Digital Threat Intelligence Report · January – June 2026

The anatomy of brand attacks in the first half of 2026

Seven defining shifts in brand impersonation and phishing, drawn from public threat intelligence (APWG, IBM X-Force, Verizon DBIR, CrowdStrike, FBI IC3, and Hornetsecurity) and read alongside how PhishFort’s own detection and takedown operations have responded to each one.
14x
Spike in AI-assisted phishing over the holidays
442%
Surge in vishing & voice-clone attacks
48%
Of breaches now involve a third party
29K+
Takedowns for a single protected brand
Section 01

Executive summary & key findings

In the first half of 2026, we saw several previously nascent attack techniques go mainstream. Drawing on public threat intelligence from APWG, IBM, Verizon’s DBIR, CrowdStrike, and the FBI’s IC3, and read alongside PhishFort’s own casework, four shifts stand out as the ones security teams should be planning around for the second half of the year.

Start with the clearest sign of what changed this cycle: how much phishing content is now AI-assisted, month by month, heading into 2026.

Share of sampled phishing emails with AI-assistance indicators, by month. Source: Hoxhunt Phishing Trends Report 2026, published March 2026.

For most of 2025, AI-generated phishing sat under 5%: background noise. Then it surged 14x in a single month over the holidays and has stayed elevated into 2026. That timing matches what we saw in our own detection pipeline almost exactly: the volume shift didn’t happen gradually across 2025, it happened over a few weeks at the turn of the year, and it’s the reason our analysts stopped treating well-written as a signal. The sites and lures we’re taking down now are indistinguishable from legitimate communications on writing quality alone, so attribution has to come from infrastructure and behavioral signals instead.

Volume and sophistication are one measure. What that actually costs organizations is another, and Business Email Compromise is the clearest line item for it, with fresh 2025 figures the FBI only just published.

Reported BEC losses, USD billions. Source: FBI Internet Crime Complaint Center (IC3) Annual Reports, 2023–2025; the 2025 figures were released in the IC3's 2025 Annual Report in April 2026.

BEC losses jumped back up in 2025 after a flat 2024, reaching $3.05 billion across nearly 24,800 complaints, and that’s just the reported, U.S.-only figure; IC3’s total cybercrime loss estimate for 2025 crossed $20.9 billion, up 26% year-over-year. This tracks closely with the BEC-via-typosquat cases our takedown team handles most often: a lookalike domain configured purely to send fraudulent invoices, with no web presence at all, evading web-based detection entirely. Standard registrar abuse channels are frequently ineffective against that kind of infrastructure, which is exactly the scenario where a direct registrar relationship is the difference between catching it before or after money has already moved.

The most-cited headline from this year’s Verizon Data Breach Investigations Report is a shift in how attackers are getting in the door in the first place. Verizon’s own report visualizes every figure with a deliberately uncertain edge, a reminder that no single number in security research is exact. We borrowed that convention below for the same reason.

By the numbers

Four headline metrics from the Verizon 2026 DBIR, Nov 2024–Oct 2025 dataset

Human element present in breach 62%
Third-party involvement in breach 48%
Vulnerability exploitation as entry point 31%
Credential abuse as entry point 13%

Share of confirmed breaches, Verizon 2026 Data Breach Investigations Report, released May 2026. The soft, fading edge on each bar (rather than a hard stop) is a deliberate nod to the DBIR’s own house style: no percentage in breach research is exact, and pretending otherwise misrepresents the data.

Vulnerability exploitation overtook stolen credentials as the single leading entry point for the first time, but the DBIR itself warns against reading that as a retreat from identity-based attacks. The human element was still present in 62% of breaches overall (up from 60% the year before), and 41% of social-engineering breaches now arrive through channels a standard email gateway can’t see at all: voice calls, SMS, collaboration platforms. That’s consistent with why we expanded PhishFort’s own monitoring this semester beyond email-based lookalike domains and into voice, social, and messaging-app impersonation. The credential-theft attempt didn’t go away, it just moved somewhere email security tooling doesn’t look.

Zooming out from any single chart, here’s how the headline metrics across our primary sources moved between their prior reporting period and the most current one available, ranging from a full year to a matter of weeks, depending on how often each source publishes.

MetricBaselineLatestChange
AI-assisted phishing shareNov 2025: 4%Jan 2026: 40%+900%
Reported ransomware losses (IC3)2024: $12.5M2025: $32.3M+159%
Third-party involvement in breachesPrior period: 30%2025 (DBIR): 48%+60%
Vulnerability exploitation as entry pointPrior period: 20%2025 (DBIR): 31%+55%
Total reported cybercrime losses (IC3)2024: $16.6B2025: $20.9B+26%
BEC losses (IC3)2024: $2.77B2025: $3.05B+10%
Human element present in breachesPrior period: 60%2025 (DBIR): 62%+3%
Global phishing attack volume (APWG)2024: 3.76M2025: 3.8M+1%
Credential abuse as entry pointPrior period: 22%2025 (DBIR): 13%−41%
Smaller move Larger increase Decrease

Baseline and latest periods vary by source and are shown per row. Annual reports compare calendar years, while the DBIR’s “prior period” and “2025” reflect its rolling Nov–Oct reporting window, and the AI-assistance figures are monthly (Hoxhunt). See Section 03 and the sources list at the end of this report for full citations.

Laid out side by side like this, the pattern is hard to miss: the metrics moving fastest are the ones tied to AI-assisted content and the operational cost of an attack once it lands (ransomware payouts, AI-phishing share), while the metrics tracking raw attack volume barely moved at all. That’s the same story our own takedown data tells: we’re not seeing dramatically more incoming threats, but the ones we are seeing take more effort to attribute, evade detection longer, and, in the BEC and executive-impersonation cases especially, cost victims more per incident. Volume was never really the right thing to optimize defenses against; severity and evasion were, and this table is the clearest illustration of that shift we’ve found in the public data.

14x
AI-assisted phishing is now the norm, not the exception
The share of phishing emails carrying AI-assistance signals held under 5% for most of 2025, then surged 14x in a single month, jumping to 56% in December before settling at 40% in January 2026, per Hoxhunt’s 2026 Phishing Trends Report. The tell-tale typos and stilted grammar that used to flag a phishing attempt are absent from a huge share of what lands in today’s inboxes.
MFA-bypass kits moved from elite tooling to commodity software

Phishing that sidesteps MFA, whether by relaying a live login through a Man-in-the-Middle (MiTM) reverse proxy or by tricking a victim into authorizing an attacker’s session outright, used to require serious attacker sophistication.

In 2026 it became a packaged, subscription product: the Kali365 kit, which abuses Microsoft’s OAuth device-authorization flow to capture access tokens without ever touching a password, sells for around $250 a month and drew a Public Service Announcement from the FBI in May.

442%
Vishing and voice-cloning attacks surged
CrowdStrike recorded a 442% jump in vishing campaigns, a rise directly linked to advances in AI voice cloning. McAfee notes that as little as three seconds of audio, lifted from a YouTube clip or voicemail greeting, is now enough to produce a convincing clone of someone’s voice.
30%
Third-party and supply-chain exposure became a boardroom issue

IBM’s Cost of a Data Breach Report 2025 found that third-party involvement in breaches doubled year-over-year to 30%, at an average cost of $4.91 million and 267 days to detect.

Verizon’s 2026 DBIR, published in May, put it in starker terms still: 48% of breaches now involve a third party in some capacity, a 60% jump from the year before. However it’s measured, a brand’s attack surface now includes its vendors and partners, not just its own domains.

Analyst note
Each of these four shifts describes the same underlying dynamic: the cost of mounting a convincing attack keeps falling. Meanwhile, the cost of defending against these attacks is also falling, but not nearly as fast. The seven trends explored in this report are the practical expressions of that gap, and how we’re working to close it.

Section 02

Seven trends defining brand attacks in the first half of 2026

This section maps the seven public threat-research trends we judged most consequential for brand and identity protection, selected for how directly they showed up in the casework our detection and takedown teams handled between January and June. Each one is explored in depth in Section 03.

Before getting into the seven trends themselves, it’s worth seeing who’s actually being targeted most, industry-wide.

Share of total phishing attack volume by targeted sector, Q4 2025. Source: APWG Phishing Activity Trends Report Q4 2025, data contributed by Crane Authentication / OpSec Security.

Telecom’s share nearly tripled quarter-over-quarter, from 5.9% in Q3 to 18.7% in Q4, while Financial Institutions, the single most-targeted sector as recently as Q2, fell out of the top three entirely. We’ve seen an echo of that reshuffling in our own casework: the SaaS and social-media-heavy sectors we protect are increasingly dealing with OAuth consent phishing and account-takeover attempts rather than the classic cloned-login-page attack, which tracks with why Trend 02 below is specifically about MFA-bypass kits rather than generic credential phishing.

