Mobile Phishing 2026: Why Email Security Leaves You Exposed

Mobile phishing attack

Last updated 11 September 2026

Key takeaways

  • Verizon’s 2026 Data Breach Investigations Report found the human element present in 62% of breaches, and reported that engagement rates for mobile-based phishing simulations ran 40% higher than for email simulations.
  • Phishing accounted for 44% of the AI-assisted initial access techniques Verizon identified in 2026, the largest single category.
  • ENISA has documented phishing-as-a-service platforms running campaigns directly over mobile messaging channels including iMessage and RCS.
  • Multi-factor authentication no longer closes the gap. Adversary-in-the-middle kits let the victim complete MFA successfully and steal the resulting session token.
  • Most organisations have no record of mobile network activity, which means no way to answer the question “did anyone click” after an attack.

Why are attackers targeting mobile instead of email?

Every security team understands phishing. Few underestimate it. Enterprise email has absorbed years of sustained investment in gateway filtering, link rewriting, attachment detonation and user reporting, and that investment produced results.

Attackers responded the way attackers always do. They moved to a channel where none of that spending applies.

Verizon’s 2026 Data Breach Investigations Report, its nineteenth edition, analysed more than 31,000 security incidents and over 22,000 confirmed breaches across 145 countries. It found the human element present in 62% of breaches, up from 60% the previous year. More pointedly for anyone responsible for a mobile fleet, it reported that engagement rates for mobile-based phishing simulations were 40% higher than for traditional email phishing simulations. Verizon’s own summary of the finding is blunt: organisations have got better at spotting phishing emails, so attackers have moved to our pockets.

That is the whole story of the last decade of mobile phishing in one sentence.

What channels do mobile phishing attacks use?

On a laptop, phishing arrives by email. On a phone, it arrives from everywhere.

SMS and RCS: Text remains the highest-trust channel most employees have, largely because organisations trained them to trust it. Banks, IT helpdesks and identity providers all use SMS for verification codes and password resets. That accumulated trust is exactly what attackers borrow.

Messaging apps: WhatsApp, Signal, Telegram and iMessage all carry links, all render them on a small screen, and none pass through an enterprise mail gateway. We looked at why the messaging app is the most dangerous app on your phone.

QR codes: A QR code moves a link from a controlled environment onto a personal device in a single scan, with the destination URL hidden until after the user has already committed. Our analysis of how QR codes sidestep cyberdefences explains the mechanism, and we walked through a real example in uncovering a sophisticated QR code phishing attack.

Collaboration tools: Teams and Slack messages from compromised external accounts carry an implicit legitimacy that email from an unknown sender does not.

Voice: Increasingly, a text message is only the opening move. The message asks the recipient to call a number, and a live operator completes the social engineering.

ENISA has tracked this professionalisation directly. Its Threat Landscape reporting documented the Lucid phishing-as-a-service platform expanding to support campaigns over mobile messaging services including iMessage and RCS, reaching targets across 88 countries. Mobile is no longer an improvised channel for phishing. It is a productised one.

Mobile phishing is also largely indifferent to operating system. These attacks depend on a person tapping a link, not on executing code inside an app, which is why iOS fleets are no safer than Android ones.

How is AI changing mobile phishing attacks?

There are many types of mobile phishing. Awareness training has spent fifteen years teaching people to look for clumsy grammar, mismatched domains and generic greetings. Those signals are largely gone.

Verizon’s 2026 report found that phishing accounted for 44% of AI-assisted initial access techniques, the single largest category. The report also observed threat actors using generative AI assistance across a median of 15 distinct techniques within documented campaigns, with some campaigns using it across 40 to 50.

On a phone, this compounds a problem that already existed. The smaller form factor hides the signals a careful reader would otherwise catch, truncated sender addresses and shortened URLs among them. Mobile use is faster, more fragmented and more distracted than desk work. A well-written lure arriving in that context has a materially better chance than the same lure sitting in an inbox on a monitor.

Why doesn’t multi-factor authentication stop mobile phishing?

MFA no longer stops mobile phishing because adversary-in-the-middle attacks steal the session token rather than the credentials. The most common objection to any mobile phishing argument is that credentials alone are no longer enough, because multi-factor authentication protects the account.

That assumption no longer holds.

Adversary-in-the-middle phishing works by relaying the victim through the real login page. The victim enters their password, completes their MFA challenge, and authenticates successfully, because the authentication is genuine. The attacker sits in the middle as a reverse proxy and takes the session token the identity provider issues afterwards. No factor was defeated. The result of the factor was stolen.

ENISA has documented AiTM kits mimicking Microsoft 365 sign-in portals circulating as commodity tooling. We set out how Corrata addresses this on our AiTM Protection page.

This has a specific consequence for mobile. The argument that SMS is trusted because it carries verification codes now cuts both ways. The channel employees have been taught to trust for authentication is the same channel being used to defeat it.

The visibility problem: nobody can answer “did anyone click”

The gap in prevention is well understood. The gap in detection gets far less attention and is often the more damaging of the two.

