Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

Digital Trends may earn a commission when you buy through links on our site. Why trust us?

Don’t open that! 93 percent of phishing emails are now ransomware

Add as a preferred source on Google

A new report suggests as much as 93 percent of all phishing emails that look to trick users into clicking a nefarious link or open a dangerous attachment, attempt to install ransomware on the user’s system. This suggests that the practice of encrypting files and demanding a ransom proves to be the most profitable way to scam PC users into giving up some coin.

This data comes out of threat management company PhishMe, which noted that phishing attacks riddled with ransomware have gone up from 56 percent of the total attacks in December 2015, to this new height just over six months later. That’s a huge increase, and shows that the malware trend is moving in one very specific direction.

Recommended Videos

But why? Adware, spyware, and other forms of nasty software have been prevalent for the better part of two decades. Why the sudden switch to this new attack format?

Protect all your hardware with Norton Security Premium

Mainly it’s because ransomware is easy. If a user pays up, you have money instantly. With stolen details they need to be sold, or credit cards used, which could potentially reveal the hacker. Ransomware is safer for them, and faster.

“If you look at the price point of paying the ransom, it is rarely more than 1 or 2 bitcoin, that’s $400 to $800, maybe $1,000 depending on the exchange rate,” said Brendan Griffin, a threat intelligence manager at PhishMe. “That’s a relatively low price point for a small to medium business.”

That’s a key point of this report too, that businesses are being targeted more by ransomware attacks. While there might be more of an emotional tie to documents and data with personal users, there is always a chance that they don’t have the technical know how to acquire the bitcoin usually required for payment. They are also less likely to have the funds to comply.

When it comes to most businesses though, a couple of bitcoins is a drop in the bucket. Ironically, it’s probably cheaper to just pay up (if indeed the files are returned to a working state) than it would be to pay someone to recover them from a back up or other means.

The report also suggests that ransomware is becoming easier to manage and distribute too, with ready-made kits allowing even those with little programming knowledge the chance to send out file-encrypting programs into the wild. Perhaps that’s why we’ve even seen some groups trying to recruit new “affiliates” for their scams.

This ease of use is leading to a more varied use of the nefarious technology too. Those behind it are trying “soft-targeted” phishing scams according to CSOOnline. This involves a blending of direct targeted email, using specific markers for a person such as their name or job title, but without trying too hard to appeal, which would perhaps set off someone more wary.

Unfortunately there aren’t any great methods of dealing with a ransomware attack just yet. Paying up is a bad idea, as it just encourages the practice. Our best suggestion would be to just back up everything important to you several times. It’s the only way to be secure from such an attack.

Jon Martindale
Jon Martindale covers how to guides, best-of lists, and explainers to help everyone understand the hottest new hardware and…
Google’s AI is digging up Chrome bugs that humans missed for years
Here's how Google is using Gemini AI to find, triage, and patch Chrome security bugs faster than ever.
Google Chrome safety feature.

I've always assumed Chrome's endless update notifications were just routine housekeeping with a batch of actually useful features every now and then. Turns out some of them are patching bugs that have been quietly sitting in the browser's code for over a decade.

So how exactly is AI catching these bugs?

Read more
The Best Password Managers for 2026
As online security evolves, so should the way you protect your accounts
password manager on a mac.

Think about how many online accounts you use in a typical week. Between work, banking, shopping, streaming, social media, and everything in between, it's easy to end up managing dozens of passwords. Remembering a different, secure password for every account simply isn't realistic, which is why so many people fall back on reusing the same login across multiple websites. That's a recipe for disaster, if you ask any cybersecurity expert.

If you're in a conundrum on how to safely handle digital privacy, password managers are a reliable solution. Rather than trying to remember every single password yourself, a credentials manager tool securely stores your login details, creates stronger passwords for new accounts, and automatically fills them in whenever you need them.

Read more
Amazon and Walmart’s AI can spot fake ‘Made in USA’ labels but won’t tell you, says study
The same chatbot that happily discusses "Made in China" claims stays silent on "Made in USA" ones.
amazon-join-the-chat-ai

When you ask an AI shopping assistant to help you find products, you probably expect it to point out misleading listings too. According to a new study, both Amazon and Walmart's AI tools can detect fake "Made in USA" claims. However, the study claims that retailers are not using those capabilities to flag or remove the misleading listings, even when the AI recognizes conflicting information on the same product page.

How did the researchers catch this fraud?

Read more