Trend 01 AI-generated phishing goes mainstream
14x growth in AI-assisted phishing share in a single month
The share of phishing emails carrying AI-assistance signals surged 14x in a single month, from under 5% to 56%, and has stayed elevated into 2026. Fluent, typo-free lures are now the baseline, not the tell.
Sources: Hoxhunt, Astra, IBM X-Force
Trend 02 MFA-bypass kits go commodity
$250/mo subscription price of the Kali365 MFA-bypass kit
Phishing that defeats MFA, from AiTM reverse proxies to OAuth device-code abuse, used to require serious skill. Kits like Kali365 now sell for around $250 a month, and the FBI issued a public advisory in May.
Sources: Hornetsecurity, FBI IC3
Trend 03 Phishing-as-a-Service lowers the skill floor
50%+ projected share of phishing incidents driven by turnkey kits by end of 2026
Turnkey phishing kits are projected to drive the majority of incidents by the end of 2026, letting low-skilled operators run campaigns that once needed a development team.
Sources: WEF, CloudSEK
Trend 04 Vishing and voice cloning surge
442% surge in vishing campaign volume recorded by CrowdStrike
CrowdStrike recorded a 442% surge in vishing campaigns. Three seconds of audio is enough to clone a voice convincingly, and government-impersonation vishing complaints to the FBI nearly doubled year over year.
Sources: CrowdStrike, McAfee, FBI IC3
Trend 05 Major events as ready-made attack infrastructure
<1 day from event announcement to the first lookalike-domain registrations
Lookalike-domain registrations often appear within a day of a major event being announced. Ticketing scams and fraudulent betting platforms tied to the FIFA World Cup 2026 were live well before kickoff, riding the seasonal spike in search interest.
PhishFort threat research, iGaming & events sector
Trend 06 DeFi phishing spikes after every protocol hack
Hours from public exploit disclosure to fake “claim your funds” sites appearing
Fake “claim your funds” and compensation sites reliably appear within hours of a public protocol exploit, targeting the same users twice.
PhishFort threat research, DeFi & Web3
Trend 07 Third-party exposure becomes a boardroom issue
30–48% share of breaches involving a third party (IBM 2025 → Verizon 2026 DBIR)
IBM found third-party involvement in breaches doubled to 30% of incidents ($4.91M avg. cost); Verizon’s 2026 DBIR put third-party involvement at 48% of all breaches, up 60% year-over-year.
Sources: IBM Cost of a Data Breach 2025, Verizon 2026 DBIR
Why these seven
None of these trends are exclusive to any one industry. What they have in common is that each one erodes a defense that used to be reliable: spotting bad grammar, trusting MFA, recognizing a voice, or assuming a vendor’s security is someone else’s problem. Section 03 walks through each one and how our own detection and takedown work has adapted.

Section 03

Trend deep-dives: what's happening and how we've worked it

Public threat intelligence tells you what’s happening across the industry. What follows pairs each trend with how PhishFort’s detection and takedown operations have actually engaged with it this semester, including the research our own team has published along the way.

Trend 01

AI-generated phishing became the default, not the exception

For years, the standard phishing-awareness advice was to look for typos and awkward phrasing. That advice stopped working almost overnight at the end of 2025. Hoxhunt’s 2026 Phishing Trends Report, drawn from over 50 million simulations and real reported threats across 125 countries, found the share of phishing emails carrying AI-assistance signals sat under 5% for most of 2025, then spiked 14x to 56% in December, before settling at 40% in January 2026 and holding there. IBM’s Cost of a Data Breach Report 2025 puts the productivity gain behind that spike in stark terms: generative AI has cut the time to produce a convincing phishing email from roughly sixteen hours to about five minutes. Verizon’s 2026 DBIR adds a rare piece of ground-truth data here: an analysis run with Anthropic covering nearly 800 threat actors, which found the median actor used AI across some 15 distinct attack techniques, with 44% of AI-assisted initial access attempts being phishing-related. The DBIR’s own conclusion is measured: AI is mostly scaling and industrializing what attackers already knew how to do, not inventing new attack types, which lines up with what we’re seeing in takedown volume more than in novel techniques.

