Cofense Intelligence reports a significant evolution in finance-themed phishing from Q1 2025 to Q1 2026, with threat actors shifting from urgency-driven subject lines to operational business language that mirrors routine financial workflows. By Q1 2026, 79% of finance-themed phishing campaigns used operational language rather than pressure tactics, making them harder to distinguish from legitimate correspondence and more likely to bypass SEGs. The campaigns leverage three main lure categories — New Business, Contracts in Progress, and Payments — and deliver credential phishing via embedded URLs and QR codes in PDF attachments.
Phishing Trends
1 post
When Routine Becomes the Threat: The Evolution of Finance-Themed Phishing