Skip to content
The Cyber Security Place

Four years, 500 organisations, and no need to change the lure

Event dated 14 May 2026 · Published 2 September 2026 · 3 sources

A phishing operation first documented in 2022 was reported in May 2026 to have reached more than 500 organisations across several industries, having rotated its infrastructure while leaving its core patterns largely unchanged. The durability is the finding. Attack techniques evolve under pressure, so a lure that has not needed rewriting in four years is evidence about the defences it meets rather than about the ingenuity behind it. Four years is long enough for every organisation involved to have run multiple awareness programmes.

The usual account of phishing is an arms race. Defenders improve filtering, attackers adapt lures, and the cycle continues with each side responding to the other. It is a satisfying story and it is the premise of most security awareness budgets.

A campaign that keeps its core intact for four years does not fit the story. Nothing forced an adaptation, because nothing was closing. The only components that rotated were the domains and hosts, which is not evolution — it is replacing consumables.

What longevity actually measures

Not attacker skill. A technique persists when the conditions that make it work persist, and the conditions here are structural: people receive messages asking them to authenticate, cannot reliably distinguish a genuine request from a good forgery, and are asked to make that judgement several times a day at speed.

None of that has changed in four years, so neither did the campaign. The infrastructure rotation says the takedowns worked — domains were being seized — and the unchanged core says the takedowns did not matter, because replacing a domain is cheap and replacing the idea would have been expensive.

Why 500 organisations is the wrong headline

The count invites the reading that this was a large operation. Spread over four years it is roughly ten organisations a month, which is a modest, patient business. What makes it notable is duration rather than volume: a small operation that nobody managed to stop.

That distinction matters for how it gets prioritised. A burst of activity gets attention and a response. A steady trickle over years never crosses the threshold at which anybody convenes a meeting, which is precisely why it lasted.

The measure that ends the campaign

Removing the judgement rather than improving it. Authentication that cannot be completed on a page the attacker controls does not depend on anybody recognising anything: the credential is bound to the site being visited, and a convincing forgery is simply a site the key will not talk to.

That is the difference between a control that degrades with tiredness and one that does not. Four years of the same lure is a long, expensive argument for the second kind, and it is an argument this campaign has been making continuously since 2022.