Q2 Phishing Report: The Latest Scams Exploiting Human Trust
- By Erich Kron, KnowBe4
- June 09, 2025

Phishing attacks just keep getting craftier — it’s a nonstop arms race out there with cybercrooks targeting unsuspecting individuals through a range of strategies aimed at pilfering personal and financial data. Whether in the guise of fake news, deceptive device codes, or spoof text messages, cybercrooks consistently adapt their methods to prey on human trust and curiosity. Below is an in-depth look at some of the craftiest phishing tactics to watch out for in Q2.
Mourning and malware: Taking advantage of emotional moments
High-profile global events that capture people's attention and evoke emotional reactions have always been a fertile ground for fraudsters. Fraudsters recently exploited the passing away of Pope Francis by creating deepfake images and false reports and publishing them on social media platforms such as Instagram, TikTok, or Facebook to attract users' attention and prompt them to find out more. Clicking on social media posts can take users to fraudulent websites that steal their personal and financial information. Some clicks redirect users to fake Google pages that promote bogus gift card offers ending in financial fraud.
Hackers use SEO poisoning to manipulate search engine rankings, inserting malicious sites between legitimate search results. Victims seeking information on Pope Francis may click on a fake URL, believing it to be legitimate, inadvertently enabling hackers to propagate malware, steal credentials, or harvest session cookies for financial gain.
Device code hijacking: Bypassing security measures
Cybercrooks have mastered the use of device code authentication to phish, tricking users into unwittingly providing access to accounts. If you've ever attempted to open a video streaming site like Netflix on your TV, it will display a numeric code that you enter on your phone. Once you enter the code, your TV logs into your streaming account without the need to log in each time the service is used.
This scam operates with insidious cleverness. Upon receiving an email or message containing a device code, the recipient is instructed to click a link and input the code to authenticate with a genuine page of the service. However, the message is not from the legitimate service; it is the work of an online attacker.

Here's what's really going down: The attacker starts a login to your account, which makes the service create a device code. They pass this code on to you and trust you to input it on the given page. If you do, you essentially authenticate their device to get into your account. At that stage, they have access as if they were you. The worst thing is that this attack does not need you to click on harmful links or malicious attachments. Instead, it uses ordinary user habits and routines to achieve success.
Smishing: The text message trap
Fraudsters are using text messages that appear to originate from reputable local institutions such as government entities, toll agencies, tax authorities, or postal services. The messages usually include official logos and branding to make them seem real. The message informs you that you have an outstanding bill, fee, or toll that you must pay and asks you to click on a link so you can settle the bill before a penalty is charged.
But the message is actually a smishing (SMS phishing) message, seeking to steal your data. If you click the link, you’re sent to a fraudulent website that harvests your personal and financial details.
Best practices to avoid and prevent phishing
Protecting against fake news and malicious websites: Encourage employees to confirm news or payment requests through official channels. Avoid interacting with viral social media posts that seem overly sensationalized. Deploy reputation-based URL filtering to block access to fraudulent sites. Keep browsers and operating systems updated to protect against malware.
- Detect and prevent smishing attacks: Inform employees about the threat of SMS phishing (smishing) and spoofed urgent payments. Utilize mobile security software to scan and block malicious links. Encourage employees to double-check financial transactions by visiting official websites rather than clicking on text message links.
- Improve human risk management: Assess vulnerabilities stemming from human behavior, including errors, manipulation, and intentional actions. By consistently analyzing end-user behaviors, implementing customized interventions, and driving behavioral change through comprehensive cybersecurity awareness training, organizations can effectively mitigate the risks posed by social engineering and phishing threats.
- Secure authentication processes: Turn off device code authentication for high-risk accounts or enforce additional verification procedures. Implement an additional layer of account protection through multi-factor authentication (MFA). Mandate password administration policies, such as strong, new passwords and regular changes.
- Implement real-time threat intelligence: Collaborate with industry cybersecurity networks to exchange intelligence and harden defenses. Track and study phishing trends to predict upcoming threats. AI-based threat detection can identify potential phishing activity in real time.
Phishing tactics constantly change, and the best defense against cybercrime is awareness. By using a converged strategy of technology, training, and active monitoring, organizations can effectively reduce exposure to phishing. Adapting responses to emerging threats and maintaining round-the-clock vigilance will boost their resilience against phishing attacks.
The views and opinions expressed in this article are those of the author and do not necessarily reflect those of CDOTrends. Image credit: iStockphoto/SvetaZi
Erich Kron, KnowBe4
Erich Kron is the security awareness advocate for KnowBe4, the cybersecurity platform that comprehensively addresses human risk management with over 70,000 customers and more than 60 million users. A 25-year veteran information security professional with experience in the medical, aerospace, manufacturing, and defense fields, he was a security manager for the U.S. Army's 2nd Regional Cyber Center-Western Hemisphere and holds CISSP, CISSP-ISSAP, SACP, and other certifications. Erich has worked with information security professionals around the world to provide tools, training, and educational opportunities to succeed in information security.