HomeNews
Phishing Risk Across 5 Key US Industries: ANY.RUN Data & Mitigation Strategies
HomeNews
Phishing Risk Across 5 Key US Industries: ANY.RUN Data & Mitigation Strategies

According to fresh ANY.RUN data, phishing exposure remains above 70% in several critical industries. This doesn’t happen because organizations aren’t protected enough. Companies have been implementing email filtering, MFA, and phishing-awareness training for years.

However, threats continue to evolve, and security methods that were highly effective yesterday can develop visibility gaps as attackers adapt.

In this article, ANY.RUN explores data-driven insights to get to the bottom of phishing risk across key industries in the United States and examines how SOC teams can mitigate it.

See our previous article on phishing risk among US-based financial organizations.

Phishing Risk Remains High Across Critical Industries

Phishing exposure statistics based on ANY.RUN submissions data, 2026

As the statistics show, very different industries face almost the same level of phishing exposure. For several critical industries, that exposure is above average. According to ANY.RUN data, phishing exposure reaches 73.4% in finance and 72.2% in manufacturing.

Part of the reason lies in how quickly threat actors evolve and adapt their techniques. AI makes convincing social engineering easier to scale, while techniques such as AiTM phishing and session theft make identity compromise increasingly difficult to prevent.

Explore broader threat landscape with H1 2026 Cyber Risk Report

Phishing campaigns increasingly combine sophisticated social engineering with identity-focused techniques, legitimate services, and evasive delivery methods.

The types of submissions most frequently analyzed in ANY.RUN’s Interactive Sandbox also show that email security alone cannot cover the entire attack surface:

Most Analyzed File Types in ANY.RUN, 2026

Finance  Government & Administration  
58.7% email messages  67.9% email messages 
16.3% archives  15.6% archives 
11.2% Office documents   6.7% PDFs  

Email remains central, while the attack surface extends further into the files, links, and other content delivered through it.

Based on ANY.RUN submissions data, 2026

And it’s hard to blame users alone. Threat actors have become skilled at mimicking legitimate and niche documents, hiding payloads inside encrypted archives, and using techniques such as QR-code phishing to make malicious content harder to recognize at a glance.

Without enhanced visibility, modern phishing attacks can be difficult to unravel even for experienced security teams. Analysts need to see beyond the initial email or file and understand what happens after a user opens a document, follows a link, or interacts with a malicious page.

The Bigger Challenge: Phishing Is Becoming an Identity Attack

A deeper look at threats targeting critical sectors shows just how much the nature of phishing has changed.

In banking, ClickFix shows 71% prevalence.

More on ClickFix

ClickFix campaigns use fake errors, CAPTCHAs, or verification prompts to manipulate users into copying and executing malicious commands themselves. This allows attackers to turn social engineering into direct execution on the victim’s device. Read more on Malware Trends Tracker

A typical ClickFix “CAPTCHA” making user run a malicious command. ANY.RUN Sandbox analysis

It is followed by EtherHiding (63.8%), a technique that abuses legitimate blockchain infrastructure to host or retrieve malicious code, and Sneaky2FA (62.3%).

More on Sneaky2FA

Sneaky2FA – a phishing-as-a-service (PhaaS) kit designed to steal credentials and authentication sessions through adversary-in-the-middle (AiTM) techniques. Read more on Malware Trends Tracker

All terms aside, what this means is that modern phishing chains can:

  • manipulate users into executing commands
  • intercept authentication sessions
  • steal credentials or tokens
  • abuse legitimate infrastructure

Only some of those threatening methods can be covered by email filtering, awareness training, and MFA. Overall, these tools cannot provide complete coverage against rapidly changing phishing techniques.

Threat Prevalence in Banking:

  • 71% of ClickFix
  • 63.8% EtherHiding
  • 62.3% Sneaky2FA

Together, these threats illustrate a broader shift: the attack no longer ends with detecting a malicious attachment. The same pattern is visible in the technology sector. Sneaky2FA and ClickFix also appear among the leading threats, alongside Tycoon, EvilProxy, and EvilTokens, reinforcing the growing focus on credentials, authentication sessions, and identity.

Key Threats in Technology:

  1. Tycoon
  2. Sneaky2FA
  3. EvilProxy
  4. ClickFix
  5. EvilTokens

Tycoon and EvilProxy use AiTM phishing techniques to capture credentials and authentication data, while EvilTokens targets access tokens and authenticated sessions. Instead of simply trying to deliver malware, these attacks increasingly target the identities and access that organizations rely on.

PhaaS makes sophisticated phishing techniques easier to deploy at scale. AI makes lures more convincing and easier to personalize. AiTM and token theft demonstrate that protecting passwords alone may not be enough to prevent compromise.

Close the visibility gaps modern phishing exploits. 
Reveal hidden attack behavior with ANY.RUN.

