# SoCyber > SoCyber is a European cybersecurity and compliance company helping organizations identify, remediate and manage security risk through specialist services, evidence-led guidance and the Kikimora.io vulnerability management platform. SoCyber focuses on European SMEs and security-sensitive organizations, mapping technical security work to regulatory outcomes (GDPR, NIS2, DORA and more). Capabilities span offensive security and penetration testing, detection and response, cloud and infrastructure security, secure AI adoption, and governance and compliance, delivered with methodology, evidence and measurable results. ## Core Information - [About SoCyber](https://so-cyber.com/about): Company experience, capabilities and approach. - [Cybersecurity Services](https://so-cyber.com/services): Overview of all SoCyber security and compliance services. - [Team](https://so-cyber.com/team): The specialists behind SoCyber. - [Contact SoCyber](https://so-cyber.com/contact): Discuss a security requirement or request an assessment. ## Offensive Security and Penetration Testing - [Web Application Penetration Testing](https://so-cyber.com/web-app-penetration-testing): Controlled, adversary-simulated testing of web applications, APIs, authentication flows and business logic. - [API Penetration Testing](https://so-cyber.com/api-penetration-testing): Assessment of API authentication, authorization, business logic and data exposure. - [Mobile App Penetration Testing](https://so-cyber.com/mobile-app-penetration-testing): Security testing of iOS and Android applications and their backends. - [Network Penetration Testing](https://so-cyber.com/network-penetration-testing): External and internal network testing, segmentation and infrastructure security. - [Wireless Penetration Testing](https://so-cyber.com/wireless-penetration-testing): Assessment of wireless networks, access controls and rogue-device exposure. - [Automated Penetration Testing](https://so-cyber.com/automated-penetration-testing): Continuous, scalable testing to complement manual engagements. - [Web and Middleware Security](https://so-cyber.com/web-middleware-security): SAST, DAST, secure code review and middleware security testing. - [Secure Code Review](https://so-cyber.com/secure-code-review): Manual and tool-assisted review of source code for security defects. - [Threat Modeling](https://so-cyber.com/threat-modeling): Structured analysis of attack surface, trust boundaries and design-level risk. - [Social Engineering](https://so-cyber.com/social-engineering): Phishing and human-targeted attack simulation to manage impersonation and manipulation risk. ## Detection and Response - [Incident Response](https://so-cyber.com/incident-response): Incident containment, investigation, recovery and forensic support. - [Digital Forensics](https://so-cyber.com/digital-forensics): Evidence acquisition and analysis for investigations and disputes. - [Cyber Threat Intelligence (CTI)](https://so-cyber.com/cyber-threat-intelligence-cti): Evidence-led intelligence for threats, exposure and decision support. - [Vulnerability Management](https://so-cyber.com/vulnerability-management): Continuous identification, prioritization and remediation tracking. ## Cloud and Infrastructure Security - [Cloud Security](https://so-cyber.com/cloud-security): Assessment and hardening of cloud configurations, identity and workloads. - [IT Systems Security](https://so-cyber.com/it-systems-security): Hardening, secure configuration and monitoring of endpoints and infrastructure. ## AI Security - [AI Best Practices](https://so-cyber.com/ai-best-practices): Principles and controls for adopting AI and LLMs securely at work. - [AI and LLM Red Teaming](https://so-cyber.com/ai-red-teaming): Testing AI systems for prompt injection, data leakage, unsafe agency and control failure. ## Governance and Compliance - [Compliance Overview](https://so-cyber.com/compliance): How SoCyber maps controls to regulatory frameworks with evidence. - [Governance, Risk and Compliance](https://so-cyber.com/governance-risk-compliance): Building and operating an effective security governance program. - [Virtual CISO (vCISO)](https://so-cyber.com/vciso): On-demand security leadership, strategy and program ownership. - [NIS2](https://so-cyber.com/nis2): Preparing governance, risk and incident-response capabilities for the NIS2 Directive. - [DORA](https://so-cyber.com/dora): ICT risk, resilience testing and third-party controls for financial entities. - [ISO 27001](https://so-cyber.com/iso-27001): Building and maintaining an effective information security management system. - [GDPR](https://so-cyber.com/gdpr): Technical and organizational measures for protecting personal data. - [SWIFT CSP](https://so-cyber.com/swift-csp): Preparing for the SWIFT Customer Security Controls Framework. - [PCI DSS](https://so-cyber.com/pci-dss): Protecting