惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Project Zero
Project Zero
F
Fortinet All Blogs
Recent Announcements
Recent Announcements
云风的 BLOG
云风的 BLOG
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
M
MIT News - Artificial intelligence
S
SegmentFault 最新的问题
Blog — PlanetScale
Blog — PlanetScale
T
Tailwind CSS Blog
WordPress大学
WordPress大学
Engineering at Meta
Engineering at Meta
S
Schneier on Security
N
News and Events Feed by Topic
N
News | PayPal Newsroom
H
Help Net Security
C
CXSECURITY Database RSS Feed - CXSecurity.com
T
The Exploit Database - CXSecurity.com
Attack and Defense Labs
Attack and Defense Labs
博客园 - Franky
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
J
Java Code Geeks
A
About on SuperTechFans
AWS News Blog
AWS News Blog
S
Secure Thoughts
The Cloudflare Blog
Hugging Face - Blog
Hugging Face - Blog
爱范儿
爱范儿
C
Cybersecurity and Infrastructure Security Agency CISA
V2EX - 技术
V2EX - 技术
Recorded Future
Recorded Future
Microsoft Azure Blog
Microsoft Azure Blog
博客园_首页
MyScale Blog
MyScale Blog
Martin Fowler
Martin Fowler
Help Net Security
Help Net Security
人人都是产品经理
人人都是产品经理
Latest news
Latest news
C
Cyber Attacks, Cyber Crime and Cyber Security
大猫的无限游戏
大猫的无限游戏
The Last Watchdog
The Last Watchdog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
月光博客
月光博客
H
Hacker News: Front Page
P
Proofpoint News Feed
N
News and Events Feed by Topic
H
Heimdal Security Blog
L
Lohrmann on Cybersecurity
有赞技术团队
有赞技术团队
L
LangChain Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog

