Phishing used to be easy to laugh off. A poorly worded email, a mismatched logo, an obvious spelling mistake gave the game away. That version of phishing is gone. In 2026, phishing is AI-written, sometimes voice-cloned, and increasingly delivered through a QR code rather than a link. It remains the single most common way attackers get into Australian businesses, and it now sits upstream of most ransomware incidents, business email compromise and executive fraud.
For CIOs and CTOs running IT and security for a 50 to 1,000 person organisation, phishing is no longer a once-a-year training topic. It is a board-level risk, and the controls that stopped it five years ago are no longer enough on their own.
Why phishing is still the way in
The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) responded to more than 1,200 cyber security incidents in the 2024–25 financial year, an 11 per cent increase on the year before. The average self-reported cost per incident for businesses rose 50 per cent to $80,850, and large organisations reported an average of $202,691 per incident.
Email is central to most of that activity. Business email compromise accounted for 15 per cent of all business-related cybercrime reported to ASD’s ACSC, and email compromise without a direct financial loss made up a further 19 per cent. Put together, roughly one in three business cybercrime reports in Australia starts with a compromised or spoofed email.
The National Anti-Scam Centre’s data tells a similar story from the consumer and small-business side. Phishing was the most reported scam type to Scamwatch in 2025, with 65,361 reports, and it has held that position into 2026, with 13,428 phishing reports in the first quarter alone and email remaining the most commonly reported point of contact.
AI has changed the economics, not just the writing
Grammar and formatting used to be reliable warning signs. They are not anymore. Multiple security vendors now estimate that somewhere between 70 and 83 per cent of phishing emails show signs of AI generation, a figure that has climbed sharply since 2023. Controlled studies of AI-written spear phishing have found it can match the success rate of an experienced human social engineer at a fraction of the cost, and generic AI phishing kits are reportedly available to criminals for as little as $75.
This is a deliberate deep dive into phishing specifically. For broader coverage of how AI is reshaping ransomware, identity attacks and Shadow AI risk across the business, see KMT’s guide to Top Cyber Security Trends and Statistics.
Four channels, one playbook
Phishing is no longer just email. Attackers now run the same core playbook, impersonate a trusted identity, create urgency, and push the target to act before they think, across four channels. A CIO’s defensive strategy needs to cover all four.
1. Email phishing
Still the highest-volume channel, and still evolving. Malicious links have overtaken attachments as the preferred delivery method, since attachments are more likely to trigger security scanning. AI personalisation now allows attackers to reference real projects, colleagues and writing styles, which is why generic staff training on spotting ‘bad English’ is losing effectiveness.
2. Vishing and deepfake CEO fraud
Voice cloning now requires as little as three seconds of audio, easily sourced from a podcast appearance, a webinar recording or a earnings call. Industry reporting has tracked a sharp rise in deepfake-enabled voice fraud attempts through 2025 and into 2026, and the FBI has classified it as one of the fastest-growing high-value fraud categories facing businesses.
The publicised 2024 case of engineering firm Arup, where a finance employee authorised a USD 25 million transfer after a video call with what turned out to be entirely fabricated executives, illustrates the ceiling on losses when this attack succeeds. Finance teams, payroll and executive assistants are the primary targets, because they are the people who can action a payment or change a bank detail directly.
3. Smishing
SMS-based phishing, typically impersonating banks, delivery companies or government agencies. National Anti-Scam Centre data shows reported SMS scam contacts fell from 77,365 in 2024 to 29,058 in 2025, which likely reflects a shift in attacker effort toward other channels rather than a genuine reduction in risk.
4. Quishing (QR code phishing)
The newest of the four, and the fastest-growing. Threat intelligence providers recorded triple-digit percentage growth in QR-based phishing through the first half of 2026. Quishing works because the destination address is hidden inside an image rather than written as text, so it bypasses the link-scanning most email security tools rely on, and it typically completes on a personal mobile phone, outside corporate device management. Some industry data suggests smaller organisations see disproportionately more QR-based attacks than large enterprises, on the assumption that mobile devices are less tightly managed.
Business email compromise: the expensive outcome
Business email compromise (BEC) is frequently the goal that email and voice phishing are building toward. It does not require malware, just a convincing enough message and a gap in payment verification. As the Australian data above shows, BEC and email compromise together account for around a third of business cybercrime reports, and losses scale with the size of the payment an attacker can convince someone to redirect.
The common thread in successful BEC cases is a single point of failure: one person, one channel, one moment of urgency, with no second channel required to confirm before money moves.
Also of interest: The 5 Types of Business Email Compromise
Why awareness training alone is no longer enough
Security awareness training still matters, but its limits are now well documented. Each additional round of phishing simulation training tends to reduce click rates by only around 5 per cent relative to the last round, and a portion of staff remain repeat clickers regardless of how much training they receive. Combined with AI-written lures that are increasingly indistinguishable from genuine correspondence, this means training has to be paired with technical controls that assume someone, eventually, will click.