payment environments and preparing for PCI DSS assessments. ## Guides Live guides also have a plain-markdown version at the same path with a .md extension, for clean ingestion without page chrome. - [Security Guides](https://so-cyber.com/guides): Practical, evidence-led guides on the threats and controls that matter, with step-by-step plans. - [Phishing in 2026 and Beyond](https://so-cyber.com/guides/phishing-threats-2026): Modern phishing as identity and workflow compromise - AI impersonation, session hijacking, OAuth abuse, QR and synthetic-voice attacks, with practical controls. Markdown: https://so-cyber.com/guides/phishing-threats-2026.md ## Full content - Service, compliance, guide and core pages have a clean Markdown version at the same path with a .md extension (for example https://so-cyber.com/web-middleware-security.md), for ingestion without page chrome. - [Everything in one file](https://so-cyber.com/llms-full.txt): This index plus the full text of every guide, for single-fetch ingestion. ## Platform - [Kikimora.io](https://kikimora.io/): Vulnerability visibility, asset discovery, remediation tracking and compliance reporting. ## Optional - [EU Funding Opportunities](https://so-cyber.com/funding): Curated EU cybersecurity funding (Digital Europe, Horizon Europe, EIC Accelerator and more), with the key parameters for each call and how SoCyber helps SMEs apply and deliver. - [News and Media](https://so-cyber.com/news): Technical analysis, regulatory updates and practical security guidance. - [Podcast](https://so-cyber.com/podcast): Conversations on cybersecurity, compliance and the threat landscape. - [Events](https://so-cyber.com/events): Live events, webinars and practical advice videos for security and compliance teams. --- # Full guide content --- title: "Phishing in 2026 and Beyond" description: "Modern phishing as identity and workflow compromise: AI impersonation, session hijacking, OAuth abuse, QR and voice attacks, and the controls that stop them." url: https://so-cyber.com/guides/phishing-threats-2026 category: Foundations level: Foundational reading_time: 12 min updated: Jun 2026 source: SoCyber - cybersecurity and compliance for European SMEs --- # Phishing in 2026 and beyond > Modern phishing is identity and workflow compromise, not just a bad email. What changed, and the controls that actually stop it. Attackers now target your identities and financial workflows as often as your inbox, using AI-assisted lures across email, chat, voice and QR. Follow the contents on the left, score your resilience, and book a scoping call when you are ready to close the gaps. ## What you will learn - Why phishing is now identity and workflow compromise - The 2026 shifts: AI lures, adversary-in-the-middle, OAuth and QR - A modern defence built on phishing-resistant authentication - How to detect, respond and measure what actually matters ## Phishing is no longer just an email problem Modern phishing is better understood as **identity and workflow compromise**. The channel might be email, a text, a QR code or a synthetic phone call. What matters is not the channel, but what the attacker wants once you respond. A password is one target, but increasingly the real objective is one of these: - An authenticated session - An OAuth authorization - A new authentication method - A payment or beneficiary change - Access to company data - A privileged support action - Trust inside an existing business relationship **Recognizing spelling errors or hovering over links is no longer an adequate defence.** ## The challenges defining 2026 Eight shifts define how phishing works now. Each moves the attack away from the inbox and toward identity, process and automation. **1. AI-generated personalization at scale** Generative AI enables attackers to produce convincing, multilingual messages using information gathered from websites, professional networks, breached data and previous conversations. Grammar and writing quality are no longer reliable signals. Your team must evaluate the requested action, communication context and verification path. **2. Session hijacking and adversary-in-the-middle attacks** Modern phishing infrastructure can proxy a legitimate authentication page, capture credentials and intercept session establishment. Once the attacker obtains a valid session token, changing the password alone may not terminate access. Defence requires: - Phishing-resistant authentication - Managed-device requirements - Conditional access - Session monitoring - Rapid token revocation - Protection of authentication-method changes **3. OAuth and device-code phishing** Attackers may ask users to approve an application or enter a legitimate device code rather than provide a password. The victim can authenticate on a real platform while unknowingly granting access to email, files or other