CyberheistNews Vol 16 #31 | August 4th, 2026
The Majority of Orgs Now Hit by Targeted Impersonation Attacks
Fifty-three percent of organizations have had an executive or employee impersonated in targeted social engineering attacks over the past year, according to a new report from Outtake. Just over half of this impersonation activity took place on social media platforms using fake profiles, followed by video platforms.
"Nearly half of all alerts (53.83%) of executive impersonation threats stem from social platforms," Outtake says. "Video and visual platforms follow at 35.05%, with open community forums (6.84%) and executive lookalike domains (3.57%) rounding out the remainder.
"Yet the per-executive risk profile varies sharply: most executives (76.2%) see nearly all activity concentrated on one surface, while others (23.8%) face attacks distributed thinly across social, lookalike domains, forums and broker-site PII exposure simultaneously."
Notably, threat actors are using AI tools to dramatically accelerate these attacks. AI can speed up reconnaissance to craft convincingly spoofed profiles, while deepfake technology can generate images and videos of executives that are indistinguishable from real life.
"Attackers use AI to skip your internal security tools completely," the researchers explain. "There's less need to break through data, network, cloud and endpoint security perimeters when adversaries can just impersonate an executive out on the open internet, where those tools don't watch.
"They target your most visible leaders on purpose because a trusted name gets them to the money faster than anything inside your network. And it lands on a handful of executives, not the whole team."
One more thing. The workforce changed. Half of it doesn't have a badge. KnowBe4 secures all of it… the people and the agents working alongside them – KnowBe4 secures the digital workforce, humans and AI agents.
Blog post with links:
https://blog.knowbe4.com/executive-impersonation-attacks-hit-majority-organizations
Become Part of Our Agent Risk Manager Early Adopter Program
Be among the first to close the gap between AI innovation and agent governance.
Join the Early Adopter Program for early access to Agent Risk Manager updates and the strategic support needed to unify agent security and human risk management.
- Real-time updates on Technical Preview: Receive regular briefings product milestones and features.
- Agent security landscape: Receive exclusive insight on the evolving AI threat landscape for your security strategy.
- Executive strategy sessions: Discuss your specific AI security challenges in consultations with our CISO Advisors.
- Product leadership demos: Get priority walkthroughs of Agent Risk Manager from the architects of the product closer to launch.
- Get the product first: Get access before general availability.
Inside the OS-Aware Phishing Kit Profiling Your Device
Most phishing attacks pick a target and commit to a tactic. This one picks the tactic based on the target, which happens dynamically, per device, in milliseconds, without the victim ever knowing a decision was made.
KnowBe4 Threat Lab analysts recently pulled apart an active "iCloud Sign-In Alert" campaign that does something most security teams haven't seen at this level of sophistication: it reads your operating system the moment you click, and silently routes you into a completely different attack depending on the answer.
Windows users get a remote access tool installed on their machine. Apple users get handed off to a credential harvester on a separate external domain. Everyone else gets walked through a fake Microsoft login while a human operator watches the credentials arrive in Telegram in real time.
One email. Three parallel operations. Your device choses which one you got.
When analysts cracked open the backend, the attacker had left directory listing enabled on their own server — handing over a complete window into the operation. Everything in this post is drawn directly from those exposed artifacts.
[CONTINUED] Blog post with links and screenshots:
https://blog.knowbe4.com/inside-os-aware-phishing-kit-profiling-your-device
2026 Phishing Threat Trends Report
In the 2026 Phishing Threat Trends Report, we find out what happens when cybercriminals manipulate the Al systems you trust to summarize your inbox.
Plus, we explore the alarming rise of multi-channel attacks on Microsoft Teams and analyze one of the biggest trends of Q1 2026: the industrialized use of reverse proxies to bypass MFA.
Download now to discover:
- Why Microsoft Teams attacks have surged by 41% in just six months
- How "Machine-Speed" prompt injection can collapse the time-to-compromise to just four seconds
- What's driving the surge in Calendar Invite Phishing, which has increased by 49% as attackers move to the "quiet sanctuary" of your schedule
- Why 84.4% of all successful phishing attacks now pass DMARC, rendering traditional identity verification obsolete
Don't let your security posture fall behind an adversary that has fully embraced industrial-scale social engineering.
What Security Can Learn From Dinosaurs
By Javvad Malik
In business, calling something a dinosaur is meant to suggest it is slow, outdated and overdue for extinction. Which is unfair to dinosaurs, who enjoyed one of the most successful runs in the history of life.
Here is what people think they mean when they use the word. Lumbering. Doomed. Obsolete. A fat target waiting for the meteor. They imagine a tar pit. They imagine extinction. They picture something huge and slow, magnificently unsuited to the world it finds itself in.
This is what dinosaurs actually were: They ruled this planet for roughly 165 million years. Not a good quarter. Not a strong decade. A whopping one hundred and sixty-five million years of total, uncontested dominance across every environment that existed.
In fact, they were so successful they did not even have the courtesy to go properly extinct. They evolved. They grew feathers, took to the air and became birds, which are sitting outside your window right now, having outlived a great many supposedly cleverer things, doing perfectly well thank you.
That is what makes dinosaurs such a useful metaphor. They were not merely successful. They were successful for long enough to adapt.
If dinosaurs are a useful model for endurance, the mayfly is a useful model for novelty mistaken for progress.
The Mayfly Business Model
A mayfly lives, on average, for about a day. It bursts into existence, it is briefly and frantically alive, it is convinced this is the only kind of life worth having and then it is gone before the sun comes up twice. It does not build anything. It does not last. It mistakes being new for being superior, right up until it is neither.
Some businesses operate on what might generously be called the mayfly model. They arrive quickly, they are loud, they have a slide deck full of the word "modern" and their central argument is essentially that they are younger than everyone else. That is the whole pitch.
Not better. Newer. As though newness were an achievement rather than simply the condition of not having been around very long.
One of the lazier tricks in business language is to make "modern" mean "new" and "legacy" mean "anything that has survived long enough to become useful." It is a clever little trick because it cannot be argued with on its own terms. Of course the new thing is more modern than the old thing. It is newer.
That is what newer means. The sleight of hand is getting you to agree that modern means better, and recent means modern and therefore the company that has been solving this problem for fifteen years is somehow behind the company that has been solving it since the last funding round.
Legacy Means It Survived
Let us reclaim the word, because the word is doing a lot of dishonest work.
Legacy, in some mouths, means old, creaky and halfway to the museum gift shop. But legacy actually means something that lasted long enough to leave one. The pyramids are legacy. They are also still standing while a great many newer, cleverer buildings have fallen down.
Your bank is legacy. You will notice you keep your money there and not in the three-week-old fintech that pivots its entire business model every time the wind changes. Legacy is not an insult. Legacy is a survival record. It is the proof that you solved a real problem for real people for long enough that you are still here.
This is where the analogy gets interesting. Being old is not the same as being unchanged. This is the entire con, and it collapses the second you poke it. People want you to believe that because a company has been around a while, it must be doing things the way it did them at the start, as though the organization climbed into a fridge in 2010 and has only just now wandered back out blinking into daylight.
But a thing can be both long-established and completely current. In fact, that is the most dangerous competitor there is, the one with the survival record and the modern capabilities, because it has the scale the newcomer cannot fake and the evolution the newcomer assumed it did not have.
The dinosaur that grew wings is not less modern than the mayfly. It is more modern, has been around for an epoch and is still up there flying while the mayfly is explaining disruption to a puddle.
[CONTINUED] at the KnowBe4 Blog:
https://blog.knowbe4.com/what-security-can-learn-from-dinosaurs
Your Kit for Securing AI Adoption
Your workforce has shifted to include autonomous agents, yet 83% of orgs lack visibility into what their agents are actually doing. While one in three enterprise employees now uses an assistant daily, most do so without security governance.
This oversight gap leaves you vulnerable as threats evolve toward sophisticated deepfakes and the new frontier of prompt injections. This kit cuts through the noise, guiding you through the next phase of agentic defense and governance to help you manage your hybrid attack surface effectively and securely.
Your kit includes:
- NEW! Research Report: From Agentic Risk to Human Wins
- Webinar: When Agents Go Off the Rails: Closing the Governance Gap
- Whitepaper: Securing The Hybrid Workforce: Protecting Humans and AI Agents in a New Era
- Webinar: How to Secure AI Adoption in Your Organization
- Whitepaper: Critical Capabilities When Evaluating AI-Powered Security Awareness Training
- Datasheet: Agent Risk Manager
Download Your Kit Now:
https://info.knowbe4.com/secure-ai-adoption-kit?utm_source=chn_email&utm_medium=email&utm_campaign=dg-sat-campaign-26&utm_content=chn_ai_kit
Let's stay safe out there.
Warm regards,
Stu Sjouwerman, SACP
Executive Chairman
KnowBe4, Inc.
