The security industry spent a decade teaching people to distrust emails. Security awareness training programs sent simulated phishing emails, measured click rates, and trained employees to scrutinize sender addresses, hover over links, and report suspicious messages. The training worked — in the sense that it made people more cautious about email.

Attackers adapted. They moved to the phone.

Mandiant's M-Trends 2026 report, based on more than 500,000 hours of frontline incident response investigations conducted in 2025, documents a striking shift in the initial infection vector landscape. Email phishing declined to just 6% of initial intrusions in 2025 — down from 14% in 2024 and 22% in 2022. Meanwhile, voice phishing rose to become the second-most commonly observed initial infection vector, at 11% of investigations. It now sits directly behind exploits, which have held the top spot for six consecutive years at 32%.

This is not a statistical fluctuation. It is a structural shift in how attackers gain their first foothold — and it has significant implications for how organizations think about their human layer of defense.

Why Voice Phishing Is Winning

The fundamental advantage of voice phishing — vishing — over email phishing is that it involves a live human being on the other end of the call. Email phishing relies on volume and technical deception: fake sender addresses, lookalike domains, urgency cues. All of these can be caught by automated filters, trained employees, and careful inspection.

A phone call is different. A skilled social engineer can read the target in real time, adjust their approach based on responses, apply escalating pressure, and counter objections as they arise. They can impersonate a colleague, a vendor, an IT helpdesk worker, or a bank employee with a convincing story that no email filter can detect — because the attack is happening in real time, in natural language, between two humans.

Mandiant's finding: Interactive attacks — voice phishing and messaging-based social engineering — are significantly more resilient against automated technical controls than email phishing. They require different detection strategies because there is no malicious URL to block, no attachment to scan, and no sender domain to flag. The attack surface is human judgment.

Mandiant specifically distinguishes between interactive attacks, which involve a live person steering the conversation in real time, and non-interactive technical lures like email phishing. This distinction matters for defenders: the controls that work against email phishing largely do not apply to voice attacks.

What These Attacks Actually Look Like

The M-Trends report documents several specific vishing campaigns that illustrate how these attacks operate in practice.

One campaign spanning the first half of 2025 involved a threat cluster using voice phishing to convince targets to provide credentials and authorize an attacker-controlled version of a legitimate SaaS application to access organizational data. The attacker impersonated technical support, walked targets through what appeared to be a legitimate authorization flow, and obtained persistent access. Affected organizations later received extortion demands for the non-release of their stolen data.

Another documented campaign came from UNC3944, a financially motivated threat cluster active since at least 2022 and with significant overlap with the publicly reported Scattered Spider group. UNC3944 targeted IT helpdesk staff directly — calling and impersonating employees who needed password resets and MFA setting changes. The target was not a regular employee but the helpdesk worker whose job is to assist people with exactly these requests. The attack exploited the helpdesk's legitimate function.

6%
email phishing as initial infection vector in 2025 — down from 22% in 2022
11%
voice phishing — now the #2 initial infection vector globally
32%
exploits — #1 for the sixth consecutive year

ClickFix: The Hybrid Attack

The M-Trends report also highlights the explosive growth of ClickFix, a social engineering technique that represents a hybrid between the old email model and the new interactive model. ClickFix involves convincing targets to manually execute malicious commands on their own machines — typically via a popup on a compromised website that instructs users to run a PowerShell command or paste something into the Windows Run dialog to "fix" a problem or verify their legitimacy.

The lures are designed to feel like legitimate technical processes: CAPTCHA verifications, video conference setup steps, driver update prompts, software compliance checks. The target executes the command themselves, believing they are resolving a technical issue. In 2025, Mandiant identified dozens of threat clusters incorporating this technique, and it became one of the most active global events tracked by Google Threat Intelligence Group.

ClickFix is effective precisely because it bypasses the need to deliver a malicious file. There is no attachment for a security tool to scan. The user is the delivery mechanism.

What This Means for Security Programs

The shift toward interactive social engineering attacks exposes a gap in most security programs. Phishing awareness training is predominantly email-focused. Simulations send fake phishing emails and measure click rates. This training is still valuable — email phishing continues to occur at 6%, and trained employees catch some of it. But it does not prepare employees for a phone call.

The controls that work against vishing are different from those that work against email phishing. They are primarily procedural rather than technical:

  • Out-of-band verification — any request for credentials, password resets, or MFA changes received via phone should be verified through a separate, established channel. Call back on a number you already have, not one provided by the caller.
  • Helpdesk verification protocols — IT helpdesks should have strict identity verification procedures that do not make exceptions for urgency or authority. Seniority is not an authentication factor.
  • Vishing simulations — the same way organizations run email phishing simulations, they should run voice phishing simulations — particularly targeting helpdesk staff and employees with access to sensitive credentials or financial systems.
  • MFA that resists social engineering — authenticator app-based MFA is significantly harder to social engineer than SMS codes. Hardware keys are harder still. The type of MFA matters as much as having MFA.
The most important reframe: Your security awareness training is probably optimized for the threat landscape of 2022. Email phishing was 22% of attacks then. It is 6% now. If your training program has not updated to reflect the rise of voice-based social engineering, it is training employees to defend against the last war.

The Broader Pattern

The vishing shift is part of a broader pattern Mandiant identifies across multiple dimensions of the threat landscape: attackers consistently adapt to make their attacks harder for technical controls to catch. When endpoint detection improved, attackers moved to living-off-the-land techniques using legitimate system tools. When email filters improved, attackers moved to voice. When perimeter defenses improved, attackers moved to identity and cloud.

This adaptability is not random. It is the rational response of well-resourced, profit-motivated adversaries to the defensive improvements organizations have made. The implication for defenders is that security programs need to evolve continuously — not just deploy tools, but regularly assess which attack vectors have become more prevalent as others have been controlled.

The phone call that replaced the phishing email is not a one-time anomaly. It is a signal about where the threat is moving, and what the next generation of security training and controls needs to address.

Source: Mandiant M-Trends 2026, Google Threat Intelligence Group (GTIG). Based on analysis of more than 500,000 hours of incident response engagements globally, January 1–December 31, 2025. Published March 2026.

See what continuous testing finds in your environment.

Tadpole deploys autonomous agents that simulate real adversaries — 24/7, across your entire attack surface.

Request early access →