Each shield is 1% of breaches across the 600 breached organizations studied in IBM's 2025 report.
16%

of breaches involved attackers using AI somewhere in the attack chain

Per IBM’s Cost of a Data Breach Report 2025, generative AI shows up in the phishing lure most often (37% of AI-involved breaches), with deepfake impersonation close behind (35%). It’s still a minority of total breaches, which is worth holding onto: AI hasn’t replaced conventional attack methods, it’s made a growing slice of them faster to produce.

We’ve had to make the same adjustment our clients are being asked to make. Our detection models were never built to catch phishing by spotting bad writing, but the volume shift is real, and it shows up most clearly in social platform abuse, including one case our research team documented where attackers bypassed Meta’s own AI-driven support system with a short, carefully worded prompt and took over a high-profile Instagram account outright. The response in cases like that isn’t content review; it’s fast, direct escalation with the platform once account compromise is confirmed.

Trend 02

MFA-bypass kits went from elite tooling to a $250-a-month subscription

Bypassing MFA used to be a capability reserved for sophisticated threat actors, built on Adversary-in-the-Middle reverse proxies that relay a live login session, MFA challenge included, straight through to the real service. In 2026 the MFA bypass became a packaged product, and the flagship example doesn’t bother relaying logins at all. The Kali365 kit, priced around $250 a month, abuses Microsoft’s legitimate OAuth device-authorization flow: the victim is talked into entering a short device code, and the attacker walks away with a Microsoft 365 access token, no password intercepted and no further MFA prompt triggered. It drew a Public Service Announcement from the FBI’s Internet Crime Complaint Center in May after Hornetsecurity’s threat lab documented active campaigns.

This is squarely in our detection lane: rogue OAuth consent screens and cloned SSO or login pages are exactly the kind of look-alike infrastructure our SaaS and technology clients ask us to hunt for continuously, not just review on complaint. Two pieces from our research team this semester walk through specific variants: a Microsoft OTP-theft flow and a Google Workspace invitation lure, both built around the same principle of borrowing a trusted login flow to slip past MFA entirely. It’s telling that NIST’s own Digital Identity Guidelines, revised in July 2025 as SP 800-63-4, moved phishing-resistant authentication (FIDO2 keys and passkeys, not SMS or app-based codes) from a recommendation to the federal baseline. The standards body updating its threat model is a strong signal that traditional MFA can no longer be treated as sufficient on its own.

Cybersecurity 4 min read

Microsoft OTP Phishing Attack: How Threat Actors Abuse Trusted Alerts

Threat actors are abusing legitimate Microsoft OTP and MFA notification systems to bypass SPF, DMARC, and traditional email defenses. Learn how this phishing attack works and how to defend against it.

Read more: Microsoft OTP Phishing Attack: How Threat Actors Abuse Trusted Alerts
Trend 03

Phishing-as-a-Service keeps lowering the skill floor

Turnkey phishing kits let an operator with no development background stand up, test, and iterate a convincing campaign in real time. Industry analysis from the World Economic Forum and CloudSEK projects that phishing kits will drive the majority of phishing incidents by the end of 2026, a shift from artisanal attacks toward an industrialized supply chain of ready-made infrastructure.

The practical effect for defenders is volume: more domains, more near-identical templates, more organizations that never expected to be a target getting hit anyway. It’s also why we built PhishFort’s takedown service to be accessible without a long procurement cycle in the first place. Organizations without an in-house security team are increasingly the ones facing professionally packaged attacks, and they need a response that doesn’t require building one from scratch.

Trend 04

Vishing and voice cloning turned a 3-second clip into a weapon

CrowdStrike recorded a 442% surge in vishing campaigns, and the driver is voice-cloning technology maturing faster than most organizations’ internal verification habits. McAfee’s research puts the bar startlingly low: about three seconds of audio, pulled from a conference recording, a voicemail greeting, or a public video, is enough to produce a clone convincing enough to fool a colleague on a live call. Verizon’s 2026 DBIR, drawing on the largest dataset in its 19-year history, confirms the shift at scale: phone-centric social engineering (voice calls and text) now succeeds roughly 40% more often than email-based attempts (a median 2% click rate versus 1.4% for email), and the report added pretexting as its own formally tracked initial access vector for the first time, already accounting for 6% of breaches.

Each shield is 1% of confirmed breaches in the DBIR's 2025 dataset.
6%

of breaches now involve pretexting as a tracked entry vector, on its first appearance in the DBIR

Six percent sounds small next to vulnerability exploitation’s 31%, but this is a brand-new category the DBIR only started measuring this edition, precisely because voice and text-based impersonation had grown common enough to warrant its own line item. A category that starts at 6% and is new by definition is one to watch, not dismiss.

