Phishing Attack News: AI-Powered Campaigns and Device-Code Fraud Surge in 2026

Phishing attack news in 2026 is dominated by a single overriding trend: artificial intelligence has industrialized phishing at a scale and speed that fundamentally changes the threat. What previously required skilled social engineers to craft convincing lures can now be produced at volume by automated platforms. The result is a 1,380% increase in device-code phishing attacks in the first four months of 2026 compared to the second half of 2025, combined with AI-generated campaigns that now account for roughly half of all observed phishing activity.

Device-Code Phishing: From Espionage Tool to Criminal Commodity

Huntress researchers documented a 1,380% surge in device-code phishing attacks between January and April 2026 compared to H2 2025. Device-code phishing exploits the OAuth 2.0 device authorization flow, which is designed for authenticating devices without keyboards, such as smart TVs. Attackers generate a legitimate device code through a real identity provider, then trick victims into entering it on a phishing page. Because the code comes from a legitimate authorization endpoint, it bypasses many anti-phishing filters.

What began as an espionage-grade technique used by nation-state actors has become a criminal commodity. Researchers identified 18 distinct device-code phishing kits in active use, with a 37x spike in detections within the tracking period. The democratization of this technique means that criminal groups without sophisticated technical capabilities can now deploy it at scale using off-the-shelf infrastructure.

AI-Generated Phishing: 14x Surge Since December

Since December 2025, AI-generated phishing campaigns have surged 14x and now represent approximately half of all observed phishing attacks. Phishing-as-a-Service (PhaaS) platforms have integrated generative AI into their toolchains, enabling subscribers to produce highly personalized phishing messages at industrial scale without requiring writing skill or language proficiency. These platforms package identity-theft infrastructure, phishing kits, and AI-powered workflow automation into subscription offerings accessible to low-skill criminal actors.

The personalization enabled by AI is what makes these campaigns particularly dangerous. Traditional mass phishing sent generic lures with obvious red flags. AI-generated phishing attack campaigns analyze publicly available information about targets -- LinkedIn profiles, company websites, press releases -- and produce messages that reference real colleagues, genuine business contexts, and accurate job titles. Detection rates for AI-personalized phishing are significantly lower than for generic lures, and victim click rates are substantially higher.

Google Calendar and Booking Platform Campaigns

Google investigated a novel phishing attack vector in June 2026 that bypasses traditional email filters by delivering lures directly through Google Calendar invites. Attackers add fake renewal notices, invoice alerts, and account verification requests directly to Calendar invitations, which appear in victims' calendars without triggering email security controls. Because Calendar notifications arrive through a trusted Google service, recipients are less likely to view them with suspicion.

A separate phishing campaign targeting the hospitality and booking industry uses emails with the display name Booking Manager (via Calendly) to create false urgency around guest complaints, bedbug inspections, room inquiries, and health certifications. The campaign operates in multiple languages including Japanese, Danish, and Dutch, demonstrating the global reach of modern phishing operations and their willingness to invest in localization.

PhaaS Platform Evolution After Tycoon 2FA Disruption

Law enforcement and platform takedowns disrupted major Phishing-as-a-Service kits including Tycoon 2FA in the first half of 2026. However, phishing volumes have not declined as a result. Threat actors have migrated to successor platforms and new PhaaS offerings that emerged within weeks of the Tycoon 2FA disruption. The resilience of the PhaaS ecosystem to platform-level disruptions reflects the low barrier to standing up replacement infrastructure and the high financial returns available to successful operators.

The services sector recorded a 65.5% year-over-year increase in phishing activity targeting billing notices, onboarding documents, renewal communications, support requests, and document-sharing workflows. These lures are effective because they mimic legitimate operational communications that employees process at high volume and low scrutiny.

Protecting Against Modern Phishing Attacks

The phishing attack news of 2026 makes clear that technical controls alone are insufficient. Organizations need a layered defense that combines technical hardening with genuine security awareness:

  • Deploy FIDO2-compliant hardware security keys for privileged accounts. Device-code phishing cannot compromise accounts protected by phishing-resistant MFA.

  • Configure email security gateways to inspect links in Calendar invitations and non-email communication channels, not just traditional email body content.

  • Run regular phishing simulation programs using AI-generated lures to test whether employees can identify sophisticated personalized attacks.

  • Implement zero-trust network access policies that limit the blast radius of compromised credentials even when a phishing attack succeeds.

  • Monitor for OAuth application consent grants. Device-code phishing results in persistent OAuth access tokens that survive password resets.

  • Train employees specifically on device-code phishing mechanics, including how to verify whether a device authorization request they receive was initiated by their own action.

The Outlook for Phishing in 2026

Phishing attack news will almost certainly continue to worsen through the remainder of 2026. The economics favor attackers: AI tools reduce campaign production costs while increasing effectiveness, PhaaS platforms lower the technical barrier to sophisticated attacks, and the shift to remote and hybrid work has expanded the attack surface of credential-based intrusions. Organizations that have not already implemented phishing-resistant authentication should treat it as their most urgent near-term security investment.

The 1,380% device-code phishing surge and 14x AI campaign growth are not anomalies. They are the new baseline. Security programs built around the phishing threat landscape of 2022 or 2023 are not equipped to defend against what is hitting inboxes today.