
Security Soapbox · 2025-06-25 · 6 min
Key moments - from our scoring
Substance score
34 / 100
Five dimensions, 20 points each
The Q1 2025 mobile threat landscape report exposes a fundamental shift in attack strategy: rather than purely technical exploits, adversaries are weaponizing AI-powered social engineering to target human behavior at industrial scale. Every measured enterprise saw phishing attacks, with over a million incidents recorded in Q1 alone. The democratization of cybercrime tools - LinkedIn scrapers, leaked databases, AI writing assistants - means threat actors like Scattered Spider (UNC-3944) can now conduct SMS phishing and voice phishing campaigns with minimal resources. Interestingly, iOS users face nearly double the phishing link exposure of Android users (14.5% vs 7.7%) because attackers adapt their approach: iOS's walled garden makes malware delivery hard, so they pivot to convincing phishing pages instead. Insurance (37.5%), legal (32%), and energy/utilities (23.7%) sectors are primary targets due to sensitive data, critical access, and employee interaction density. Yet despite sophisticated threats, basic failures dominate: 46.3% of enterprise devices run outdated operating systems, 5.2% lack screen locks, and 3.4% aren't encrypted. Malware families like Triada and Coper continue stealing data and banking credentials. The core vulnerability isn't technical - it's human trust combined with security hygiene negligence.
Over a million mobile phishing and social engineering attacks hit enterprise users in Q1 2025, with 100% of measured enterprises experiencing these attacks.
iOS devices face nearly twice as many phishing links (14.5% vs 7.7%) because iOS's locked-down architecture makes malware delivery difficult, forcing attackers to pivot to convincing phishing pages instead of malware.
Insurance was the top target at 37.5%, followed by legal at 32% and energy/utilities at 23.7%, due to sensitive data handling and critical access points that make employees vulnerable to social engineering.
They use readily available tools like LinkedIn scrapers, leaked phone databases, and AI to write convincing SMS messages, enabling SMS phishing (smishing) and voice phishing campaigns without needing technical malware expertise.
46.3% of enterprise devices run outdated operating systems, 5.2% lack screen locks, and 3.4% aren't encrypted, creating basic vulnerabilities exploited by malware families like Triada and Coper.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode surfaces a handful of genuinely useful data points from a single report, but they're thin on analysis and padded with obvious security-awareness commentary. The 6-minute format means little depth beyond headline stats.
iOS devices actually saw almost twice as many malicious web links and phishing sites as Android. We're talking 14.5% versus 7.7%
the top targets for mobile phishing in Q1, insurance was number one at 37.5 percent, then legal at 32 percent, and energy and utilities at 23.7 percent
The iOS-versus-Android phishing inversion is a genuinely counterintuitive finding worth noting, but the rest of the episode leans on well-worn AI-democratisation-of-cybercrime framing and basic security hygiene platitudes that circulate everywhere.
Well, in Q1, iOS devices actually saw almost twice as many malicious web links and phishing sites as Android
AI is making it much worse, much faster. Your phone is always a target
There are no named guests and no credentials established for either host; this is a scripted two-voice narration format almost certainly AI-generated, with zero practitioner insight or first-hand operator experience on offer.
That's exactly it. That's the urgent issue we're diving into today
Look, the mobile threat scene is always changing. It's complex
The episode does cite concrete numbers, named threat actors, specific malware families, and industry breakdowns pulled from a report, which lifts it above pure hand-waving; however, all evidence traces back to a single unnamed report and lacks any independent corroboration or contextual analysis.
also known as UNC-3944. Oh, yeah. They hit Caesars and MGM, right?
Over 94 malicious apps found on work devices in Q1 alone Things like Triada which steals your data quietly or Coper, which can grab banking details and even read your texts
The dialogue is transparently scripted call-and-response with no real probing, no pushback on any claim, and questions that exist solely to cue the next block of report narration rather than to challenge or deepen understanding.
How does that work?
What's that tell us?
Computed from the transcript - who did the talking, and the words that came up most.
The Q1 2025 Lookout Mobile Threat Landscape Report highlights emerging human risk and AI as the primary drivers of security threats. This most recent report emphasizes that attackers are targeting individuals through their mobile devices early in their attacks - exploiting the native trust we have in these devices and our natural tendencies to engage with communications that drive curiosity.
Transcribed and scored by The B2B Podcast Index.
All right. Think about your phone for a second. It's probably right there, maybe in your hand, holds basically everything right. We trust these things completely.
But what if that trust is actually being used against us? That's exactly it. That's the urgent issue we're diving into today. We're looking at the Q1 2025 mobile threat landscape report.
