Kaseya has released The 2026 Kaseya INKY Email Security Report, which shows that phishing remains the primary attack vector for bad actors, with 26% of all cybercrime complaints filed with the FBI being phishing-related and $2.8 billionin reported business email compromise (BEC) losses alone.
Of the more than 4.5 billion emails that Kaseya’s INKY solution processed in 2025, 281 unique brands were impersonated. While cybercriminals have often relied on copying well-known brands to build trust, AI-generated layouts have allowed impersonators to more closely resemble a legitimate email from top financial institutions and retail brands.
“In the past year, AI-generated phishing became the baseline,” said Dave Baggett, SVP of Security Suite, Kaseya. “Attackers can now produce highly convincing messages at scale, which means the traditional signals security tools relied on for years – bad grammar, suspicious domains, obvious links – are disappearing. Defenders now have to evaluate intent and context, not just indicators.”
When it comes to future trends, attackers are expanding phishing techniques using calendar invitations, protected documents, and callback phone numbers.






