The anatomy of brand attacks in the first half of 2026
What's inside this report
Executive summary & key findings
In the first half of 2026, we saw several previously nascent attack techniques go mainstream. Drawing on public threat intelligence from APWG, IBM, Verizon’s DBIR, CrowdStrike, and the FBI’s IC3, and read alongside PhishFort’s own casework, four shifts stand out as the ones security teams should be planning around for the second half of the year.
Start with the clearest sign of what changed this cycle: how much phishing content is now AI-assisted, month by month, heading into 2026.
Share of sampled phishing emails with AI-assistance indicators, by month. Source: Hoxhunt Phishing Trends Report 2026, published March 2026.
For most of 2025, AI-generated phishing sat under 5%: background noise. Then it surged 14x in a single month over the holidays and has stayed elevated into 2026. That timing matches what we saw in our own detection pipeline almost exactly: the volume shift didn’t happen gradually across 2025, it happened over a few weeks at the turn of the year, and it’s the reason our analysts stopped treating well-written as a signal. The sites and lures we’re taking down now are indistinguishable from legitimate communications on writing quality alone, so attribution has to come from infrastructure and behavioral signals instead.
Volume and sophistication are one measure. What that actually costs organizations is another, and Business Email Compromise is the clearest line item for it, with fresh 2025 figures the FBI only just published.
Reported BEC losses, USD billions. Source: FBI Internet Crime Complaint Center (IC3) Annual Reports, 2023–2025; the 2025 figures were released in the IC3's 2025 Annual Report in April 2026.
BEC losses jumped back up in 2025 after a flat 2024, reaching $3.05 billion across nearly 24,800 complaints, and that’s just the reported, U.S.-only figure; IC3’s total cybercrime loss estimate for 2025 crossed $20.9 billion, up 26% year-over-year. This tracks closely with the BEC-via-typosquat cases our takedown team handles most often: a lookalike domain configured purely to send fraudulent invoices, with no web presence at all, evading web-based detection entirely. Standard registrar abuse channels are frequently ineffective against that kind of infrastructure, which is exactly the scenario where a direct registrar relationship is the difference between catching it before or after money has already moved.
The most-cited headline from this year’s Verizon Data Breach Investigations Report is a shift in how attackers are getting in the door in the first place. Verizon’s own report visualizes every figure with a deliberately uncertain edge, a reminder that no single number in security research is exact. We borrowed that convention below for the same reason.
By the numbers
Four headline metrics from the Verizon 2026 DBIR, Nov 2024–Oct 2025 dataset
Share of confirmed breaches, Verizon 2026 Data Breach Investigations Report, released May 2026. The soft, fading edge on each bar (rather than a hard stop) is a deliberate nod to the DBIR’s own house style: no percentage in breach research is exact, and pretending otherwise misrepresents the data.
Vulnerability exploitation overtook stolen credentials as the single leading entry point for the first time, but the DBIR itself warns against reading that as a retreat from identity-based attacks. The human element was still present in 62% of breaches overall (up from 60% the year before), and 41% of social-engineering breaches now arrive through channels a standard email gateway can’t see at all: voice calls, SMS, collaboration platforms. That’s consistent with why we expanded PhishFort’s own monitoring this semester beyond email-based lookalike domains and into voice, social, and messaging-app impersonation. The credential-theft attempt didn’t go away, it just moved somewhere email security tooling doesn’t look.
Zooming out from any single chart, here’s how the headline metrics across our primary sources moved between their prior reporting period and the most current one available, ranging from a full year to a matter of weeks, depending on how often each source publishes.
| Metric | Baseline | Latest | Change |
|---|---|---|---|
| AI-assisted phishing share | Nov 2025: 4% | Jan 2026: 40% | +900% |
| Reported ransomware losses (IC3) | 2024: $12.5M | 2025: $32.3M | +159% |
| Third-party involvement in breaches | Prior period: 30% | 2025 (DBIR): 48% | +60% |
| Vulnerability exploitation as entry point | Prior period: 20% | 2025 (DBIR): 31% | +55% |
| Total reported cybercrime losses (IC3) | 2024: $16.6B | 2025: $20.9B | +26% |
| BEC losses (IC3) | 2024: $2.77B | 2025: $3.05B | +10% |
| Human element present in breaches | Prior period: 60% | 2025 (DBIR): 62% | +3% |
| Global phishing attack volume (APWG) | 2024: 3.76M | 2025: 3.8M | +1% |
| Credential abuse as entry point | Prior period: 22% | 2025 (DBIR): 13% | −41% |
Baseline and latest periods vary by source and are shown per row. Annual reports compare calendar years, while the DBIR’s “prior period” and “2025” reflect its rolling Nov–Oct reporting window, and the AI-assistance figures are monthly (Hoxhunt). See Section 03 and the sources list at the end of this report for full citations.
