Phishing in 2026: the new tactics targeting small businesses

Tobava Security Team · · 6 min read
← All articles

The advice most people carry — look for bad spelling, be suspicious of odd phrasing — was built for phishing that no longer exists. Here's what's actually changed, and which signals still hold.

What generative AI changed

Poor grammar was never inherently part of phishing. It was an artefact of attackers writing in a second language, and it doubled as a filter: recipients who didn't notice obvious errors were likelier to fall for the rest.

That artefact is gone. Modern phishing is fluent, correctly formatted, and contextually appropriate. Three things followed:

1. Volume with personalisation. Previously, attackers chose between mass generic campaigns and slow, hand-crafted targeted ones. Now a scraped LinkedIn profile produces a personalised message referencing your actual role, colleagues and projects — at scale.

2. Style mimicry. Given a handful of a person's real emails — from a breach, a compromised mailbox, or public correspondence — a model reproduces their tone, sign-off and habits convincingly.

3. Voice and video. Deepfaked voice calls "confirming" an email request have moved from research demo to reported incidents. The callback verification step many businesses relied on now needs a known-good number, not one supplied in the request.

The red flags that still work

Content-based detection is weaker now. Structural signals still hold:

What actually protects a small team

Verification rules that don't depend on judgment. "Bank detail changes require a phone call to a number already on file" works when someone is tired and busy. "Be careful with suspicious emails" doesn't. See business email compromise for the full set.

MFA on every account. Phishing that captures a password gets far less if a second factor is required — and passkeys defeat credential phishing outright, since the credential won't work on a lookalike domain.

External sender banners. A visible marker on mail from outside your domain makes display-name spoofing obvious immediately.

SPF, DKIM and DMARC at enforcement. These stop attackers spoofing *your exact domain*, which protects your customers and suppliers from messages that appear to come from you. Setup guide here.

A no-blame reporting culture. The worst outcome is someone clicking, realising, and staying silent for six hours out of embarrassment. Early reporting is the difference between an incident and a disaster — so make reporting a mistake explicitly consequence-free, and mean it.

Training that works

Annual slide decks don't change behaviour. What does:

If someone clicks

  1. Disconnect the device from the network if credentials or a download were involved
  2. Change the password immediately, from a different device
  3. Terminate active sessions on the account
  4. Check forwarding rules and connected apps — the most commonly missed step
  5. Tell everyone else what the attempt looked like; the same message is usually sitting in other inboxes
  6. If money moved, call the bank immediately. Speed determines whether recall is possible

Try Tobava Mail free

Encrypted email, a private inbox, and a full workspace — built by a cybersecurity company. No ads, no tracking, no message scanning.

Create your free account