they knew the action was risky. Proofpoint described the combined result as 68% of employees knowingly putting their organizations at risk. These figures have different denominators: 96% applies only to adults who reported taking a risky action, while 68% is Proofpoint’s derived overall share.

Ryan Kalember, Proofpoint’s chief strategy officer, summarized the gap: “Knowing what to do and doing it are two different things.” Proofpoint also reported that 94% of surveyed participants said they would pay more attention to security if controls were simpler and more user-friendly. Together, these findings point to convenience and usability as important parts of the security problem, alongside training.

How common were successful phishing and ransomware incidents?

In Proofpoint’s survey of IT professionals, 71% of surveyed organizations reported at least one successful phishing attack in 2023, compared with 84% in 2022. These are reported experiences among survey respondents; they do not mean that 71% of all organizations were breached.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The same report found that 69% of surveyed organizations reported a ransomware infection in 2023, up from 64% in 2022. The share that reported paying a ransom fell to 54% from 64%. These are survey results, not a census of all organizations or a measure of every ransomware incident.

What did Proofpoint report about BEC, MFA bypass, and phone-based attacks?

Business email compromise

Proofpoint said it detected and blocked an average of 66 million business email compromise (BEC) attacks per month. That is Proofpoint’s own detection telemetry, not a count of all BEC attacks worldwide. BEC is email fraud that uses impersonation or deception; schemes can involve fraudulent invoices, payroll redirection, advance-fee fraud, or extortion. Proofpoint’s BEC overview explains the threat.

MFA bypass

Proofpoint reported more than one million EvilProxy MFA-bypass attacks per month, while 89% of surveyed security professionals believed MFA completely protected against account takeover. The contrast highlights a risk of treating MFA as complete protection. MFA remains a valuable security measure, but organizations should not assume it prevents every account takeover or phishing technique.

Telephone-oriented attack delivery

Proofpoint reported an average of 10 million telephone-oriented attack delivery (TOAD) incidents per month, with a peak of 13 million in August 2023. TOAD attacks use phone calls as part of the delivery or persuasion process, often to draw a target into a fraudulent interaction. These figures are Proofpoint-reported observations, not a global incident census.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How Proofpoint assembled the report

Proofpoint released the tenth annual report on February 27, 2024. Its overview describes a commissioned survey of 7,500 working adults and 1,050 IT professionals in 15 countries, along with 183 million simulated phishing attacks sent by Proofpoint customers and more than 24 million suspicious emails reported by customer end users. The accompanying release separately describes Proofpoint telemetry spanning more than 2.8 trillion scanned emails across 230,000 organizations. Survey responses, customer simulation results, user-reported messages, and company telemetry are distinct evidence sources and should not be treated as interchangeable.

The reviewed report summaries do not provide questionnaire wording, sampling weights, response rates, or confidence intervals. The survey statistics therefore describe the respondents and reported organizational experiences; they do not establish a precise rate for every employee or organization. Attack and behavior figures refer to 2023 and were published in 2024.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the findings mean for security programs

The report suggests that organizations should measure behavior and make secure actions practical, rather than treating course completion as proof that people will act safely. Relevant program measures include whether simulations reflect current threats, whether employees report suspicious messages, and how people respond in both simulations and real incidents. Proofpoint’s materials do not establish that a particular security-awareness vendor or product outperforms another.

  • Design for usability: Review whether security controls make the safe choice clear and convenient; 94% of survey participants said simpler, more user-friendly controls would make them pay more attention to security.
  • Measure actions as well as knowledge: Track reporting and response behavior in addition to training participation or quiz scores.
  • Keep simulations current: Test against realistic, changing lures rather than relying only on familiar examples.
  • Use multiple defenses: Retain MFA while planning for bypass attempts and other routes to account compromise.

In its follow-up guidance, Proofpoint advises watching for urgency, requests for sensitive information, emotional appeals, mismatches between sender addresses and display names, and lookalike domains. It notes that AI-generated phishing may avoid obvious spelling or grammar mistakes. These cues can help employees scrutinize a message, but they are not a guaranteed detection checklist.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.