A new report from KnowBe4 reveals that AI-driven phishing attacks have become the dominant threat vector for organizations worldwide. The Phishing Threat Trends Report Volume Seven, released May 1, 2026, found that 86% of phishing attacks were powered by artificial intelligence, marking a significant escalation in how cybercriminals target businesses.

The research analyzed attacks from more than 3,000 unique threat actors over a six-month period. Beyond this headline finding, the report documents a fundamental shift in attack methods. Cybercriminals are no longer limiting their efforts to email inboxes alone; instead, they are expanding into calendar invitations, messaging tools, and other collaboration platforms that businesses increasingly rely on for daily operations.

Expanding Attack Surfaces Beyond Email

The report identified several emerging threats that signal how attackers are diversifying their approach. Calendar invite phishing surged by 49% in the six-month period, while Microsoft Teams attacks climbed 41%. Additionally, threat actors increased their use of reverse proxies to steal Microsoft 365 credentials by 139%, exploiting vulnerabilities in widely deployed enterprise tools.

Jack Chapman, SVP of Threat Intelligence at KnowBe4, said: “The inbox is no longer the only front line for coordinated social engineering attacks. Cybercriminals are actively broadening the email threat landscape. As businesses rely on tools for real-time collaboration, cybercriminals have added this to their attacks, along with targeting people’s calendars.”

Multi-Channel Orchestration and Targeted Social Engineering

A critical trend emerging from the data is the shift from single-vector attacks to coordinated, multi-channel campaigns. Rather than relying on one method to compromise targets, attackers now combine multiple tactics across different platforms simultaneously. This coordinated approach makes detection and defense significantly more difficult.

The report also highlighted increased sophistication in social engineering tactics. More targeted attacks were discovered, with internal team impersonation appearing in 30% of attacks from threat actors in the first quarter of 2026. Attackers are studying organizational structures and mimicking legitimate colleagues to increase the likelihood of successful compromise.

AI-Enabled Attacks Present New Challenges

Chapman stated: “Social engineering is becoming more targeted, making it more difficult to discern what is legitimate versus what is malicious. The Phishing Threat Trends Report volume seven finds that phishing in 2026 is disciplined, persistent, multi-channel and increasingly AI-enabled.” He added that protecting organizations requires securing both human employees and the artificial intelligence agents they use.

The integration of AI technology into phishing campaigns has raised the bar for attackers, enabling them to generate more convincing messages, identify high-value targets more efficiently, and automate large-scale operations at minimal cost. Organizations must now defend against threats that combine human psychology with machine learning capabilities.

Implications for Organizations

The findings underscore the need for comprehensive cybersecurity strategies that extend beyond traditional email filtering. Organizations must monitor collaboration tools, implement strong authentication across all platforms, and provide ongoing security awareness training. The report indicates that a coordinated defense addressing both technology and human behavior is essential.

KnowBe4 noted that the Phishing Threat Trends Report Volume Seven is available for download, offering detailed analysis and additional insights from the research.