July 2026 Phishing Trends: AI-Powered Scams and How to Spot Them
The latest phishing attacks use AI to generate convincing emails. Here's what the data shows and how on-device detection helps.
| Signal | Pre-AI phishing (pre-2024) | AI-assisted phishing (2025–2026) |
|---|---|---|
| Language fluency | Often broken grammar, inconsistent formality | Native-quality prose; impersonates brand voice convincingly |
| Personalization | Mostly generic ("Dear Customer") | Targeted, references the recipient's name, role, or recent activity when available |
| Sender domain matching | Lookalike domains (paypa1.com) | Compromised legitimate domains + AI-crafted display names |
| Volume / variability | High volume, low variability (same template many recipients) | High volume, high variability (each email rephrased by an LLM) |
| Defense that still works | Header inspection + skepticism + spam filters | On-device semantic analysis of the email body (what is it actually asking for?) |
The AI Phishing Wave
The Anti-Phishing Working Group (APWG) reported a 22% increase in phishing attacks in Q2 2026 compared to the same period in 2025 [1]. More concerning: a growing percentage of these attacks use AI-generated content that is indistinguishable from legitimate email at first glance [2]. Traditional heuristic-based detection, which looks for spelling errors and suspicious links, is increasingly ineffective against AI-generated phishing [3].
What the Data Shows
APWG's Q2 2026 report documents several trends: brand-impersonation attacks targeting financial institutions increased 15% [4]; spear-phishing attacks targeting executives (BEC attacks) rose 18% [5]; and credential-harvesting attacks using fake login pages increased 31% year-over-year [6]. The FBI Internet Crime Complaint Center (IC3) reported $5.6 billion in losses from phishing-related crimes in 2025 [7].
How On-Device Detection Helps
On-device AI analysis can detect patterns that heuristic filters miss: semantic inconsistency (the email sounds like a brand but uses unusual phrasing), structural analysis (the email structure differs from legitimate brand templates), and behavioral signals (urgent payment requests with unusual timing) [8]. Because the analysis runs locally, there is no privacy tradeoff — your email content never leaves your device [9].
Coming to the App Store: Veilsort's next version will use FoundationModels to detect AI-generated phishing patterns that traditional filters miss — all on-device, all private.
Sources & Citations
- APWG. 'Q2 2026 Phishing Activity Trends Report.' apwg.org
- APWG. 'AI-Generated Phishing Analysis.' apwg.org
- NIST. 'Phish Scale (NISTIR 8358).' nist.gov
- APWG. 'Brand Impersonation Statistics.' apwg.org
- FBI IC3. 'Business Email Compromise Report.' ic3.gov
- APWG. 'Credential Harvesting Trends.' apwg.org
- FBI IC3. '2025 Internet Crime Report.' ic3.gov
- NIST. 'Phishing Detection Methodology.' nist.gov
- Apple. 'On-Device Processing.' developer.apple.com