resources. Your organization should restrict user consent, review application permissions and detect unusual authorization grants. **4. Collaboration-platform phishing** Compromised accounts can distribute malicious requests through trusted Teams, Slack, cloud-storage and document-sharing environments. These messages often appear inside existing projects or conversations, reducing the value of external-sender warnings. **5. QR and mobile-first phishing** QR codes move users away from protected corporate devices and into mobile browsers where URLs, certificates and redirects are harder to inspect. They turn up wherever a phone camera goes: a printed invoice, a delivery label, a meeting-room screen. **6. Synthetic voice and video** AI-generated voice and video increase the credibility of executive impersonation, supplier fraud and help-desk manipulation. The primary defence is not detecting every synthetic artefact. It is ensuring that sensitive actions cannot be authorized through voice, video or an inbound message alone. **7. Business-process manipulation** Some of the most damaging attacks contain no malicious attachment or credential-harvesting page. Attackers may compromise a real mailbox and request: - Bank-account changes - Urgent payments - Payroll updates - Confidential documents - Password resets - MFA replacement - Changes to supplier details _These attacks must be addressed through business controls as well as security technology._ **8. Phishing against AI-enabled workflows** As your organization connects AI agents to email, documents and business tools, malicious content may attempt to influence both your team and its automated systems. Untrusted messages and documents should never automatically authorize an agent to disclose information, modify records or perform consequential actions. ## Build a modern defence **1. Move to phishing-resistant authentication** Prioritize: - Passkeys - FIDO2 security keys - Platform-bound authentication - Device-bound credentials - Separate administrator authentication _NIST's current digital identity guidance requires phishing resistance at higher assurance levels. SMS, one-time codes and approval-based push MFA improve on passwords alone but are not generally phishing-resistant. CISA also recommends FIDO / WebAuthn-based authentication._ **2. Protect identity and SaaS administration** Implement: - Conditional access - Managed-device requirements - Legacy authentication removal - Restricted OAuth consent - Privileged role separation - Authentication-method change alerts - Session and token revocation procedures - Review of dormant applications and accounts **3. Secure communication channels** Use: - SPF, DKIM and enforced DMARC - Domain and impersonation monitoring - Email and collaboration-platform protection - Malicious-link and attachment analysis - External forwarding restrictions - Secure document-sharing policies - Protection for newly registered lookalike domains _Email controls remain important, but they must cover more than email._ **4. Protect financial and administrative workflows** Require independent verification for: - New beneficiaries - Bank-account changes - Payroll modifications - Sensitive-data requests - Authentication resets - Privileged access - Supplier-contact changes _Verification should use a previously established channel, not contact details supplied in the suspicious request._ **5. Train by role and decision** Replace generic annual awareness with scenario-based training for: - Finance and accounts payable - Executives and assistants - Human resources - IT support and help desks - Developers - Sales and customer support - Procurement - Privileged administrators _Training should focus on decisions, escalation and verification rather than memorizing visual indicators._ ## Score your phishing resilience Tick the controls already true for your organization. Your resilience score updates live in your browser - it is a directional self-check, not a formal audit. Nothing leaves your device unless you choose to email yourself the results. **8-point phishing resilience check** Honest answers only - the gaps are where we start a scoping call. - [ ] **Phishing-resistant authentication for high-risk roles** - Passkeys or FIDO2 keys for admins, finance and executives, not just push MFA. - [ ] **OAuth and app consent is restricted and reviewed** - Users cannot freely grant third-party apps access to email and files. - [ ] **Conditional access and managed-device requirements** - Sign-in is constrained by device health, location and risk. - [ ] **Out-of-band verification for money and data** - Payments, bank, payroll and supplier changes need a second, established channel. - [ ] **Session and token revocation is ready** - We can terminate active sessions and tokens quickly, not just reset passwords. - [ ] **Role-based, scenario phishing