Phishing attacks: 2026 Guide

Phishing attacks: 2026 Guide

Natalie Moore
April 23, 2026· 9 min read

The scariest thing about phishing attacks is not that the emails are always brilliant. It is that attackers often need only one person to click once. The FBI's 2024 Internet Crime Report shows that phishing/spoofing remained one of the top internet crime categories by complaint volume, while reported internet crime losses exceeded $16 billion for the year.[1]

This is not a curiosity list. We will use 10 real incidents to break down what attackers were trying to steal, why the attacks worked, and where individuals and organizations should reinforce defenses.

If you need the basics first, read What is phishing?.

Use the digital privacy guide as the wider checklist: it connects this issue to accounts, devices, identifiers, and data-broker exposure.

Key Takeaways

  • Phishing does not target only ordinary users. It can compromise corporate finance teams, political campaigns, and critical infrastructure.
  • Successful phishing usually relies on three things: a false identity, urgency, and a fake login page or malicious attachment.[2]
  • Polished grammar is no longer a reliable safety signal because AI can make phishing text sound natural.[2]
  • The strongest everyday defenses are password managers, MFA, out-of-band transfer checks, and avoiding logins through email links.

What counts as a notable phishing attack?

A phishing incident does not have to be the largest to be instructive. It has to show an attack pattern clearly.

Attack patternCommon targetsMain result
Fake login pageEmail, cloud storage, social media accountsCredential theft, account takeover
Business email compromiseFinance, HR, vendorsWrong payments, invoice fraud
Malicious attachmentEmployee computers, corporate networksMalware, ransomware, lateral movement
Social media lureJournalists, activists, public figuresPrivate data leaks, surveillance risk

CISA describes two core phishing goals: stealing login credentials or persuading users to download malware.[3]The 10 examples below mostly fall into those two groups.

What can 10 phishing attacks teach us?

1. Google and Facebook vendor impersonation fraud

The U.S. Department of Justice disclosed that an attacker impersonated a hardware vendor and sent fake invoices and emails to Google and Facebook, stealing more than $100 million.[4]

The lesson is simple: when companies are large and workflows are complex, attackers can hide inside normal vendor communication.

2. Crelan Bank CEO fraud

Belgian bank Crelan disclosed in its 2016 annual report that it had suffered "fake CEO" fraud worth nearly EUR 70 million.[12]The attackers used the pressure of executive authority to push finance workflows past normal skepticism.

This is less about technical sophistication and more about authority. Any large transfer needs a second confirmation outside email.

3. Sony Pictures intrusion

The Sony Pictures incident is often remembered as a major data breach and destructive attack, but one suspected entry point involved targeted phishing against employees with system access.[5]

The lesson: the target is not always a "regular employee." It may be someone with critical permissions.

4. Ukraine power grid attack

In 2015, Ukrainian power companies suffered a cyberattack that left about 225,000 customers without power. CISA's analysis noted phishing emails and malicious documents aimed at office networks as part of the attack chain.[6]

This is a representative case of phishing moving from "steal accounts" to "affect the physical world."

5. Colonial Pipeline ransomware incident

The Colonial Pipeline incident disrupted fuel supply along the U.S. East Coast. Public reporting and advisories pointed to a single compromised VPN account and missing MFA as major risk factors.[7]

It is a reminder that stolen credentials do not always come from a brand-new email. They may come from old breaches and reused passwords.

6. Hillary Clinton campaign email leak

During the 2016 U.S. presidential campaign, John Podesta's Gmail account was compromised after a phishing email, and the messages were later published.[8]

For ordinary users, the warning is clear: one "change your password" link can become the doorway into an entire mailbox.

7. Celebrity iCloud photo leak

In 2014, private photos of multiple celebrities were leaked. Later DOJ case materials showed that attackers used phishing emails to obtain usernames and passwords, then accessed victims' accounts.[9]

This was not a cloud service "leaking automatically." It was account credentials being tricked out of people.

8. Apple support impersonation targeting celebrity accounts

The DOJ also disclosed a case in which an attacker impersonated Apple support and asked athletes and performers for account information and security-question answers, then took over accounts.[10]

Security-question answers are effectively passwords. They should not be shared by email or direct message.

9. Locky ransomware emails

Locky ransomware spread widely through fake invoices, fake shipping notices, and Office attachments. HKCERT in Hong Kong rated it as an extremely high risk and warned that malicious attachments could be macro documents or compressed files.[13]

The keyword here is "attachment." If the sender is unexpected and you did not expect the file, do not open it just to "take a look."

