
Phishing didn’t get rarer as awareness training spread — it got harder to recognize. Industry threat reports put the large majority of phishing attempts in 2026 as at least partly AI-generated: personalized, well-written, and increasingly delivered outside plain email — over SMS, QR codes and even cloned voices. The old advice (“watch for typos and a generic greeting”) still applies, but it’s no longer close to sufficient on its own.
Why Phishing Got Harder to Spot in 2026
Three shifts changed the game:
- AI writes the lure now. Broken English and generic “Dear Customer” openers used to be the easiest tell. AI-generated phishing mail is grammatically clean, personalized with real names and context (often scraped from LinkedIn or breached data), and can be produced at volume for almost no cost.
- Voice cloning lowered the bar for impersonation. Modern voice-cloning tools need only a few seconds of real audio — a voicemail greeting, a conference talk — to generate a convincing fake. A widely reported 2024 case saw a Hong Kong finance employee wire roughly $25 million after a video call with what appeared to be the company’s CFO and colleagues — all deepfaked.
- The channel moved beyond email. QR-code phishing (“quishing”) and SMS phishing (“smishing”) are both climbing sharply — QR codes are attractive to attackers specifically because most email security scanning still focuses on links and attachments, not images.
The Classic Red Flags — Still Worth Checking, Just Not Enough Alone
- Sender domain, not display name. Any name can display over any address — a message showing your CEO’s name proves nothing until you check what’s actually after the @.
- Urgency plus authority. “Approve this transfer before 5pm” from someone who outranks you is the oldest trick in the book, and still the most effective.
- Hover before you click. The visible link text and the actual destination URL are often different — hovering (or long-pressing on mobile) reveals the real target before you commit.
- Unexpected attachments, especially ones asking you to “enable content.” That’s a macro-enabled document requesting permission to run code.
New Tactics to Watch For in 2026
AI-Personalized Spear Phishing
Instead of a mass blast, attackers now generate individually tailored messages referencing your actual role, recent LinkedIn activity, or a real vendor relationship — pulled from public data or previous breaches. The “this doesn’t sound like something a scammer would know” instinct is exactly what these messages are built to defeat.
Voice Cloning and Deepfake Vishing
A call or video that sounds and looks like your CEO, requesting an urgent wire transfer or credential reset, can no longer be trusted on voice or video alone. The single most effective defense is a second-channel verification rule: any unusual money movement or credential request gets confirmed through a separate, pre-agreed channel — a callback to a known number, not one provided in the request itself.
QR Code Phishing (“Quishing”)
A QR code embedded in an email or PDF routes to a credential-harvesting page instead of the legitimate destination it claims to be. It’s effective specifically because scanning it happens on a personal phone, often outside your organization’s email security and network protections entirely. Treat a QR code in a business email with the same suspicion as a raw link — don’t scan it on a device that bypasses your normal safeguards.
SMS Phishing (“Smishing”)
Fake delivery notifications, bank alerts and “your account is locked” texts now make up a meaningful share of all phishing attempts. The same rule applies: don’t tap the link in the text — go to the actual service directly (app or bookmarked site) and check from there.
MFA Fatigue (“Push-Bombing”)
If your account is protected by push-based multi-factor authentication, an attacker who already has your password can trigger repeated approval prompts, hoping you’ll tap “approve” just to make the notifications stop. A login prompt you didn’t initiate is itself the phishing attempt — decline it and change your password immediately.
A Practical Detection Checklist
- Check the actual sender address, not the display name.
- Hover or long-press any link before clicking to see the real destination.
- Treat urgency + authority + an unusual request (money, credentials, gift cards) as the pattern to distrust, regardless of how well-written the message is.
- Verify any voice or video request for money or access through a separate, pre-known channel — never the contact info given in the request itself.
- Be as suspicious of a QR code in a business email as you would be of a raw link.
- Don’t approve an MFA prompt you didn’t just trigger yourself.
- When in doubt, ask — report it to IT/security rather than guessing.
If You Already Clicked Something
- Don’t panic, but don’t wait either — act within minutes, not hours.
- Change the password for the affected account immediately, and anywhere else you reused it.
- Report it to your IT/security team so they can check for further compromise and alert others who may have received the same message.
- If you entered financial details, contact your bank or card issuer directly.
- Watch the account for unusual activity over the following days, not just the first hour.
What Businesses Should Do Beyond Training
User awareness matters, but it’s not the only layer. Technical controls that don’t depend on someone noticing in time:
- DMARC enforced at quarantine/reject (see our SPF/DKIM/DMARC guide) — stops a meaningful share of domain-spoofed phishing before it reaches an inbox at all.
- Admin-level visibility and DLP — catching unusual send patterns and data movements, not just relying on the recipient to spot the lure.
- S/MIME for internal-critical communication — cryptographic signing that makes a genuinely spoofed internal message technically detectable, not just suspicious-looking.
How XgenPlus Helps
XgenPlus combines anti-phishing and spam filtering, SPF/DKIM/DMARC enforcement, DLP and an in-house PKI/Certificate Authority for S/MIME signing under one admin console — so detection isn’t resting on every individual employee catching every AI-polished lure. Built on 25+ years in email infrastructure across 50M+ mailboxes, including deployments where phishing-driven compromise is a regulatory as well as an operational risk.
Frequently Asked Questions
How has phishing changed in 2026 compared to a few years ago?
The biggest shift is AI: most phishing attempts today are at least partly AI-generated, meaning the old tells — bad grammar, generic greetings — are far less reliable. Attacks have also spread beyond email into SMS (smishing), QR codes (quishing) and even voice-cloned calls or video (vishing/deepfakes).
What’s the single most useful habit for spotting phishing today?
Check the actual sender domain, not the display name, and treat “urgency + authority + an unusual request” as the pattern to distrust regardless of how polished the message looks — AI has made polish meaningless as a signal.
How do I protect against deepfake voice or video phishing?
Verify any unusual request for money or credentials through a separate, pre-agreed channel — call back a known number, not one provided in the suspicious request itself. Voice and video can no longer be trusted alone to confirm identity.
Is a QR code in an email actually dangerous?
Yes — QR-code phishing (“quishing”) is rising sharply specifically because most email security scanning focuses on links and attachments, not embedded images, and scanning happens on a personal phone that often bypasses organizational protections. Treat a QR code in a business email like a suspicious link.
What should I do immediately if I think I clicked a phishing link?
Change the password for the affected account right away (and anywhere else you reused it), report it to your IT/security team so they can check for wider compromise, and if you entered financial details, contact your bank or card issuer directly.
Final Thoughts
Phishing in 2026 isn’t defeated by spotting typos — it’s defeated by a small set of habits (checking the real sender, verifying unusual requests through a second channel, distrusting urgency) plus technical controls that don’t rely on any one person catching every attempt. Both matter; neither is sufficient alone.
- See XgenPlus’s anti-phishing & email security controls — filtering, DMARC enforcement, DLP and admin visibility.
- S/MIME signing — make internal-critical mail cryptographically verifiable, not just plausible-looking.
- Talk to our team about hardening your organization’s email against 2026-era phishing.