Explore for Your SOC

On top of that, attackers increasingly abuse trusted, legitimate services and infrastructure, making malicious activity harder for both users and traditional security controls to recognize.

All of this points to a major security gap: visibility. Blocking the original email is only one layer of defense. Your SOC needs more.

Mitigation: Gain Visibility Before Phishing Turns Into a Breach

Modern phishing attacks are built to evade static controls, abuse legitimate services, and hide malicious behavior behind user interaction. It takes enhanced threats visibility both into the wider threat landscape and malicious activity happening inside specific campaigns.

This is where behavioral analysis and threat intelligence can give defenders the upper hand.

Expose the Full Attack Chain in Seconds

Instead of relying only on the initial email, URL, or file, analysts can safely detonate suspicious content in ANY.RUN’s Interactive Sandbox and observe the attack as it unfolds. With its capabilities, SOC analysts gain an additional layer of visibility into malware and phishing behavior.

The JavaScript file import inside PDF Viewer. Investigation within ANY.RUN Sandbox

Automated Interactivity performs the actions needed to expose evasive behavior without repetitive manual effort, helping analysts investigate threats involving password-protected archives, CAPTCHAs, malicious QR codes, and other interactive attack chains. In-browser data inspection provides deeper visibility into browser activity, redirects, scripts, requests, and other artifacts involved in the attack.

Most importantly, all of this takes just seconds.

Average MTTD with ANY.RUN is just 14 seconds, with similarly fast detection across the critical industries: 16.3 sec for banking and 17 sec for technology.

The result is a much clearer and faster path from alert to response:

Suspicious email → Detonate safely → Reveal behavior → Identify the threat → Respond

Full-scale visibility into threat behavior, including evasive phishing, helps streamline daily SOC workflows and accelerate response before threats can progress further.

Turn threat visibility into faster response. 
Achieve 14-second average MTTD with ANY.RUN. 

Explore for Your SOC

For SOC teams, this means:

  • Faster threat detection: identify malicious behavior in seconds.
  • Less manual investigation: automate repetitive interactions and analysis steps.
  • Greater visibility: expose redirects, scripts, network activity, and complete attack chains.
  • Faster response: move from suspicious artifact to informed action sooner.
  • Reduced risk exposure: contain threats before they can progress across the infrastructure.
  • Stronger privacy and compliance: keep sensitive investigations private and support enterprise security requirements.

Investigate Beyond a Single Phishing Attempt

A detected attack can also become a starting point for broader threat investigation.

With Threat Intelligence Lookup (TI Lookup), analysts can search threat data by industry, geography, malware, IOCs, techniques, and other parameters to understand whether suspicious activity is part of a wider campaign or relevant to their environment. AI-powered natural-language search makes this threat data easier to explore without constructing complex queries manually.

TI Lookup query: submissionCountry:”us” AND industry:”Manufacturing”

AI search in TI Lookup turns natural language requests into queries that let you explore threat landscape

For organizations facing high phishing exposure, Threat Intelligence Feeds (TI Feeds) extends this visibility into daily detection and response workflows. Fresh, high-confidence IOCs derived from real-world investigations can be delivered directly into the existing security stack, helping teams detect emerging threats, enrich alerts, and respond without adding more manual work.

Threat Intelligence Feeds by ANY.RUN deliver 99% unique indicators to security stacks

Together, threat intelligence and interactive sandboxing help SOC teams investigate threats faster, strengthen detection, reduce manual enrichment, and turn individual phishing incidents into actionable knowledge that protects the wider environment.

Conclusion

Phishing remains heavily represented across finance, manufacturing, government, banking, and technology. Credential theft, token compromise, malicious execution, and multi-stage attack chains increasingly blur the line between phishing and identity attacks.

Reducing phishing risk therefore means more than stopping suspicious emails. SOC teams need fast behavioral visibility into what those emails, links, and files actually do.

With average detection times of 16–17 seconds in banking and technology, ANY.RUN’s Interactive Sandbox helps teams expose complex attack behavior quickly, while ANY.RUN Threat Intelligence lets them investigate the wider threat context by industry, geography, and related activity.

About ANY.RUN

ANY.RUN is a leading provider of interactive malware analysis and threat intelligence solutions trusted by 16,000+ organizations and 700,000+ security professionals worldwide, including 74 of the Fortune 100 companies.

Its Interactive Sandbox and Threat Intelligence solutions help SOC teams analyze suspicious files and URLs, uncover malicious behavior, enrich alerts with actionable context, and connect related activity across files, infrastructure, and campaigns. This helps teams investigate threats faster, make more confident response decisions, and contain malicious activity before it creates wider business impact.

What do you think about this post?

0 answers

  • Awful
  • Average
  • Great

No votes so far! Be the first to rate this post.

0 comments