Phishing Threat Trends Report evaluates attacks from more than 3,000 unique threat actorsĀ
KnowBe4 has announced a new research, Phishing Threat Trends Report Volume Seven. The report finds a seismic shift in the attack vectors utilized to conduct phishing attacks, including touchpoints outside of traditional email communication such as calendar invitations and messaging tools.Ā
āThe inbox is no longer the only front line for coordinated social engineering attacks,ā said Jack Chapman, SVP of Threat Intelligence, KnowBe4. āCybercriminals are actively broadening the email threat landscape. As businesses rely on tools for real-time collaboration, cybercriminals have added this to their attacks, along with targeting peopleās calendars. This attack method targets people and technology together. This escalation in scale of threat brings a whole new issue to the forefront.ā
Key findings from the report include the following revelations from the last six months:
- 86% of phishing attacks were AI driven
- 49% increase in calendar invite phishingĀ
- 139% surge in the use of Reverse Proxies as a tool to steal Microsoft 365 credentials
- 41% escalation in Microsoft Teams attacks
- A new trend shifting from single-vector attacks to multi-channel orchestration
- More targeted social engineering was discovered, exemplified by internal team impersonation which was seen in 30% of attacks from threat actors in Q1 2026
āSocial engineering is becoming more targeted, making it more difficult to discern what is legitimate versus what is malicious,ā said Chapman. āThe Phishing Threat Trends Report volume seven finds that phishing in 2026 is disciplined, persistent, multi-channel and increasingly AI-enabled. As cybercriminals expand their attack channels and evolve their tactics, we must focus our protection efforts on securing humans and the AI agents they utilize.ā
For more details, see the 2026 KnowBe4 Phishing Threat Trends Report Volume Seven report here.
