Skip to content

Executive Summary

Modern social engineering is evolving to resist detection by incorporating sophisticated techniques that move beyond simple grammatical errors or obvious visual cues. Threats are increasingly designed to appear legitimate and occur during routine workflows, targeting authentication tokens instead of just passwords. The proliferation of cybercrime-as-a-service tools, coupled with the accelerating capabilities of Artificial Intelligence, allows malicious actors to create highly tailored lures, build rapport through nuanced communication, and automate the research phase for targets. Specific attack vectors include QR code phishing, which is growing rapidly in email attacks, and novel methods like ConsentFix that leverage legitimate sign-in flows to steal authorization codes without triggering standard security prompts. Furthermore, deepfake technology introduces a risk where visual or audio evidence can be highly convincing, complicating verification processes during live interactions. The focus must shift from relying solely on spotting errors to establishing verification channels and utilizing advanced monitoring to detect subtle behavioral patterns across the entire digital environment.

Facts Only

* Bad grammar was identified as an initial tell in phishing attempts.
* AI tools are used to clean up language and tailor lures for recipients.
* Attackers use AI to build rapport before executing attacks.
* QR code phishing accounted for one in nine detected phishing emails in ESET’s telemetry in the first half of 2026.
* QR codes are ranked as the fastest-growing email-based attack vector by Microsoft.
* ConsentFix redirects victims through a legitimate Microsoft sign-in flow to extract OAuth authorization codes.
* AI-fix targets legitimate domains belonging to Anthropic, OpenAI, and Microsoft with fake troubleshooting instructions.
* CrashFix is a fake ad blocker that directs targets to the Chrome Web Store and delays alerts.
* Deepfake audio and video are used in calls, which can result in financial transfers of over US$25 million.
* Almost 70% of security incidents occur during typical business hours, with 90% on workdays.
* Investigations take 41% of the time within a fortnight and 34% take two to six weeks.
* Awareness training adoption is highest among businesses that have suffered multiple incidents.

Full Take

The narrative suggests a critical tension between the increasing sophistication of adversarial methods—driven by AI and commoditized services—and the often slower, reactive capabilities of organizational defenses and training. The core challenge lies in shifting security reliance from surface-level awareness to deep contextual verification. When attackers can perfectly mimic legitimate workflows (like using session tokens or leveraging trusted domains) and generate highly convincing content (deepfakes), human vigilance becomes insufficient as a primary defense. The movement described forces a reevaluation of where trust should be placed: not in the message's superficial appearance, but in external, non-visual artifacts like network telemetry and behavioral patterns across an environment. The implication is that institutional defenses must evolve beyond policing employee mistakes to focusing on layered, automated verification that operates faster than the attack cycle itself. The system risks creating a feedback loop where the cost of investigation (time and resources) becomes prohibitive for smaller entities, exacerbating the resource gap between sophisticated threat actors and lean operational teams. What are the systemic implications for accountability when human error is amplified by scalable tools? How can organizational structures be designed to support proactive verification rather than merely retrospective blame?

From the original · ESET Research

Many of today’s phishing attempts are no longer betrayed by poor grammar, a sketchy URL or a crude login page. To be sure, it does still pay to look out for these red flags, but their absence doesn’t make a message legitimate.
Read the full story at welivesecurity.com

Sentinel — Human

Confidence

The text functions as well-researched commentary, effectively synthesizing emerging cybersecurity tactics with systemic organizational failures, exhibiting a strong human editorial voice despite employing machine-like structuring.

Signals Detected
low severity: Sentence length variance is erratic; employs complex phrasing and varied rhythm typical of sophisticated journalism.
low severity: Maintains a clear, evolving argumentative thread across disparate examples (QR codes, ClickFix, deepfakes) without sacrificing rhetorical flow.
medium severity: Uses specific, verifiable data points (ESET telemetry percentages, survey references) to anchor abstract arguments, suggesting reference to specific reports rather than pure synthesis.
low severity: Specific technical mechanisms (ConsentFix, ClickFix variants) are explained in a way that suggests deep domain knowledge, balanced against the general tone.
Human Indicators
Idiosyncratic emphasis on linking operational reality (SMB constraints, investigation times) with theoretical security principles.
The structure smoothly moves from immediate threats (phishing) to technical evasion methods (QR codes) to systemic failures (training gaps) and finally to the required response (MDR).
The concluding paragraphs ground the abstract concerns in specific organizational challenges (SMB resource constraints), which is characteristic of investigative reporting.
The devil is still in the email | Huntaegis