This is the trend our Executive Protection work is built around: tracking impersonation, cloned likenesses, and misuse of an executive’s identity across the open and dark web before it’s weaponized in a call. Voice cloning doesn’t change what we monitor for so much as it raises the stakes of catching an impersonation attempt early, since by the time a vished call happens, the deception has usually already been rehearsed.

Learn more about PhishFort’s Executive Protection

Trend 05

Major events became ready-made attack infrastructure

Large sporting and cultural events reliably produce a spike in brand-specific search interest, and threat actors treat that spike as free distribution. Fraudulent ticketing sites and lookalike betting platforms tied to the FIFA World Cup 2026 were live and indexed well before the tournament itself began, positioned to intercept fans searching for tickets or looking to place a bet.

Our iGaming and events-sector monitoring picked this pattern up early this semester, which is why our research team published two separate pieces on it: one on the gambling and betting angle, the other specifically on the ticketing scams. Both link back to a pattern our takedown team sees every time a major event is announced: registrations for lookalike domains often appear within a day of the announcement, well ahead of the event itself.

Cybersecurity 6 min read

FIFA World Cup 2026 ticketing scams

PhishFort researchers identified multi-stage fake FIFA ticketing sites harvesting credentials, PII, and payment data. Here's how the infrastructure works and what to monitor.

Read more: FIFA World Cup 2026 ticketing scams
Trend 06

DeFi phishing spikes in the hours after every protocol hack

A protocol exploit doesn’t end the attack. For the affected users, it often starts a second one. Fake “claim your compensation” or “revoke your exposed approvals” sites reliably appear within hours of a public hack disclosure, targeting the same users who are already anxious and searching for guidance, and exploiting the fact that the real remediation advice often does involve visiting a wallet-permissions tool.

This is a pattern we’ve worked directly with Revoke.cash on this semester, publishing joint guidance on how legitimate post-hack remediation differs from the phishing sites that copy it, specifically around wallet permission revocation, which is exactly the kind of action attackers now impersonate.

Trend 07

Third-party and supply-chain exposure became a boardroom issue

IBM’s Cost of a Data Breach Report 2025 found that third-party involvement in breaches doubled year-over-year to 30% of incidents, averaging $4.91 million and 267 days to detect and contain, the longest of any breach category, because it exploits trust relationships rather than technical weaknesses. Verizon’s 2026 DBIR, released in May and drawing on over 22,000 confirmed breaches, found an even sharper picture: 48% of all breaches now involve a third party in some capacity, a 60% increase year-over-year. Part of what’s driving this is infrastructure abuse that has nothing to do with the victim organization’s own network: compromised IoT and smart-home devices are increasingly used to route malicious traffic through legitimate residential IP addresses, which lets attackers walk straight past perimeter controls built to flag suspicious data-center traffic.

Our research team covered this residential-proxy pattern in detail this semester, and it’s a useful example of why brand protection increasingly has to look beyond an organization’s own domains. The infrastructure being abused to attack you, or a partner you rely on, often belongs to someone else entirely. Forrester’s Top Cybersecurity Threats In 2026 report flags this as a forward-looking concern too, naming AI software supply chain risk (driven by open-source model and framework adoption) as one of the threat categories security leaders should treat as non-negotiable for the year ahead.

Cybersecurity 7 min read

IoT Botnet Residential Proxy Risk for Enterprise Networks

Compromised smart home devices route attack traffic through legitimate residential IPs — bypassing your perimeter controls. Here's how it works and what stops it.

Read more: IoT Botnet Residential Proxy Risk for Enterprise Networks

Section 04

Market context: where current defenses fall short

Across the incidents documented in the first semester of 2026, a consistent set of operational gaps emerges in how organizations attempt to defend against brand impersonation, regardless of which tools or vendors they currently use.

Observed gapHow it manifests in practiceSectors most affected
Detection without executionThe most common failure pattern: threat intelligence platforms identify and alert on brand impersonation incidents but lack the operational capability to act on those alerts.

The alert tells organizations a fake domain exists; it does not remove it. The gap between awareness and response is where harm accumulates.

