Group-IB: the average price of phishing kits rose 149% YoY to $304 in 2019 and the number of kit sellers grew 120%
Context & Ripple Effects
Group-IB's numbers capture the moment the phishing kit trade stopped being a hobbyist bazaar: prices up 149% to $304 and seller count up 120% in a single year signal both professionalization and demand. That sits on earlier groundwork — PhishLabs had already found half of phishing sites sporting the browser padlock by late 2018, showing kits were shipping with credibility features baked in.
The pricing also lines up with the broader attack economy: hack-for-hire services charging $100-$400 to phish 2FA and take over email accounts show what turnkey attack tooling commands at retail. Rising kit prices are the supply-side echo of that willingness to pay.
First-order effects
- Kit sellers gain pricing power and margin: with 120% more sellers competing, the ones charging $304-plus are selling differentiation (templates, evasion, support) rather than raw code.
- Entry cost for aspiring phishers rises, pushing the least-funded buyers toward cheaper one-off tools or out of the market entirely.
Second-order effects
- The kit model graduates into subscriptions: by 2021 Microsoft exposed a Phishing-as-a-Service operation selling 120+ templates at $80-$100, exactly the recurring-revenue structure that $304 kits point toward.
- Defenders respond on the authentication side — physical security keys, which the hack-for-hire reporting flags as a prevention for 2FA-phishing attacks, become the countermeasure enterprises buy as kit quality climbs.
Third-order effects
- If kits keep absorbing tradecraft, intrusion methods shift away from malware altogether — consistent with CrowdStrike's finding that malware-free intrusions rose from 40% of cases in 2019 to 79% in 2024, with voice phishing overtaking email phishing as the top initial access method.
- Cybercrime consolidates around platform vendors who rent capability rather than sell code, mirroring legitimate SaaS economics and complicating attribution and takedown efforts for law enforcement.
The trend: Phishing is industrializing from one-off kit sales into full subscription platforms, feeding the broader shift toward malware-free intrusions that endpoint defenses struggle to see.