Phishing gets smarter, not louder: Inside Zscaler’s 2026 threat report

Phishing emails are down. Phishing damage is up. That’s the uncomfortable finding at the heart of the ThreatLabz 2026 Phishing and Initial Access Report from Zscaler, which tracked attacker behaviour across its global security cloud through 2025 and into early 2026.

Fewer lures, bigger payoffs

After peaking at over 2 billion hits in 2023, phishing volume on the Zscaler cloud fell nearly 20% year-over-year in both 2024 and 2025. That’s not attackers retreating; it’s them getting smarter. Stronger email filters and identity defences have pushed criminals away from mass spam and toward fewer, sharper attacks that mimic real business workflows. The Services sector saw a 65.5% jump in attacks, and Government rose 50%, as scammers exploited routine trust in billing, renewals, and public communications.

AI is the new phishing factory

Artificial intelligence has quietly become the industry’s most efficient con artist. ThreatLabz identified over 413,000 AI-generated websites, with roughly 9% flagged as malicious, many of which were built using mainstream “text-to-site” tools like Manus AI, Blackbox AI, and Lovable. What once required a developer and days of work can now be produced with a single prompt in under an hour, allowing attackers to spin up convincing brand clones from fake Coinbase wallets to counterfeit government portals almost instantly.

Hiding in plain sight

Perhaps the most striking figure: 95.2% of all phishing activity in 2025 moved through encrypted (HTTPS) channels, up from 87% for malicious traffic overall. This means the moment of compromise increasingly happens quietly inside a browser session, not in an inbox, making it invisible to security tools that don’t inspect encrypted traffic.

MFA no longer a safety net

The report details phishing kits like BlackForce, which combine real-time credential theft with the ability to intercept one-time MFA codes as victims type them, turning a simple phishing click into a full account takeover within seconds, even when multi-factor authentication is enabled.

Reconnaissance before the strike

Long before an attack lands, adversaries are scouting. ThreatLabz’s decoy network recorded 89.9 million hostile interactions from 1.37 million unique attacker IPs across 520 customer environments in just six months. Manufacturing, financial services, and banking absorbed more than half of this activity, with attackers scanning for exposed logins, VPNs, and collaboration platforms they can exploit for entry.

What this means for 2026

Zscaler’s predictions for the year ahead read like a warning label: AI agents phishing other AI agents, deepfake voice and video replacing traditional social engineering, and phishing evolving into persistent, multi-channel campaigns that blend email, SMS, and messaging apps into one coordinated con.

The core message for security leaders is simple: phishing volume is no longer a proxy for phishing risk. As attacks grow quieter, faster, and more convincing, defences built solely on inbox filtering are no longer enough. The action needs to shift toward visibility into encrypted traffic, identity verification, and catching attackers during reconnaissance before the first click ever happens.

Author