Root cause: intelligence vs. action
Financial services, enterprise technology
Automation failure in complex hostingAutomated takedown systems succeed in straightforward cases: cooperative registrars, mainstream hosting, DMCA-responsive jurisdictions. They fail systematically against fast-flux infrastructure, bulletproof offshore hosting, and non-cooperative registrars.

The cases where automation fails are precisely where the attacker has invested in evasion, meaning the hardest cases go unresolved.

Root cause: no manual escalation path
iGaming, crypto, high-value targets
No contractual accountabilityEnterprise buyers in financial services and corporate security increasingly require contractual SLAs with defined response windows and financial penalties for misses.

Current market offerings are predominantly SLA-free, with removal timelines stated as estimates rather than commitments, a gap that is becoming a deal-breaker for regulated organizations.

Root cause: market hasn’t demanded it yet
Financial services, legal, enterprise
Reactive-only postureMost current tools are complaint-driven: a human discovers a fake domain, submits it for removal, and the process begins. In fast-moving campaigns, iGaming and crypto especially, attackers have already redeployed by the time a complaint is submitted.

Continuous monitoring that detects newly-registered lookalike domains before they are weaponized is structurally different from complaint-handling.

Root cause: workflow design, not technology
All sectors, acute in iGaming, crypto, events
Structural observation
These four gaps compound each other. An organization that detects threats but cannot execute removal develops alert fatigue. One that uses automation without manual escalation has a systematically incomplete defense. One that operates reactively will always lag an attacker who redeploys faster than the removal cycle completes. Effective brand protection requires all four components working together: detection, execution, accountability, and continuous monitoring.

Section 05

Recommendations: building a resilient brand protection posture

The following recommendations emerge directly from the January–June 2026 threat data. They are organized as operational controls: specific, implementable measures that address the attack patterns and defensive gaps documented in this report.

R1

Move from incident response to continuous monitoring

The single most impactful posture change available to most organizations. Continuous monitoring of new domain registrations, certificate transparency logs, and social media for lookalike assets allows detection before a domain is weaponized, not after victims have been harmed. In iGaming and crypto, where redeployment occurs within 24–72 hours of takedown, monitoring is not a supplement to removal services; it is the primary defense layer.
R2

Require manual escalation capability in any takedown vendor

Automated takedown systems are effective for the majority of straightforward cases but fail systematically against the hardest targets. Before engaging a brand protection vendor, organizations should explicitly evaluate the manual escalation pathway: what happens when automated routes fail? Does the vendor have direct registrar relationships? Can they engage in-jurisdiction legal processes? The answers determine whether complex cases get resolved or become permanent vulnerabilities.
R3

Audit and actively maintain the full domain portfolio

Expired domains are an exploitable attack surface. Organizations should maintain an active inventory of all registered domains, including legacy product sites, campaign microsites, and brand variants, and either renew them proactively or monitor them after expiration. The expired domain attack bypasses new-domain detection heuristics because it carries legitimate history, making it particularly dangerous and particularly easy to prevent with basic portfolio hygiene.
R4

Establish false positive review relationships before an incident occurs

Organizations in technology and DeFi should proactively identify which downstream security vendors (Cloudflare, Cisco Talos, OpenDNS, Palo Alto, FortiGuard, Trend Micro) could blocklist their domains through automated or adversarial reporting, and establish contacts with each before an incident occurs. Once a domain is flagged across multiple blocklists, removal from all of them requires separate processes, significantly easier to navigate with pre-existing relationships.
R5

Demand contractual SLAs for social media takedowns

Executive impersonation on social media causes harm that compounds daily. Organizations with material exposure (financial services, wealth management, high-profile executives) should require contractually guaranteed response windows with financial penalties for misses as a baseline procurement requirement. Vendors unable to offer contractual accountability should be disqualified from the evaluation. The market is beginning to supply this capability, but buyers must demand it explicitly.

Section 06

How PhishFort responds to these threats

The seven trends in this report aren’t abstract to us. They describe the actual attacks our detection and takedown teams worked through this semester, across every sector we protect. What follows is an account of how we work, what we do when a threat surfaces, and where the results show up in practice.

The most important thing to understand about brand impersonation is that detection without action is not protection. A great many organizations already know when they are being attacked. They receive abuse reports, their users complain, they see fake sites in search results. What they lack is the operational capability to make those sites disappear quickly and reliably. That gap is exactly what PhishFort was built to close.

Our approach combines AI-native detection with a dedicated SOC team that validates every threat before acting. We do not generate alerts for your team to chase. We investigate, classify, and, in the vast majority of cases, handle takedowns end-to-end, without requiring meaningful time from the organizations we protect.

What we do

Five connected capabilities. Explore any of them, or see them work together in a live walkthrough of your own exposure.

Detection

AI models trained to spot phishing kits and impersonation the moment they spin up, with every verdict validated by a human analyst.
Learn more about Detection

Takedowns

Direct relationships with registrars, hosts, and platforms. 99.76% success rate, even against bulletproof hosting and fast-flux DNS.
Learn more about Takedowns

Brand Monitoring

Continuous scanning across domains, app stores, social platforms, and the dark web, around the clock, tracking re-emergence after takedown.
Learn more about Brand Monitoring

Executive Protection

Tracking impersonation, leaked PII, and deepfakes tied to your leadership team, across the open, deep, and dark web.
Learn more about Executive Protection

Dark Web Intelligence

Real-time signals from phishing kits, breach dumps, and threat-actor chatter, enriched and validated before they ever reach you.
Learn more about Dark Web Intelligence
Get a live demo

Section 07

Where the results show up

Numbers are more useful than claims, so here are results from organizations that have made their experience with PhishFort public, spanning crypto, iGaming, and Web3, three of the highest-volume attack surfaces described in this report. Each one illustrates what changes when the gap between detecting a threat and actually removing it closes.

Success story: Hardware Wallets
Trezor / SatoshiLabs
Trezor invented the hardware wallet, and its users’ crypto assets, once lost to phishing, are gone permanently. Before PhishFort, the internal security team caught roughly 300 to 400 threats a year through manual monitoring. Since integration, over 29,000 fake websites and malicious domains have been taken down at the same headcount, with most threats resolved before the internal team has time to act.
29,000+
takedowns executed
99.76%
success rate
4–6h
avg. resolution
Read the full story →
Success story: Crypto Exchange
Bitkub, Thailand's #1 crypto exchange
Bitkub’s security engineers were losing 25 hours a week to manual incident reporting. The partnership returned that time to platform architecture and threat hunting: roughly 2,800 takedowns in 2025 alone, including bulk Meta phishing accounts removed in single operations. The Chief Security Officer called PhishFort “an essential extension of our security function.”
~2,800
takedowns in 2025
25 hrs
reclaimed per week
unlimited takedown model
Read the full story →
Success story: Sportsbook, Multi-jurisdictional
Global sportsbook operator
This multi-jurisdiction sportsbook faced mirror sites built to bypass geofencing controls, letting users in restricted regions reach unlicensed, look-alike betting platforms carrying its branding. PhishFort’s continuous monitoring identified and dismantled that infrastructure at scale, neutralising more than 1,400 threats.
1,400+
threats neutralised
Multi-jur.
geofence-bypass coverage
Read the full story →
Success story: iGaming Platform
Global iGaming operator
This operator’s internal team was manually handling around 800 threats a year, a ceiling set by manual review rather than the real scale of the problem. Within twelve months of onboarding, detection and actioning had scaled past 4,700 threats a year with no increase in headcount.
~800 → 4,700+
threats/year, before → after
12 mo.
to reach full scale
Read the full story →

From the PhishFort research team

Beyond the pieces already linked in Section 03, here are two more from the PhishFort blog that round out the picture, written for security practitioners and directly relevant to the gaps described in Section 04.
View all

See what's targeting your brand right now

We can show you the active threats against your domain and brand assets in a single session, no long procurement cycle required. Most organizations see results they were not expecting within the first hour.

Request a demo

Get a takedown

Primary sources cited in this report
Verizon 2026 Data Breach Investigations Report (May 2026)
IBM Cost of a Data Breach Report 2025
NIST SP 800-63-4, Digital Identity Guidelines (July 2025)
Forrester, Top Cybersecurity Threats In 2026
APWG Phishing Activity Trends Reports, Q1 2025–Q1 2026
FBI Internet Crime Complaint Center (IC3), annual reports
CrowdStrike 2025 Global Threat Report
McAfee voice-cloning research
Hoxhunt Phishing Trends Report 2026
World Economic Forum & CloudSEK, phishing-kit projections
Hornetsecurity threat lab, MFA-bypass kit research

Figures are attributed to their original source at first use throughout this report. Where two reports measure a related metric differently (for example, third-party breach involvement), both are presented with their respective methodology rather than merged into a single number.