Threats
Phishing in 2026: why the old advice stopped working and what replaces it
A generation of security training taught people to look for bad spelling — a habit that fails hardest when the target is a person rather than a company. That was never the vulnerability — it was a symptom of the attacker's constraints, and those constraints are gone.
Last reviewed August 25, 2026
- Spelling was never the signal. Bad grammar was the cost of writing at scale in a second language, and generated text removed that cost entirely.
- The fake page is often the real page. An adversary-in-the-middle proxy relays your login live, so what you inspect looks correct because it is.
- Passkeys and hardware keys remove the failure mode rather than reducing its odds: the credential will not produce a valid response for a domain that is not the real one.
- The money is in payment fraud, not malware. Business email compromise carries no payload to detect, which is why the control has to be procedural.
Why did the old advice stop working?
Because it was advice about symptoms. For fifteen years the standard guidance was to watch for spelling errors, awkward grammar and stilted phrasing, and it worked well enough to be worth teaching. What nobody said out loud was why those tells existed: someone was writing thousands of messages in a language they did not speak natively, at a price point that ruled out proofreading.
Generated text removed the constraint rather than improving the writing. Roughly four in five phishing emails are now machine-written, and the measured consequence is stark — click rates near half of recipients, against something closer to one in eight for hand-written equivalents. Four and a half times the effect, at a cost per message low enough that the targeting which used to be reserved for executives is now affordable against everybody.
That last part is the shift that matters and it gets the least attention. Spear phishing was expensive: researching a target, learning the relationships, drafting something specific. The trade press was writing about it as a distinct category as early as mid-2015, precisely because its scarcity made it notable. What has changed is not that the technique improved. It is that the research and the drafting became close to free, so the quality that distinguished a targeted attack is now available at the volume of an untargeted one.
The practical fallout is that "look carefully at the message" has stopped being a control. A person examining a well-made lure will find nothing wrong with it, because there is nothing wrong with it. Defences that depend on the recipient noticing something are working against an adversary that no longer produces anything to notice.
Where the chain breaks
Five stages, and the proportion of a campaign that survives each one. The steep drop sits between following the link and typing something into it — which is the last point where a person still has a decision to make.
What is left to notice
Language is no longer a tell. Structure still is — the parts of a message an attacker cannot fake without compromising something. The example below is fictional and carries six of them; open each one, or click the highlighted fragment it belongs to.
- From
- Finance Team <billing@northbrook-logistics.co>
- Reply-To
- [email protected]
- Subject
- Updated remittance details — action required
Hi,
Following our recent banking migration we have updated our banking details. Please make sure the new account is used for invoice 4471, which is due before close of business today.
The revised remittance advice is available here:
https://portal.northbrooklogistics.com/invoices
Many thanks,
Accounts Receivable
The display name and the address disagree
The name says Finance Team, which is a department you recognise. The address is a domain you have never sent anything to. Display names are free text and are set by whoever sends the message; the address is the only part that is checked by anything.
The domain is close, but not the one
Your supplier is northbrooklogistics.com. This is a different registration: a hyphen added and the top-level domain changed. Both changes are invisible at a glance and neither requires compromising anything — the attacker simply bought a domain nobody was watching.
A deadline that prevents checking
Urgency is not a red flag because attackers are impatient. It is there to remove the step where you walk over and ask someone. Any request that would survive a twenty-minute delay is not damaged by taking it; a request that cannot survive one is telling you something.
The link text is not the destination
The visible text is the real supplier address. The href underneath points somewhere else entirely. Link text is display text and can say anything; hovering shows the destination in most clients, and on a phone a long press does the same.
The request routes around a process
Changing payment details is exactly the kind of instruction that organisations have a procedure for, and exactly the kind that arrives by email asking you to skip it. The control that defeats this costs nothing: bank changes are confirmed by calling a number you already had, never one in the message.
Replies go somewhere else again
The From address and the Reply-To address are different, which is legitimate in some newsletters and almost nothing else. If you reply, the conversation leaves the domain the message appeared to come from without any further action from the attacker.
Every one of those six survives perfect prose, because none of them is about how the message is written. They are about where it came from, where it goes and what it asks you to skip. That is a much shorter list than the old guidance and it has the advantage of still being true.
The strongest of the six is the last one, and it is not really about email at all. A request that routes around an existing process is suspicious regardless of how it arrives, how well it is written, or how plausible the sender appears — and that judgement does not degrade when the writing improves.
Two of the six also carry a warning about how they are usually taught. The domain and the link destination are checkable, and the checking is genuinely harder than training material implies: a lookalike registered this morning looks entirely ordinary, and inspecting a destination requires either hovering on a desktop or a deliberate long press on a phone. Presenting these as easy wins produces people who believe they checked when they glanced, which is a worse position than knowing you cannot tell and verifying another way instead.
