Organizations across industries are facing a surge in email-based attacks, with phishing, impersonation, and account takeover attempts driving a significant increase in breaches. Attackers are leveraging email as the primary entry point, with malware delivered via email rising by over 130% year-over-year and scams and phishing incidents also seeing substantial growth. The manufacturing, retail, and healthcare sectors are particularly targeted, with attackers exploiting outdated systems and user behavior to bypass security controls, resulting in business disruption, data loss, and financial fraud.
At the same time, advancements in AI-driven technologies such as voice cloning are making social engineering attacks even more effective. Red teaming exercises have demonstrated that AI-enabled deepfakes can convincingly impersonate employees, tricking help desks into resetting credentials and granting unauthorized access. These sophisticated vishing attacks highlight the urgent need for organizations to test their defenses against both traditional and emerging social engineering techniques, and to educate staff on recognizing and responding to these evolving threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Security reporting highlighted that AI-generated content was making phishing and business email compromise messages more convincing and more difficult for employees to identify. It also noted that only about 1% of malicious emails now deliver malware, underscoring a shift toward social-engineering-heavy attacks.
Attackers increasingly used response-based social engineering tactics such as callback phishing while traditional link-based phishing declined. Vendor email compromise also grew, with attackers attempting to steal more than $300 million over the year.
Reporting indicates manufacturing was the most targeted industry for email-based attacks, followed by retail and healthcare. The same reporting notes healthcare's outdated systems and weak security practices as factors worsening exposure.
A reported 78% of organizations experienced an email breach in the previous 12 months, with phishing, impersonation, and account takeover cited as the most common attack types. These incidents often led to follow-on impacts such as ransomware infections or data loss.
TechTarget published a case study on a real-world AI voice-cloning attack framed as a red-teaming exercise. No additional dated incident details were provided in the reference content.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.