Skip to content

Phishing Rises Across Channels, Email Defense Evasion, and Executive Impersonation at Massive Scale

Feature image
Last Modified Date: Sep 23, 2026
The Optery Dispatch

Welcome to The Optery Dispatch — a newsletter delivering the latest insights on threat intelligence and proactive cybersecurity strategy. In Issue #17, published September 24, 2026, we cover:

  • Phishing expands across communication channels: APWG reports more than one million attacks in the second quarter as vishing, smishing, wire-transfer BEC, job scams, and social-media threats increase.
  • KnowBe4 details a phishing campaign engineered to evade automated inspection by routing victims through legitimate Google services.
  • AI-assisted executive impersonation reaches massive scale: Microsoft detects a campaign that sent more than one million emails in three days.

Special Note – Upcoming Webinar: An Ethical Hacker’s Perspective on Exposed Data and Social Engineering

See how attackers use exposed personal information to identify targets, develop pretexts, and find paths into organizations.

On October 28 at 10 a.m. PT / 1 p.m. ET, Optery’s Paul Mander and Manit Sahib, Founder and CEO of Cytadel, will discuss how attackers use exposed personal and professional information to identify targets, map relationships, and launch social engineering attacks, as well as what security teams can do to make their employees and organizations more difficult to target.

Save your spot: Target Intelligence: An Ethical Hacker’s Perspective on Exposed Data and Social Engineering

Phishing Rises Across Voice, Text, Business Email, and Social Media

APWG records more than one million attacks as vishing, smishing, and wire-transfer BEC increase

The Anti-Phishing Working Group recorded 1,069,681 reported phishing attacks during the second quarter of 2026, a 10.1% increase from the 971,181 attacks observed during the previous quarter.

APWG counted 425,808 attacks in June alone, the highest monthly total since April 2023. SaaS and webmail services were the most frequently attacked category, rising from 20% of phishing attacks in the first quarter to 29.1% in the second.

Telephone-based attacks also continued to rise. Vishing increased by 20%, while smishing increased by 40% from the first quarter to the second quarter. Researchers also reported an increasing volume of email and social-media job scams in which attackers impersonated recruiters and companies to gain job seekers’ trust.

Business email compromise showed especially sharp growth. Fortra found that the number of wire-transfer BEC attacks increased by 88%. The average amount requested rose 45%, from $42,663 to $61,732.

Much of the increase was attributed to Scripted Sparrow, a BEC group based in Nigeria, South Africa, and Türkiye that uses fake executive-coaching invoices and fabricated email reply chains between coaching companies and executives. Gift cards remained the most common BEC cash-out method, followed by wire transfers and payroll diversion.

APWG also documented increased threat activity across social-media platforms. Impersonation accounted for 32.7% of the threats analyzed by ZeroFox, while scams accounted for about 23%. Confirmed threat activity across Meta Ads increased 571% from the previous quarter, while activity on LinkedIn increased 106%. APWG emphasizes that these figures represent growth rates, not total incident counts.

As social engineering attacks continue to increase and attackers diversify their delivery methods across email, telephone calls, text messages, social media, and paid advertising, organizations should extend personal data removal as broadly as possible across their workforce to minimize the amount of exposed contact information and personal details attackers can use to identify and target employees. 

Read the APWG Q2 2026 Phishing Activity Trends Report

Phishing Campaign Uses Google Infrastructure to Bypass Security Controls

Attackers route victims through legitimate services before dynamically impersonating their organizations

KnowBe4 Threat Lab has documented an active, wide-scale phishing campaign that routes victims through legitimate Google services before sending them to credential-harvesting pages or attempting to install remote-access software.

The campaign uses six different Google services across several redirect paths. Because the links initially lead through trusted Google infrastructure, the sending domain, embedded link, and intermediate destinations may appear legitimate to email gateways, firewalls, and automated URL-analysis systems.

The victim’s email address is carried through the redirect chain in the URL fragment, the portion following the “#” symbol. Browsers do not send this fragment to servers, preventing the email address from appearing in server logs along the redirect path and concealing the campaign’s pre-targeted nature from most URL scanners.