Latest news

LG G6 vs. LG G5: I compared the latest OLED TV models, and it's a surprisingly tough choice I saw the 'MacBook Pro for Linux users' for the first time, and it's a legit Windows threat I'm putting Motorola above Samsung when it comes to flip phones - and won't think twice I got an early look at ChatGPT Images 2.0, and it's impressive - with one exception I tested Surfshark's new Dausos VPN protocol - here's how it compares to WireGuard How to easily encrypt your files on an Android phone - for free I'm not giving up on DJI cameras yet - not when they can upset my GoPro like this The best website builders for small businesses in 2026: Expert tested and reviewed Why I'm recommending last year's phones over 2026 models - with one exception This powerful Gemini setting made my AI results way more personal and accurate After testing this HP laptop, I get why its 'boring' design is adored by business users The best TV antenna of 2026: Expert tested Your old iPad or Android tablet can be your new smart home panel - here's how Apple's original AirTag still tracks effectively, and you can get a 4-pack for its best price ever T-Mobile will give you an iPad for $99 when you sign up for a new line - here's how How to qualify for Apple's education discount - and get a $499 MacBook Neo for school T-Mobile will give you a Samsung Galaxy Watch 8 for free - how to get yours Prolonged AI use can be hazardous to your health and work: 4 ways to stay safe Verizon will give you a free iPad or Apple Watch with your next iPhone - how the deal works The best laptops of 2026: Expert tested and reviewed I hid 4 Bluetooth trackers (including AirTags) to test their reliability - here's how Android rivals compared I stopped using my iPhone's hotspot after testing this 5G router - and that won't change The best Kindles in 2026: Expert recommended Does Best Buy price match? Everything to know about matching prices online and in-store The best WordPress hosting services of 2026: Expert tested and reviewed The best Apple Watch of 2026: Expert tested and reviewed The best TV screen cleaners of 2026: Expert recommended The best 50-inch TVs of 2026: Expert tested I traded my Sonos Era 300 for Denon's new home speaker - and see no reason to go back AI-powered website builders have come a long way - here's your best option in 2026 Amazon just slashed $250 off the Google Pixel 10 - and a Prime subscription isn't required I found the apps slowing down my PC - how to kill the biggest memory hogs These companies are actually upskilling their workers for AI - here's how they do it Verizon will give you Meta Ray-Bans for free with this Fios Internet deal - how to get yours I tried the new Gemini app for Mac - it has one major advantage over the web version How Google's updated AI Mode will ease your tab clutter when you search Why this MagSafe battery pack is our readers' favorite model right now - especially at its price T-Mobile will give you a Google Pixel 10a for free - plus an extra gift OpenAI's Codex Desktop can run your computer now - and has its own browser Want to build a startup that gets acquired? This founder shares 5 proven tips Google to pay $135M settlement to Android phone users - how to claim your share if you qualify Want to stand out on LinkedIn? Try this career strategist's top 3 tips for strengthening your profile I've used Dell's new XPS 16 for a week, and it's the Windows laptop to beat in 2026 You can get 50% off YouTube Premium for 1 year right now - but the deal ends soon Tidal vs. Qobuz: I tried both hi-res streaming services, and they couldn't be more different This stroller turns into a carry on-suitcase, and I recommend it for traveling parents The best small business VoIP providers of 2026: Expert tested and reviewed Protect your devices with our pick for the best antivirus software, now over 60% off MacBook Neo vs. Surface: Why spiraling RAM prices are bruising Microsoft's PC business but not Apple's I tried Google's new desktop app for Windows, and I'll never search the old way again Microsoft's Windows 11 laptop deal for students comes with a $500 bonus - what's included You can buy an LG B5 OLED for $1,500 off at Best Buy - and it comes with a free 4K TV Why Zorin OS 18.1 is simply the best Linux distro - for anyone Why Netgear just got the first FCC router ban exemption in the US Microsoft's latest Windows update now confirms if your PC is Secure Boot-protected - how it works Can this $70 Linux app make up for the lack of Photoshop? I tried it to find out 'Like handing out the blueprint to a bank vault': Why AI led one company to abandon open source iPhone charging slowly? 6 quick fixes to try before blaming your battery Roku TV vs. Fire Stick: Why I'm looking beyond streaming resolution when comparing the two AI is getting better at your job, but you have time to adjust, according to MIT The best internal communication tools of 2026: Expert tested and reviewed Half of all US employees use AI at work now - and waste almost 8 hours a week doing it I've been subscribed to a data removal service a month now - what I wish I knew sooner You can use Linux 7.0 on these 7 distros today - here's what to expect How I share audio from my Android phone to multiple earbuds (and why it's a big deal) Why the Apple Watch's 20-minute calibration test is worth your time - especially if you're data curious I swapped my Sony WH-1000XM6 for lower-end JBL headphones, and they still sounded great I tested ChatGPT Plus vs. Gemini Pro to see which is better - and if it's worth switching I used the 'Plus Five' rule to fix my iPhone's slow wireless charging - here's how it works The new rules for AI-assisted code in the Linux kernel: What every dev needs to know 'Job seekers have to be detectives': 3 signs that listing is a scam How the latest Netrunner distro delivers a Linux productivity powerhouse This Linux distro offers an easy DNS switcher - but there's more to it that I like I tested Artix Linux: An enjoyable systemd-free distro for experienced users (and ChromeOS speeds) How I boosted my portable solar panels' power by up to 30% - 11 expert-approved tips How I disabled 'fast startup' on my Windows 11 laptop to stop overnight battery drain 30 years later, I returned to Enlightenment Linux to test the Elive beta - and it's much better Here's my favorite email trick for cleaning up inbox clutter - automatically The $30 Google TV stick may be the budget Chromecast successor we've been waiting for The best AR and MR glasses in 2026: Expert tested and reviewed This handy electric screwdriver is now 50% off - here's where to snag the deal This Ryobi yard essentials bundle packs a free power tool - how to get yours After trying these boomless headphones in the office, I'm feeling hopeful for the future of work tech I used this EcoFlow battery to run my 3,000-sq-ft home in a blackout - here's how it kept my AC on Microsoft's Windows Insider Program is no longer a confusing mess Forget Shokz: I tried the Suunto Spark earbuds for a month, and they've sold me on air conduction iOS 26.4 brings essential upgrades to your iPhone - including a vital security fix YouTube Premium is getting a price increase in June - but you can save $32 with one change Your router may be vulnerable to Russian hackers, FBI warns: 5 steps to take now I walked 3,000 steps with my Apple Watch, Google Pixel, and Oura Ring - this tracker was most accurate I stopped guessing which AA batteries are dead - this charging station keeps them in check for me My favorite Android Auto find is these hidden shortcuts that are highly customizable AirDrop is coming to older Samsung phones - is yours supported? How to get it early I'm no longer using Google Photos as just a cloud storage - 5 tools that elevate the app The best data removal services of 2026: Expert tested and reviewed The best Samsung TVs of 2026: Expert tested and reviewed The best mobile scanning apps of 2026: Expert tested and reviewed The best HP laptops of 2026: Expert tested and reviewed After using Lenovo's new Yoga laptop, I'm wondering if Windows makers are running out of ideas Samsung S95H vs. Samsung S95F: I compared the OLED TVs and wasn't prepared for the upset
Mobile phishing is a bigger threat than email now - how to stay protected
2026-05-20 · via Latest news
iPhone 17e
Kyle Kucharski/ZDNET

Follow ZDNET: Add us as a preferred source on Google.


ZDNET's key takeaways

  • Verizon's DBIR reveals top business security trends.
  • Mobile phishing is outpacing email-based attacks.
  • Companies need mobile-focused phishing training.

Mobile attack vectors are outstripping email threats as we become more able to detect traditional phishing attempts, Verizon said in a new report exploring the data breach landscape and the impact on businesses worldwide.

Also: Worried about the nationwide Canvas data breach? Take these 6 steps now

In Verizon's 2026 Data Breach Investigations Report (DBIR), the company said that mobile-centric cyberattacks are increasing in popularity and have a higher click rate than the same phishing attempts sent via email, which raises questions about whether our existing phishing protections are adequate.

