Phishing attacks are now engineered to blend into your workflow

Phishing isn’t what it used to be. It’s not just poorly spelled emails from fake princes anymore. Modern phishing attacks are engineered to look exactly like the work you do every day.

That’s the argument from Abnormal Security’s latest research. They analyzed nearly 800,000 attacks and found something that flips the conventional wisdom on its head. The old advice — slow down, check the link, think before clicking — is increasingly irrelevant. Because these attacks don’t look suspicious. They look like normal work.

Take file-sharing phishing. Impersonating SharePoint, Dropbox, Google Drive, or DocuSign accounts for 12.4% of all phishing overall. But in financial services, that number nearly doubles to 22.2%. Why? Because a finance employee’s inbox is full of loan docs, audit packages, and compliance disclosures all day. A notification that someone shared a document isn’t unusual. It’s muscle memory.

Attackers are also getting smarter about evading detection. One in five phishing attacks now uses redirect links — a chain of intermediate URLs designed to hide where the link actually goes. TinyURL dominates because it’s frictionless — no account, no authentication, no record. And attackers are abusing Twitter/X’s t.co redirect infrastructure by posting malicious links there first, getting a clean, reputable-looking URL for free.

Here’s where it gets tactical. Small organizations see link shorteners in only 1.6% of phishing attacks. Large enterprises? 3.5% — more than double. Attackers are sizing up defenses and adjusting their techniques accordingly.

Brand impersonation hits 24.1% of phishing attacks in hospitality. A hotel deals with dozens of branded services — booking sites, payment portals, loyalty programs. A fake notification from any one of them looks completely normal. Healthcare? Only 7.1%. Fewer consumer-facing brands to impersonate.

Security teams need to shift their thinking. Stop asking “are our employees aware of phishing?” Start asking “what does phishing actually look like in our environment?”

The answer will be different for every organization. That’s the point.