TL;DR: Microsoft Teams attacks rose 41% in six months, calendar invite phishing increased 49%, prompt injection can reduce time-to-compromise to four seconds, and 84.4% of successful phishing now passes DMARC, according to Knowbe4’s 2026 Phishing Threat Trends Report. The findings show identity verification, inbox trust, and MFA assumptions are all being industrialised faster than many security programmes can adapt.
At a glance
What this is: This report tracks how phishing is shifting into AI-assisted inbox abuse, multi-channel collaboration attacks, and reverse-proxy MFA bypass, with a standout finding that prompt injection can collapse compromise time to seconds.
Why it matters: It matters because IAM, PAM, and identity verification teams now have to defend against attacks that exploit trusted workflows, not just passwords, and those attacks increasingly involve AI systems and human identities together.
By the numbers:
- Why Microsoft Teams attacks have surged by 41% in just six months
- What’s driving the surge in Calendar Invite Phishing, which has increased by 49% as attackers move to the quiet sanctuary of your schedule
- Why 84.4% of all successful phishing attacks now pass DMARC
👉 Read KnowBe4's 2026 Phishing Threat Trends Report on AI agent abuse and MFA bypass
Context
Phishing is no longer limited to malicious emails that ask a user to click a link. The current problem is trust abuse across email, collaboration tools, calendar systems, and AI assistants that summarise or act on messages. For identity teams, that means the control boundary now extends beyond login events into the integrity of the workflow itself, including how humans, service accounts, and AI agents consume and relay information.
The report’s core message is that attackers are industrialising social engineering and using AI to compress decision time. That creates a genuine intersection with identity governance because the same trust assumptions that protect human users also govern non-human identities, delegated access, and AI-mediated actions. In this context, the organisation’s starting position is typical rather than exceptional: most enterprises still treat phishing as a user-awareness issue when it has become an identity and workflow integrity problem.
Key questions
Q: What breaks when phishing can steal a valid session instead of just a password?
A: When phishing steals a valid session, MFA no longer guarantees safety because the attacker inherits the authenticated state rather than replaying credentials. That breaks assumptions in access reviews, anomaly detection, and many conditional-access policies. Teams need controls that bind sessions to devices, detect token replay, and treat session abuse as a distinct identity threat.
Q: Why do collaboration platforms complicate phishing defence?
A: Collaboration platforms blend internal staff, vendors, and guests into one trusted-looking interface, which makes malicious requests look routine. That weakens user scrutiny and increases click likelihood. Defenders should treat shared threads as a governed trust boundary and restrict how external identities can place content there.
Q: How can security teams govern AI assistants that summarise inbox content?
A: Security teams should classify AI assistants as governed intermediaries with limited read, write, and action permissions. They should restrict access to sensitive threads, block execution on identity-related requests, and monitor for prompt injection patterns. If the assistant can misread or obey malicious content, it becomes part of the attack path.
Q: Who is accountable when phishing-resistant MFA is bypassed through fallback methods?
A: Accountability sits with the identity programme that approved the downgrade path, not just the user who clicked through it. If policy still permits weaker methods, the organisation has left the control boundary open. Frameworks such as NIST SP 800-63 and zero trust guidance expect assurance to be maintained across the full authentication journey.
Technical breakdown
Reverse proxies and MFA bypass in modern phishing chains
Reverse proxy phishing sits between the user and the real login page, relaying credentials, session cookies, and challenge responses in real time. That means the attacker does not need to break MFA in the abstract. They only need to capture a valid session after the user completes authentication. This is why token theft and session hijacking have become more important than password guessing. The control failure is often not weak authentication itself, but the absence of device binding, phishing-resistant authentication, and session-level anomaly detection.
Practical implication: treat session theft as a first-class identity threat, not only failed logins.
Machine-speed prompt injection against AI inbox helpers
Prompt injection works when untrusted content influences how an LLM interprets instructions, priorities, or output. In inbox and productivity assistants, that can turn a message into a hidden control channel that changes what the AI extracts, suppresses, or forwards. The risk is not that the model becomes conscious or autonomous, but that it can be steered into violating the user’s intent within a single interaction. For identity programmes, this is an NHI governance issue because AI assistants are acting as credential-adjacent intermediaries inside business workflows.
Practical implication: restrict what AI assistants can read, summarise, and act on inside identity-sensitive workflows.
Why collaboration tools expand the identity attack surface
Microsoft Teams, calendar systems, and similar collaboration platforms now act as trust amplifiers. A message inside these systems often carries more credibility than a plain external email, which helps attackers bypass user suspicion. Calendar invite phishing works because the event object itself becomes the lure, and the user’s routine trust in scheduling tools lowers scrutiny. The broader issue is that identity verification is being abused through context, not just credentials. Security teams should therefore view collaboration platforms as identity-bearing channels with their own governance requirements.
Practical implication: apply phishing controls and content validation to collaboration platforms, not only email.
Threat narrative
Attacker objective: The attacker wants to capture trusted access paths and weaponise them for account takeover, session hijacking, and faster multi-channel social engineering.
- Entry begins when attackers place malicious content into trusted channels such as email, Teams, or calendar invites, or use reverse proxies to stand up fake login flows.
- Escalation occurs when the victim completes authentication or interacts with an AI assistant, giving the attacker valid session material or manipulated workflow output.
- Impact follows when stolen sessions, bypassed MFA, or misled AI summaries are used to access accounts, move laterally, or accelerate follow-on phishing and fraud.
NHI Mgmt Group analysis
AI-assisted phishing is becoming an identity governance problem, not just a user-awareness problem. When an attacker can steer an inbox assistant or hijack a session token, the control failure is not limited to user error. It exposes gaps in how organisations govern trust-bearing workflows, session boundaries, and AI-mediated access. Identity teams should therefore treat phishing as a governance and assurance issue across humans, NHIs, and AI assistants.
