Menlo Report: 1 in 5 Phishing Links Evade URL Filters

David Kowalski··5 min read
Close-up of a browser address bar on a laptop screen in an office

One in five phishing links that employees actually click goes completely undetected by legacy URL filtering. That is the central finding of Menlo Security's 2026 Browser Threat Report, and it quantifies something security teams have long suspected: a meaningful share of phishing traffic sails straight past the tools bought specifically to stop it. When the filter stays silent, the only control left between the attacker and the credential is the person holding the mouse.

The report, announced on 10 June 2026, is based on real enterprise browser telemetry rather than survey answers, which makes its numbers unusually hard to dismiss.

What the 2026 Browser Threat Report Found

Across the analysis period, Menlo identified 115,842 evasive phishing attacks - campaigns specifically engineered to defeat automated inspection before a human ever sees them. The headline statistic is worth restating precisely: among phishing links that users actively clicked, one in five was not flagged by legacy URL filtering at all. These were not borderline cases that produced a warning banner. They were clean verdicts on malicious pages.

The report also counted 4,937 zero-day phishing attacks - brand-new pages blocked by behavioral analysis before any reputation service had ever seen the URL. Every one of those would have been invisible to a defense that relies on known-bad lists, because at the moment of the click, nothing about the URL was known at all.

The Evasion Playbook

How do phishing pages beat automated inspection? The report catalogs four techniques doing most of the work:

  • CAPTCHA abuse. Attackers put a CAPTCHA in front of the phishing page. Automated scanners cannot solve it, so they see a harmless challenge page - while the human victim clicks through to the credential harvest.
  • Traffic distribution systems (TDS). Redirection layers fingerprint each visitor and route security crawlers to benign content while real users in the target region are forwarded to the live attack.
  • HTML smuggling. The malicious payload is assembled inside the browser from innocuous-looking fragments, so nothing dangerous crosses the network perimeter in inspectable form.
  • Brand impersonation. Pixel-perfect clones of familiar login pages defeat both automated visual checks and casual human inspection.

None of these techniques exploits a software vulnerability. They exploit the assumptions inspection tools make - and every one of them fails when it finally reaches an alert human who pauses before typing a password.

When 'Trusted' Domains Do the Attacker's Work

Perhaps the most uncomfortable number in the report: one in three highly evasive threats originated from websites already classified as safe. Menlo counted 52,185 threats hosted on trusted domains, including mainstream services like Google Drive, Dropbox, and SharePoint - a finding also highlighted by Infosecurity Magazine.

This inverts the mental model most filtering is built on. Reputation-based controls assume malicious content lives on shady infrastructure; attackers responded by moving onto infrastructure with impeccable reputations. A phishing page served from a legitimate file-sharing platform inherits that platform's TLS certificate, domain age, and category rating. To the filter, it looks like business as usual. To the employee, the familiar domain in the address bar reads as a green light.

The address bar saying sharepoint.com or drive.google.com is no longer evidence that a page is safe. It is only evidence of where the attacker chose to host it.

Links Are the Weapon of Choice

The browser-side findings line up with what email telemetry shows. Proofpoint's Human Factor research (2025) found that malicious URLs were used four times more often than malicious attachments, as detailed in its Human Factor URL phishing analysis. Attachments get sandboxed, detonated, and stripped; a link defers the malicious moment until the victim's own browser session, where the evasion techniques above take over.

Put the two datasets together and the attacker economics become clear: deliver a link because links get through email defenses, then host the payload behind a CAPTCHA on a trusted domain because that gets through web defenses. Each layer of the stack is bypassed with a technique tailored to that layer's blind spot.

The Case for Trained Humans as the Last Line

None of this argues for ripping out URL filtering - it still removes enormous volumes of commodity threats. The argument is about what happens in the residual 20 percent. When the filter has no verdict and the domain looks trustworthy, the deciding factor is whether the employee notices that something is off: a login prompt that appeared from a shared document, a CAPTCHA guarding a file that should have opened directly, a familiar brand asking for credentials in an unfamiliar flow.

Those instincts are trainable, and they are measurable. Phishing simulations that mirror real evasive tradecraft - lures hosted on trusted-looking services, credential prompts behind an extra click - reveal exactly which users and teams would fall for the traffic that filters miss. Platforms like empowsec combine that simulation data with per-user risk scoring, so security teams can direct awareness training at the people most likely to face - and fail - the one-in-five scenario. The stack handles the 80 percent; the humans have to be ready for the rest.

Key Takeaways

  • 1 in 5 clicked phishing links evades legacy URL filtering entirely, per Menlo Security's 2026 Browser Threat Report - 115,842 evasive attacks identified.
  • Attackers defeat inspection with CAPTCHA abuse, TDS redirection, HTML smuggling, and brand impersonation - techniques aimed at scanners, not software flaws.
  • 1 in 3 highly evasive threats came from sites already rated safe, with 52,185 threats hosted on trusted domains including Google Drive, Dropbox, and SharePoint.
  • 4,937 zero-day attacks appeared before reputation services knew the URLs existed; Proofpoint's Human Factor research (2025) shows URLs outnumbered malicious attachments 4 to 1.
  • Assume a fifth of malicious links will reach the browser: train employees on evasive lure patterns, simulate trusted-domain phishing, and measure who needs help before attackers do.
Share: