Phishing Attacks in 2026: What Your Team Must Know
Phishing Has Evolved -- Has Your Team Kept Up?
Phishing remains the number one attack vector against Australian businesses. The Australian Signals Directorate (ASD) reported that phishing was involved in over 70% of cybercrime incidents affecting SMEs in 2023-24. But the phishing emails of 2026 look nothing like the poorly-spelled Nigerian prince scams of a decade ago.
Attackers are now using generative AI to craft grammatically perfect, contextually relevant phishing messages at scale. They are using deepfake voice cloning to impersonate your CEO on a phone call. And they are embedding malicious links in QR codes that bypass traditional email filters entirely.
If your team's phishing awareness is based on advice from 2020, you are already behind. Here is what Australian SMEs need to know right now.
The Modern Phishing Landscape: Types of Attack
Email Phishing (Still the Biggest Threat)
Traditional email phishing remains the most common form, but it has become significantly harder to detect. AI-generated phishing emails now:
- Use perfect Australian English with local slang and references
- Reference real events (e.g., ATO tax deadlines, bushfire relief, local council notices)
- Mimic the exact formatting and branding of legitimate companies (banks, Australia Post, Telstra, Xero)
- Are personalised using data scraped from LinkedIn, company websites, and social media
For detailed protection strategies against email-based attacks, see our business email compromise protection guide.
SMS Phishing (Smishing)
Smishing attacks exploit the trust people place in text messages. Common Australian smishing lures include:
- Fake delivery notifications (Australia Post, DHL, Amazon)
- MyGov or ATO messages claiming a tax refund or debt
- Toll road payment reminders (Linkt, CityLink)
- Bank security alerts requesting "verification"
These messages often include shortened URLs that redirect to convincing fake login pages designed to harvest credentials.
Voice Phishing (Vishing)
Voice phishing has taken a sinister leap forward with AI voice cloning. Attackers can now clone a voice from as little as three seconds of audio -- easily obtained from a company's YouTube channel, podcast appearance, or voicemail greeting. Vishing attacks targeting Australian SMEs include:
- Calls impersonating the CEO or CFO requesting urgent wire transfers
- Fake IT support calls claiming to fix a "detected security issue"
- Calls from "the ATO" threatening legal action unless immediate payment is made
QR Code Phishing (Quishing)
Quishing is one of the fastest-growing attack vectors in 2026. Attackers place malicious QR codes:
- In phishing emails (bypassing URL scanning by email security tools)
- On physical stickers placed over legitimate QR codes in cafes, parking meters, and offices
- In fake invoices, delivery notices, or event tickets sent by post
When scanned, these codes direct victims to credential harvesting pages or trigger malware downloads on mobile devices.
Spear Phishing
Unlike broad-spectrum phishing, spear phishing targets specific individuals within your organisation. Attackers research their targets thoroughly, often combining information from:
- LinkedIn profiles (job titles, responsibilities, connections)
- Company website (team pages, press releases, partner announcements)
- Previous data breaches (email/password combinations)
- Social media (personal details, interests, recent activities)
Finance staff, office managers, and anyone with payment authority are the most common targets.
Red Flags: How to Spot a Phishing Attempt
Train your team to watch for these warning signs across all communication channels:
- Urgency and pressure: "Your account will be suspended in 24 hours," "This invoice is overdue -- pay immediately," "The CEO needs this done before end of day."
- Unexpected requests: Any request to change payment details, share credentials, or bypass normal approval processes should trigger suspicion -- regardless of who it appears to come from.
- Mismatched sender details: The display name says "Commonwealth Bank" but the email address is from a random domain. On mobile, tap the sender name to reveal the actual address.
- Suspicious links: Hover over links (do not click) to preview the URL. Look for misspellings, extra characters, or unfamiliar domains. On mobile, long-press a link to preview.
- Requests to bypass MFA: "Enter the code we just sent you" or "Approve the login notification" when you did not initiate a login. Having MFA properly configured is your strongest defence here.
- Unusual file attachments: Especially .zip, .iso, .html, or macro-enabled Office documents (.xlsm, .docm).
- Too good to be true: Prize notifications, unexpected refunds, or unsolicited business opportunities.
What to Do When You Receive a Suspected Phishing Message
Every staff member should know these steps:
- Do not click, reply, or call back. Do not open attachments or scan QR codes.
- Report it internally. Forward the message to your IT team, MSP, or designated security contact. Most email clients have a "Report phishing" button -- use it.
- Verify through a separate channel. If the message claims to be from a colleague, client, or supplier, contact them directly using a known phone number or email address -- not the one in the suspicious message.
- If you have already clicked or entered credentials: Change your password immediately, report it to IT, and monitor your accounts for unusual activity. Time is critical.
- Report to the ACSC. Forward suspicious emails to ReportCyber at cyber.gov.au. Report suspicious SMS by forwarding to 0429 999 888 (the ACMA scam reporting number).
Building a Phishing-Aware Culture
Technical controls like email filtering and MFA are essential, but they are not enough. A phishing-aware culture means your people are your strongest line of defence, not your weakest link.
- Regular training: Short, frequent sessions beat annual compliance lectures. 15 minutes per month is more effective than a 3-hour annual session. See our staff training guide for practical approaches.
- Simulated phishing tests: Run realistic (but safe) phishing simulations to measure and improve staff awareness. Many Australian MSPs and security providers offer this as a service.
- Positive reporting culture: Never punish staff for reporting a suspected phish -- even if it turns out to be legitimate. You want people to over-report, not stay silent out of fear of looking foolish.
- Verification procedures: Establish mandatory call-back verification for any request to change payment details, transfer funds, or share sensitive information -- no matter who appears to be asking.
- Share real examples: When someone in your team receives a phishing attempt, share it (anonymised if needed) with the whole team. Real-world examples are the best training material.
Defending against phishing requires controls across multiple domains. In the IDIA framework, phishing defences span two pillars: the Identity pillar covers access control, authentication, and MFA -- ensuring that even if credentials are stolen, attackers cannot get in -- while the Infrastructure pillar covers email filtering, endpoint protection, and network security that block malicious messages before they ever reach your team. Thinking about phishing through these two pillars helps you see the full picture rather than relying on any single control.
Assess Your Organisation's Phishing Resilience
Phishing resilience is not just about technology -- it is about people, processes, and culture working together. Platforms like How's My Cyber use the IDIA framework (Identity, Data, Infrastructure, Assurance) to organise every control into a clear operating model that works alongside any standard. Start with the free CYBER9 assessment to benchmark your business across nine critical domains -- including email security and staff awareness -- in under 10 minutes. Understand where your business is most vulnerable to social engineering attacks and get actionable steps to close the gaps.
How secure is your business?
Take the free CYBER9 assessment and get your security score in under 10 minutes. No credit card required.
Try CYBER9 Free