THE barrier to sophisticated cybercrime has collapsed.

The culprit?

The widespread availability of pre-packaged malicious software known as “phishing kits.”

These low-cost, ready-to-use packages now arm virtually anyone with minimal technical knowledge to launch complex data-stealing scams, sparking a dangerous rise in online threats.

Phishing kits are now easily bought on the dark web and on messaging apps like Telegram — often priced under $25. Security experts call them a “force multiplier” for cybercriminals seeking to steal personal information, commit identity theft, access bank accounts, and deploy damaging malware.

“Phishing kits put powerful attack tools into the hands of people who may not have the skills to build them on their own,” said Adrianus Warmenhoven, a cybersecurity expert at NordVPN.

Equipped with drag-and-drop website builders and email templates, Warmenhoven added, these kits allow even the least technical attackers to launch professional-looking scams.

Phishing-as-a-Service Rises

The danger is compounded by the rise of Phishing-as-a-Service (PhaaS), subscription-based models that transform phishing into a structured, organized cybercrime business by handling everything from hosting to victim targeting.

“Phishing kits and PhaaS platforms lower the barrier to entry, so we’re seeing a surge in the number and variety of attacks. That means consumers need to be more alert than ever,” Warmenhoven said.

Research consistently highlights the scale of the problem. A 2023 report by the Anti-Phishing Working Group (APWG) noted that the number of phishing attacks hit a record high in the first quarter of that year, underscoring the threat’s relentless nature.

The report pointed to the growing sophistication of “man-in-the-middle” attacks, which are often facilitated by these readily available kits.

NordVPN’s own 2024 analysis revealed a troubling trend in brand impersonation: Google, Facebook, and Microsoft were the most commonly targeted brands. The analysis uncovered nearly 85,000 fake Google URLs alone last year, all designed to harvest user credentials.

Protection is Key

Security experts say the defense against this evolving threat is simple vigilance. Warmenhoven offered simple, foundational advice: “Phishing attacks are one of the most common and effective ways cybercriminals gain access to sensitive data.”

To safeguard against attacks, he recommends using multi-factor authentication (MFA) on all accounts.

Users should also meticulously check links for misspellings and inconsistencies before clicking. He advised consumers to “be cautious of unsolicited emails, especially those offering deals or urgent requests.”

It is also crucial to keep all device software regularly updated to patch security vulnerabilities and to use anti-malware tools to scan all downloaded files.

“Always verify the legitimacy of files before downloading,” Warmenhoven said.