Phishing Evolves Beyond Grammar and URLs, Threatening Business Security
Sophisticated phishing attacks are increasingly bypassing traditional detection methods by leveraging AI, QR codes, and token theft, necessitating advanced containment strategies for businesses.

Phishing attacks are no longer easily identifiable by poor grammar or suspicious URLs, as modern social engineering schemes are meticulously designed to withstand scrutiny and appear legitimate. Attackers are leveraging advanced techniques to subvert standard security measures, reaching employees during active workflows when they are more susceptible to believing requests. This evolution demands a shift in focus from simple detection to rapid containment and response.
The cybercrime-as-a-service economy has democratized access to sophisticated phishing kits, while the proliferation of AI has drastically reduced the time and effort required for target research and message tailoring. AI tools can now generate polished, contextually appropriate lures for individual recipients, making traditional language-based detection obsolete. Furthermore, attackers are employing AI to build rapport with targets before launching their attacks, further increasing the deception.
One significant development is the use of QR codes in phishing campaigns. By embedding malicious links within QR codes, attackers circumvent the ability for users to hover over URLs to inspect them. This 'device hop' from a scanned QR code on a mobile device to a potential target on a corporate network also complicates tracking and attribution. ESET telemetry indicated that QR code phishing accounted for one in nine detected phishing emails in the first half of 2026, highlighting its growing prevalence.
Beyond QR codes, attackers are bypassing traditional login page defenses. Techniques like ConsentFix trick victims into navigating through legitimate, compromised websites and real authentication flows, ultimately leading to the extraction of authentication tokens rather than passwords. This method is particularly effective against users with active sessions, as it bypasses multi-factor authentication (MFA) prompts. Similarly, social engineering tricks like ClickFix and its variants, such as AI-fix, prompt users to execute malicious commands directly in their terminals.
Even the use of deepfake audio and video is becoming a concern. Lifelike synthetic media can be used to impersonate senior colleagues or trusted individuals, potentially leading employees to authorize fraudulent transactions. While older deepfakes might have detectable flaws, even imperfect imitations can be convincing when presented within a plausible work context, as demonstrated by a case where a finance employee made significant wire transfers after a call with deepfake versions of senior management.
While security awareness training remains a vital component of defense, it is no longer sufficient on its own. The effectiveness of such training is diminished when attacks are designed to anticipate learned employee behaviors. The true measure of resilience lies not just in preventing the initial click, but in the robustness of preventive controls and the speed with which an organization can detect and contain any subsequent malicious activity.
ESET's research also indicates that employees often recognize phishing attempts but fail to report them due to a lack of clear reporting channels. This missed opportunity prevents organizations from learning about new attack vectors and potentially identifying larger, ongoing campaigns. Proactive threat intelligence and robust incident response capabilities are therefore critical to mitigating the evolving landscape of email-borne threats.