Disclosure: This article was provided by ANY.RUN. The information and analysis presented are based on their research.
Across five key industries analyzed by ANY.RUN, including finance, banking, manufacturing, technology, and government, phishing exposure reached 69.9%.
What stands behind this number in reality? Which threats are targeting your industry? How are their TTPs changing? Which indicators should your team prioritize?
Threat intelligence helps security leaders answer these questions. Data from real-world investigations reveals which threats are gaining prevalence, which attack methods recur across industries, and where organizations may need to adjust detection and response priorities.
Below are key findings from ANY.RUN’s latest data and practical steps organizations can take to mitigate phishing risk.
Why Does Phishing Remain a Major Risk Across US Industries?
Phishing campaigns increasingly combine sophisticated social engineering with identity-focused techniques, legitimate services, and evasive delivery methods. AI makes convincing lures easier to scale, while adversary-in-the-middle (AiTM) phishing and session theft increasingly target credentials and authenticated sessions.
ANY.RUN data shows how these risks manifest across five critical industries. The highest exposure levels appear in finance at 73.4% and manufacturing at 72.2%, showing that phishing remains a significant risk across industries with very different operations and security environments.
What Do the Most Common Phishing Threats Tell Us?
Across all five industries analyzed, the leading threats by volume share across ANY.RUN submissions in 2026 are:
- Tycoon — 15%
- Sneaky2FA — 13.4%
- ClickFix — 10.4%
- EvilProxy — 9.8%
- EvilTokens — 6.5%
This points to a shift in modern malware and phishing that affects critical industries, including American companies and organizations. Attacks increasingly extend beyond malicious attachments into credential theft, session compromise, token abuse, and user-driven execution.

File-type data reinforces this broader attack surface. Emails account for 58.7% of analyzed files in finance and 67.9% in government and administration, where archives and PDFs make up another 22.3% combined. Phishing chains can move from the initial message into attachments, links, and post-click activity, making them harder to address through inbox controls alone.
This increases the need for deeper threat context to understand evolving techniques, identify relevant threats, and adjust detection and response priorities.
How Can Threat Intelligence Help Organizations Prepare?
Security leaders and SOC teams need a clear understanding of the threats affecting their industry, region, and environment. This includes current TTPs, IOCs, threat context, and emerging malicious activity.
In practice, threat intelligence can support three key areas:
1. Investigate and Hunt Threats Relevant to Your Organization
When phishing threats vary by industry and region, teams need to know which ones matter to their organization.
Threat Intelligence Lookup (TI Lookup) lets security teams search real-world threat data by industry, geography, malware, IOCs, techniques, and other parameters. Analysts can explore relationships between threats, pivot to related sandbox investigations, and enrich suspicious indicators with additional context.
The intelligence is built from real-world investigations contributed by 16,000 SOC teams and 700,000 security professionals, with links back to related sandbox analyses for deeper investigation. AI-powered search also lets analysts use natural-language requests instead of building complex queries manually.
Bring threat data from 16K+ SOC teams into your workflows for proactive security. Integrate TI Lookup.
For example, teams can investigate threats specifically affecting US manufacturers with TI Lookup queries like: submissionCountry:“us” AND industry: “Manufacturing”

For SOC teams, this means faster threat investigations, less manual research, and more relevant intelligence for detection and response. By narrowing intelligence to the threats that matter to their industry and environment, teams can prioritize risks more effectively and make faster, better-informed security decisions.
2. Turn Threat Research Into Security Priorities
As phishing techniques evolve, teams need current research to understand what is changing and how to prepare.
TI Reports provides constantly updated, expert-written research on malware, campaigns, techniques, and emerging threats, with actionable insights for security teams.
Reports can be filtered by region, industry, and threat type, helping organizations focus on research relevant to their risk profile, understand emerging attack patterns, and use those insights to refine detection and proactive security priorities.
3. Bring Threat Intelligence Into Detection Workflows

Understanding phishing threats is only part of the challenge. Teams also need fresh indicators available where detection happens.
TI Feeds delivers real-time IOCs with threat context directly into SIEM, SOAR, and other security workflows. With 99% unique IOCs, real-time updates, and ready-to-use integrations, teams can strengthen detection and enrichment without adding manual research.

Bring real-time threat intelligence from 16K+ SOCs into your security stack. Integrate TI Feeds.
Conclusion
Knowing what is behind that exposure is what makes the data actionable. Security leaders should focus on three priorities:
- Understand the threats most relevant to their industry and region.
- Continuously validate security assumptions against fresh threat data.
- Turn threat intelligence into clear detection and response priorities.
ANY.RUN Threat Intelligence helps teams investigate the threat landscape directly and provides curated research to help organizations understand what is changing and prepare accordingly.
(Featured Image by Ann H on Pexels)