PS: Everyone's a Builder Now. That Changes Security Training:
https://blog.knowbe4.com/everyone-is-a-builder-security-training
PPS: Eliminate your AI security blind spot with KnowBe4’s Agent Risk Manager. Learn more here:
https://www.knowbe4.com/products/ai-agent-risk-manager
- Aristotle (384-322 BC)
- Bruce Lee - Martial Artist (1940-1973)
You can read CyberheistNews online at our Blog
https://blog.knowbe4.com/cyberheistnews-vol-16-31-the-majority-of-orgs-now-hit-by-targeted-impersonation-attacks
Microsoft Observed 7.6 Billion Phishing Emails in Q2 2026
Researchers at Microsoft warn that phishing emails are still the top initial access vector, with more than two billion phishing threats detected each month during the second quarter of 2026.
"Microsoft detected approximately 7.6 billion email-based phishing threats throughout the quarter, with monthly volumes declining modestly from 2.7 billion in April to 2.4 billion in June," the researchers write. "Credential phishing remained the dominant objective behind malicious payloads, while business email compromise (BEC) activity largely returned to historical norms after a brief, anomalous surge in April.
"Notable campaigns observed during the quarter also demonstrated how threat actors combine automation, trusted services and multi-stage delivery chains to scale operations."
Notably, Microsoft observed a business email compromise (BEC) campaign that targeted 42,000 organizations in under three hours. "On June 1, 2026, Microsoft Defender Research observed a high-volume BEC campaign that used automation to operate at scale," the researchers write.
"Over a send window of under three hours (14:08–16:52 UTC), the actor reached more than 67,000 users across more than 42,000 organizations, almost exclusively in the United States. Targeting spanned a broad range of industries rather than a single vertical, most notably retail and consumer goods (17%), technology and software (15%) and financial services (14%).
"The campaign ran two lures in succession from shared infrastructure: a request impersonating sales executives to obtain aging report data and customer contact details and a payroll diversion pretext impersonating the CEO or President to redirect salary payments to attacker-controlled bank accounts."
The researchers also warn of a surge in Microsoft Teams phishing, which can evade email security filters. "While email remains the dominant initial access vector, threat actors increasingly abused Microsoft Teams during Q2 to deliver social engineering, phishing and malware payloads," Microsoft says.
"Unlike email, Teams traffic typically bypasses secure email gateways and benefits from the perceived legitimacy of a colleague-initiated chat, which can make lures particularly effective in this environment. Teams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding roughly flat into May (+one%), then increasing another 10% into June."
Microsoft has the story:
https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/
And here is something you can do about it immediately:
https://www.knowbe4.com/products/defend
Report: AI-Enhanced Mobile Phishing Attacks Are Surging
Attackers are increasingly using AI tools to assist in phishing attacks against mobile devices, according to a new report from Zimperium.
"According to some sources, AI-assisted phishing campaigns have reportedly grown at a rate of more than 1200%," the researchers write. "Zimperium's data shows that phishing events detected on employee mobile devices grew 380% since January 2025, and the number of devices where employees clicked a malicious link grew 110% in 2025 over the previous year.
"The report also found that AI is used to generate content estimated to be 4.5x more convincing than anything human-written while almost 86% of phishing attacks now contain AI-generated elements."
AI can craft extremely convincing phishing messages, which appear even more realistic on the smaller screen of a smartphone. Zimperium says mobile-targeted phishing already has a high success rate, and AI tools will only improve these attacks.
"Mobile-targeted phishing, which is inclusive of various messaging tools (SMS, Telegram, WhatsApp, etc.), QR codes (quishing) and device-aware email, generally sits outside the organization's security perimeter and has a success rate that is 40% higher than traditional PC-based phishing attacks," the report says.
"AI didn't invent mobile phishing. It just made every text, every email, every PDF convincing enough to fool even the most vigilant employees. AI has provided the scale and efficacy that was once only available to the most sophisticated criminal organizations."
The researchers note that most people use mobile devices for both work and personal uses, increasing the potential impact of phishing attacks.
"Combining this mostly unprotected and largely unmonitored medium with what is traditionally the most effective attack technique, social engineering, we are seeing what is arguably historic scale and efficacy of data and credential theft, banking fraud and enterprise compromise - all enabled by AI that is easily accessible by even the most under resourced cybercriminals."
The workforce changed. Half of it doesn't have a badge. KnowBe4 secures all of it… the people and the agents working alongside them – KnowBe4 secures the digital workforce, humans and AI agents.
Zimperium has the story:
https://www.prnewswire.com/news-releases/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile-302837491.html
What KnowBe4 Customers Say
"Hi Bryan, Things are going very well. Your onboarding customer success team, Britni D., did a fantastic job getting us up and running. I can honestly say this has to be one of the best onboardings I’ve been able to be a part of for a hosted solution. Thanks for reaching out and I’m looking forward to a long relationship with KnowBe4!"
- G.G., Director of Technology
- A (highly) personalized scam is coming for you:
https://www.washingtonpost.com/opinions/2026/07/28/ai-is-gaining-ability-personalize-cyberattacks-enabling-phishing-scale/ - Malwarebytes: We found 120 fake Walmart stores trying to steal your credit card:
https://www.malwarebytes.com/blog/scams/2026/07/we-found-120-fake-walmart-stores-trying-to-steal-your-credit-card - U.S. Bans Foreign-Made Humanoid Robots, Targeting China Over National Security:
https://www.securityweek.com/us-bans-foreign-made-humanoid-robots-targeting-china-over-national-security/ - When AppSec Scanners Become a Supply Chain Attack Vector:
https://www.darkreading.com/application-security/when-appsec-scanners-become-supply-chain-attack-vector - Job candidates are sneaking AI prompt injections into their applications:
https://www.fastcompany.com/91581812/job-candidates-sneaking-prompt-injections-into-their-applications-resume-ai-screening - AI Scammers Are Now Better at Building Trust Than Humans:
https://www.wired.com/story/ai-scammers-are-better-at-building-trust-than-humans/ - Social engineering attack hits UK Dept of Education helpdesk systems:
https://www.ukauthority.com/articles/social-engineering-attack-hits-dfe-helpdesk-systems - Tech support scammers sent more than 13 million emails targeting Japanese organizations:
https://www.trendmicro.com/en_us/research/26/g/tech-support-scams-targeting-japan.html - Iran-linked social engineering attacks target Persian speakers around the world:
https://www.techtimes.com/articles/321439/20260723/iranian-state-spyware-hides-fake-vpn-apps-targeting-persian-speakers-worldwide.htm - Scammers can now buy AI-enhanced phone farms:
https://www.infosecurity-magazine.com/news/researchers-aienhanced-phone-fraud/
- Virtual Vaca #1 - MONTENEGRO Europe's Most Beautiful Country Nobody Talks About:
https://youtu.be/k5MA_p0_Bds - Virtual Vaca #2 - RÉUNION ISLAND TRAVEL TIPS (2026):
https://youtu.be/yQ9khBkHuzE - Virtual Vaca #3 - Curitiba, Paraná, Brazil in 4K HDR:
https://youtu.be/jW9rMXgFxro - Wingsuit Flight Through The KING-KONG Gap:
https://youtu.be/XsRweY7C-Gc - Seven Affordable Personal eVTOL Aircraft You Can Actually Buy in 2026. I want one!
https://youtu.be/FavAptU-724 - Women's Football - 1918 Film Restored to Life in Color:
https://youtu.be/SV5x8ExmEOg - The Genius Valve Designed by Nikola Tesla:
https://www.youtube.com/shorts/icdaAjYUE7o - Need some space? See the Impossible in 8K HDR Dolby Vision Ultra HD 60fps:
https://youtu.be/nje3ax9o-x4 - Pro Riders vs Impossible Bike Obstacle Course Race:
https://youtu.be/SChm4DyivOU - This Car Can Drift By Itself. The BYD Denza Z. :
https://youtu.be/jg5yWCaW7nM - Losing a Head Doesn't Stop This Robot From Battling Another in the Ring:
https://youtu.be/FEcPelBd9t0 - For Da Kids #1 - Someone Threw This Tiny Cat Away, Now She Travels The World:
https://www.youtube.com/watch?v=6t_cFMgMSZc - For Da Kids #2 - Woman Pads Her Entire Home For 2-Legged Puppy:
https://youtu.be/g9JdMQcKy84 - For Da Kids #3 - Wild Goose Runs to Greet Woman Every Day:
https://youtu.be/BfhxvznpH9s - For Da Kids #4 - Exhausted Raccoon Swims Toward Paddle Boarders for Help:
https://youtu.be/1EGapztHRDU - For Da Kids #5 - 8 Minutes of Baby Animals: Pure Joy and Cuteness:
https://youtu.be/3Rf0dIk_Eec