And our mission really is to unpack how attackers are using AI now, exploiting basic human instincts, curiosity, trust to get around the usual security stuff. And it turns our trust in these phones into a huge vulnerability for us, for businesses, everyone. Okay, let's get into that. Because the numbers, well, they really show this change in strategy, don't they?
They do. The report found over a million mobile phishing and social engineering attacks on enterprise users. Just in Q1. A million, yeah.
It's kind of staggering. But here's the kicker. And frankly, it's a real wake-up call. 100% of enterprise's lookout protects were hit by these socially engineered phishing attacks.
Every single one. Every single one. And what's really fascinating here is how attacks have changed. It's not just about fancy malware anymore.
It's about using our own nature against us. Attackers are boosting social engineering with AI, hating those basic human traits, curiosity, trust, maybe a sense of urgency. It almost sounds too easy for these kinds of results So AI isn just making attacks better it making them what easier for more people to do like democratizing cybercrime Alarmingly yes All Intactor needs now really are things like sales tools you can just buy maybe a LinkedIn scraper or some leaked phone number Stuff that's out there.
Exactly. And then AI to write these really short, really believable SMS messages. It's like fishing on an industrial scale. Wow.
And a key example is Scattered Spider. You might have heard of them, also known as UNC-3944. Oh, yeah. They hit Caesars and MGM, right?
Big breaches. Those were the ones. And more recently, they've been going after UK and US retail and insurance companies, too. They love SMS phishing, smishing and voice phishing.
To calling people up, too. Yep. Tricking employees into giving up logins. Even those single sign-on tokens.
The keys to the kingdom, basically. That paints a pretty clear picture of targeting the human. But what about the phones themselves? Does having an iPhone versus an Android change your risk?
Okay, so this next bit might challenge what you think. You know how iOS has that walled garden reputation for security? Yeah, it's supposed to be safer. Well, in Q1, iOS devices actually saw almost twice as many malicious web links and phishing sites as Android.
We're talking 14.5% versus 7.7%. Twice as many.
How does that work? It's about the attacker's strategy. See, for Android, because it's more open, they'll often try to sneak in actual malware. But for iOS, getting malware on there is way harder.
Right, Apple's pretty locked down. So they pivot They don target the phone as much they target you the user with super convincing phishing pages It less about cracking the code more about tricking you into handing over your details OK that makes sense And the industry is being hit Yeah. Also, maybe not the usual suspects. Right.
We often focus on, say, health care or banks. But the top targets for mobile phishing in Q1, insurance was number one at 37.5 percent, then legal at 32 percent, and energy and utilities at 23.7 percent.
insurance, legal, energy. Why them specifically? Well, if you think about it, it connects back to that human layer. These industries are packed with sensitive data, critical access points, and people are interacting with this stuff constantly.
Insurance. Insurance and legal, so much personal, valuable data handled by employees, prime social engineering targets, and energy and utilities. A breach there isn't just data loss, it could disrupt critical services. So the human entry point is incredibly high stakes.
And remember, scattered spider, they've really focused on insurance lately. So it's clear these human-focused attacks are really dominant. But for listeners, what about the, you know, the old school threats? Bugs?
Bad apps? Are they still a factor? Oh, absolutely. Don't discount them.
Basic vulnerabilities are still a huge issue, often exploited simply because people, well, they don't update their devices. They don't update fatigue. Exactly. That delay, that human factor, creates massive openings.
Q1 saw a lot of attacks hitting flaws in the Chrome browser engine. something millions use every day. And actual malware Still finding lots of that Still a big problem Over 94 malicious apps found on work devices in Q1 alone Things like Triada which steals your data quietly or Coper, which can grab banking details and even read your texts. So Coper could essentially empty your bank account.
Potentially, yes. It gives attackers the keys to your digital wallet. So even with all the fancy AI stuff, we're still kind of tripping over basic security, like leaving the digital front door unlocked. What's that tell us?
It tells us that basic security hygiene is, well, more vital than ever. Look at this. Nearly half, 46.3% of enterprise devices were running old operating systems.
Almost half. Wow. Yeah. Huge security holes right there.
And simpler things, too. 5.2% didn't even have a screen lock. 3.
4% weren't encrypted. These aren't complex hacks. They're just failures in basic security that can give away everything on the device. Okay.
So wrapping this up, what's the main takeaway for, you know, for you listening to this? How do you navigate this? Look, the mobile threat scene is always changing. It's complex.
But right now, human risk is the main weak point. And AI is making it much worse, much faster. Your phone is always a target. So understanding these threats and honestly, just keeping up with basic security hygiene updates, locks, encryption, it's crucial for your data and maybe your companies too.
So given how attackers are zoning in on our instincts or trust, here's something to think about. What bit of native trust, something we do every day online without thinking, might be the next big target for these cyber criminals? Something to ponder until our next deep dive.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.