Your gateway approved it. We read what it was built to do.
Every attack in this study had already cleared the secure email gateways these organizations were running, and reached the inbox anyway. We decoded 32,052 of them into their genome: the small set of facts that defines an attack even when its sender, its link, and its lure keep changing. Here is what that framework let us see about the mail slipping past detection today.
0
attacks that reached the inbox past existing defenses
0%
already passed SPF, DKIM, and DMARC
0
distinct genomes across the quarter
0
of them carry 78% of all volume
Methodology. Q2 2026. 32,052 attacks that reached the inbox past existing defenses, across multiple industries. Each one scored against three taxonomies: attack, evasion, and personalization.
The idea
Strip the disguise, and one thing doesn't change.
The sender, the link, the impersonated brand, the exact wording: these change from message to message, and they are meant to. Underneath them sits a structure that does not, because it is what makes the attack the attack. We call it the genome, and it is three facts. Here is a real vendor-fraud lure your gateway would deliver, read the way our platform reads it.
An email your gateway let through
Acme Logistics Billing
billing@acme-logistics.co
Updated banking details for Q3 invoice
SPF passDKIM passDMARC passreputation clean
✓ GATEWAY VERDICT: DELIVERED
So we read it ourselves
What is it asking for?
Move a real payment to a new bank account.
● Intent · Vendor / Invoice Fraud
How did it get in?
A look-alike domain on a hijacked reply thread, carrying hidden instructions meant to steer an AI reviewer.
It names a real vendor and a live invoice, timed to when payment is due.
● Personalization · Business Relationship + Business Event
The genome
Vendor-Invoice Fraud × lookalike domain + thread hijack × named vendor + live invoice
Two messages with the same three facts are the same attack, even when the brand, the wording, and the dollar amount all differ. That triple is the genome, and it is the part a signature can't keep up with.
The framework
Three questions. Three taxonomies.
Each axis of the genome is a formal taxonomy we apply to every message. Read them as the same three questions the demo just asked: what does the attacker want, how do they get in, and how do they earn the click. Hover any category to see what it covers.
● What they want
Attack
6 categories · 40+ subtypes
Credential HarvestingA working login or live session. Standard and spear phishing, AiTM, quishing, OAuth consent.Business Email CompromiseA fraudulent payment or data release. CEO fraud, vendor-invoice fraud, payroll diversion, thread hijacking.Malware DeliveryCode execution on the endpoint. Macro documents, container files, HTML smuggling, malicious links.Consumer FraudA consumer-grade payout. Advance-fee, counterfeit goods, sextortion, fake employment, malvertising.DisinformationBelief or market movement. Fabricated documents, narrative seeding, public-authority impersonation.Infrastructure AbuseDelivery capacity for the rest. Account hijack, relay abuse, domain-reputation hijack.
The most stable axis. The list of things a victim can be made to do is short, so intent changes least.
Organized by the defense each technique defeats, not by how it looks. The axis that shifts month to month.
● How they earn the click
Personalization
Corporate + personal, 62 data points
Organizational StructureReporting lines, approval and signatory chains. Who signs off on a wire above a threshold.Business RelationshipVendors, advisers, financial counterparties. A named supplier with an open purchase order.Business EventDeals, filings, cycle events, milestones. Quarter-end close, an announced acquisition.Professional IdentityTitle, mandate, functional scope. Authority to approve wires up to a stated limit.Personal & Life-EventThe person as an individual. Contact surface, social graph, and moments of change an attacker can time to.
The axis with the most room left, and the one whose cost is collapsing fastest as target data becomes cheap.
A real detection carries one attack tag and a stack of evasion and personalization tags. That stack is the genome.
Where the risk is
3.6% of the attacks carry almost all of the danger.
Volume and risk point in opposite directions. Priced in dollars against a FAIR loss model, the thin sliver of mail that actually moves company money carries nearly all of the modeled organizational exposure. Everything else is loud and close to harmless on the balance sheet.
Both bars below are the same group of messages: the ones built to move company money. The top bar counts them. The bottom bar prices them.
Counted as messages
0%of all attacks
Priced in dollars
98–99.7%of the dollar risk
One slice of mail, two very different sizes. It is a rounding error by count and almost the entire loss by dollars. A defense queue sorted by volume is sorted against the money.
Two front doors
Most of what lands is after the employee, not the company.
Business Email Compromise comes for the company's funds. Its consumer-grade counterpart, delivered to the work inbox, comes for the employee's own wallet, and it is the larger share of what arrives.
0%
target personal finances
Consumer-grade fraud aimed at the employee: fake billing, refunds, and callback scams. Loud, high-volume, and a rounding error on the company's balance sheet.
0%
of money-direct attacks aim at the wallet
Of the mail that goes straight for money, 93% hunts the individual, not company funds. The remaining sliver, Business Email Compromise, is where the organizational loss actually concentrates.
Top genomes
The loudest designs and the most dangerous ones barely overlap.
Twelve genomes carry 78% of all volume. But the designs that fill the queue are almost never the ones that move money. Ranked by volume, then by modeled dollars, the two lists are nearly disjoint, which is the whole case for pricing a queue in dollars, not counts.