Most enterprise security teams have no log of mobile device network activity. Mobile device management and unified endpoint management platforms, Intune and Workspace ONE included, report on device state, configuration, compliance and installed applications. They do not report on where the device went.

Consider what that means in practice. Your CEO receives a targeted message impersonating the CFO and forwards it to you. The natural first question is whether anyone else received it, and whether anyone acted on it. Without any record of mobile network activity, there is no way to search the fleet for the indicators of compromise. There is no way to know.

This has moved from an operational irritation to a regulatory one. Under NIS2, in-scope organisations face an early warning obligation within 24 hours of becoming aware of a significant incident, followed by a fuller notification within 72 hours. A blind spot that prevents you determining scope is a blind spot that prevents you meeting a deadline.

Why the traditional fix does not suit mobile

The established way to extend enterprise protection to mobile devices is to route their traffic back to a central gateway, using a VPN or a proxy, and apply inspection there.

For mobile fleets, this approach carries three problems that have only become more acute.

Privacy: Backhauling all traffic from a device an employee also uses personally means the employer inspects that personal traffic. This is uncomfortable in any jurisdiction and difficult to defend under GDPR. It is also the reason mobile security rollouts stall.

Performance and reliability: Every request takes a detour. Every device depends on a single control point. If the gateway is unavailable, the fleet is affected.

Data residency: Routing European employees’ traffic through infrastructure outside the EU raises questions that European organisations are increasingly required to answer in procurement.

How does on-device mobile phishing protection work?

Corrata takes a different route. Rather than sending traffic to a gateway, protection runs on the device itself.

Corrata inspects 100% of network traffic on the device without routing it through a cloud relay. Connections to malicious destinations are blocked in real time. Because network traffic inspection happens locally, personal traffic is never routed to the employer or to a third party, which addresses the privacy objection rather than managing it. Because there is no central chokepoint, there is no single point of failure and no latency penalty from backhauling.

The same mechanism that blocks the connection also records it. Security teams get fleet-wide visibility of mobile network activity, which turns “did anyone click” from an unanswerable question into a search.

What we see in the field

This is not theoretical for us. Corrata’s own analysts have taken apart live campaigns using exactly these techniques, including a QR code phishing attack that used a legitimate cloud service to host its landing page in order to sail past reputation-based filtering. Independent testing puts the share of threats Corrata detects that other solutions miss at 23%.

Closing the gap

Mobile phishing persists because of a structural mismatch rather than a lack of effort. Enterprise security was built around a perimeter that mobile devices sit outside, and around an inbox that mobile attacks never pass through. Awareness training helps at the margins. It cannot be the primary control against an AI-written lure arriving by text on a small screen, halfway through a working day.

Three questions are worth putting to your current setup:

  1. When an employee receives a phishing link by SMS, WhatsApp or QR code, what actually stops them reaching the destination?
  2. When a session token is stolen through an adversary-in-the-middle page, what detects it?
  3. When someone forwards you a suspicious message tomorrow morning, how long does it take to establish whether anyone else in the organisation clicked it?

If the honest answer to any of those is “nothing”, or “weeks”, the gap is still open.

Next steps

Our Guide to Mobile Phishing sets out how attacks are reaching employees across SMS, messaging apps and QR codes, and what closes each channel.

To see how Corrata handles this on your own fleet, request a demo.

Running a fleet of up to 250 devices? Corrata Essentials delivers the same protection, packaged for smaller teams.

Mobile Phishing Protection: Frequently asked questions

Smishing is phishing delivered by SMS or text message. Mobile phishing is the broader category, covering SMS, messaging apps, QR codes, mobile browsers, social platforms and in-app links. All smishing is mobile phishing. Not all mobile phishing is smishing.

No. Secure email gateways inspect messages passing through corporate mail infrastructure. A phishing link delivered by SMS, WhatsApp or QR code never touches that infrastructure, so no email control applies to it.

Not reliably. Adversary-in-the-middle phishing kits let the victim complete MFA legitimately and then steal the resulting session token. The authentication succeeds, which is precisely why nothing flags it.

Not meaningfully. Mobile phishing relies on a user tapping a link rather than on executing code, so it works largely independently of the operating system.

No. MDM and UEM platforms report on device configuration, compliance and installed applications. They have no visibility of the network connections a device makes, which is where phishing activity is visible.

Only by holding a record of mobile network activity. Without one there is no way to search the fleet for indicators of compromise after an attack is identified.

Related Resources

Related Resources

Read the latest news on endpoint threat detection and response from the experts.

Read the latest news on endpoint threat detection and response from the experts.

  • types of malware
    blog

    Blog

    15 Different Types of Malware and What They Do

    Read more
  • Mobile Malware Detection Header-selection
    blog

    Blog

    Mobile Malware Detection on Work Phones

    Read more
  • AI Scams
    blog

    Blog

    AI Wrote the Scam Text, and it is Better Than the Last One

    Read more
  • NIS2 and DORA
    blog

    Blog

    What NIS2 and DORA mean for the device in your pocket

    Read more