The corollary is worth stating plainly, because it runs against how this subject is usually presented. For a well-made lure the correct answer is often that you cannot tell from the message, and the response to that is not to look harder. It is to leave the message and verify through something you chose — a number you already had, a colleague you can walk to, an address you typed yourself.
Why doesn't multi-factor authentication settle it?
Because the modern attack does not try to defeat the second factor. It asks you for it and passes it on. In an adversary-in-the-middle attack the page you land on is a proxy: it fetches the real login screen, shows it to you, forwards what you type, relays the authentication prompt back, and waits. You approve. The real service issues a session, and the proxy keeps it.
Inspecting the page does not help, which is what makes this different from earlier credential theft. There is no imperfect replica to catch, because it is not a replica. The certificate is valid, the branding is correct, the behaviour matches — it is the genuine site, relayed through somebody else's server. The only wrong thing is the address bar, on a domain chosen to survive a glance.
The measurement is unambiguous. Roughly three in five accounts compromised through phishing had multi-factor enabled when it happened, and these attacks grew by something close to 150 per cent in a year. Multi-factor authentication is still worth having and still stops a great deal — it is simply no longer sufficient against this specific technique, and saying otherwise leaves people confident about a control that is being walked past.
There is a second consequence that catches incident responders. Because the attacker holds a session cookie rather than a password, resetting the password changes nothing. Sessions have to be revoked explicitly, and a response that stops at "we forced a password reset" leaves the intruder logged in.
The control that actually removes the problem
Phishing-resistant authentication — passkeys and hardware security keys — is the only item on this page that eliminates the failure mode instead of reducing its probability. The reason is mechanical rather than a matter of degree.
The credential is bound to the domain it was registered against. When a proxy on a lookalike domain asks for it, the authenticator does not produce a weaker response or a warning: it produces nothing valid, because the origin does not match what it holds. There is no user decision in that path, which means there is no user error available to exploit.
Rollouts stall for predictable reasons and they are worth naming, because "we looked at passkeys" usually means one of them. Legacy applications that only accept passwords. Shared accounts that nobody wants to own. Contractors and seasonal staff whose device situation is unclear. Executives who resist carrying a key. None of those is a reason to abandon the control; all of them are reasons to sequence it, starting with the accounts whose compromise would matter most.
Partial coverage still helps here, which is a genuine difference from the multi-factor story. Protecting the twenty accounts that can move money or change infrastructure removes the outcomes that hurt most, even while the rest of the organisation is still on codes. The sequencing question is which accounts, not whether to start.
The version with no payload at all
Business email compromise is phishing stripped of everything a filter can act on. No attachment, no link, no malicious content — a message that asks for money to be moved, usually impersonating an executive under time pressure or a supplier announcing new bank details. The trade press was already putting the losses in the billions when it started tracking the category around mid-2016, and it has stayed the most expensive form of the attack since.
Technical defences have very little purchase on it. A plain-text message from a registered domain with no payload gives a filter almost nothing to score, which is why organisations with well-configured commercial filtering still take these losses. The failure is procedural and so is the fix.
One rule handles most of it: bank details are verified by calling a number the organisation already held, never one contained in the message requesting the change. It is unglamorous, costs nothing, and fails only when someone is allowed to skip it under pressure — which is precisely the scenario the attacker constructs.
The second rule matters as much and gets forgotten. Make it socially safe for a junior finance clerk to delay a request from a senior executive. Every published account of a large payment fraud contains a moment where someone was uneasy and proceeded anyway, and no amount of training overrides an organisational culture where questioning a director is a career risk.
Is awareness training worth the money?
For some outcomes and not for others, and the distinction has become sharper as lures improved. Training people to identify a well-made phishing message is close to hopeless when the message contains nothing to identify. Training them to verify payment changes, and to report anything odd fast, produces measurable results and keeps producing them.
The programmes that go wrong share a design flaw: they measure click rate. It is easy to collect and it looks like progress, and it drives behaviour nobody wants. Simulations get tuned to be catchable so the number improves. Staff learn to spot the internal exercise rather than the real thing. And clicking becomes shameful, which suppresses the reporting that actually matters.
Report rate and report speed are the better measurements, and they point the programme in a useful direction. An organisation where a third of recipients report a live campaign within ten minutes is in a strong position regardless of how many clicked, because the security team knows about it while it is still running.
That reframes the design work. Make reporting a single obvious action rather than a form. Respond to every report, including the wrong ones, so that reporting feels useful. And when somebody does click, treat it as the system working — they told you — rather than as a failure to be recorded against them.
It stopped being an email problem
The word still says email and the traffic has moved. Text messages carry a large share of consumer-facing lures, and they arrive on a device with a small screen where the destination of a link is hard to inspect. Collaboration platforms carry internal impersonation that inherits the trust of the workspace it appears in. Calendar invitations deliver links without ever passing an email filter.
Voice has changed the most and the fastest. Synthesised speech has made a convincing call in a familiar voice inexpensive, and the combination that works is depressingly simple: a message that creates a problem, followed by a call from someone who sounds like the person who would solve it. The call supplies the pressure and the reassurance at once.
None of that requires a new defensive idea, which is the encouraging part. The habit that answers a suspicious email — stop, and verify through a channel you chose rather than the one that contacted you — answers all of these unchanged. What does need updating is the training material, which in most organisations still shows a screenshot of an inbox and nothing else.
The one genuinely new requirement is a verification method that does not rely on recognising a voice. Some organisations have settled on a spoken phrase agreed in advance for finance approvals. It sounds theatrical until the first time somebody receives a call from their chief executive that turns out to be a recording.
Text deserves a specific note because the constraints of the device do half the attacker's work. A link on a phone shows a shortened address, a long press to inspect it is a habit almost nobody has, and the message arrives in the same thread as legitimate ones from the same short code. Advice written for a desktop mail client — hover the link, check the header — describes actions that either do not exist on the device or are impractical enough that nobody performs them.
What do you do in the hour after someone clicks?
The response to a successful phish is short, ordered, and different from what most runbooks say, because the thing the attacker holds is usually a session rather than a password.
Revoke sessions, then reset the password. That order matters. A reset alone leaves an active session working, and organisations discover this by watching the intruder continue to read mail for a day after the account was supposedly secured. Every major identity platform has a sign-out-everywhere action; find it before you need it, because searching for it while an attacker is live costs the exact minutes that matter.
Check what was configured, not just what was read. The first thing an intruder does with a mailbox is arrange to keep access and stay quiet: a forwarding rule to an outside address, a filter that moves anything mentioning invoices straight to a folder nobody opens, an application consent granted to something that keeps working after the password changes. Undoing the compromise means undoing those, and they survive a password reset untouched.
Assume the mailbox was read and act on it. If the account handled payment approvals, the supplier details it discussed are now known to somebody else, and the follow-up fraud often arrives weeks later against a different person entirely. Tell the affected counterparties. It is an awkward conversation and considerably less awkward than the one after the money leaves.
What the filter can and cannot do
Email filtering removes an enormous volume of low-effort attack and deserves more credit than it gets. It also has a ceiling that is structural: a meaningful share of phishing reaches inboxes at organisations running well-configured commercial products, and that was being reported as a measured finding as early as 2019. The number has not improved in the direction anyone hoped.
The ceiling exists because the hardest messages to catch contain the least to analyse. A plain-text request from a legitimate, newly registered domain with no attachment and no link presents almost no signal. Reputation systems need history to score, and a domain bought this morning has none — which is why disposable domains remain the standard tooling rather than an exotic technique.
Two configuration items still repay the effort more than most purchases. Enforce domain authentication properly, so that messages claiming to come from your own domain and failing the check are rejected rather than delivered with a warning label nobody reads. And mark external mail visibly, which does not stop anything by itself but makes internal impersonation take one step more work.
There is a quieter cost to filtering that deserves stating, because it shapes how people behave. Every message held for review, every warning banner attached to a legitimate newsletter, teaches recipients that the system cries wolf. Organisations that tune aggressively and never revisit the false positives end up with staff who dismiss the warnings by reflex — which converts a control into a decoration, and does it slowly enough that nobody notices the moment it stopped working.
Common questions
What is phishing?
A message that impersonates something you trust in order to get you to hand over credentials, authorise a payment or run something. The channel has expanded well past email — text messages, calendar invitations, collaboration tools and voice calls all carry it now.
Does multi-factor authentication stop phishing?
Not the modern kind. In adversary-in-the-middle attacks the fake page relays your login to the real site in real time, passes the prompt through to you, and captures the resulting session. Most accounts compromised through phishing had multi-factor enabled at the time.
Why has phishing suddenly got harder to spot?
Because the tells people were taught to look for were artefacts of writing in a second language at scale. Spelling, grammar and awkward phrasing were never the vulnerability — they were the cost of the attacker's constraints, and generated text removed that cost.
How much more effective are AI-written lures?
Measured click rates land around four to five times higher than hand-written equivalents, at a fraction of the cost per message. That combination matters more than either number alone: it makes targeted quality affordable at untargeted volume.
What is adversary-in-the-middle?
A phishing page that proxies the real login instead of imitating it. You see the genuine site because it is the genuine site, relayed. Everything you type is forwarded, including the second factor, and the attacker keeps the session cookie that results.
What actually defeats credential phishing?
