According to fresh ANY.RUN data, phishing exposure remains above 70% in several critical industries. This doesn’t happen because organizations aren’t protected enough. Companies have been implementing email filtering, MFA, and phishing-awareness training for years.
However, threats continue to evolve, and security methods that were highly effective yesterday can develop visibility gaps as attackers adapt.
In this article, ANY.RUN explores data-driven insights to get to the bottom of phishing risk across key industries in the United States and examines how SOC teams can mitigate it.
See our previous article on phishing risk among US-based financial organizations.
Phishing Risk Remains High Across Critical Industries

As the statistics show, very different industries face almost the same level of phishing exposure. For several critical industries, that exposure is above average. According to ANY.RUN data, phishing exposure reaches 73.4% in finance and 72.2% in manufacturing.
Part of the reason lies in how quickly threat actors evolve and adapt their techniques. AI makes convincing social engineering easier to scale, while techniques such as AiTM phishing and session theft make identity compromise increasingly difficult to prevent.
Explore broader threat landscape with H1 2026 Cyber Risk Report
Phishing campaigns increasingly combine sophisticated social engineering with identity-focused techniques, legitimate services, and evasive delivery methods.
The types of submissions most frequently analyzed in ANY.RUN’s Interactive Sandbox also show that email security alone cannot cover the entire attack surface:
Most Analyzed File Types in ANY.RUN, 2026
| Finance | Government & Administration |
|---|---|
| 58.7% email messages | 67.9% email messages |
| 16.3% archives | 15.6% archives |
| 11.2% Office documents | 6.7% PDFs |
Email remains central, while the attack surface extends further into the files, links, and other content delivered through it.

And it’s hard to blame users alone. Threat actors have become skilled at mimicking legitimate and niche documents, hiding payloads inside encrypted archives, and using techniques such as QR-code phishing to make malicious content harder to recognize at a glance.
Without enhanced visibility, modern phishing attacks can be difficult to unravel even for experienced security teams. Analysts need to see beyond the initial email or file and understand what happens after a user opens a document, follows a link, or interacts with a malicious page.
The Bigger Challenge: Phishing Is Becoming an Identity Attack
A deeper look at threats targeting critical sectors shows just how much the nature of phishing has changed.
In banking, ClickFix shows 71% prevalence.
More on ClickFix
ClickFix campaigns use fake errors, CAPTCHAs, or verification prompts to manipulate users into copying and executing malicious commands themselves. This allows attackers to turn social engineering into direct execution on the victim’s device. Read more on Malware Trends Tracker

It is followed by EtherHiding (63.8%), a technique that abuses legitimate blockchain infrastructure to host or retrieve malicious code, and Sneaky2FA (62.3%).
More on Sneaky2FA
Sneaky2FA – a phishing-as-a-service (PhaaS) kit designed to steal credentials and authentication sessions through adversary-in-the-middle (AiTM) techniques. Read more on Malware Trends Tracker
All terms aside, what this means is that modern phishing chains can:
- manipulate users into executing commands
- intercept authentication sessions
- steal credentials or tokens
- abuse legitimate infrastructure
Only some of those threatening methods can be covered by email filtering, awareness training, and MFA. Overall, these tools cannot provide complete coverage against rapidly changing phishing techniques.
Threat Prevalence in Banking:
- 71% of ClickFix
- 63.8% EtherHiding
- 62.3% Sneaky2FA
Together, these threats illustrate a broader shift: the attack no longer ends with detecting a malicious attachment. The same pattern is visible in the technology sector. Sneaky2FA and ClickFix also appear among the leading threats, alongside Tycoon, EvilProxy, and EvilTokens, reinforcing the growing focus on credentials, authentication sessions, and identity.
Key Threats in Technology:
Tycoon and EvilProxy use AiTM phishing techniques to capture credentials and authentication data, while EvilTokens targets access tokens and authenticated sessions. Instead of simply trying to deliver malware, these attacks increasingly target the identities and access that organizations rely on.
PhaaS makes sophisticated phishing techniques easier to deploy at scale. AI makes lures more convincing and easier to personalize. AiTM and token theft demonstrate that protecting passwords alone may not be enough to prevent compromise.
On top of that, attackers increasingly abuse trusted, legitimate services and infrastructure, making malicious activity harder for both users and traditional security controls to recognize.
All of this points to a major security gap: visibility. Blocking the original email is only one layer of defense. Your SOC needs more.
Mitigation: Gain Visibility Before Phishing Turns Into a Breach
Modern phishing attacks are built to evade static controls, abuse legitimate services, and hide malicious behavior behind user interaction. It takes enhanced threats visibility both into the wider threat landscape and malicious activity happening inside specific campaigns.
This is where behavioral analysis and threat intelligence can give defenders the upper hand.
Expose the Full Attack Chain in Seconds
Instead of relying only on the initial email, URL, or file, analysts can safely detonate suspicious content in ANY.RUN’s Interactive Sandbox and observe the attack as it unfolds. With its capabilities, SOC analysts gain an additional layer of visibility into malware and phishing behavior.

