Mobile phishing scams surge, yet enterprises overconfident
A report released Thursday by mobile security company Lookout indicates that mobile phishing scams are increasingly severe, yet enterprises are not paying enough attention to this threat. The survey shows that nearly 60% of enterprises have experienced incidents involving executive impersonation via SMS or voice, and 77% have encountered at least one such attack in the past six months, but only half of respondents expressed high concern.

Mobile security company Lookout noted in a report released on Thursday that mobile phishing scams are becoming an increasingly serious threat, but businesses are clearly not paying enough attention to this threat.
The report shows that nearly 60% of businesses have "experienced incidents due to executive impersonation scams conducted via text messages or voice calls," and 77% of businesses have experienced at least one such attack in the past six months. However, despite how prevalent these attacks are, the report found that "only half of respondents are highly concerned about this threat."
The survey is based on questionnaires from more than 700 security leaders, and the results reflect "a dangerous situation: businesses are overconfident, and their vulnerability to modern threats is far greater than they realize," Lookout stated in the report.
Hackers are increasingly using mobile voice and SMS phishing messages to trick employees into handing over passwords, thereby gaining access to corporate networks through legitimate accounts—accounts that do not easily trigger alerts on security monitoring platforms.
In May of this year, the U.S. Federal Bureau of Investigation (FBI) warned that hackers are using these techniques, including AI voice cloning, to impersonate U.S. government officials. Researchers also noted that impersonation attacks pose a risk to corporate executives as well, because such attacks exploit trust relationships and may further reach colleagues or family members.
The notorious cybercrime group Scattered Spider has intensified attacks on critical infrastructure sectors over the past few months. The group relies heavily on impersonation scams and other social engineering tactics, often tricking help desk employees into resetting passwords to gain access to corporate networks.
"Because traditional security solutions cannot provide visibility into these attacks," Lookout said, "most of these manipulative attempts go unnoticed until things escalate, making defense extremely difficult."
In Lookout's survey, about half of respondents admitted to "lacking consistent visibility into social engineering attacks facing their networks," and the security company believes this lack of preparedness against common attack methods is concerning.
Another seemingly contradictory finding is that Lookout discovered 96% of security leaders are confident their employees can identify phishing attempts, yet "more than half reported incidents where employees fell for executive impersonation scams via text messages."
Lookout said its findings highlight "the urgent need for businesses to reassess their cybersecurity strategies, moving beyond mere confidence to implement robust solutions that provide real-time visibility and proactive protection against the evolving threat landscape."
Lookout noted that advanced security software is only part of the solution. Businesses also need to conduct "ongoing security awareness training specifically targeting mobile threats" and foster "a culture of vigilance as well as convenient, blame-free reporting channels."