Phishing in 2026: The New Tactics You Need to Know About

Phishing is no longer a poorly written email from a Nigerian prince. In 2026, it’s a perfectly crafted message that mimics the exact tone of your CFO, accompanied by a call from an AI-cloned voice confirming the request. It’s a link sent via WhatsApp from what appears to be a real vendor, referencing an internal project that only five people in your company know about.

Phishing has evolved faster than any other cybersecurity threat, and Latin America is one of the regions most affected. According to IBM, the region is among the hardest-hit by phishing globally, with Brazil accounting for 53% of incidents, followed by Mexico and Peru. This article analyzes the new tactics shaping phishing in 2026 and what IT leaders can do to protect their organizations.

Tactic 1: AI-Generated Phishing

Language models have eliminated the linguistic and stylistic barriers that once made phishing easily recognizable. Attackers now generate emails that are grammatically flawless, contextually relevant, and personalized for each target. A modern phishing email may mention your name, your job title, your company, a specific project you’re working on, and the name of your direct supervisor—all automatically extracted from LinkedIn and other public sources.

According to recent reports, about 83% of today's phishing emails are generated by AI. This not only improves the quality of each attempt but also allows attackers to scale up massively: what once required manual research is now automated in seconds.

Tactic 2: Voice and Video Deepfakes

Voice cloning is no longer the stuff of science fiction. With just a few seconds of audio—taken from a recorded presentation, a podcast, or a previous call—an attacker can replicate an executive’s voice with enough precision to fool even trained employees. There have already been documented cases in which fraudulent transfers were authorized following a call featuring a cloned CEO’s voice.

Video deepfakes add another layer of complexity. Attackers can create fake video calls on platforms like Teams or Zoom where the caller looks and sounds like a real executive. By 2026, deepfake scams will already account for a significant portion of global fraudulent activity, and companies in Latin America—where voice authentication is still an informal but common trust mechanism—are particularly vulnerable.

Tactic 3: Multichannel Phishing

Phishing is no longer limited to email. Attackers now orchestrate campaigns that use multiple channels simultaneously: an initial legitimate email followed by a “confirmation” message on WhatsApp, a fake notification on Slack, or an SMS with a verification link. This multichannel tactic increases the attack’s credibility because the employee perceives consistency across multiple touchpoints.

In Latin America, where WhatsApp is the de facto business communication tool, this attack vector is particularly effective. Social engineering attacks via WhatsApp increased by 155% in 2025, and the trend continues to accelerate.

Tactic 4: QRishing (phishing via QR codes)

QR codes have become commonplace in the business world: restaurant menus, office Wi-Fi access, event registration forms, and links to shared documents. Attackers exploit this trust by placing malicious QR codes in contexts that appear legitimate—from posters in common areas to email attachments.

A malicious QR code can redirect users to a fake login page that steals credentials, download malware onto the device, or initiate an unauthorized transaction. When scanning a QR code, users cannot inspect the URL before interacting with it, which eliminates one of the few red flags that trained users know to look for.

Tactic 5: BEC 3.0 (Business Email Compromise with AI)

Corporate email compromise fraud has evolved into its third generation. Attackers no longer just spoof email addresses—they combine actual access to compromised accounts with AI scripts that replicate the executive’s writing style and voice deepfakes to “confirm” instructions over the phone. The result is an attack that is nearly impossible to distinguish from a legitimate request.

The sectors most affected by this type of attack are finance (38% of detected campaigns), healthcare (21%), and energy and critical infrastructure (17%).

How to Protect Your Organization

Defending against modern phishing requires a multi-layered approach. Email protection with AI-powered analysis is essential, but it is not enough. Organizations need ongoing training with realistic simulations that reflect current tactics, out-of-band verification protocols for any financial or access requests, phishing-resistant multi-factor authentication, and continuous monitoring for compromised identities.

Above all, IT leaders must accept that phishing is no longer just a problem of “careless users.” It is a problem of sophisticated social engineering that requires equally sophisticated defenses.

Pint Solutions implements layers of protection against phishing, ranging from email security to employee training and identity protection. If you'd like to assess how prepared your organization is, we can help.