Automated Interactivity performs the actions needed to expose evasive behavior without repetitive manual effort, helping analysts investigate threats involving password-protected archives, CAPTCHAs, malicious QR codes, and other interactive attack chains. In-browser data inspection provides deeper visibility into browser activity, redirects, scripts, requests, and other artifacts involved in the attack.
Most importantly, all of this takes just seconds.
Average MTTD with ANY.RUN is just 14 seconds, with similarly fast detection across the critical industries: 16.3 sec for banking and 17 sec for technology.
The result is a much clearer and faster path from alert to response:
Suspicious email → Detonate safely → Reveal behavior → Identify the threat → Respond
Full-scale visibility into threat behavior, including evasive phishing, helps streamline daily SOC workflows and accelerate response before threats can progress further.
For SOC teams, this means:
- Faster threat detection: identify malicious behavior in seconds.
- Less manual investigation: automate repetitive interactions and analysis steps.
- Greater visibility: expose redirects, scripts, network activity, and complete attack chains.
- Faster response: move from suspicious artifact to informed action sooner.
- Reduced risk exposure: contain threats before they can progress across the infrastructure.
- Stronger privacy and compliance: keep sensitive investigations private and support enterprise security requirements.
Investigate Beyond a Single Phishing Attempt
A detected attack can also become a starting point for broader threat investigation.
With Threat Intelligence Lookup (TI Lookup), analysts can search threat data by industry, geography, malware, IOCs, techniques, and other parameters to understand whether suspicious activity is part of a wider campaign or relevant to their environment. AI-powered natural-language search makes this threat data easier to explore without constructing complex queries manually.
TI Lookup query: submissionCountry:”us” AND industry:”Manufacturing”

For organizations facing high phishing exposure, Threat Intelligence Feeds (TI Feeds) extends this visibility into daily detection and response workflows. Fresh, high-confidence IOCs derived from real-world investigations can be delivered directly into the existing security stack, helping teams detect emerging threats, enrich alerts, and respond without adding more manual work.

Together, threat intelligence and interactive sandboxing help SOC teams investigate threats faster, strengthen detection, reduce manual enrichment, and turn individual phishing incidents into actionable knowledge that protects the wider environment.
Conclusion
Phishing remains heavily represented across finance, manufacturing, government, banking, and technology. Credential theft, token compromise, malicious execution, and multi-stage attack chains increasingly blur the line between phishing and identity attacks.
Reducing phishing risk therefore means more than stopping suspicious emails. SOC teams need fast behavioral visibility into what those emails, links, and files actually do.
With average detection times of 16–17 seconds in banking and technology, ANY.RUN’s Interactive Sandbox helps teams expose complex attack behavior quickly, while ANY.RUN Threat Intelligence lets them investigate the wider threat context by industry, geography, and related activity.
About ANY.RUN
ANY.RUN is a leading provider of interactive malware analysis and threat intelligence solutions trusted by 16,000+ organizations and 700,000+ security professionals worldwide, including 74 of the Fortune 100 companies.
Its Interactive Sandbox and Threat Intelligence solutions help SOC teams analyze suspicious files and URLs, uncover malicious behavior, enrich alerts with actionable context, and connect related activity across files, infrastructure, and campaigns. This helps teams investigate threats faster, make more confident response decisions, and contain malicious activity before it creates wider business impact.




0 comments