TL;DR: Microsoft Teams attacks rose 41% in six months, calendar invite phishing increased 49%, prompt injection can reduce time-to-compromise to four seconds, and 84.4% of successful phishing now passes DMARC, according to Knowbe4’s 2026 Phishing Threat Trends Report. The findings show identity verification, inbox trust, and MFA assumptions are all being industrialised faster than many security programmes can adapt.
NHIMG editorial — based on content published by KnowBe4: 2026 Phishing Threat Trends Report, Vol. 7
By the numbers:
- Why Microsoft Teams attacks have surged by 41% in just six months
- Why 84.4% of all successful phishing attacks now pass DMARC
Questions worth separating out
Q: What breaks when phishing can steal a valid session instead of just a password?
A: When phishing steals a valid session, MFA no longer guarantees safety because the attacker inherits the authenticated state rather than replaying credentials.
Q: Why do collaboration platforms complicate phishing defence?
A: Collaboration platforms blend internal staff, vendors, and guests into one trusted-looking interface, which makes malicious requests look routine.
Q: How can security teams govern AI assistants that summarise inbox content?
A: Security teams should classify AI assistants as governed intermediaries with limited read, write, and action permissions.
Practitioner guidance
- Harden session controls against reverse-proxy phishing Prioritise phishing-resistant authentication, device binding, and token theft detection so a valid MFA challenge does not automatically produce a reusable session.
- Restrict AI assistants in identity-sensitive workflows Limit what inbox and productivity assistants can read, summarise, forward, or execute when messages involve credentials, approvals, access requests, or privileged operations.
- Extend phishing controls into collaboration platforms Apply message validation, link inspection, and user coaching to Microsoft Teams, calendar invites, and similar platforms rather than concentrating only on email.
What's in the full report
KnowBe4's full report covers the operational detail this post intentionally leaves for the source:
- Breakdown of the Teams, calendar, and reverse-proxy attack patterns behind the headline trends
- The report’s quantitative evidence on prompt injection speed, DMARC bypass, and channel-specific abuse
- Additional context on how attackers are industrialising multi-channel phishing across inbox and collaboration workflows
- Source examples and trend framing that help teams compare these patterns against their own telemetry
👉 Read KnowBe4's 2026 Phishing Threat Trends Report on AI agent abuse and MFA bypass →
AI agent abuse, Teams phishing, and MFA bypass: are controls keeping up?
Explore further
AI-assisted phishing is becoming an identity governance problem, not just a user-awareness problem. When an attacker can steer an inbox assistant or hijack a session token, the control failure is not limited to user error. It exposes gaps in how organisations govern trust-bearing workflows, session boundaries, and AI-mediated access. Identity teams should therefore treat phishing as a governance and assurance issue across humans, NHIs, and AI assistants.
A question worth separating out:
Q: Who is accountable when phishing-resistant MFA is bypassed through fallback methods?
A: Accountability sits with the identity programme that approved the downgrade path, not just the user who clicked through it. If policy still permits weaker methods, the organisation has left the control boundary open. Frameworks such as NIST SP 800-63 and zero trust guidance expect assurance to be maintained across the full authentication journey.
👉 Read our full editorial: Phishing trends show AI agent abuse and MFA bypass scaling fast