Phishing threats are evolving rapidly as cybercriminals revive and refine old tactics to target individuals and businesses across the Middle East, according to a new review by Kaspersky released on February 5, 2026. The global cybersecurity company has identified three major phishing techniques gaining traction in the region: calendar-based attacks, voice message deceptions, and sophisticated multi-factor authentication (MFA) bypass schemes.
These findings emphasize the critical need for user vigilance, comprehensive employee training programs, and advanced email protection solutions to counter these persistent and evolving threats. The techniques are particularly relevant to organizations in the GCC region, where the trend is already visible in regional threat telemetry data.
Calendar-Based Phishing Targets Office Workers
A tactic originally from the late 2010s has reemerged with renewed focus on business-to-business (B2B) environments. Calendar-based phishing involves attackers sending emails with calendar event invitations that often contain no body text, hiding malicious links within the event description. When opened, the event automatically adds to the user’s calendar, with reminders urging them to click links leading to fake login pages that mimic services like Microsoft.
This method is increasingly plausible in GCC organizations because it targets exactly the workflows that dominate regional corporate life. Previously aimed at Google Calendar users in mass campaigns, this approach now specifically targets office employees. Kaspersky advises companies to conduct regular phishing awareness training, such as simulated attack workshops, to teach employees how to verify unexpected calendar invites before clicking any links.
Voice Message Deception with CAPTCHA Evasion
Phishers are deploying minimalist emails that pose as voice message notifications, containing sparse text and a link to a basic landing page. Clicking the link triggers a chain of CAPTCHA verifications designed to bypass security bots, ultimately directing users to a fraudulent Google login page that validates email addresses and captures credentials.
This multi-layered deception fits the Middle East’s communication culture particularly well, as voice notes and voicemail notifications are familiar to users in the region. The CAPTCHA step is a known evasion technique designed to defeat automated scanning and increase the likelihood that the victim is a real person. This highlights the need for interactive employee training modules on recognizing suspicious links and advanced email server protection solutions like Kaspersky SecureMail.
Understanding Phishing Threats Through MFA Bypass Attacks
Sophisticated phishing campaigns are now targeting multi-factor authentication (MFA) by mimicking cloud storage services like pCloud. These emails, disguised as neutral support follow-ups, lead to fake login pages on lookalike domains such as pcloud.online. The pages interact with the real pCloud service via API, validating emails and prompting for one-time password (OTP) codes and passwords, granting attackers complete account access upon successful login.
MFA bypass via fake cloud-service logins represents one of the most important evolutions for the Middle East precisely because many GCC organizations have made genuine progress on baseline security and now rely heavily on MFA. To counter this threat, organizations should implement mandatory cybersecurity training and deploy email security solutions like Kaspersky Security for Mail Servers, which flags fraudulent domains and API-driven attacks.
Expert Recommendations and Protection Strategies
“With phishing schemes growing more deceptive, Kaspersky urges users to treat unusual email attachments, like password-protected PDFs or QR codes, with caution and verify website URLs before entering any credentials. Organizations should adopt comprehensive training programs, which includes real-world simulations and best practices for spotting phishing attempts. Additionally, deploying robust email server protection solutions ensures real-time detection and blocking of advanced phishing tactics.”
Roman Dedenok, Anti-Spam Expert at Kaspersky
Kaspersky is a global cybersecurity and digital privacy company founded in 1997, with over a billion devices protected to date from emerging cyberthreats and targeted attacks. The company’s comprehensive security portfolio includes leading digital life protection for personal devices, specialized security products and services for companies, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats.





