Executive Summary
Facts Only
* Bad grammar was identified as an initial tell in phishing attempts.
* AI tools are used to clean up language and tailor lures for recipients.
* Attackers use AI to build rapport before executing attacks.
* QR code phishing accounted for one in nine detected phishing emails in ESET’s telemetry in the first half of 2026.
* QR codes are ranked as the fastest-growing email-based attack vector by Microsoft.
* ConsentFix redirects victims through a legitimate Microsoft sign-in flow to extract OAuth authorization codes.
* AI-fix targets legitimate domains belonging to Anthropic, OpenAI, and Microsoft with fake troubleshooting instructions.
* CrashFix is a fake ad blocker that directs targets to the Chrome Web Store and delays alerts.
* Deepfake audio and video are used in calls, which can result in financial transfers of over US$25 million.
* Almost 70% of security incidents occur during typical business hours, with 90% on workdays.
* Investigations take 41% of the time within a fortnight and 34% take two to six weeks.
* Awareness training adoption is highest among businesses that have suffered multiple incidents.
Full Take
From the original · ESET Research
Many of today’s phishing attempts are no longer betrayed by poor grammar, a sketchy URL or a crude login page. To be sure, it does still pay to look out for these red flags, but their absence doesn’t make a message legitimate.Read the full story at welivesecurity.com
Sentinel — Human
The text functions as well-researched commentary, effectively synthesizing emerging cybersecurity tactics with systemic organizational failures, exhibiting a strong human editorial voice despite employing machine-like structuring.