Machine-speed compromise creates a new named concept: workflow trust collapse. The report’s four-second compromise claim captures how quickly a trusted interaction can be converted into attacker control. Once a workflow collapses at that speed, traditional review, escalation, and approval cycles arrive too late. Practitioners should redesign controls around pre-action validation and session-level resistance, not post-event detection alone.
Calendar and collaboration abuse shows that identity now extends into the message layer. Teams, invites, and inbox summaries are no longer neutral transport channels. They are identity-bearing surfaces where attackers can shape perception before any authentication event is challenged. Practitioners should align email security, collaboration security, and IAM governance instead of managing them as separate domains.
Reverse proxy MFA bypass validates the shift from credential theft to session theft. Passwords and second factors still matter, but they are no longer the main prize. Attackers increasingly want the authenticated session because it bypasses the user journey entirely. Security programmes should reweight their risk models toward token protection, device binding, and continuous session evaluation.
Phishing metrics should now be read as control failure indicators, not just threat volume indicators. A 41% rise in Teams attacks or a 49% rise in calendar invite abuse matters less as a headline than as evidence that trusted channels are absorbing attacker innovation faster than policies are adapting. The practical conclusion is clear: identity governance must expand into collaboration, AI, and session controls.
What this signals
Phishing programmes are converging with identity governance because attackers now target the trust fabric around users, not just the mailbox. The practical signal for security teams is that collaboration security, IAM, and AI oversight need shared telemetry. The control question is no longer whether a message was malicious. It is whether the workflow that carried it could be trusted at all.
Workflow trust collapse: that is the pattern enterprises need to watch. Once an attacker can influence a calendar invite, a Teams message, or an AI summary in seconds, the organisation’s response speed becomes the limiting factor. Teams should map these channels to the same risk logic they use for privileged access and session integrity.
For identity programmes, the next step is to integrate session protection, phishing-resistant authentication, and AI assistant governance into one operating model. If those controls remain separate, attackers will continue to move through the seams. That is also why the wider NHI picture matters, because compromised service accounts and tokens often become the downstream consequence of a human trust failure.
For practitioners
- Harden session controls against reverse-proxy phishing Prioritise phishing-resistant authentication, device binding, and token theft detection so a valid MFA challenge does not automatically produce a reusable session. Focus especially on administrative and high-impact user populations where session hijack has the highest blast radius.
- Restrict AI assistants in identity-sensitive workflows Limit what inbox and productivity assistants can read, summarise, forward, or execute when messages involve credentials, approvals, access requests, or privileged operations. Treat the assistant as a governed intermediary, not a passive convenience feature.
- Extend phishing controls into collaboration platforms Apply message validation, link inspection, and user coaching to Microsoft Teams, calendar invites, and similar platforms rather than concentrating only on email. Attackers are moving into quieter channels because users grant them default trust.
- Reassess identity telemetry for session theft Instrument for impossible travel, token reuse, device mismatch, and suspicious session duration so compromise can be detected after authentication rather than only at the login boundary. Use these signals to identify when a normal sign-in has become an active intrusion.
Key takeaways
- AI-assisted phishing is turning inboxes, chats, and calendar workflows into identity attack surfaces that conventional awareness training cannot fully protect.
- The report’s metrics show attackers are compressing time to compromise and shifting into channels that users already trust, which makes detection and session protection more important than ever.
- Security teams should respond by hardening sessions, governing AI assistants, and extending phishing controls into collaboration platforms where identity trust is being exploited.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | The report covers prompt injection against AI assistants and workflow abuse. | |
| NIST CSF 2.0 | PR.AC-4 | The article is about identity assurance and access control failure across trusted channels. |
| NIST SP 800-53 Rev 5 | IA-2 | MFA bypass and session hijacking directly implicate authentication controls. |
| NIST AI RMF | MANAGE | AI inbox helpers and prompt injection create governance and risk-management concerns. |
| MITRE ATT&CK | TA0006 , Credential Access; TA0001 , Initial Access | Reverse proxies and phishing aim to capture credentials and sessions at initial access. |
Place AI assistants under managed approval, scope, and monitoring rules before they touch identity-sensitive workflows.
Key terms
- Reverse Proxy Phishing: A phishing method where an attacker places an intermediary server between the user and the real login service. The user signs in on a fake site that relays the authentication flow, allowing the attacker to capture live credentials and often MFA tokens during the legitimate session.
- Prompt Injection (Agentic): An attack where malicious instructions are embedded in content that an AI agent reads — causing the agent to execute unintended actions using its own legitimate credentials. A primary vector for agent goal hijacking and identity abuse.
- Session Theft: Session theft is the reuse of an already authenticated access context, usually through stolen cookies, tokens, or browser artifacts. It is dangerous because the attacker may not need to know the password at all. For IAM and NHI governance, it means authentication success cannot be treated as proof of legitimate intent.
- Collaboration Channel Abuse: The misuse of trusted collaboration tools such as Teams, calendar systems, and internal messaging to deliver phishing or social engineering payloads. These channels amplify trust, reduce user suspicion, and can carry identity-related abuse into everyday workflows.
What's in the full report
KnowBe4's full report covers the operational detail this post intentionally leaves for the source:
- Breakdown of the Teams, calendar, and reverse-proxy attack patterns behind the headline trends
- The report’s quantitative evidence on prompt injection speed, DMARC bypass, and channel-specific abuse
- Additional context on how attackers are industrialising multi-channel phishing across inbox and collaboration workflows
- Source examples and trend framing that help teams compare these patterns against their own telemetry
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, secrets management, and workload identity. It helps security practitioners connect identity controls to the broader trust and access problems this report highlights.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org