Threats

7 Phishing Tactics That Are Working in 2026 (And How to Defend Against Each)

Phishing has evolved past the obvious "Nigerian prince" stereotypes. Here are 7 tactics actively succeeding against organizations in 2026 — what makes each effective and how to defend against it.

On this page 16 sections
  1. 1 1. AI-generated personalized phishing
  2. 2 2. MFA fatigue attacks
  3. 3 3. Vendor email compromise
  4. 4 4. Living-off-the-land phishing
  5. 5 5. Voice/SMS phishing (vishing/smishing) coordinated with email
  6. 6 6. Calendar invite phishing
  7. 7 7. Browser session hijacking via phishing
  8. 8 The general defenses that work across tactics
  9. 9 1. Phishing-resistant MFA for high-risk accounts
  10. 10 2. User training that updates with threat evolution
  11. 11 3. Verification protocols for high-impact actions
  12. 12 4. Email security that addresses modern threats
  13. 13 5. Detection and response when prevention fails
  14. 14 What's likely coming next
  15. 15 The implementation priorities
  16. 16 The takeaway

Phishing has gotten substantially more sophisticated. The obvious red flags from a decade ago — bad grammar, generic greetings, suspicious links — have largely been addressed by attackers. Modern phishing attacks succeed against organizations that would have spotted the old-style attacks easily. Here are 7 tactics actively producing results for attackers in 2026, with the defenses that work against each.

1. AI-generated personalized phishing

The tactic: attackers use LLMs to generate phishing emails personalized to each target. The emails reference real projects, real colleagues, and real organizational details extracted from public sources (LinkedIn, company website, GitHub, conference talks).

Why it works: the personalization defeats the "this seems generic" instinct that catches less-targeted phishing. Recipients see emails that appear to come from someone who knows their work.

Defense: Phishing-resistant MFA on critical accounts. Verification of unusual requests through separate channels (call the person, don't reply to the email). Awareness training that addresses personalized phishing specifically.

2. MFA fatigue attacks

The tactic: attacker who has obtained credentials repeatedly triggers MFA notifications, hoping the user eventually approves one out of frustration or assumption that something is broken.

Why it works: users often don't understand what MFA notifications mean. Multiple notifications create anxiety that can override the security intent. Some users just want the notifications to stop.

Defense: Number matching MFA (where users must enter a number shown on the screen). Restrict MFA push frequency. User training that explains MFA notifications and what to do about unexpected ones. Alert SOC on excessive MFA push attempts.

3. Vendor email compromise

The tactic: attacker compromises a legitimate vendor's email account, then sends phishing emails or invoice fraud from the compromised account to the vendor's customers.

Why it works: the email genuinely comes from a trusted vendor address. SPF, DKIM, and DMARC pass because the email is technically legitimate. Recipients have no reason to be suspicious.

Defense: Out-of-band verification of payment changes (always call to confirm bank account changes, regardless of email source). Vendor security requirements (require vendors to maintain security standards). Anomaly detection for unusual payment patterns.

4. Living-off-the-land phishing

The tactic: attacker uses legitimate platforms (Google Workspace, Microsoft 365, OneDrive, Dropbox) to host malicious content. Phishing emails contain links to legitimate platform URLs that ultimately lead to the malicious content.

Why it works: URL filtering tools see legitimate domains and don't block. Users see familiar URLs and trust them. The platforms' reputation legitimizes the phishing.

Defense: URL analysis that follows redirects rather than evaluating only the visible URL. Email security that scans content downloaded through linked platforms. User training that addresses platform-hosted phishing.

5. Voice/SMS phishing (vishing/smishing) coordinated with email

The tactic: attacker sends a legitimate-seeming email, then follows up with a phone call or SMS to the same target. The combination of channels increases credibility and pressure.

Why it works: single-channel phishing can be questioned. Multi-channel coordinated phishing creates an appearance of legitimacy that's harder to challenge. The phone call or SMS provides urgency that email alone might not.

Defense: Verification protocols that work across channels. Training that addresses multi-channel phishing specifically. Treat all unsolicited contact about urgent matters as suspicious.

6. Calendar invite phishing

The tactic: attacker sends calendar invites that contain phishing links or that establish fake meetings to subsequently abuse. The invites appear in users' calendars and create natural-seeming context for follow-up.

Why it works: calendar invites bypass email security in many configurations. Users have a learned trust of calendar entries. Meeting context provides legitimate-seeming reason for follow-up communication.

Defense: Email security that scans calendar invites equivalently to other email. User training that addresses calendar-based threats. Restrict external calendar invite acceptance to known senders.

7. Browser session hijacking via phishing

The tactic: attacker uses phishing to steal browser session cookies rather than passwords. The cookie theft bypasses MFA because the authentication has already happened.

Why it works: session cookies represent already-authenticated state. Even MFA doesn't prevent use of stolen cookies during their valid lifetime. The attack is invisible to users who notice nothing unusual.

Defense: Short session lifetimes for sensitive applications. Cookie binding to device characteristics where supported. Session anomaly detection (geographic anomalies, behavior anomalies). Reduced cookie scope (specific to required operations).

The general defenses that work across tactics

While each tactic has specific defenses, several broader defenses reduce success across many tactics:

1. Phishing-resistant MFA for high-risk accounts

FIDO2 hardware keys, certificate-based authentication, and other phishing-resistant methods defeat the most-common credential phishing entirely. The hardware investment is modest; the protection is substantial.

2. User training that updates with threat evolution

Annual training that covers the same topics every year doesn't address current tactics. Training should update as attacker tactics evolve, with specific examples of recent campaigns.

3. Verification protocols for high-impact actions

Out-of-band verification for payments, password resets, sensitive data sharing, and other high-impact actions catches phishing that single-channel verification misses. The friction is acceptable for the protection.

4. Email security that addresses modern threats

Email security capabilities have evolved; older configurations often don't address current threats. Periodic review of email security configuration against current threat landscape is appropriate.

5. Detection and response when prevention fails

No phishing defense is perfect. Detection capability (logging, monitoring, EDR) catches attacks that get past prevention. Response capability (IR plans, communication protocols) limits damage when attacks succeed.

What's likely coming next

Threat trends suggest several directions for phishing evolution over the next 1-2 years:

  • Deepfake voice phishing using AI-generated voices that mimic real executives or colleagues
  • Real-time AI assistants for attackers, providing live coaching during voice phishing attempts
  • Cross-channel coordinated attacks spanning email, voice, SMS, and social media
  • Targeted attacks against specific high-value individuals using extensive personalization investment
  • Supply chain phishing compromising trusted vendors to reach their customers

Defenders should expect each of these to become more common. Defenses appropriate to current threats may not be sufficient for emerging ones.

The implementation priorities

If you're evaluating your current phishing defense:

  1. Audit MFA coverage and quality. Phishing-resistant MFA on critical accounts is the most-reliable defense.
  2. Review email security configuration. Many configurations haven't been updated as threats evolved.
  3. Update user training. Cover current tactics, not just historical ones.
  4. Establish verification protocols. For payments, password resets, and other high-impact actions.
  5. Test detection capability. Know what would happen if phishing succeeded — can you detect and respond?

The takeaway

Phishing has evolved substantially. Defenses appropriate to historical phishing don't address current tactics. The 7 tactics above are actively succeeding against organizations in 2026; the defenses described work against each but require deliberate implementation.

Audit your current phishing defenses against the modern threat landscape. The gap between what you have and what you need is probably larger than expected, and addressing it is among the highest-ROI security investments available.