started · updated
Cybersecurity trends show evolving phishing tactics and training effectiveness
Cybercriminals are evolving their tactics to bypass traditional security measures through advanced social engineering. New methods include targeting digital corporate calendars via malicious invitations and ICS files. These calendar-based attacks exploit the inherent trust users place in scheduling tools, often bypassing email filters because calendar entries are frequently viewed as harmless.
Another emerging trend involves phishing campaigns that eschew malicious links or malware entirely. Instead, attackers use emails to prompt victims to call a specific phone number. Once on the call, criminals use psychological manipulation to extract sensitive information, a method that renders standard antivirus and link-scanning software ineffective.
Despite these evolving threats, a study titled ‘Phishing by Industry Benchmarking Report 2026’ indicates that consistent security awareness training can significantly mitigate risk. Analyzing 42 million simulations across 64,000 companies, the report found that employee susceptibility to phishing can drop by 83 percent after one year of continuous training. In Europe, the average ‘Phish-Prone Percentage’ fell from 31.1 percent to 5.4 percent following a year of security education.