TL;DR: Vishing attacks rose 449%, phishing sent from legitimate platforms increased 70%, and attacks bypassing secure email gateways climbed 38%, according to KnowBe4’s 2025 Phishing Threat Trends Report, Vol. 6, highlighting how social engineering now blends voice, brand abuse, and trusted delivery paths. That combination weakens traditional email-only defences and raises the value of identity-aware controls.
At a glance
What this is: This report tracks how phishing is shifting toward voice phishing, legitimate-platform abuse, and email delivery that bypasses secure gateways.
Why it matters: It matters because security teams need to align email, identity, and awareness controls with attacker use of trusted brands, legitimate platforms, and human trust.
By the numbers:
- Why vishing attacks have increased by 449% in 2025
- Why there’s been a 70% increase in attacks sent from legitimate platforms
- What’s driving the 38% increase in attacks bypassing secure email gateways
👉 Read KnowBe4's 2025 Phishing Threat Trends Report on vishing, platform abuse, and SEG bypass
Context
Phishing is no longer limited to obvious spoofed emails. The current governance gap is that attackers increasingly use voice phishing, compromised brands, and legitimate delivery platforms to exploit trust before technical controls or user awareness can intervene. That shifts the problem from simple message filtering to identity, brand, and session trust management.
For IAM and security teams, the relevance is direct. When attackers use trusted brands or legitimate platforms, they are effectively borrowing identity context to improve credibility, evade email controls, and accelerate follow-on compromise. That makes the report relevant not only to email security but also to identity verification, access governance, and fraud-aware defence.
Scattered Spider’s activity is a typical example of this broader pattern, not an outlier. The attack surface is moving toward social engineering that uses trusted channels, which means practitioner defences need to move just as quickly.
Key questions
Q: How should security teams reduce vishing success against privileged users?
A: Security teams should harden the workflows that vishing targets first: password resets, MFA resets, help desk overrides, and privileged support requests. Require out-of-band verification, separate approval paths for high-risk users, and telemetry that flags unusual recovery activity. The goal is to make persuasion insufficient on its own, even when the attacker sounds legitimate.
Q: Why do legitimate-platform phishing campaigns bypass traditional controls so often?
A: They bypass traditional controls because many defences assume malicious delivery comes from suspicious infrastructure. When attackers use trusted SaaS accounts, compromised brands, or approved sending services, reputation-based filters become less reliable. Organisations need account behaviour monitoring, identity verification, and post-delivery detection to catch what gateway controls cannot see.
Q: What do organisations get wrong about secure email gateways and phishing defence?
A: The main mistake is treating the secure email gateway as the primary trust boundary. Gateways help, but they do not verify the human behind the request, the legitimacy of a support interaction, or the safety of a recovered account. Phishing defence needs identity-aware controls, not just better filtering.
Q: What should organisations do when helpdesk password recovery is a phishing target?
A: Organisations should unify helpdesk and self-service recovery under one verification standard, then require all exceptions to be logged and reviewed. The aim is to remove split trust models, because attackers often target the channel with the weakest identity proofing and the most pressure-driven operators.
Technical breakdown
Why vishing works as an initial access path
Vishing is voice-based social engineering used to persuade a target to reveal credentials, approve access, or bypass a control. Unlike email phishing, it exploits real-time interaction, urgency, and human uncertainty, which makes it effective against help desks, service desks, and employees with elevated access. Once an attacker has a convincing pretext, the path to account takeover often depends less on malware than on procedural weakness. In IAM terms, the attack succeeds where identity proofing, call-back verification, and step-up authentication are weak or inconsistently applied.
Practical implication: strengthen out-of-band verification for password resets, MFA resets, and privileged access requests.
How legitimate-platform abuse changes phishing detection
When attackers send phishing from legitimate platforms, they are not necessarily spoofing infrastructure. They are abusing trusted SaaS or cloud delivery paths, stolen accounts, or misused tenant reputations to increase deliverability and reduce suspicion. This creates a governance problem because filtering based on sender reputation alone becomes less effective. The security boundary shifts toward content inspection, identity assurance for sending accounts, and behavioural detection across mail, cloud, and collaboration tooling. Secure email gateways can reduce exposure, but they cannot fully solve trust in a compromised legitimate sender.
Practical implication: inspect account behaviour and tenant reputation, not just email headers and domain reputation.
Why SEG bypass matters to identity and fraud teams
A secure email gateway is designed to detect and block malicious mail before it reaches the user. But if the attacker uses a trusted platform, a compromised account, or a delivery route the gateway cannot fully inspect, the message can bypass the expected control layer. That matters for identity teams because the attacker’s real objective is often credential theft, session takeover, or onboarding of a fraudulent trust relationship. The control gap is not only filtering failure. It is the assumption that inbound email security can stand alone without identity verification and user authentication hardening.
Practical implication: pair mail filtering with identity controls that reduce the value of stolen credentials and session tokens.
Threat narrative
Attacker objective: The attacker’s objective is to gain trusted access pathways that increase deliverability, credential capture, and account takeover opportunities.
- Entry occurs through vishing or trusted-platform phishing that convinces a user or help desk to reveal credentials or approve access.
- Escalation follows when the attacker reuses those credentials, resets authentication factors, or leverages a compromised brand or account to expand trust.
- Impact is achieved through account takeover, broader campaign delivery, or downstream intrusion enabled by identity trust abuse.
