
Phishing used to be relatively easy to recognize: a suspicious email, an unfamiliar sender, a strange link and perhaps a few obvious spelling mistakes.
Today, the most effective attacks can look very different.
A message from your bank says your account has been restricted. A colleague urgently asks you to open a document. Your "IT support" team calls to help resolve an authentication issue. A text message tells you that an important payment or delivery requires your attention.
The details change, but the objective remains the same: convincing you to take an action that benefits the attacker.
This is where phishing meets social engineering. Instead of trying to break through a technical security control, attackers manipulate people into opening the door for them.
Phishing is no longer a niche technique or a problem limited to suspicious emails. It has become one of the most common ways attackers gain an initial foothold.
According to ENISA's 2025 Threat Landscape, phishing accounted for approximately 60% of observed initial intrusion vectors, making it the leading method identified in its analysis. The category includes phishing, vishing, malspam and malvertising.
The significance of that number goes beyond the volume of messages being sent. Modern phishing operations are increasingly organized and scalable, using ready-made phishing kits, phishing-as-a-service and automated tools to reach large numbers of potential victims.
And stealing a password is only one possible objective.
An attacker may want an employee to approve a login, reveal an authentication code, transfer money, disclose sensitive information or visit a malicious website.
The channel can change. The manipulation stays the same.
Artificial intelligence is adding another layer to the problem: it makes convincing social engineering faster and easier to scale.
Attackers can use AI to create polished messages, adapt language, personalize communication and generate large numbers of variations for different targets.
According to ENISA, AI-supported phishing campaigns represented more than 80% of observed social engineering activity worldwide by early 2025.
The important change is not simply better grammar.
For years, people were taught to look for obvious warning signs: spelling mistakes, awkward translations, generic greetings or poorly written requests. Those signals are becoming less dependable.
An AI-assisted message can be fluent, professional and tailored to its recipient. It can reference the right company, the right role or the right context.
In other words, phishing does not necessarily have to look suspicious anymore.
It can look like a standard conversation.
Email remains an important attack surface, but attackers increasingly use other channels to reach people.
SMS, phone calls, messaging platforms and social media can all be used to create the same sense of trust and urgency that makes phishing effective.
APWG reported a 40% increase in smishing attacks between Q1 and Q2 2026.
The shift matters because these channels change the way people interact with a message.
An email gives you a sender address to inspect. However, a text arrives among dozens of everyday conversations. A phone call puts a real-time voice on the other end of the interaction. A message on a social platform does not ring any alarm bells even though its coming from an unfamiliar account.
The attack does not have to announce itself as a cybersecurity threat.
It can simply feel like a normal conversation.
The most effective social engineering attacks rarely begin with an obviously suspicious request. They begin with a reason to act.
Your account is about to be blocked.
Your manager needs a payment processed immediately.
Your authentication needs to be "verified."
Your package cannot be delivered until you confirm your details.
The underlying techniques are familiar: urgency, authority, fear, curiosity and trust.
The attacker creates a situation in which acting quickly feels more reasonable than stopping to verify.
That is why one of the most useful questions to ask is not:
"Does this message look fake?"
but:
“What is this message asking me to do?”
If the answer involves money, credentials, authentication, sensitive information or an unusual request, that is the moment to slow down.
Technical controls such as multi-factor authentication, endpoint protection and email security remain essential. But attackers increasingly design their techniques around those controls rather than simply trying to defeat them.
A phishing page can imitate a legitimate login flow. A fraudulent support call can ask a user to complete an authentication step. An attacker may attempt to obtain authentication information or an already authenticated session rather than simply stealing a password.
The lesson is not that security technology is failing.
It is that security works in layers.
And awareness is a layer we often forget about.
KnowBe4's 2026 benchmarking report analyzed 42 million simulated phishing tests involving 14.8 million users across 64,000 organizations worldwide. The global average Phish-prone Percentage fell from 33.2% before security awareness training to 4.2% after one year of continuous training.
The goal of awareness training is not to make people cybersecurity experts. It is to build a habit of pausing before taking an unexpected or high-impact action.
Look at the actual email address and domain, not just the displayed name.
A deadline, account restriction or threat of immediate consequences is a reason to verify, not a reason to rush.
If you need to access a bank, corporate platform or other service, open the official app or website yourself.
Never share passwords, MFA codes or authentication approvals with someone who asks for them unexpectedly.
If someone asks for a payment, sensitive document or unusual action, contact them through a trusted channel you find yourself.
A suspicious message reported quickly can help security teams investigate it and prevent the same campaign from reaching others.
And if you already clicked or shared information, report it immediately. A fast response gives your security team more opportunity to contain the incident.
Cybersecurity is often described through technology: authentication, encryption, monitoring, detection and protection.
But social engineering reminds us that security is also about human decisions.
The moment between receiving a message and acting on it can become an important security control in itself.
So when a message creates unusual urgency, asks for something unexpected or simply feels slightly off, take a moment.
Pause. Verify. Report.
Because the attack may start with a conversation.
But you decide how it ends.
This article is part of our Cybersecurity Awareness Month series.
Find the full series on our Blog.
Stay informed. Stay secure.