July 2026 Phishing Trends: AI-Powered Scams and How to Spot Them

The latest phishing attacks use AI to generate convincing emails. Here's what the data shows and how on-device detection helps.

Pre-AI phishing vs. AI-assisted phishing (mid-2026 observed patterns)
SignalPre-AI phishing (pre-2024)AI-assisted phishing (2025–2026)
Language fluencyOften broken grammar, inconsistent formalityNative-quality prose; impersonates brand voice convincingly
PersonalizationMostly generic ("Dear Customer")Targeted, references the recipient's name, role, or recent activity when available
Sender domain matchingLookalike domains (paypa1.com)Compromised legitimate domains + AI-crafted display names
Volume / variabilityHigh volume, low variability (same template many recipients)High volume, high variability (each email rephrased by an LLM)
Defense that still worksHeader inspection + skepticism + spam filtersOn-device semantic analysis of the email body (what is it actually asking for?)

The AI Phishing Wave

The Anti-Phishing Working Group (APWG) reported a 22% increase in phishing attacks in Q2 2026 compared to the same period in 2025 [1]. More concerning: a growing percentage of these attacks use AI-generated content that is indistinguishable from legitimate email at first glance [2]. Traditional heuristic-based detection, which looks for spelling errors and suspicious links, is increasingly ineffective against AI-generated phishing [3].

What the Data Shows

APWG's Q2 2026 report documents several trends: brand-impersonation attacks targeting financial institutions increased 15% [4]; spear-phishing attacks targeting executives (BEC attacks) rose 18% [5]; and credential-harvesting attacks using fake login pages increased 31% year-over-year [6]. The FBI Internet Crime Complaint Center (IC3) reported $5.6 billion in losses from phishing-related crimes in 2025 [7].

How On-Device Detection Helps

On-device AI analysis can detect patterns that heuristic filters miss: semantic inconsistency (the email sounds like a brand but uses unusual phrasing), structural analysis (the email structure differs from legitimate brand templates), and behavioral signals (urgent payment requests with unusual timing) [8]. Because the analysis runs locally, there is no privacy tradeoff — your email content never leaves your device [9].

Coming to the App Store: Veilsort's next version will use FoundationModels to detect AI-generated phishing patterns that traditional filters miss — all on-device, all private.

Sources & Citations

  1. APWG. 'Q2 2026 Phishing Activity Trends Report.' apwg.org
  2. APWG. 'AI-Generated Phishing Analysis.' apwg.org
  3. NIST. 'Phish Scale (NISTIR 8358).' nist.gov
  4. APWG. 'Brand Impersonation Statistics.' apwg.org
  5. FBI IC3. 'Business Email Compromise Report.' ic3.gov
  6. APWG. 'Credential Harvesting Trends.' apwg.org
  7. FBI IC3. '2025 Internet Crime Report.' ic3.gov
  8. NIST. 'Phishing Detection Methodology.' nist.gov
  9. Apple. 'On-Device Processing.' developer.apple.com

Enjoyed this post?