Mobile social engineering takes center stage

Based on data collected from more than 31,000 real-world security incidents in 2025, with 22,000 confirmed data breaches impacting organizations in 145 countries, Verizon says that "mobile is more dangerous than email."

Also: The best mobile antivirus software of 2026: Expert tested and reviewed

A set of phishing simulation assessments backs up this claim, in which mobile-centric attack vectors -- including voice-based phishing (vishing) and text scams -- were successful lures, achieving a 40% higher click-through rate than traditional email phishing scams.

The human element

People are often the weakest link in security systems, and threat actors know it. However, that doesn't mean we aren't improving our general cybersecurity awareness; it just means cybercriminals are switching up their tactics.

According to Verizon's report, the "human element" was present in 62% of known and recorded data breaches, a marginal increase of 2% year over year.

Also:The shadowy SIM farms behind those incessant scam texts - and how to stay safe

Unfortunately, the data reveals that many cybercriminals are abusing our trust to steal data, commit payment fraud, or act as a precursor to severe security incidents, including ransomware deployment and extortion.

When sending a phishing email isn't enough, they have begun what Verizon calls "pretexting," a concerning development that highlights how psychology now more often plays a part in modern cyberattacks.

Pretexting vs. phishing

Social engineering, which accounts for 16% of all breaches, refers to psychological exploitation to persuade us to take actions that risk our personal security and privacy, or that of a business, such as our employer.

These tactics can range from a member of staff allowing a criminal posing as a delivery driver to enter a secure building to someone posing as one of your loved ones in a financial emergency.

When applied to mobile technology, phishing often takes the form of fake texts, voice notes, and calls for nefarious purposes. It's not just a cybercriminal pretending to be you and calling your telecoms provider to swap your SIM; if "pretexting" is used as a tactic, a foundation of trust is laid between the criminal and the victim before a trap is sprung.

Also: How to check if a text message is spam on Android - and the free tool I rely on

Consider it an upgrade over generic phishing attempts used in targeted, more sophisticated attacks. For example, an employee in finance could be targeted, with a friendly rapport built through mobile messaging and calls, and with an attacker pretending to be an executive, team member, or vendor. When enough trust has been established, the victim is then tricked into changing an invoice's payment details, sending cash unwittingly to a criminal instead of a supplier.

Average click-through rates for simulated email phishing campaigns in Verizon's dataset were 1.4%, compared to phone-based phishing rates of around 2%, a 40% increase.

"Regardless of the terminology, various attackers have been leveraging these means by impersonating help desk agents or users needing a password reset, with moderate levels of success," the report says. "The bottom line here is that social attacks using phone-centric vectors -- text messages, voice, or callback-focused emails -- are more successful in our dataset than using the traditional email vector defenders are used to."

More key security trends

Verizon's research also revealed that nearly a third (31%) of breaches now start with the exploitation of vulnerabilities, marking the first time that exploiting security flaws has surpassed the use of stolen credentials as an initial entry point into a target system, now recorded as the reason for 13% of incidents.

This shift is believed to be due to AI. According to the report, AI is being leveraged by cybercriminals to reduce the time required to exploit vulnerabilities, "shrinking the window for defense from months to mere hours."

Also: This simple ChatGPT trick helps you spot scams before you click or respond

Furthermore, only 26% of critical vulnerabilities recorded by CISA were fully patched and resolved in 2025, a drop from 38% in 2024.

Another interesting trend that organizations should be aware of is shadow AI. Businesses have long been aware of shadow IT, the use of devices and online services by employees without explicit approval, but now shadow AI is also a potential security risk.

In total, 67% of employees are using non-corporate AI accounts on their company-issued devices. Shadow AI was the third most common non-malicious insider threat recorded last year, with users frequently submitting sensitive, confidential company data to these models, including source code, research, and technical documents.

How to stay protected

As the sample sizes are small, the common threads of Verizon's research on mobile-centric phishing do have some caveats. However, this is because few data points were available, as there don't appear to be many companies conducting mobile-focused phishing simulations or training -- which, in turn, has revealed a potential problem.

Phishing training is nothing new, although its benefits are debatable, especially when it is considered just an annual exercise to tick a box. But with few organizations considering the mobile aspect of modern phishing tactics, they may be exposing themselves to greater risks, especially when employees are using their own devices to access corporate networks and systems.

If cybercriminals are allowed to bypass security systems by contacting unwitting employees directly, investments in anti-phishing defenses could be rendered worthless.

For organizations, the answer is developing new strategies to combat traditional and evolving phishing threats across email and mobile. With "pretexting" also on the rise, training should teach staff that phishing is no longer just spray-and-pray emails -- these criminals will tug at your heartstrings and exploit your trust to achieve their goals.

Also: Cloud attacks are getting faster and deadlier - 4 ways to secure your business

Furthermore, these attacks can occur through employee-owned devices, which are outside your control and could pose invisible threats to corporate security, so organizations should reconsider permitting access or revoking bring-your-own-device schemes. It might save companies cash in the short term to allow members of staff to use their own smartphones, but a data breach isn't cheap.