Mobile Phishing Attacks Hit 2.5 Million In A Year As AI-Assisted Attacks on Employee Devices Surge 

Zimperium's data shows malicious link clicks up 400% year over year, with SMS, QR-code, and PDF lures drawing attackers toward channels sitting outside the enterprise perimeter.

Published on Jul 29, 2026

Enterprise mobile devices are now the front line of AI-assisted phishing, according to a new mobile threat report published today.

Zimperium detected more than 2.5 million phishing attacks on employee mobile devices over the last twelve months, with malicious link clicks up 400% and the number of devices where an employee clicked at least one up 151%.

Phishing events overall climbed 460% between early 2024 and May 2026, and mobile-targeted phishing succeeds around 40% more often than traditional email phishing.

Other research has linked AI with this spike. KnowBe4 recently found that 86% of phishing campaigns are now AI-generated, and Microsoft’s 2025 Digital Defense Report estimated AI-produced lures are 4.5 times more convincing than human-written equivalents.

Phishing channels are shifting to target areas outside of the enterprise security perimeter. SMS drives 39% of mobile threats, QR phishing (quishing) grew 146% Quarter over Quarter (QoQ) in Q1 2026, and malicious PDFs rose from 19% of payloads in January to 29% by March. Brand-identified targeting grew 5.4 times Year over Year (YoY).

AI-Assisted Malware Follows the Same Curve

Under the mobile phishing (mishing) surge sits a second trend: malware that generates its own code at runtime.

Zimperium’s report cited LAMEHUG, an APT28 campaign that relied on AI to design polymorphic malware on every execution.

The report also mentioned PromptLock, the first identified AI-powered ransomware, and VoidLink, a malware framework Verizon’s 2026 Data Breach Investigations Report calls a point of no return for automated threat development, built end-to-end by an AI-powered agent in six days without a human developer.

The banking ecosystem is being heavily targeted. Zimperium tracked 34 active malware families targeting 1,243 financial brands across 90 countries in 2025. Three of them (TsarBot, CopyBara and Hook) reached more than 60% of the banking and fintech apps in its mobile banking heist dataset.

Static signature detection cannot catch malware that rewrites itself each run. Zimperium’s remediation guidance is to implement layered runtime detection of each stage of the attack chain.

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Alessandro Mascellino
Alessandro Mascellino Cybersecurity Reporter

Alessandro Mascellino is a British-Italian freelance journalist specializing in technology and gaming. He has contributed to several publications, including Wired, The Independent, and Android Police. By day, he works as a journalist. By night, he co-manages a game studio that creates narrative games.