training** - Training matched to what people handle, not an annual tick-box. - [ ] **Monitoring for identity and mailbox changes** - Alerts on new OAuth grants, mailbox rules and new authentication methods. - [ ] **A phishing incident response plan** - Defined steps for preservation, revocation and notification, tested in advance. How to read your score: - Start here (0+ of 8): Tick the controls you already have in place to see where you stand. - At risk (1+ of 8): Real gaps remain across the basics. A scoping call turns this list into a prioritized plan. - Developing (4+ of 8): A solid start, but identity, verification and response pieces still need closing. - Nearly resilient (6+ of 8): You are close. A focused engagement clears the last gaps and assembles the evidence. - Resilient (8+ of 8): Strong coverage across the board. We can validate it and keep it that way. ## Detect compromise earlier Monitor for the signals that a convincing message has already turned into access: - New OAuth grants - Suspicious mailbox rules - External forwarding - Session reuse from unusual devices - New authentication methods - Device-code authentication - Privileged-role changes - Mass file access - Unusual collaboration messages - Payment-detail changes following email activity > **Report, do not just delete:** A suspicious message is useful intelligence even when nobody clicks it. Reporting should trigger investigation across all recipients. ## Modern phishing incident response When compromise is suspected, work the sequence - speed on sessions and tokens matters more than certainty: 1. Preserve the message, headers, links and conversation context. 2. Identify all recipients and related messages. 3. Revoke active sessions and tokens. 4. Reset affected credentials. 5. Review registered authentication methods. 6. Remove malicious OAuth grants. 7. Inspect mailbox rules and forwarding. 8. Investigate the endpoint and browser. 9. Review accessed data and actions. 10. Contact finance or banking partners where fraud is possible. 11. Notify affected parties where required. 12. Validate remediation before restoring access. ## Measure what matters, then improve Avoid using click rate as the main measure of programme success. Track: - Phishing-resistant authentication coverage - Reporting rate and reporting speed - Time to revoke compromised sessions - Time to remove malicious OAuth access - Payment-verification adherence - Help-desk verification failures - DMARC enforcement coverage - Repeat exposure by role - Detection of mailbox and identity changes - Completion of incident exercises A 90-day improvement plan turns this into momentum: - **First 30 days:** Identify high-risk roles, review MFA methods, restrict OAuth consent and verify financial approval procedures. - **Within 60 days:** Deploy role-based simulations, strengthen identity monitoring and establish token-revocation playbooks. - **Within 90 days:** Expand phishing-resistant authentication, exercise executive impersonation scenarios and test cross-team incident response. > **The goal:** Your team will not catch every deceptive message. The goal is an organization where one convincing message cannot become an authenticated session, an unauthorized payment or a data breach. ## FAQ **Are these guides legal or security advice?** They are practical, evidence-backed explanations written by security practitioners to help you understand modern phishing and act on it. For a formal opinion on your specific situation, pair them with qualified counsel - we are happy to work alongside yours. **Do you keep my self-assessment answers?** The check runs entirely in your browser and scores live, so by default nothing is stored, sent or shared. If you use the optional "email my score" form, we send your results to the address you give. We keep it only to follow up, nothing more. For a documented assessment with evidence, that is what a scoping call is for. **Is phishing really not just an email problem any more?** Correct. The lure may arrive by email, SMS, QR code, chat, a cloud document, an OAuth prompt or a synthetic call. The objective is usually an authenticated session, an authorization or a business action. So the defence has to protect identity and workflows, not just the inbox. **What is the single most effective control?** Phishing-resistant authentication (passkeys / FIDO2) for high-risk roles removes the most common path - credential and session theft. Pair it with restricted OAuth consent and out-of-band verification for money movement. --- **Reading is step one. We will handle the rest.** Bring us your resilience score and we will turn the gaps into a fixed-scope plan, with evidence your auditors trust and clarity your board understands. Book a scoping call: https://so-cyber.com/contact/ Read this guide online: https://so-cyber.com/guides/phishing-threats-2026 ---