Once the victim reaches the attacker-controlled site, the phishing kit uses the email domain to construct a customized login page. It retrieves the organization’s logo, captures a current screenshot of its public website for the page background, places the victim’s email address in the login form, and displays the organization’s name in the browser tab. It also verifies that the domain has working email infrastructure and can localize the page into 16 languages.

KnowBe4 observed lures impersonating document-sharing services, Microsoft 365 help desks, FedEx, Intuit QuickBooks, government-benefit communications, and voicemail notifications. Some were addressed to named recipients at specific organizations, while the campaign’s observed targets spanned manufacturing, government, finance, and nonprofit organizations.

Depending on the lure, victims were directed either to a credential or device-code harvesting flow or to a fake identity-verification process that installed ScreenConnect. Submitted credentials were sent to the attackers through Telegram. The credential harvester deliberately rejected the first password entered so the victim would submit it again before being redirected to the organization’s real website.

This campaign underscores the limits of relying on email security alone. By routing links through trusted Google infrastructure, the attackers created a path designed to appear legitimate to email gateways, firewalls, and automated analysis systems. For organizations, this reinforces why personal data removal is a necessary complement to email security, helping reduce the volume of targeted social engineering directed at an organization’s workforce. 

Read the KnowBe4 Threat Lab analysis

AI-Assisted Executive Impersonation Campaign Sends More Than One Million Emails in Three Days

Attackers combined spoofed executives, fabricated invoices, and fake email threads to solicit ACH payments of nearly $50,000 from targeted companies

Microsoft detected more than one million financial fraud emails sent to enterprise users between August 3 and 5. The attackers used multiple third-party email service accounts, with 87.7% of the messages directed at recipients in the United States.

The campaign impersonated executives such as CEOs, CFOs, and company presidents at multiple targeted companies and attempted to convince their accounts payable departments to process ACH payments of nearly $50,000. The emails supported the requests with fabricated ServiceNow invoices and fake forwarded conversations between the targeted companies’ executives and a supposed ServiceNow executive. Payment instructions directed recipients to attacker-controlled bank accounts. 

The campaign also used recently registered lookalike domains and personalized invoices containing the recipient company’s name and executive information. Microsoft found no evidence that ServiceNow or the other legitimate organizations referenced in the messages had been compromised.

Microsoft identified several signs consistent with generative AI being used to develop the email templates, including extensively commented HTML, structured section labels, and highly uniform construction. However, the company cautioned that these indicators do not establish how much of the campaign content AI generated.

Defenders could still identify inconsistencies, including missing headers in the supposed forwarded conversations, mismatched display names and sender addresses, unusual wording, and formatting that did not resemble a genuine email thread. Microsoft recommends layered email authentication and spoof protection, correctly configured mail-flow connectors, advanced anti-phishing controls, and post-delivery remediation for messages later identified as malicious.

Microsoft also notes that threat actors collect publicly available information about organizations, executives, finance personnel, vendors, and business relationships to construct targeted invoice-fraud narratives. 

Microsoft detected more than one million emails in just three days, illustrating the enormous reach a single social engineering campaign can achieve. Indicators consistent with AI-assisted template development show how attackers can use AI to tailor fraudulent messages for specific organizations and recipients while distributing them at high volume. As this AI-enabled capacity grows, personal data removal becomes more important than ever because it limits the publicly available information attackers can use to identify employees and executives, impersonate trusted people, and construct targeted social engineering narratives. 

Read the Microsoft Security report

Thanks for reading! Want us to write about something specific? Submit a topic or idea.

If you’re looking to reduce your organization’s exposed PII and dramatically lower the volume of phishing, voice and messaging scams, credential theft attempts, and other PII-based threats your team has to defend against, Optery can help. We find and remove dozens more exposed profiles per person on average than competing services, and we prove it with before-and-after screenshots.

Get started here: Optery for Business

Subscribe to receive future editions of The Optery Dispatch

 

Ready to Protect Your Employees and Company?


Ready to safeguard your employees’ data?

See why Optery is the leader in enterprise-grade personal data removal.
Request a Demo