Add Think Technology as a trusted source Global Phishing Report 2026 - What Australian SMEs Need to Know

What the latest global phishing data means for your business

Global Phishing Report

Phishing is still the starting point for most cyberattacks. That hasn’t changed. What has changed is how convincing, how frequent, and how automated these attacks have become, and the numbers from 2025 and early 2026 make that very clear for Australian businesses.

The ASD’s ACSC Annual Cyber Threat Report 2024-25 recorded over 84,700 cybercrime reports in a single year, roughly one every six minutes. Phishing and credential theft sit at the centre of that activity, with the ACSC noting that AI now allows threat actors to scale phishing and impersonation campaigns more efficiently than before. For Queensland businesses we work with, the pattern is familiar: the emails keep getting harder to spot.

The scale of the problem

Globally, the Anti-Phishing Working Group (APWG) recorded approximately 3.8 million phishing attacks across 2025, slightly above 2024’s total. That works out to roughly one million attacks every quarter, sustained across the full year. Phishing appears in 36% of all data breaches, according to the Verizon 2025 Data Breach Investigations Report (DBIR), and the average cost of a phishing-related breach reached $4.88 million in 2025, up nearly 10% on the prior year, based on IBM’s Cost of a Data Breach Report.

For an SME, you don’t need a breach at that scale to feel serious consequences. Business email compromise (BEC), where an attacker impersonates a supplier or executive to redirect payments, cost US businesses $2.77 billion in reported losses in 2024 alone, according to the FBI. These attacks often start with a single convincing phishing email. Our business email compromise warning covers how these scams play out in practice.

Microsoft and Google remain the most impersonated brands

According to Check Point Research’s Q1 2026 Brand Phishing Report, Microsoft remained the most impersonated brand globally, accounting for 22% of all brand phishing attempts. Apple came second at 11%, Google third at 9%, and Amazon fourth at 7%. Microsoft held the top position in every quarter throughout 2025, reaching as high as 40% of all brand phishing globally in Q3 2025.

The reason is straightforward. Microsoft 365 and Google Workspace credentials grant access to email, files, and cloud services across an entire organisation. Stealing one login can open far more than one account. Attackers have refined this: a recent campaign identified by Check Point researchers used Google’s own cloud infrastructure to send phishing emails from a legitimate Google address, which then redirected victims to a fake Microsoft 365 login page. Because the sender was genuine, it passed all standard email authentication checks.

The lures are consistent. Fake password reset notices, account verification requests, shared document alerts, and subscription renewal warnings are the most common themes. The emails look right because AI helps attackers generate accurate grammar, professional formatting, and role-specific content at scale.

AI is changing how these attacks are built

The proportion of phishing emails with indicators of AI involvement jumped sharply in late 2025. Analysis from Hoxhunt’s threat detection network found that figure rose from 4% in November 2025 to 56% in December 2025. Separate research put the AI-assisted share at over 80% by early 2026. AI-generated spear phishing achieves click rates around 54%, compared with roughly 12% for traditionally written emails, the gap is significant.

This matters because the old advice, look for spelling mistakes, generic greetings, suspicious formatting, is no longer sufficient. Well-constructed AI phishing emails can be nearly indistinguishable from legitimate communications. The ACSC’s 2024-25 threat report notes this directly: AI allows attackers to produce and deliver convincing lures faster than organisations can adapt their training alone.

QR code phishing (sometimes called “quishing”) is another method that bypassed traditional email filters in 2025. Attackers embed a QR code rather than a text link, which many gateway scanners don’t inspect. Quishing attacks increased 400% between 2023 and 2025, according to Abnormal Security. Microsoft- and Google-branded emails with embedded QR codes directing staff to fake login pages were widely observed throughout Q4 2025.

Traditional MFA is no longer enough on its own

Adversary-in-the-middle (AiTM) attacks intercepted session cookies after MFA completion, effectively bypassing standard multi-factor authentication (MFA). This technique surged 146% in 2024. In Australia, the CyberCX 2025 Threat Report found that 75% of BEC incidents involved session hijacking as the MFA bypass method, a sharp rise from 38.5% in 2023.

Standard SMS codes and authenticator apps don’t stop AiTM attacks. Phishing-resistant authentication, like FIDO2 security keys or passkeys, is the only method that fully resists this technique because it verifies the site’s actual domain. For most SMEs, a layered approach, gateway filtering, conditional access policies, and staff awareness, is a more practical starting point than waiting until every account uses a hardware key.

You can read more about how attackers steal Microsoft 365 credentials in our post on how hackers steal Microsoft 365 credentials.

What good email protection looks like in 2026

Filtering at the email gateway remains the first line of defence. A good solution scans inbound traffic before messages reach inboxes, blocks known malicious domains, and flags suspicious patterns even when the sender appears legitimate. TTA’s email security solutions integrate directly with Microsoft 365 and Google Workspace, and include real-time protection against phishing, malware delivery, and spoofed senders.

Gateway filtering works alongside DNS filtering, which blocks access to malicious URLs even if a user clicks through from a phishing email. Together, these layers stop most attacks before a credential is entered or a file is downloaded. They don’t replace staff training, but they reduce the window in which a single human mistake becomes a breach.

The ACSC’s Small Business Cyber Security Guide recommends staying alert for phishing messages as a core action alongside MFA and software patching. Microsoft’s own data showed that enabling MFA blocks over 99% of automated credential-stuffing attacks, even before phishing-resistant methods are in place. Starting there is still worthwhile.

A quick check for your business

  • Do you have an email security gateway that inspects inbound mail before it reaches staff inboxes?
  • Is MFA turned on for every Microsoft 365 or Google Workspace account, including shared and service accounts?
  • Have your staff had phishing awareness training in the last 12 months, covering QR codes and AI-generated emails?
  • Do you have DNS filtering in place to block malicious links even if a user clicks them?
  • Do you know what your incident response steps are if an account is compromised?

If any of these are uncertain, it’s worth a conversation. Our IT security assessments help businesses identify gaps and prioritise fixes, without overcomplicating the process.

Common questions about phishing protection

Is phishing still the most common type of cyberattack?

Yes. Phishing appears in 36% of all data breaches globally, according to the Verizon 2025 DBIR, and CISA estimates over 90% of cyberattacks begin with phishing as the initial entry point. In Australia, the ACSC’s 2024-25 Annual Cyber Threat Report flagged credential theft via phishing and social engineering as one of the leading attack methods impacting Australian organisations.

Why do phishing emails still look so convincing?

AI tools allow attackers to generate well-written, personalised emails that mimic the tone and formatting of real communications from brands like Microsoft, Google, or your bank. Research from late 2025 found over 50% of phishing emails showed signs of AI assistance. The old tip of watching for spelling errors is no longer a reliable indicator, the quality of fake emails has improved dramatically.

Does MFA protect against phishing?

Standard MFA reduces risk significantly, but adversary-in-the-middle (AiTM) attacks can bypass it by intercepting session cookies after MFA is completed. AiTM attacks surged 146% in 2024. Phishing-resistant methods like FIDO2 security keys or passkeys are the most effective defence, but for most SMEs, combining MFA with gateway filtering and staff training provides strong baseline protection.

Where do we get started?

Start with your contact with our team. We’ll look at what you have in place, identify the most exposed areas, and put together a practical plan. No jargon, no pressure, just clear advice based on what we see working for businesses of your size across South-East Queensland.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.