Laid out side by side like this, the pattern is hard to miss: the metrics moving fastest are the ones tied to AI-assisted content and the operational cost of an attack once it lands (ransomware payouts, AI-phishing share), while the metrics tracking raw attack volume barely moved at all. That’s the same story our own takedown data tells: we’re not seeing dramatically more incoming threats, but the ones we are seeing take more effort to attribute, evade detection longer, and, in the BEC and executive-impersonation cases especially, cost victims more per incident. Volume was never really the right thing to optimize defenses against; severity and evasion were, and this table is the clearest illustration of that shift we’ve found in the public data.
Phishing that sidesteps MFA, whether by relaying a live login through a Man-in-the-Middle (MiTM) reverse proxy or by tricking a victim into authorizing an attacker’s session outright, used to require serious attacker sophistication.
In 2026 it became a packaged, subscription product: the Kali365 kit, which abuses Microsoft’s OAuth device-authorization flow to capture access tokens without ever touching a password, sells for around $250 a month and drew a Public Service Announcement from the FBI in May.
IBM’s Cost of a Data Breach Report 2025 found that third-party involvement in breaches doubled year-over-year to 30%, at an average cost of $4.91 million and 267 days to detect.
Verizon’s 2026 DBIR, published in May, put it in starker terms still: 48% of breaches now involve a third party in some capacity, a 60% jump from the year before. However it’s measured, a brand’s attack surface now includes its vendors and partners, not just its own domains.
Seven trends defining brand attacks in the first half of 2026
This section maps the seven public threat-research trends we judged most consequential for brand and identity protection, selected for how directly they showed up in the casework our detection and takedown teams handled between January and June. Each one is explored in depth in Section 03.
Before getting into the seven trends themselves, it’s worth seeing who’s actually being targeted most, industry-wide.
Share of total phishing attack volume by targeted sector, Q4 2025. Source: APWG Phishing Activity Trends Report Q4 2025, data contributed by Crane Authentication / OpSec Security.
Telecom’s share nearly tripled quarter-over-quarter, from 5.9% in Q3 to 18.7% in Q4, while Financial Institutions, the single most-targeted sector as recently as Q2, fell out of the top three entirely. We’ve seen an echo of that reshuffling in our own casework: the SaaS and social-media-heavy sectors we protect are increasingly dealing with OAuth consent phishing and account-takeover attempts rather than the classic cloned-login-page attack, which tracks with why Trend 02 below is specifically about MFA-bypass kits rather than generic credential phishing.
Trend deep-dives: what's happening and how we've worked it
Public threat intelligence tells you what’s happening across the industry. What follows pairs each trend with how PhishFort’s detection and takedown operations have actually engaged with it this semester, including the research our own team has published along the way.
AI-generated phishing became the default, not the exception
For years, the standard phishing-awareness advice was to look for typos and awkward phrasing. That advice stopped working almost overnight at the end of 2025. Hoxhunt’s 2026 Phishing Trends Report, drawn from over 50 million simulations and real reported threats across 125 countries, found the share of phishing emails carrying AI-assistance signals sat under 5% for most of 2025, then spiked 14x to 56% in December, before settling at 40% in January 2026 and holding there. IBM’s Cost of a Data Breach Report 2025 puts the productivity gain behind that spike in stark terms: generative AI has cut the time to produce a convincing phishing email from roughly sixteen hours to about five minutes. Verizon’s 2026 DBIR adds a rare piece of ground-truth data here: an analysis run with Anthropic covering nearly 800 threat actors, which found the median actor used AI across some 15 distinct attack techniques, with 44% of AI-assisted initial access attempts being phishing-related. The DBIR’s own conclusion is measured: AI is mostly scaling and industrializing what attackers already knew how to do, not inventing new attack types, which lines up with what we’re seeing in takedown volume more than in novel techniques.
of breaches involved attackers using AI somewhere in the attack chain
Per IBM’s Cost of a Data Breach Report 2025, generative AI shows up in the phishing lure most often (37% of AI-involved breaches), with deepfake impersonation close behind (35%). It’s still a minority of total breaches, which is worth holding onto: AI hasn’t replaced conventional attack methods, it’s made a growing slice of them faster to produce.
We’ve had to make the same adjustment our clients are being asked to make. Our detection models were never built to catch phishing by spotting bad writing, but the volume shift is real, and it shows up most clearly in social platform abuse, including one case our research team documented where attackers bypassed Meta’s own AI-driven support system with a short, carefully worded prompt and took over a high-profile Instagram account outright. The response in cases like that isn’t content review; it’s fast, direct escalation with the platform once account compromise is confirmed.

AI Account Takeover: When a Helpful Chatbot Becomes a Security Risk | PhishFort
How attackers bypassed Meta's AI support with a 30-word prompt and took over the White House Instagram, and what it means for your security architecture.
Read more: AI Account Takeover: When a Helpful Chatbot Becomes a Security Risk | PhishFortMFA-bypass kits went from elite tooling to a $250-a-month subscription
Bypassing MFA used to be a capability reserved for sophisticated threat actors, built on Adversary-in-the-Middle reverse proxies that relay a live login session, MFA challenge included, straight through to the real service. In 2026 the MFA bypass became a packaged product, and the flagship example doesn’t bother relaying logins at all. The Kali365 kit, priced around $250 a month, abuses Microsoft’s legitimate OAuth device-authorization flow: the victim is talked into entering a short device code, and the attacker walks away with a Microsoft 365 access token, no password intercepted and no further MFA prompt triggered. It drew a Public Service Announcement from the FBI’s Internet Crime Complaint Center in May after Hornetsecurity’s threat lab documented active campaigns.
This is squarely in our detection lane: rogue OAuth consent screens and cloned SSO or login pages are exactly the kind of look-alike infrastructure our SaaS and technology clients ask us to hunt for continuously, not just review on complaint. Two pieces from our research team this semester walk through specific variants: a Microsoft OTP-theft flow and a Google Workspace invitation lure, both built around the same principle of borrowing a trusted login flow to slip past MFA entirely. It’s telling that NIST’s own Digital Identity Guidelines, revised in July 2025 as SP 800-63-4, moved phishing-resistant authentication (FIDO2 keys and passkeys, not SMS or app-based codes) from a recommendation to the federal baseline. The standards body updating its threat model is a strong signal that traditional MFA can no longer be treated as sufficient on its own.

Microsoft OTP Phishing Attack: How Threat Actors Abuse Trusted Alerts
Threat actors are abusing legitimate Microsoft OTP and MFA notification systems to bypass SPF, DMARC, and traditional email defenses. Learn how this phishing attack works and how to defend against it.
Read more: Microsoft OTP Phishing Attack: How Threat Actors Abuse Trusted Alerts
Google Workspace Phishing Attack: Compromised Accounts & Cross-Platform Malware | PhishFort
Learn how the Google Workspace invite phishing attack works, how attackers abuse Google Sites for credential theft and malware delivery, and how to prevent account takeover attacks.
Read more: Google Workspace Phishing Attack: Compromised Accounts & Cross-Platform Malware | PhishFortPhishing-as-a-Service keeps lowering the skill floor
Turnkey phishing kits let an operator with no development background stand up, test, and iterate a convincing campaign in real time. Industry analysis from the World Economic Forum and CloudSEK projects that phishing kits will drive the majority of phishing incidents by the end of 2026, a shift from artisanal attacks toward an industrialized supply chain of ready-made infrastructure.
The practical effect for defenders is volume: more domains, more near-identical templates, more organizations that never expected to be a target getting hit anyway. It’s also why we built PhishFort’s takedown service to be accessible without a long procurement cycle in the first place. Organizations without an in-house security team are increasingly the ones facing professionally packaged attacks, and they need a response that doesn’t require building one from scratch.

Phishing Domain Takedown Services: 7 Powerful Insights for Fintech
Learn how phishing domain takedown services reduce fintech fraud, stop fake domains, and overcome evasion tactics with measurable results.
Read more: Phishing Domain Takedown Services: 7 Powerful Insights for FintechVishing and voice cloning turned a 3-second clip into a weapon
CrowdStrike recorded a 442% surge in vishing campaigns, and the driver is voice-cloning technology maturing faster than most organizations’ internal verification habits. McAfee’s research puts the bar startlingly low: about three seconds of audio, pulled from a conference recording, a voicemail greeting, or a public video, is enough to produce a clone convincing enough to fool a colleague on a live call. Verizon’s 2026 DBIR, drawing on the largest dataset in its 19-year history, confirms the shift at scale: phone-centric social engineering (voice calls and text) now succeeds roughly 40% more often than email-based attempts (a median 2% click rate versus 1.4% for email), and the report added pretexting as its own formally tracked initial access vector for the first time, already accounting for 6% of breaches.
of breaches now involve pretexting as a tracked entry vector, on its first appearance in the DBIR
Six percent sounds small next to vulnerability exploitation’s 31%, but this is a brand-new category the DBIR only started measuring this edition, precisely because voice and text-based impersonation had grown common enough to warrant its own line item. A category that starts at 6% and is new by definition is one to watch, not dismiss.
This is the trend our Executive Protection work is built around: tracking impersonation, cloned likenesses, and misuse of an executive’s identity across the open and dark web before it’s weaponized in a call. Voice cloning doesn’t change what we monitor for so much as it raises the stakes of catching an impersonation attempt early, since by the time a vished call happens, the deception has usually already been rehearsed.
Learn more about PhishFort’s Executive Protection
Major events became ready-made attack infrastructure
Large sporting and cultural events reliably produce a spike in brand-specific search interest, and threat actors treat that spike as free distribution. Fraudulent ticketing sites and lookalike betting platforms tied to the FIFA World Cup 2026 were live and indexed well before the tournament itself began, positioned to intercept fans searching for tickets or looking to place a bet.
Our iGaming and events-sector monitoring picked this pattern up early this semester, which is why our research team published two separate pieces on it: one on the gambling and betting angle, the other specifically on the ticketing scams. Both link back to a pattern our takedown team sees every time a major event is announced: registrations for lookalike domains often appear within a day of the announcement, well ahead of the event itself.

The FIFA World Cup 2026 Is Already a Brand Threat — Especially If You're in Gambling
Staged phishing infrastructure, fake betting apps, and social media impersonation campaigns are live before June 11. Here's how threat actors are targeting gambling brands — and how to respond.
Read more: The FIFA World Cup 2026 Is Already a Brand Threat — Especially If You're in Gambling
FIFA World Cup 2026 ticketing scams
PhishFort researchers identified multi-stage fake FIFA ticketing sites harvesting credentials, PII, and payment data. Here's how the infrastructure works and what to monitor.
Read more: FIFA World Cup 2026 ticketing scamsDeFi phishing spikes in the hours after every protocol hack
A protocol exploit doesn’t end the attack. For the affected users, it often starts a second one. Fake “claim your compensation” or “revoke your exposed approvals” sites reliably appear within hours of a public hack disclosure, targeting the same users who are already anxious and searching for guidance, and exploiting the fact that the real remediation advice often does involve visiting a wallet-permissions tool.
This is a pattern we’ve worked directly with Revoke.cash on this semester, publishing joint guidance on how legitimate post-hack remediation differs from the phishing sites that copy it, specifically around wallet permission revocation, which is exactly the kind of action attackers now impersonate.

DeFi Phishing After a Protocol Hack: How Threat Actors Steal Smart Contract Permissions
When a DeFi protocol gets hacked, fake revoke sites appear within hours. Here's the exact attack sequence threat actors use—and how to shut it down.
Read more: DeFi Phishing After a Protocol Hack: How Threat Actors Steal Smart Contract PermissionsThird-party and supply-chain exposure became a boardroom issue
IBM’s Cost of a Data Breach Report 2025 found that third-party involvement in breaches doubled year-over-year to 30% of incidents, averaging $4.91 million and 267 days to detect and contain, the longest of any breach category, because it exploits trust relationships rather than technical weaknesses. Verizon’s 2026 DBIR, released in May and drawing on over 22,000 confirmed breaches, found an even sharper picture: 48% of all breaches now involve a third party in some capacity, a 60% increase year-over-year. Part of what’s driving this is infrastructure abuse that has nothing to do with the victim organization’s own network: compromised IoT and smart-home devices are increasingly used to route malicious traffic through legitimate residential IP addresses, which lets attackers walk straight past perimeter controls built to flag suspicious data-center traffic.
Our research team covered this residential-proxy pattern in detail this semester, and it’s a useful example of why brand protection increasingly has to look beyond an organization’s own domains. The infrastructure being abused to attack you, or a partner you rely on, often belongs to someone else entirely. Forrester’s Top Cybersecurity Threats In 2026 report flags this as a forward-looking concern too, naming AI software supply chain risk (driven by open-source model and framework adoption) as one of the threat categories security leaders should treat as non-negotiable for the year ahead.

IoT Botnet Residential Proxy Risk for Enterprise Networks
Compromised smart home devices route attack traffic through legitimate residential IPs — bypassing your perimeter controls. Here's how it works and what stops it.
Read more: IoT Botnet Residential Proxy Risk for Enterprise NetworksMarket context: where current defenses fall short
Across the incidents documented in the first semester of 2026, a consistent set of operational gaps emerges in how organizations attempt to defend against brand impersonation, regardless of which tools or vendors they currently use.
| Observed gap | How it manifests in practice | Sectors most affected |
|---|---|---|
| Detection without execution | The most common failure pattern: threat intelligence platforms identify and alert on brand impersonation incidents but lack the operational capability to act on those alerts. The alert tells organizations a fake domain exists; it does not remove it. The gap between awareness and response is where harm accumulates. Root cause: intelligence vs. action | Financial services, enterprise technology |
| Automation failure in complex hosting | Automated takedown systems succeed in straightforward cases: cooperative registrars, mainstream hosting, DMCA-responsive jurisdictions. They fail systematically against fast-flux infrastructure, bulletproof offshore hosting, and non-cooperative registrars. The cases where automation fails are precisely where the attacker has invested in evasion, meaning the hardest cases go unresolved. Root cause: no manual escalation path | iGaming, crypto, high-value targets |
| No contractual accountability | Enterprise buyers in financial services and corporate security increasingly require contractual SLAs with defined response windows and financial penalties for misses. Current market offerings are predominantly SLA-free, with removal timelines stated as estimates rather than commitments, a gap that is becoming a deal-breaker for regulated organizations. Root cause: market hasn’t demanded it yet | Financial services, legal, enterprise |
| Reactive-only posture | Most current tools are complaint-driven: a human discovers a fake domain, submits it for removal, and the process begins. In fast-moving campaigns, iGaming and crypto especially, attackers have already redeployed by the time a complaint is submitted. Continuous monitoring that detects newly-registered lookalike domains before they are weaponized is structurally different from complaint-handling. Root cause: workflow design, not technology | All sectors, acute in iGaming, crypto, events |
Recommendations: building a resilient brand protection posture
The following recommendations emerge directly from the January–June 2026 threat data. They are organized as operational controls: specific, implementable measures that address the attack patterns and defensive gaps documented in this report.
Move from incident response to continuous monitoring
Require manual escalation capability in any takedown vendor
Audit and actively maintain the full domain portfolio
Establish false positive review relationships before an incident occurs
Demand contractual SLAs for social media takedowns
How PhishFort responds to these threats
The seven trends in this report aren’t abstract to us. They describe the actual attacks our detection and takedown teams worked through this semester, across every sector we protect. What follows is an account of how we work, what we do when a threat surfaces, and where the results show up in practice.
The most important thing to understand about brand impersonation is that detection without action is not protection. A great many organizations already know when they are being attacked. They receive abuse reports, their users complain, they see fake sites in search results. What they lack is the operational capability to make those sites disappear quickly and reliably. That gap is exactly what PhishFort was built to close.
Our approach combines AI-native detection with a dedicated SOC team that validates every threat before acting. We do not generate alerts for your team to chase. We investigate, classify, and, in the vast majority of cases, handle takedowns end-to-end, without requiring meaningful time from the organizations we protect.
What we do
Detection
Takedowns
Brand Monitoring
Executive Protection
Dark Web Intelligence
Where the results show up
Numbers are more useful than claims, so here are results from organizations that have made their experience with PhishFort public, spanning crypto, iGaming, and Web3, three of the highest-volume attack surfaces described in this report. Each one illustrates what changes when the gap between detecting a threat and actually removing it closes.
From the PhishFort research team

In-House vs Outsourced Phishing Domain Takedowns for Banks
Compare three models for phishing domain takedowns: in-house program, per-incident service, and managed service. Decision criteria, process steps, and outcome metrics for security teams.

Google Sites Phishing: How Attackers Abuse Trusted Infrastructure
Threat actors are using sites.google.com to host fake Workspace portals that deploy infostealers and crypto drainers. Here's how the attack works.
See what's targeting your brand right now
We can show you the active threats against your domain and brand assets in a single session, no long procurement cycle required. Most organizations see results they were not expecting within the first hour.
Figures are attributed to their original source at first use throughout this report. Where two reports measure a related metric differently (for example, third-party breach involvement), both are presented with their respective methodology rather than merged into a single number.