Loudest by volumebroadcast · near-zero organizational risk
High volume, low danger. Consumer fraud aimed at the employee's wallet.
Most dangerous by modeled dollarstargeted · six-figure exposure each
1
Vendor / Invoice Fraud · Look-alike sender
look-alike domaincorporate targeting
2
Executive / CEO Fraud · Wire request
+ scanner evasioncorporate targeting
3
Business Advance-Fee · Deal pretext
content pretextcorporate targeting
4
Thread Hijacking · Reply-chain takeover
compromised accountcorporate targeting
5
Vendor / Invoice Fraud · Scanner-hardened
look-alike + scannercorporate targeting
A few dozen messages each, together carrying almost all the modeled organizational exposure.
Build detection against the right column first, even though the left column is where the noise is.
How it evolves
A small catalog that mutates instead of inventing.
Watched as a population, the threat behaves less like endless novelty and more like a family tree. New designs descend from old ones by single changes, the catalog barely turns over, and even the delivery trick migrates in the open.
0
459 designs. Twelve run the show.
The whole quarter reduces to 459 distinct genomes, and just 12 carry 78% of volume while wearing more than 730 brands on top. When a new design appears, 96% of the time it is a single mutation of one already in circulation.
96% one mutation away
Signatures chase 730 brands; the genome underneath stays countable.
0%
The catalog barely turns over.
Of the genomes active in April, 86% were still active in June, and genuinely new designs fell to under 2% of volume by June. This is an equilibrium, not a stream of invention.
April designs still active in June
Block today's set and a successor of similar size drifts up by single mutation.
Same lure, a new envelope.
Attackers did not change what the callback scam is, only how it arrives. Across the quarter the delivery channel migrated in plain sight, the mutate-not-invent pattern at the level of the envelope.
Phone-callback delivery34.1% → 7.1% ↓
Apr
Jun
Calendar-invite delivery4.6% → 16.8% ↑
Apr
Jun
Match the design, not the delivery trick, and the detection survives the swap.
<0%
Personalization is the next wave.
Fewer than 2% of attacks personalize today, and where they do it stays shallow. It is the one axis that is at once cheap, barely used, and rewarded, and it sits directly on top of the money-movement fraud that carries the risk.
personalized todayuntapped headroom
As AI collapses the cost of target data, this is where creativity heads next.
Why it matters
Why one or two gateways keep missing this.
Every attack in the study had already passed a secure email gateway, sometimes two stacked together. That is not a story about weak products. It is a story about what a gateway is built to match, and where modern attacks have moved.
0%
passed SPF, DKIM, and DMARC. The mail that carries the risk no longer looks suspicious, because attackers now send from infrastructure that authenticates. 94% on Google tenants · 74% on Microsoft.
No bad reputation
They send from compromised tenants, legitimate services, and look-alike domains they control, so the mail authenticates and carries clean reputation.
✕ reputation check clears
No bad indicator
The infrastructure is trusted and rotates constantly. By the time an indicator is known-bad, the operator has already moved to the next domain and mailbox.
✕ signature has nothing to match
No bad content
The payload is often just a plausible business request. It reads like ordinary correspondence, so content scanning and even intent classifiers pass it.
✕ looks like normal business
The takeaway
The surface is the disguise. The genome is the attack.
A dozen designs carry most of the volume while wearing hundreds of brands and burning through infrastructure by the hour. Match the surface and you are always a step behind. Match the genome, the intent plus the evasion plus the targeting, and the detection survives every domain the operator throws away. That is the part a gateway was never built to read, and it is the part that decides whether the money moves.
The full report
The methods, the models, and the full catalog sit behind this summary.
This page reports the findings. The Q2 2026 Phishing Genome study documents how they were derived: the FAIR risk decomposition, the labeling methodology, and the complete genome catalog. It is written to be reproduced and built against, and every figure is traceable to a released data file.
01
Dollar-risk model and priors
The FAIR loss decomposition, the Monte-Carlo configuration, and every prior, sufficient to reproduce the ranking against your own telemetry.
02
Detection backlog, ranked by exposure
Each money-movement genome mapped to a concrete signal set, ordered by modeled dollar exposure rather than by volume.
03
The complete taxonomies
All 44 attack subtypes, 36 evasion techniques, and 62 personalization data-points, each with a working definition.
04
The full genome catalog
Top 20 designs by volume and top 20 by modeled exposure, as cards with month-by-month composition.
05
Operators, lifecycle, and platform
Infrastructure-linked campaign clustering, genome persistence and decline across the quarter, and within-platform authentication rates by provider.
06
Methods and external corroboration
Dual-independent labeling and agreement, catalog-saturation estimation, and where the findings align with Proofpoint, FBI IC3, and Verizon DBIR.
Q2 2026 Phishing Genome study
39 pages · PDF · StrongestLayer Threat Research
Thanks — opening the study now.
Something went wrong. Please try again.
Work email only — free providers (gmail, outlook, yahoo, etc.) aren't accepted.