Phishing-resistant authentication — passkeys and hardware security keys — because the credential is bound to the real domain and simply will not produce a valid response for a proxy. It is the only control on this subject that removes the failure mode rather than reducing its odds.
Is awareness training worth doing?
For some things, yes. It measurably helps with payment fraud and with getting people to report quickly. It does not reliably teach anyone to identify a well-made lure, and programmes that measure success by click rate tend to optimise for a number rather than for safety.
What is business email compromise?
Phishing without a payload: a message that simply asks for money to be moved, usually impersonating an executive or a supplier changing bank details. There is nothing malicious to detect, which is why it defeats filters and why the control has to be procedural.
How should someone report a suspicious message?
In one step, to somewhere that responds. Reporting speed is the single most useful behaviour to cultivate, and it collapses the moment the route is a multi-field form or the reporter fears being told off for a false alarm.
Do email filters still help?
Considerably, and they were never going to be sufficient. A meaningful share of phishing reaches inboxes at organisations running well-configured commercial filtering, and messages carrying no link and no attachment give a filter almost nothing to act on.
What about voice and text?
Both are growing, and voice has changed character with synthesised speech: a call in a familiar voice asking to approve a prompt is now inexpensive to produce. The verification habit that answers it is the same one that answers email — call back on a number you already had.
What single change helps most?
Rolling out phishing-resistant authentication to the accounts that matter. If that is blocked, the runner-up is a payment verification rule that no message can override, because the losses concentrate in payment fraud rather than in malware.
Phishing coverage
763 reports on phishing and email fraud, newest first.
- Under Siege: How Healthcare Organizations Can Fight Back
November 26, 2021 · cpomagazine.com
- The most wonderful time of the year - for cybercriminals
November 26, 2021 · securitybrief.asia
- MediaTek chipset-based Android phones vulnerable to hackers: Check Point Research
November 25, 2021 · deccanherald.com
- Industrial cybersecurity market to reach $22.3 billion by 2026
November 12, 2021 · helpnetsecurity.com
- Stellar Cyber integrates security platform with Barracuda Networks
November 12, 2021 · securitybrief.asia
- 4 ways companies can increase their cybersecurity
November 12, 2021 · techrepublic.com
- 'Bait attacks' become go-to method for cyber criminals
November 11, 2021 · securitybrief.asia
- Organizations believe they are ready for ransomware attacks
November 10, 2021 · helpnetsecurity.com
- Securing ‘Digital India’ With a Zero Trust Approach
November 10, 2021 · cisomag.eccouncil.org
- Top Five Cybersecurity Threats And How To Avoid Them
November 10, 2021 · forbes.com
- Younger generations care little about cybersecurity
November 8, 2021 · helpnetsecurity.com
- Mobile phishing exposure in the energy industry surged 161% in 2021
November 8, 2021 · helpnetsecurity.com
- Scammers using Google Ads to steal $500k of cryptocurrency
November 8, 2021 · securitybrief.asia
- Hackers Use SEO Poisoning to Spread Ransomware
November 2, 2021 · cisomag.eccouncil.org
- Tech support scams top the list of cyber security threats
November 1, 2021 · techguide.com.au
- Lack of Threat Awareness Creates Hybrid Work Risks
November 1, 2021 · securityboulevard.com
- AI Phishing Defense Leader SlashNext Closes $26 Million Series B Funding
October 29, 2021 · prnewswire.com
- Tech support scams are the number 1 phishing threat
October 28, 2021 · securitybrief.asia
- Most firms think remote employees pose more risk than office workers
October 28, 2021 · itproportal.com
- Phishing attack exploits Craigslist and Microsoft OneDrive
October 27, 2021 · techrepublic.com
- What Agencies and Industry Can Learn from Sharing Cyber Threat Intel
October 26, 2021 · nextgov.com
- COVID: Proof of vaccination phishing scam hits the web
October 26, 2021 · securitybrief.asia
- SolarWinds Attacker Targets Cloud Service Providers in New Supply Chain Threat
October 26, 2021 · darkreading.com
- How social engineering contributes to successful ransomware attacks
October 25, 2021 · itproportal.com
- Tech support scams becoming the top phishing threat to consumers
October 22, 2021 · helpnetsecurity.com
- Supply chain attacks are a bigger risk than ever
October 22, 2021 · itproportal.com
- Rackspace highlights top security challenges of today's organisations
October 21, 2021 · securitybrief.asia
- Allocators and Managers Remain Vulnerable to Cybersecurity Threats
October 21, 2021 · institutionalinvestor.com
- Cyber Security Month in the WFH Era: Three Key Steps to Secure Hybrid Teams
October 20, 2021 · itsecuritycentral.teramind.co
- VPN Provider's Misconfiguration Exposes One Million Users
October 20, 2021 · infosecurity-magazine.com