The volume and sophistication of phishing attacks have surged dramatically in the second quarter of 2026, posing a significant challenge to enterprise security. A new report from Egress reveals a 28% quarter-over-quarter increase in phishing emails, with a concerning 52.2% rise in malicious emails successfully bypassing traditional Secure Email Gateways (SEGs). This escalation is fueled by threat actors' widespread adoption of Artificial Intelligence (AI) to automate, scale, and personalize their campaigns. Attackers are using multi-channel tactics, extending their reach beyond email to SMS (smishing), QR codes (quishing), and enterprise collaboration platforms. Microsoft remains the most impersonated brand, highlighting the continued focus on exploiting user trust in major technology providers.
The modern phishing landscape is characterized by three key trends: AI-driven automation, brand impersonation at scale, and multi-channel delivery.
AI-Powered Attacks: Cybercriminals are using AI toolkits, readily available on the dark web, to craft highly convincing and personalized phishing lures. This includes generating flawless text, creating deepfake audio and video, and deploying AI chatbots to impersonate trusted individuals like executives or IT support. This has led to a sharp increase in "payloadless" attacks—those that rely purely on social engineering to trick a user into taking an action, such as wiring funds or revealing credentials. These attacks now account for nearly 19% of all phishing attempts.
Brand Impersonation: Attackers continue to abuse the trust users place in well-known brands. Microsoft is the most impersonated brand, featured in 38% of all brand phishing attempts, followed by Google at 11%. These campaigns often take the form of large-scale "commodity attacks" that spoof popular brands with fake promotions or security alerts, leading to massive spikes in phishing attempts for targeted organizations.
Multi-Channel Expansion: The attack surface is no longer limited to email. Threat actors are diversifying their delivery methods, using SMS for "smishing," QR codes for "quishing," and direct messaging on platforms like Microsoft Teams and LinkedIn. This approach bypasses email-centric security controls and catches users in environments where they may be less guarded.
The evolution of phishing tactics demonstrates a clear effort to circumvent specific layers of security.
T1566.002).T1598.001).T1598.003).T1566T1566.002T1598.001T1598.003T1071.001The surge in sophisticated phishing poses a direct threat to organizations of all sizes. Successful attacks can lead to credential theft, ransomware deployment, data breaches, and significant financial loss from Business Email Compromise (BEC). The increasing effectiveness of these attacks means that a higher percentage are reaching end-users, placing immense pressure on human vigilance as the last line of defense. The operational impact includes increased workload for security teams investigating alerts, higher costs for incident response, and a potential loss of productivity if collaboration platforms are compromised or need to be restricted.
No specific IOCs were provided, as the articles discuss general trends rather than a single campaign.
Security teams can hunt for signs of sophisticated phishing by looking for behavioral anomalies:
log_sourceEmail Gateway Logsurl_patternteams.microsoft.com/l/message/log_sourceMobile Device Management (MDM)command_line_pattern(no link/attachment)Detection:
Response:
Strategic Mitigation:
Tactical Mitigation:
p=reject to prevent direct domain spoofing.AI-powered phishing campaigns are overwhelming SOCs with a massive volume of unique, personalized alerts, causing analyst burnout and increasing the risk of missed critical threats.
The industrialization of AI-powered phishing is creating an unprecedented challenge for Security Operations Centers. Attackers leverage AI to generate thousands of unique, highly convincing, and personalized phishing lures, bypassing traditional signature-based detection. This results in an overwhelming deluge of alerts for Tier 1 analysts, leading to severe alert fatigue, burnout, and a significantly increased risk of critical threats being overlooked. The shift necessitates new strategies for SOCs, focusing on advanced alert correlation, context enrichment, and behavioral analysis to manage the unmanageable volume and identify true threats amidst the noise.
AI-generated phishing attacks surged 14x, with a 50x rise in malicious SVG files and a record tax-themed campaign.
New research reveals a dramatic 14-fold increase in AI-generated phishing attacks in 2026, significantly escalating the threat. Attackers are leveraging AI to create highly personalized campaigns, including a record-breaking tax-themed phishing wave that saw a 400% increase in tax authority impersonations. A critical new evasion tactic involves a 50x rise in malicious SVG file attachments, designed to bypass traditional email security filters by embedding scripts within seemingly benign image files. This highlights evolving TTPs and an increased challenge for detection.
New phishing campaign targets hospitality, abusing Calendly and Google redirects to deliver a Node.js implant for persistent access.
A sophisticated phishing campaign is targeting the hospitality industry by leveraging legitimate services like Calendly and Google's URL redirection to bypass email security. Emails sent via Calendly's notification system pass authentication checks, leading to links that use Google redirects to obscure the final malicious payload. This payload is a Node.js-based implant designed to establish persistent access. This 'authentication laundering' technique highlights the evolving methods attackers use to evade detection, with specific IOCs identified including C2 IP 178.16.54.27 and domain sec-safe-dc.info.
Phishing campaigns now use device fingerprinting to deliver OS-specific payloads, increasing success rates and making detection harder.
New research from Cofense reveals that modern phishing campaigns are dynamically adapting payloads based on the victim's operating system and device. Upon clicking a malicious link, the attacker's infrastructure analyzes the browser's user-agent string to determine the OS (Windows, macOS, mobile) and delivers a tailored payload, such as an .exe for Windows or a .dmg for macOS. This technique, leveraging T1592 (Gather Victim Host Information), significantly increases the likelihood of successful compromise by ensuring compatibility, moving beyond generic 'spray-and-pray' tactics. This makes attacks harder to detect and raises the overall threat level of phishing.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.