Sam's News — email-security — 2026-08-20¶
Security¶
8 Phishing 3.0: AI-Driven Agent-Versus-Agent Email Attacks Emerge¶
AI-driven 'Phishing 3.0' attacks now feature agentic AI systems that autonomously research targets, compose personalized messages, and adapt campaigns across email, collaboration tools, and live calls. Traditional email defenses from a decade ago are increasingly ineffective. Microsoft tracked phishing platforms generating tens of millions of messages monthly, while a documented case at engineering firm Arup involved a deepfake video call that convinced an employee to approve approximately $25 million in transfers.
- Agentic AI performs reconnaissance in seconds (previously manual)
- Microsoft tracked platforms generating tens of millions of messages monthly
- 48% of security professionals ranked agentic AI as top attack vector (2026 Dark Reading poll)
- Documented case: deepfake CFO impersonation at Arup, ~$25 million transfer approved
- Three phishing evolution stages: 1.0 (payloads), 2.0 (socially engineered), 3.0 (AI + deepfakes)
Sources: The Hacker News AI Web Searched
8 NSA Alerts Zimbra Users of Russian State-Sponsored Phishing Campaign¶
The NSA and partners issued a cybersecurity advisory warning Zimbra Collaboration Suite users of a Russian state-sponsored phishing operation.
Sources: National Security Agency (NSA) (.gov) Web Search, National Security Agency (NSA) (.gov) Web Search, National Security Agency (NSA) (.gov) Web Search Update to: NSA Alerts on Russian State-Sponsored Phishing Campaign Targeting Zimbra Users
7.5 QR-Code Phishing (Quishing) Bypasses Corporate Email Defenses¶
QR-code-based phishing attacks (quishing) have become a popular alternative to traditional email phishing and can evade corporate security measures.
- Malicious QR codes were embedded in 11% of phishing emails in H1 2026
- Quishing bypasses email filters because URLs are encoded visually rather than as readable text
- QR codes redirect victims from protected corporate environments to personal mobile devices with fewer security controls
- Attackers often combine quishing with trusted brand impersonation and urgency tactics to increase success rates
Sources: WeLiveSecurity Web Search Update to: QR-Code Phishing (Quishing) Embedded in 11% of Phishing Emails in H1 2026
7.5 Business Email Compromise Prediction: Detecting Compromised Credentials Before BEC Attacks¶
Group-IB uses threat intelligence to detect compromised credentials before they are used in business email compromise attacks.
Sources: Group-IB Web Search, Group-IB Web Search, Group-IB Web Search, Group-IB Web Search Update to: Business email compromise detection predicts attacks through compromised credentials analysis
7.5 Microsoft Warns of Multistage Phishing Campaign Targeting Healthcare Organizations¶
Microsoft Threat Intelligence warned of a large-scale phishing campaign reaching over 35,000 users across 13,000 organizations, with healthcare the most targeted sector. Attackers used credential-theft emails and adversary-in-the-middle techniques to intercept authentication tokens and bypass multifactor authentication.
- Campaign reached 35,000+ users across 13,000+ organizations, primarily in U.S.
- Healthcare industry most heavily targeted sector
- Attackers bypassed multifactor authentication using token interception techniques
- Microsoft recommended phishing-resistant MFA, email security controls, and awareness training
Sources: American Hospital Association AI Web Searched
7 Identifying Modern Phishing Scams: Generative AI's Impact on Email Attacks¶
Criminals increasingly use generative AI to create linguistically sophisticated phishing emails nearly indistinguishable from legitimate messages. Modern attacks employ sophisticated technical tricks including exploitation of Microsoft's OAuth Device Authorization Grant (OAuth device code flow) to bypass two-factor authentication, targeting login credentials, session tokens, and personal information.
- Generative AI creates professionally styled phishing emails with legitimate-looking design
- Attacks exploit Microsoft OAuth device code flow to bypass 2FA
- Bypass targets legitimate device sign-in procedure without browser requirement
- Modern attacks significantly more sophisticated than earlier phishing with poor grammar/design
Sources: PCWorld AI Web Searched
7 Security Awareness Training Significantly Reduces Phishing Attack Success Rates¶
Studies show that human error is the critical vulnerability in 95% of breaches, and targeted security awareness training significantly reduces phishing susceptibility.
Sources: EdTech Magazine Web Search, EdTech Magazine Web Search, EdTech Magazine Web Search, EdTech Magazine Web Search Update to: Security Awareness Training Significantly Reduces Phishing Success Rates
7 Phishing and BEC Attacks Exploiting Amazon SES Cloud Email Service¶
A new phishing scheme leverages Amazon SES cloud email service to distribute malicious messages at scale.
- Attacks exploit Amazon SES cloud email service for phishing and BEC
- Attackers compromise or create SES accounts for distribution
- Messages bypass security filters due to trust in Amazon infrastructure
- Research published May 2026 by Kaspersky
Sources: Kaspersky Securelist AI Web Searched, Securelist Web Search, Securelist Web Search, Securelist Web Search
7 Ethereum user loses 810 ETH in Tornado Cash phishing attack via fake site¶
An Ethereum user lost 810 ETH (approximately $1.86 million) in a phishing attack that directed them to a counterfeit Tornado Cash website.
Sources: Pluang RSS, Crypto News RSS, Cryptonews.net RSS, The Cryptonomist RSS
7 Operation Asterix phishing campaign targets 885,000 phone numbers including Binance users¶
A phishing campaign dubbed Operation Asterix has targeted 885,000 phone numbers with a focus on cryptocurrency exchange users.
Sources: bloomingbit RSS, Bitcoin World RSS