The devil is still in the email – but wearing a new mask

https://web-assets.esetstatic.com/wls/2026/09-26/email-phishing-evolution-ai.png

Business Security

When phishing can increasingly pass familiar checks, avoiding or limiting the damage depends on how quickly your company can detect and contain the attack

28 Sep 2026 • 6 min. read

Many of today’s phishing attempts are no longer betrayed by poor grammar, a sketchy URL or a crude login page. To be sure, it does still pay to look out for these red flags, but their absence doesn’t make a message legitimate. Modern social engineering schemes are increasingly designed to withstand scrutiny and to provide reassurance where an attack might once have left some giveaways.

By extension, email-borne threats in particular are now built to meet as little resistance as possible. They subvert legitimate workflows and reach employees mid-task, when their accounts are authenticated and any incoming requests for action feel like part of an ordinary working day. Some techniques go after live sessions themselves, with attackers...

Copyright of this story solely belongs to www.welivesecurity.com. To see the full text click HERE

Read more