10. Social phishing against activists and journalists

Some attacks against journalists and activists begin by building a relationship, then sending a cloud document link or fake login page. Amnesty Tech reported sophisticated phishing against Google and Outlook accounts used by human rights defenders and journalists in the Middle East and North Africa.[14]

That shows phishing is not always crude mass mail. It can be slow, customized, and backed by background research.

Why do these phishing attacks work?

Not because victims are "stupid."

Attackers often press several buttons at once:

  • Time pressure: account alerts, failed orders, executives demanding payment;
  • Trusted identity: banks, bosses, coworkers, cloud services, support agents;
  • Realistic path: lookalike domains, short links, familiar login pages;
  • Scary consequence: account closure, fines, missed payments;
  • Excessive permissions: one account can reach email, files, finance, or internal systems.

CISA warns that grammar mistakes are no longer a reliable sign because AI-era phishing emails may read naturally.[2]

How can ordinary people protect themselves?

Start by hardening daily habits.

  1. Do not log in to banking, email, or cloud services through links in emails.
  2. Turn on MFA for email, social media, payment accounts, and cloud storage.
  3. Use a password manager to generate a different long password for every site.
  4. Treat urgent transfers, verification codes, and security-question answers with default suspicion.
  5. Verify suspicious messages through official websites, apps, or known phone numbers.[2]
  6. If you already clicked a link, change passwords, sign out of all devices, and check forwarding rules.

For more recovery steps, read What to do if you clicked a phishing link.


What should companies and teams strengthen?

Anti-phishing work cannot rely only on telling everyone to be careful.

DefensePurpose
Mandatory MFAReduces direct login risk after password theft
Two-person payment reviewBlocks CEO fraud and fake invoices
Email security gatewayFilters malicious links, attachments, and spoofed domains
Least privilegeReduces the blast radius of one compromised account
Drills and reporting channelHelps employees report quickly instead of hiding mistakes

CISA, NSA, FBI, and MS-ISAC joint guidance also emphasizes handling both credential theft and malware delivery paths.[3]

Summary

  • The shared pattern in phishing attacks is using trust to bypass technical defenses.
  • Large companies, government teams, public figures, and ordinary users can all become targets.
  • The most overlooked habit is out-of-band verification before transfers, password changes, or code sharing.
  • For individuals, password managers and MFA are the two highest-value steps.
  • For teams, least privilege, payment review, and fast reporting are just as important.

FAQ

Do phishing attacks happen only in email?

No. Phishing can happen through text messages, social media DMs, phone calls, QR codes, search ads, and fake support chats. CISA also lists texts, social media messages, and calls as common forms.[2]

Why do large companies still fall for phishing?

Large companies have many workflows, vendors, and permission layers. Attackers need only one person, one process gap, or one account without MFA to expand impact.

Should I reply to a suspicious email to confirm it?

No. Confirm through the official website, a known phone number, an internal system, or an in-person channel.

Can MFA stop phishing completely?

No, but it greatly reduces the risk of a stolen password being used directly. Stronger options include phishing-resistant authentication such as hardware security keys or passkeys.[11]

I clicked a phishing link but did not enter a password. Is that serious?

Still be careful. The link may record your device, IP address, and browser information, or try to download malware. Close the page, clear downloads, run a security scan, and watch for account anomalies.

If a phishing email has perfect grammar, can it still be fake?

Yes. AI tools make fluent phishing text easier to generate, so do not rely only on spelling or grammar.[2]

No. A VPN protects your network connection and reduces IP exposure, but it cannot decide whether a login page is fake. It is useful as one layer of privacy and public Wi-Fi protection; account safety still depends on MFA, password managers, and verification.


Disclaimer This article is for cybersecurity education and does not constitute legal, forensic, or incident-response advice. If an organization has been compromised, contact professional security teams and appropriate law-enforcement or regulatory channels.

AethoVPN publishes this guide, but a VPN connection cannot resolve the issue discussed here: phishing attacks.

Sources

[1]FBI Internet Crime Report 2024 [2]CISA Recognize and Report Phishing [3]CISA Phishing Guidance [4]U.S. DOJ Google and Facebook fraud case [5]FBI Sony Pictures update [6]CISA Ukraine power grid cyberattack analysis [7]CISA Colonial Pipeline ransomware advisory [8]U.S. DOJ GRU indictment [9]U.S. DOJ celebrity phishing case [10]U.S. DOJ Apple support impersonation case [11]NIST SP 800-63B Authentication [12]Crelan 2016 Annual Report [13]HKCERT Locky Ransomware Encrypts Victim Data [14]Amnesty International phishing attacks targeting journalists and activists

Sources checked 8 May 2026.


Related Articles:

Start your 3-day free trial

Sign up to experience all premium features at no cost.

*Available only to new users. Each user is limited to one trial.

Phishing attacks: 2026 Guide | AethoVPN