Fewer Phishing Emails, More Precision: Zscaler 2026 Data

Daniel Okafor··5 min read
Analyst reviewing a declining trend line on a security analytics dashboard

For the first time in years, phishing volume is falling. Zscaler's ThreatLabz 2026 Phishing and Initial Access Report shows attacks declining roughly 20 percent in both 2024 and 2025, after exceeding two billion blocked hits in 2023. If that sounds like good news, look closer: attackers have not retreated. They have traded volume for precision, and the campaigns that remain are harder to spot than anything the mass-blast era produced.

The Complacency Trap in a Falling Trend Line

As Help Net Security reported, ThreatLabz attributes the decline not to attackers giving up but to a deliberate pivot: away from indiscriminate spray-and-pray blasts and toward targeted lures that mimic routine business workflows. Instead of a million generic 'password expired' emails, attackers send a few thousand messages that look like the invoice approvals, e-signature requests, HR notifications, and voicemail alerts your employees process on autopilot every day.

This is the complacency trap. A security dashboard showing 20 percent fewer phishing detections invites the conclusion that the problem is shrinking. In reality, the noise is shrinking while the signal gets sharper. The emails that were easiest to filter, and easiest for employees to recognize, are exactly the ones disappearing. What survives is engineered to pass both machine and human inspection.

Phishing Pages From a Prompt: AI Site Builders at Work

One of the report's most concrete findings is how thoroughly AI tooling has been absorbed into the phishing supply chain. ThreatLabz identified 413,524 AI-generated websites, of which 37,447 were classified as malicious. AI site builders such as Manus AI and Blackbox AI let attackers assemble convincing phishing pages with, in the report's words, little more than a prompt and a few iterations.

The implications for defenders are uncomfortable. The traditional tells of a fake login page, such as clumsy layouts, mismatched fonts, and broken English, were artifacts of attackers doing rushed manual work. When a landing page is generated by the same class of tools that legitimate businesses use to build theirs, visual inspection stops being a reliable defense. Employees need to anchor their suspicion in context and process, not polish: Was I expecting this? Does this request bypass a normal procedure? Is the domain actually the one I know?

Who Gets Hit, and Which Brands Get Borrowed

The targeting data shows the shift clearly. The services sector saw a 65.5 percent year-over-year increase in phishing, even as overall volume fell, a strong indicator that attackers are concentrating fire on industries rich in credentials, client data, and payment workflows. Meanwhile, Microsoft and Google remain the most-impersonated brands, which makes sense: their login pages guard email, documents, and identity for most of the corporate world.

Independent data points in the same direction. Check Point's Q1 2026 brand phishing ranking put Microsoft at 22 percent of brand-impersonation attempts, followed by Apple at 11 percent, Google at 9 percent, Amazon at 7 percent, and LinkedIn at 6 percent. The brands your employees trust most are precisely the ones attackers wear as a disguise.

Encrypted Delivery and the MFA Bypass Problem

Two further findings explain why these leaner campaigns succeed. First, over 95 percent of phishing now arrives via encrypted channels, which means organizations that do not inspect encrypted traffic are effectively blind to most of it. Second, adversary-in-the-middle and browser-in-the-middle techniques, exemplified by phishing-as-a-service offerings like 'BlackForce', are built to capture session tokens rather than just passwords.

That last point deserves emphasis with every employee who believes MFA makes them safe. In an adversary-in-the-middle attack, the victim logs into what looks like the real Microsoft or Google page, completes the real MFA challenge, and the attacker silently captures the resulting session token. From the service's perspective, the attacker is now the authenticated user. MFA was not broken; it was relayed. The only step in that chain the attacker cannot automate is convincing a human to click the link in the first place, which keeps human judgment squarely on the critical path.

What This Means for Your Simulation Program

If phishing has evolved past mass blasts, phishing simulations built on mass-blast templates are testing for a threat that is fading. A program aligned with the 2026 landscape looks different:

  • Simulate workflows, not just warnings. Use lures that mirror invoice approvals, e-signature requests, shared documents, payroll updates, and voicemail notifications, the routine business traffic ThreatLabz says attackers now imitate.
  • Lead with the big brands. Microsoft and Google impersonations dominate real attacks, so they should feature prominently in your test rotation.
  • Train past the polish. Teach employees that a flawless-looking page proves nothing in the AI era, and that verifying the domain and the context is what counts.
  • Explain MFA bypass in plain language. Employees who understand that one click can hand over an authenticated session take links more seriously than those told MFA has them covered.
  • Target the follow-up. Use per-user and per-team risk data to give extra practice to the people attackers are most likely to reach.

This is where a modern platform earns its keep. empowsec's phishing simulation library includes workflow-style and brand-impersonation scenarios, and its risk scoring highlights which departments still click, so security awareness training lands where the data says it is needed rather than being sprayed evenly across the company.

Key Takeaways

  • Falling volume is not falling risk. Phishing declined about 20 percent in 2024 and again in 2025, but the surviving campaigns are targeted and workflow-shaped.
  • AI has commoditized quality. With 413,524 AI-generated sites observed and page builders that work from a prompt, visual polish no longer separates real from fake.
  • Trusted brands are the disguise. Microsoft, Google, and other household names top both Zscaler's and Check Point's impersonation data.
  • MFA is being relayed, not broken. Adversary-in-the-middle kits capture session tokens after a successful login, so the click itself is the battle.
  • Evolve your simulations. Test employees against the precise, routine-looking lures of 2026, not the mass blasts of 2020.

The attackers read the same trend lines defenders do, and they adapted first. The organizations that stay ahead will be the ones that treat a quieter inbox as a reason to sharpen training, not relax it.

Share: