Zscaler, Inc. announced the findings of the Zscaler ThreatLabz 2026 Phishing and Initial Access Report, highlighting a strategic shift in cybercrime economics where attackers prioritize precision over volume. Despite a 20% year-over-year decline in overall phishing volume, the report details a surge in the sophistication and effectiveness of attacks powered by generative AI. The research, based on telemetry from the Zscaler Zero Trust Exchange, underscores a growing reliance on encrypted channels to evade detection, with 95.2% of phishing attempts now hiding within encrypted traffic.
AI-Driven Attack Evolution
ThreatLabz identified over 413,000 AI-generated phishing site instances, with nearly 10% flagged as explicitly malicious. Attackers are utilizing tools such as Manus AI, Blackbox AI, and Lovable AI to rapidly create polished, brand-consistent phishing portals. This "text-to-site" weaponization allows adversaries to eliminate traditional indicators of compromise, such as poor grammar, making high-fidelity lures more difficult to detect.
Sector and Geographic Impact
The Services sector experienced the most significant impact, with targeted hits jumping 65.5% as adversaries exploited trust-based workflows involving billing and renewals. Manufacturing and Government sectors also remained primary targets, with Government hits increasing 50% as attackers sought high-value intelligence. Geographically, the U.S. remained a top target for email phishing, while Brazil saw a 2,522% surge in phishing hosting, becoming a top-five global origin.
Key Findings and Statistics
The report provides a detailed breakdown of the evolving threat landscape and the methods employed by adversaries to bypass security controls.
| Metric |
Finding |
| Phishing Volume Change |
Down 20% YoY |
| Services Sector Hits |
Up 65.5% YoY |
| Encryption Usage |
95.2% of phishing attempts in encrypted traffic |
| AI-Generated Sites |
413,524 instances identified |
| Deception Interactions |
89.9 million hostile interactions recorded |
| Unique Attacker IPs |
1.37 million unique IPs identified |
Reconnaissance and Evasion Tactics
Deception telemetry revealed large-scale pre-compromise activity, recording 89.9 million hostile interactions from 1.37 million unique attacker IPs over six months. Attackers are leveraging legitimate cloud infrastructure for reconnaissance, using over 121,000 unique Public Cloud-hosted IPs to probe environments. To bypass defenses, sophisticated kits like "BlackForce" are being deployed to hijack active sessions and circumvent multi-factor authentication in real-time. Additionally, 87% of malicious activity is now delivered via HTTPS, making encryption the default for cybercriminals.
Mitigation Strategies
To counter these threats, Zscaler emphasizes the necessity of a Zero Trust architecture. The Zscaler Zero Trust Exchange platform aims to minimize attack surface discovery, eliminate initial compromise through AI-driven inline inspection, stop lateral movement, and prevent data loss. The report's methodology analyzed over 500 trillion daily signals from January to December 2025, supplemented by deception telemetry observed between October 2025 and March 2026.