The one control that neutralises most credential phishing
Phishing-resistant multi-factor authentication, delivered through FIDO2 security keys or passkeys, is the single highest-leverage technical control available today. In plain terms, the login process is cryptographically tied to the real website address, so even if a user is fooled into visiting a fake login page, the fake page cannot capture anything usable.
Microsoft’s own reporting and US CISA guidance both put the effectiveness of phishing-resistant MFA at blocking more than 99 per cent of identity-based attacks, even when an attacker already holds a valid username and password. SMS codes and app push approvals are considerably better than no MFA at all, but both can still be intercepted or approved under pressure, commonly referred to as MFA fatigue. Adoption of true phishing-resistant methods remains low industry-wide, with recent reporting putting it in the range of 10 to 15 per cent of users, which means most organisations are still exposed on their most sensitive accounts.
Practical priority: roll phishing-resistant MFA out to finance, IT administration and executive accounts first, then expand across the organisation.
A practical checklist for CIOs and CTOs
- Deploy phishing-resistant MFA (FIDO2 keys or passkeys) for finance, IT admin and executive accounts first, then expand to the rest of the business.
- Put a verbal, out-of-band verification step in front of any payment change or urgent fund transfer request, regardless of how convincing the request looks or which channel it arrives through.
- Treat QR codes with the same suspicion as unknown links. Scan on a managed device where possible, and check the destination before entering any credentials.
- Enforce email authentication (SPF, DKIM and DMARC) to make domain spoofing harder and improve legitimate email deliverability.
- Keep phishing simulations running, but refresh the content regularly. Old-style, typo-laden test emails no longer reflect what staff will actually face.
- Assume some phishing attempts will get through, and pair prevention with 24/7 monitoring and response so a single click does not automatically become a breach.
Spotting phishing in 2026
Grammar is no longer a reliable warning sign. The more useful indicators are structural, and apply across all four channels:
- Unusual urgency around money, credentials or access, regardless of how well the message is written.
- Any request to change bank details, payment destinations or approvals, especially arriving outside normal hours or through an unusual channel.
- A sender name that looks right but an email address, phone number or domain that does not quite match on closer inspection.
- A phone or video call requesting something a finance or IT process should never approve on a single channel.
- A QR code from an unexpected source, or one that appears to have been added to a document, poster or invoice that people normally scan without a second thought.
- Pressure to bypass a normal approval step ‘just this once’.
If you suspect a phishing attempt
Report it internally immediately, and do not click, scan or reply. Verify any financial or credential request through a separate, already-known channel before acting on it, such as calling a colleague on a known number rather than the number provided in the message. Businesses can also report phishing and cybercrime to ASD’s ACSC through ReportCyber, and consumer-facing scams to the National Anti-Scam Centre’s Scamwatch service.
How KMT can help
Preventing phishing from becoming a breach takes more than staff awareness. It takes layered technical controls, 24/7 monitoring, and a partner who treats security as the foundation rather than an add-on. KMTech’s Managed Security Service Provider offering combines identity protection, email security and continuous monitoring to catch what training alone will miss.
For a view of where your organisation currently stands, book a Cyber Risk Assessment, which includes your Essential Eight maturity and phishing exposure, with no obligation.
If you would like more information on KMT’s Dark Web Monitoring service or Managed Cyber Security offering, please contact us.
Frequently asked questions
What is phishing and how has it changed in 2026?
Phishing is a social engineering attack that tricks people into handing over sensitive information or installing malware, usually by impersonating a trusted person or organisation. In 2026, most phishing content is written or assisted by AI, and the attack now spans email, phone calls, text messages and QR codes rather than email alone.
Why is phishing still successful when spam filters are so advanced?
Modern phishing increasingly targets people rather than technical filters. AI-written messages are personalised and grammatically clean, QR codes hide the destination address from link scanners, and voice cloning bypasses email security entirely by moving the attack to a phone or video call.
What is quishing?
Quishing is QR code phishing. Attackers embed a malicious web address inside a QR code rather than as plain text, which allows it to bypass many email security filters. The code is typically scanned on a personal mobile phone, which is often outside corporate device management.
How does deepfake voice fraud target businesses?
Attackers clone an executive’s voice from publicly available audio, sometimes with as little as three seconds of a sample, then call or video call finance or payroll staff to authorise a payment or change bank details. It succeeds by exploiting trust in a familiar voice rather than any technical vulnerability.
Does multi-factor authentication stop phishing?
Standard MFA helps but is not phishing-proof. SMS codes and app push approvals can still be intercepted or approved under pressure. Phishing-resistant MFA, using FIDO2 security keys or passkeys, is reported to block more than 99 per cent of identity-based attacks, even when an attacker already has the correct password.
What should staff do if they suspect a phishing email, call or QR code?
Do not click, scan or reply. Report it internally straight away, and verify any request involving money, credentials or access through a separate channel that is already known to be genuine, rather than any contact details supplied in the suspicious message.
How often should staff receive phishing awareness training?
Ongoing rather than annual. Training content needs regular refreshing to reflect current tactics such as AI-written lures, deepfake voice calls and QR codes, and should be paired with technical controls such as phishing-resistant MFA, since training alone reduces but does not eliminate risk.
Last updated:




