DNS Security · 3 min read

DNS-borne threats surge 30% as phishing infrastructure pre-positions

DNSFilter's 2026 annual report recorded a 30% rise in threats and a sharp jump in the number of threats the average user meets each day — much of it staged in advance and led by phishing.

Global network connectivity across the earth

Published 3 February 2026

Almost every attack — phishing, malware delivery, or command-and-control call-home — has to make a DNS lookup before it can do anything. DNSFilter's 2026 annual security report shows that chokepoint is busier and more hostile than ever.

What the data shows

  • Threats on the network grew 30% between October 2024 and September 2025.
  • The average internet user encountered 66 threats per day in 2025, more than double the 29 seen in 2024.
  • Over 7.6 million threat-related domains appeared between August and November 2025 — a 20% increase — much of it dormant infrastructure staged ahead of campaigns.
  • Phishing made up roughly 30% of malicious DNS traffic, the leading category, followed by suspicious and malware domains.

Why it matters

Attackers increasingly register large volumes of domains and let them sit unused, so reputation and blocklists that rely on known-bad history miss them at launch. Combined with AI-assisted phishing, that means users face more convincing lures pointing at infrastructure that looks clean — until it isn't. Blocking the lookup is the earliest and cheapest place to break the chain.

How iconnet helps

Protective DNS (VeraDNS) filters DNS lookups network-wide, blocking known-malicious and newly-registered domains before a connection is ever made. It is a low-cost, SASE-ready control that stops phishing and command-and-control at the earliest possible point — on and off the corporate network — and complements the firewall and endpoint defences already in place.

Talk to a security specialist

Tell us about your environment and goals. Our engineers will help you scope the right solution — no obligation.