In short: Bi.Zone's Digital Risk Protection team published its H1 2026 findings on August 27, 2026: phishing domains blocked fell 73% compared with H1 2025. Behind that headline, however, is a warning — attackers have not retreated, they have pivoted. Instead of blasting millions of identical messages at broad audiences, they now craft personalised lures aimed at specific individuals, with a single domain hosting multiple bespoke sub-domain attacks. AI has made this shift accessible even to inexperienced criminals.
What the H1 2026 numbers actually say
Bi.Zone Digital Risk Protection identified and blocked 13,500 phishing domains in the first half of 2026 — 73% fewer than in the same period of 2025. That looks like progress. In practice it signals an architectural shift in attacks, not a retreat from them.
Alongside phishing domains, the team found in the same six months:
- More than 3,500 published files containing sensitive data;
- 3,300 of those sourced from infostealer logs — programmes that collect passwords, cookies, and form data from infected machines;
- Over 200 files containing compromised organisational databases;
- More than 500,000 messages detected in reputation-attack campaigns targeting companies.
Total exposure is not shrinking. It is migrating into formats that are harder to detect at scale.
One domain, multiple targets: how the new tactic works
The core change is from carpet-bombing to sniper fire. Where phishers once registered thousands of near-identical domains aimed at broad audiences, they now use a single domain to attack several specific victims simultaneously — each gets a bespoke sub-domain page built around real information about that person or organisation.
This extends the lifespan of each phishing asset. Detecting and blocking a domain with thousands of generic pages is straightforward for automated defences. Tracking down a cluster of unique sub-domains — each with distinct, contextually appropriate content that exists for only a short window — is far harder. Defences must evaluate threats one at a time, while attackers complete campaigns before any block takes effect. Think of the difference between mailing junk flyers to a city versus calling each target individually with a personalised script.
Most warning signs of fraudulent pages remain valid even for personalised phishing sub-domains — see our guide on how to check a website for fraud for a practical checklist.
The AI factor: phishing democratised
Dmitry Kiryushkin, head of Bi.Zone Digital Risk Protection, states it plainly: "AI simplifies this task. Now even an inexperienced cybercriminal can independently produce quality phishing."
Creating a convincing personalised email previously required fluency in the target's language, understanding of corporate culture, and skill in mimicking legitimate business correspondence. Today generative models handle this automatically: feed them a LinkedIn profile, a company website, or data from a breached database, and they produce a grammatically correct, contextually appropriate message referencing real details about the recipient.
This changes the threat landscape. Poor spelling and generic greetings — "Dear Customer!" — were once reliable warning signals. They are no longer. A personalised message can address you by name, mention a real counterparty, and reference a project you are actively working on.
AI-driven phishing is often paired with voice cloning — for how that combination works and how to counter it, see our explainer on voice deepfake scams.
What this means for ordinary users
The goal of personalised phishing is identical to mass phishing: steal credentials, payment data, or install malware. The difference is hit rate. A targeted attack is more likely to succeed because the victim does not register the threat — the message looks like expected correspondence from a familiar source.
Corporate database breaches (200+ files in a single half-year per Bi.Zone) feed these attacks directly: attackers obtain employee names, job titles, work emails, and deal details, then turn that information into bespoke lures. Infostealer logs (3,300 files in the same period) provide another layer of raw material: if your passwords or browser cookies were stolen by a stealer at any point, they may be used to personalise an attack against you or your colleagues. For SMS-phishing defence and breach-check steps, see our guide on smishing: what it is and how to protect yourself.
How to protect yourself
Stop trusting message quality as a safety signal. Correct grammar, your real name, familiar context — AI can generate all of these from open sources or leaked data. Evaluate the request, not the presentation: an unusual ask, a link, or an attachment should raise a flag even when the message looks flawless.
Verify the channel, not just the sender. If a message from a "colleague" or "partner" contains an unexpected request, call them on a number you already have, or message them in your corporate platform to confirm. Email addresses are trivial to spoof; answering a verification call from a known number is far harder for an attacker.
Enable two-factor authentication (2FA) everywhere possible. Even if a password is stolen, a second factor makes access significantly harder. Prefer an authenticator app over SMS — for details on how attackers exploit SMS 2FA, see our piece on MFA fatigue and push bombing.
Use a password manager. It only autofills on the genuine domain — a look-alike sub-domain gets nothing, and the manager's silent refusal to fill is itself a warning worth heeding.
At the network-privacy layer, LiMP VPN encrypts all device traffic and hides DNS queries from your ISP. It will not stop a phishing email arriving in your inbox, but it limits the metadata collection that attackers use to personalise lures. See our pricing page for plan options.
