Back to updates Updates · Updated Jan 2026

2. The Rise of Phishing and Social Engineering

High

Cybercriminals exploit human psychology through phishing emails, fake login pages and impersonation techniques. These attacks bypass technical defenses by manipulating users into revealing sensitive information, clicking malicious links or downloading infected files.

Typical signals

  • Lookalike domains, OAuth consent phishing, MFA-prompt bombing
  • Adversary-in-the-Middle (AitM) proxy flows (token/session theft)
  • Smishing/QR-phishing + "CAPTCHA" lures to credential harvesters

Current-state check

  • Shift from attachments to URLs and "malwareless" credential theft
  • Protect collaboration tooling (Teams/SharePoint) and IdP portals
  • Controls: phishing-resistant MFA, URL isolation, DMARC enforcement
Book a call