NHI Mgmt Group analysis
Trusted-channel abuse is now a core phishing governance problem. The report shows that attackers are no longer relying only on malicious links and spoofed domains. They are leveraging voice, legitimate platforms, and brand trust to bypass the first line of defence. For practitioners, that means phishing defence has become an identity assurance problem as much as a mail security problem.
Identity verification is becoming a control boundary for email compromise. When attackers can impersonate a brand or socially engineer a support interaction, the decisive control is not message filtering alone. It is whether the organisation can verify the person, account, or request before access is granted. This is where IAM, PAM, and fraud controls converge, especially for reset workflows and privileged requests.
Brand impersonation creates a verification trust gap. That gap is the space between what a user believes is legitimate and what the security stack can actually prove. In practice, attackers exploit that gap to move from persuasion to persistence. Security teams should treat trusted-brand abuse as a governance issue, not just a training issue.
Email security must be evaluated as part of a broader identity programme. SEG bypass statistics matter because they show the limit of control layers that assume the sender is the only trust anchor. Modern phishing campaigns use delivery context, human trust, and identity deception together. The practitioner takeaway is to align email security, identity proofing, and privileged workflow controls under one risk model.
What this signals
Phishing programmes are converging with identity assurance programmes. As vishing and legitimate-platform abuse grow, the practical boundary is no longer just inbox filtering. Teams need to decide where verification lives, how recovery is approved, and what telemetry proves that a request is genuine before access changes are made.
Verification trust gap: the gap between user trust in a message or call and the organisation’s ability to prove the request is legitimate is now a measurable control problem. That gap affects identity verification, help desk security, and privileged access workflows, so practitioners should align recovery controls with identity telemetry and support auditability.
The broader signal is that attackers are turning the user, the help desk, and the collaboration platform into an integrated access path. Security teams should expect more campaigns that blend social engineering with session abuse, and they should map those paths to identity controls rather than treating them as isolated email events.
For practitioners
- Harden reset and recovery workflows Require stronger verification for password resets, MFA resets, and help desk account recovery, especially for privileged users and support staff. Use step-up checks that do not depend on the same channel under attack. Link this to your NHI Lifecycle Management Guide where service accounts or shared identities are involved.
- Review trusted-platform abuse detection Add detections for suspicious use of legitimate platforms, unusual tenant behaviour, and anomalous sending patterns. Do not rely only on domain reputation or attachment scanning. Align the controls with the MITRE ATT&CK Enterprise Matrix for initial access and credential access mapping.
- Tie phishing response to identity telemetry Correlate email, identity provider, and help desk activity so that a suspicious message is not treated as an isolated mail event. Look for resets, new device enrolment, session anomalies, and unusual privilege requests following delivery. Use the 52 NHI Breaches Analysis to benchmark identity-driven intrusion patterns.
- Segment privileged support paths Separate support workflows for high-risk identities from routine user assistance. Require independent approval for factor changes, enforce call-back verification, and limit who can override recovery controls. For deeper NHI governance context, review the Ultimate Guide to NHIs , Key Challenges and Risks.
Key takeaways
- Vishing, legitimate-platform abuse, and SEG bypass show that phishing has become an identity trust problem, not just a mail filtering problem.
- The report’s figures point to a sharp shift in attacker behaviour, with voice, brand impersonation, and trusted delivery paths doing more of the work.
- Practitioners should harden recovery workflows, verify high-risk requests out of band, and correlate email events with identity telemetry.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0001 , Initial Access; TA0006 , Credential Access | The report centres on social engineering and credential capture. |
| NIST CSF 2.0 | PR.AC-1 | Phishing defence depends on identity assurance and access control. |
| NIST SP 800-53 Rev 5 | IA-2 | Authentication safeguards are central to resisting phishing-driven account takeover. |
| CIS Controls v8 | CIS-6 , Access Control Management | The article highlights how access workflows are exploited after trust is gained. |
| NIST AI RMF | GOVERN | Identity-aware phishing response needs accountability for risk decisions and controls. |
Strengthen identity verification and access approval controls where phishing can trigger account changes.
Key terms
- Vishing: Voice phishing is a social engineering technique that uses phone calls or voice channels to persuade a target to reveal information or approve access. It succeeds by exploiting trust, urgency, and procedural shortcuts, often bypassing technical controls that would have stopped a direct login attack.
- Secure Email Gateway: A secure email gateway is a control layer that inspects email before it reaches users and can also inspect outbound mail. It filters malicious content, enforces policy, and reduces exposure to phishing, malware, and data leakage, but it does not replace identity governance or account monitoring.
- Identity verification: Identity verification is the process of confirming that a user, workload, or agent is the entity it claims to be before access is granted. In AI-heavy environments, that verification must include the requester, the system acting on its behalf, and the sensitivity of the action.
- Impersonation: Impersonation is a controlled administrative action that lets an authorised operator assume a user context for debugging or support. In a well-governed setup it preserves audit logging, limits exposure of credentials, and keeps production authentication separate from local troubleshooting.
What's in the full report
KnowBe4's full report covers the operational detail this post intentionally leaves for the source:
- The report's scenario discussion of what happens after a user responds to vishing.
- The broader breakdown of Scattered Spider's campaign methods against global retail giants.
- The report's full stat set on legitimate-platform abuse and secure email gateway bypass.
- The original research context behind the 2025 phishing trend data and how it was compiled.
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, secrets management, and workload identity with a practitioner focus. It is designed for security teams building stronger identity controls across human, machine, and agentic environments.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org