A comprehensive study by Kaspersky reveals that 88.5% of phishing attacks credentials are the primary target, with cybercriminals focusing on stealing login information rather than financial data. The analysis of campaigns from January through September 2025 shows a clear shift in attack strategies across the cyberthreat landscape.

Middle East Faces 47 Million Phishing Attacks Credentials Targeting

According to Kaspersky data, over 47 million phishing links were clicked in the Middle East region between November 2024 and October 2025. All these malicious links were successfully detected and blocked by Kaspersky security solutions, preventing potential data breaches.

The research breakdown shows that while 88.5% of attacks targeted account credentials, another 9.5% focused on personal data including names, addresses, and birth dates. Only 2% of attacks specifically targeted bank card details, indicating a strategic shift in cybercriminal priorities.

Dark Web Markets Drive Credential Theft Economy

Stolen credentials rarely serve single-use purposes. Instead, data from multiple phishing attacks credentials campaigns gets consolidated into comprehensive data dumps sold on dark web markets for as little as $50. The pricing structure varies significantly based on account value and access level.

  • Global internet portal credentials: $0.90 average price
  • Cryptocurrency platform access: $105 average price
  • Online banking credentials: $350 average price
  • Personal documents (passports, ID cards): $15 average price

Kaspersky Digital Footprint Intelligence data shows that account age, balance, linked payment methods, and security settings all influence final pricing in these underground markets.

Our analysis shows that credentials account for nearly 90% of phishing attempts. Once collected, logins, passwords, phone numbers, and personal details are aggregated, checked, and resold, sometimes years after the initial theft.

Olga Altukhova, Senior Web Content Analyst at Kaspersky

Essential Protection Against Phishing Attacks Credentials Theft

To combat the rising threat of credential-focused phishing attacks, Kaspersky recommends implementing multi-layered security measures. These include using comprehensive cybersecurity solutions like Kaspersky Premium, which employs advanced detection technology to analyze website characteristics and identify suspicious patterns.

  • Enable multi-factor authentication on all compatible accounts
  • Use unique passwords for each online service
  • Regularly monitor bank statements and account activity
  • Verify website URLs before entering personal information
  • Install comprehensive cybersecurity solutions with real-time protection

As cybercriminals continue refining their techniques, the combination of old breach data with new intelligence allows for highly personalized attacks targeting executives, finance staff, and individuals with valuable digital assets. Proactive security measures remain the most effective defense against evolving phishing attacks credentials targeting strategies.