KnowBe4 has announced new research, ‘Phishing Threat Trends Report Volume Seven’, based on an evaluation of attacks from more than 3,000 unique threat actors. The report highlights a ‘seismic shift’ in the attack vectors utilised to conduct phishing attacks, including touchpoints outside of traditional email communication such as calendar invitations and messaging tools.
Key findings from the report include the following changes compared to the previous report:
- 86% of phishing attacks were AI-driven.
- 49% increase in calendar invite phishing.
- 139% surge in the use of reverse proxies as a tool to steal Microsoft 365 credentials.
- 41% escalation in Microsoft Teams attacks.
- A new trend, shifting from single-vector attacks to multi-channel orchestration.
- More targeted social engineering was discovered, exemplified by internal team impersonation which was seen in 30% of attacks from threat actors in Q1 2026.
The inbox is no longer the only front line for coordinated social engineering attacks. Cybercriminals are actively broadening the email threat landscape. As businesses rely on tools for real-time collaboration, cybercriminals have added this to their attacks, along with targeting people’s calendars. This attack method targets people and technology together. This escalation in scale of threat brings a whole new issue to the forefront.
Jack Chapman, SVP of Threat Intelligence, KnowBe4.






