Phishing Activity: Key Statistics
November 1, 2020 - January 31, 2021

We analyzed URLs, domain names, and IP addresses that have been reported for phishing. These and other metadata - e.g., registration data, DNS zone data, attack type and targeted brand - allow us to determine where phishers are acquiring resources for their criminal activities. Indicators of compromise allow us to distinguish hostnames delegated from domains that were purposely registered for phishing campaigns from hostnames assigned to compromised web sites that were delegated from domain names for legitimate purposes.

During the November 1, 2020 to January 31, 2021 period, we measured phishing reports, phishing attacks, and the number of unique domain names reported for use in phishing attacks. We also measured famous brands that were targeted by phishers.

Measurement Count
Total number of phishing reports this quarter 450,334
Phishing attacks reported 193,058
Unique domain names reported for phishing 146,724
Top-level Domains (TLDs) where we observed phishing 494
Registrars that had gTLD domains under management reported for phishing 481
Hosting Networks (ASNs) where phishing web sites were reported 2,362
Brands targeted in phishing attacks 1,034