The devil is still in the email – but wearing a new mask
What happened
Business Security When phishing (messages that impersonate someone to obtain passwords or money) can increasingly pass familiar checks, avoiding or limiting the damage depends on how quickly your company can detect and contain the attack Tomáš Foltýn 28 Sep 2026 • , 6 min. read Many of today’s phishing attempts are no longer betrayed by poor grammar, a sketchy URL or a crude login page.
To be sure, it does still pay to look out for these red flags, but their absence doesn’t make a message legitimate. Modern social engineering schemes are increasingly designed to withstand scrutiny and to provide reassurance where an attack might once have left some giveaways.
They subvert legitimate workflows and reach employees mid-task, when their accounts are authenticated and any incoming requests for action feel like part of an ordinary working day. Some techniques go after live sessions themselves, with attackers shifting their focus from stealing passwords to stealing authentication tokens. These shifts are developing faster than many companies can come to grips with them.
Sources & evidence
- ESET WeLiveSecurity Primary / official
The devil is still in the email – but wearing a new mask ↗
https://www.welivesecurity.com/en/business-security/devil-email-wearing-new-mask/