“This time it’s personal” was the tagline for Jaws: The Revenge – a film that, despite failing to make much of a splash with critics or audiences, introduced a different kind of threat. This wasn’t a shark randomly attacking unsuspecting swimmers. It was portrayed as hunting a specific family.
Nearly forty years later, the same phrase perfectly captures the evolution of one of cyber security’s oldest threats. Phishing hasn’t simply become more common. It’s become personal.
According to Cisco Talos’ latest Incident Response Trends report, covering March to June 2026, phishing accounted for the initial attack vector in just over half of all incidents investigated. That statistic alone should concern every boardroom. But the real story isn’t the volume of attacks. It’s that the nature of phishing has fundamentally changed.
For years, organisations have trained employees to spot the warning signs: poor spelling, awkward grammar, suspicious email addresses and implausible requests. It was sensible advice because those were the hallmarks of traditional phishing campaigns.
Today, many of those tell-tale signs have disappeared.
Artificial intelligence has transformed phishing from a numbers game into a precision weapon. Instead of blasting millions of generic emails across the internet and hoping that someone clicks, attackers can now research individuals, understand their roles, mimic writing styles, reference current projects and maintain convincing conversations over multiple exchanges.
The objective is no longer simply persuading someone to click a malicious link. It’s earning just enough trust for the victim to complete the attack themselves.
In many respects, cybercriminals have embraced personalisation faster than many marketing departments. That’s why calling these attacks “phishing” almost feels inadequate. The label remains the same, but almost everything beneath it has changed.
We’re already seeing the consequences.
A recent phishing campaign targeting Havas UK used fake recruitment communications sophisticated enough to prompt a public warning from the company’s Chief People Officer, who observed that these scams are becoming increasingly difficult to distinguish from legitimate approaches.
In the cryptocurrency world, one investor reportedly lost around 400,000 XRP after responding to what appeared to be a routine software update for a hardware wallet. The email looked genuine. The branding was convincing. The timing made sense. Believing he was carrying out a normal security update, he inadvertently handed attackers everything they needed.
Neither victim fell for an obvious scam. They trusted something that looked entirely legitimate.
Business users face an even broader range of threats.
Researchers have recently uncovered phishing toolkits targeting Microsoft 365 users that exploit legitimate authentication processes rather than simply stealing usernames and passwords. By abusing OAuth device authorisation, attackers can register trusted devices against corporate accounts, effectively working around traditional multi-factor authentication.
Meanwhile, the UK’s National Cyber Security Centre has warned of a Russian state-supported campaign using so-called “zero-click” techniques against vulnerable email platforms. In these cases, users don’t even have to click a malicious link or open an attachment. Simply viewing a specially crafted email can be enough to compromise an account.
The lesson is clear. Technology controls remain essential, but they are no longer sufficient on their own.
This shift is also reflected in the brands criminals choose to impersonate. Microsoft continues to dominate phishing campaigns, while Google, Apple, Amazon and LinkedIn remain among the most frequently copied organisations. More tellingly, ChatGPT has now entered the list of the world’s most impersonated brands, with attackers sending convincing subscription payment emails designed to harvest payment details.
As AI platforms become part of everyday business life, they become trusted brands. And trusted brands become valuable disguises.
For business leaders, this represents a significant challenge. The traditional approach to awareness training assumed employees could learn to recognise obviously suspicious messages. But what happens when the email is perfectly written? When it references yesterday’s meeting? When it comes from what appears to be a trusted supplier? When the conversation continues naturally after the first reply?
The human remains the preferred attack vector because trust remains the easiest way into almost every organisation.
That doesn’t mean awareness training has become obsolete. Far from it. But it does mean it needs to evolve. Annual compliance exercises and simplistic phishing simulations are no longer enough. Employees need to understand how modern social engineering works across email, collaboration platforms, messaging applications and even voice calls. They should be encouraged to verify unexpected requests, challenge unusual instructions and feel confident picking up the phone to confirm a payment request or access approval.
Alongside that, organisations must continue investing in modern email security, identity protection, behavioural analytics, conditional access policies and rapid threat detection. Cyber resilience today depends on combining intelligent technology with informed people.
Ultimately, phishing is no longer just an email problem. It’s a trust problem.
For years we’ve taught employees how to recognise the shark circling in the water.
In 2026, the danger is very different. The shark already knows your name, your job title, your colleagues and the projects you’re working on. It knows which brands you trust and how you communicate.
This time, it really is personal.
If you would like to explore how organisational culture, human behaviour and practical security measures can work together to reduce phishing and social engineering risk, please get in touch with us.
——————————————————————————————————————–
Image of Great White Shark by PixelLabs from Pixabay
If you found this article of interest, please don’t forget to sign up for our NEWSLETTER for the latest industry news and insights delivered direct to your mailbox.
