KnowBe4 Blog

Phishing

Learn about current phishing techniques, notable campaigns and attacks, what to watch out for 'in the wild', and more.

Human Error Remains at the Core of AI-Enabled Social Engineering

AI is making social engineering attacks significantly more effective, according to a new report from cyber insurance firm Resilience. These attacks were behind more than 85% of losses in ...

Report: Vishing and Device Code Phishing Are Surging

Social engineering remains a central part of modern cyberattacks, according to a new report from CrowdStrike. Attackers are increasingly turning to voice phishing because it bypasses ...

Report: One-Quarter of Breaches Are Enabled by AI-Driven Attacks

A new report commissioned by IBM has found that one in four breaches is now AI-enabled, up 56% from last year.

Anatomy of an Agent Tesla BEC Attack: From Inbox to In-Memory Infostealer

Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal

Microsoft Observed 7.6 Billion Phishing Emails in Q2 2026

Researchers at Microsoft warn that phishing emails are still the top initial access vector, with more than 2 billion phishing threats detected each month during the second quarter of 2026.

Warning: Compromised Hotel Routers Send Users to Phishing Sites

Attackers are using compromised hotel Wi-Fi routers to redirect users to Microsoft 365 phishing sites, according to researchers at ReliaQuest. The attacks were observed in multiple U.S. ...

Report: Scams Are Surging as Attackers Abuse Trusted Workflows

Threat actors are increasingly abusing trusted workflows to carry out attacks, according to a new report from Gen Digital.

Iranian APT Launches AI-Assisted Spear Phishing Attacks

The Iran-linked threat actor APT42 is using AI-assisted phishing attacks to target U.S. organizations amidst the Iran-US war, according to researchers at DarkAtlas.

Report: Employees Are Overconfident in Their Ability to Spot Scams

A survey from Trustmi found that most employees believe they’d be able to spot a social engineering attack, but those same employees still rely primarily on outdated guidance to spot red ...

The Blind Spot: How “Bulletproof” Phishing Redirectors Slip Past SEGs

By Shikhar Dalela and Jeewan Singh Jalal The operators named the kit themselves. Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called ...