Phishing has left the inbox — and the data agrees
The headline statistic here isn't a rounding error. It sits inside a converging body of evidence from security research firms, government cyber agencies, and incident responders — all making the same point from different angles. Email remains the largest single channel, but it's now one of several, and the others are growing far faster than email is.
One in three phishing attacks now arrives through channels other than email.
That figure comes from Push Security's December 2025 Top Phishing Trends report. It doesn't stand alone — a set of corroborating numbers, each from a different vantage point, describe the same structural change.
increase in voice phishing between H1 and H2 2024. H1 2025 already exceeded all of 2024.
CrowdStrike, 2025 Global Threat Reportof phishing-related incident response engagements in Q1 2025 involved vishing — more than email.
Cisco Talos, Q1 2025rise in QR code phishing through 2025. 83% of phishing sites now target mobile rendering.
Hoxhunt / Zimperium, 2025The Australian data — ASD's ACSC
ASD's ACSC confirms the same pattern in its Annual Cyber Threat Report 2024–25, published October 2025. Social engineering — with phishing as its largest sub-category — was recorded in 60% of all incidents reported to the ACSC in FY2024–25. The report is explicit that this includes phone-based, SMS-based, and messaging-based delivery, not just email.
More operationally, the report places SMS on equal footing with email as a delivery channel for information-stealer malware, and names quishing and callback phishing specifically — including a case study of a Royal ransomware campaign against an Australian education institution.
The one-in-three statistic is the global view. The ACSC data is what a CISO or risk committee member will recognise as the national reality. Both point to the same place.
Six channels, six different dynamics
"Phishing" as an undifferentiated term is losing its usefulness. A program that covers "phishing" without distinguishing between channels is training people on a generic category — not on the specific decision they'll actually face. Each channel below has its own trust dynamic and its own teachable moment.
SMS-based phishing
Fake delivery notices, bank alerts, ATO impersonation, fake MFA prompts. SMS feels more personal and more trusted than email — which is exactly why it works.
Voice-based phishing
The canonical pattern is help-desk impersonation — calling the help desk pretending to be an employee, or calling an employee pretending to be IT.
WhatsApp, Signal, Telegram
State-sponsored targeting of Signal and WhatsApp users flagged by the FBI. The trust dynamics that make these apps useful for work make them useful for attackers.
LinkedIn as the executive channel
A compromised peer account sends an investment, recruitment, or partnership approach. Because it's from a trusted network, it bypasses the mental model used to screen cold contact.
QR code phishing
Increasingly embedded in PDF attachments to evade URL scanning — and the page that loads sits outside every enterprise control the organisation has invested in.
Microsoft Teams and Slack
Attacks typically come from a compromised internal account or federation exploit. The message lands in an interface people treat as internal — scepticism drops accordingly.
The attack vector for a major Australian operator was a phone call
In mid-2025, Qantas — Australia's flagship airline — disclosed a breach affecting up to six million customer records, widely attributed to the threat group tracked as Scattered Spider (also UNC3944 / Octo Tempest), though Qantas itself has not officially confirmed the specific attacker.
The initial access vector, consistent with the group's known tradecraft, was help-desk voice phishing — not an email.
The group's methods are documented in the joint advisory issued in July 2025 by CISA, the FBI, ASD's ACSC, the AFP, and the UK's NCSC. The advisory names push bombing, SIM-swap attacks, and MFA fatigue as ongoing techniques. This is Australian critical infrastructure, on the public record — and the entry point was a phone call to a help desk.
Five forces, operating together
None of this is accidental. The move from an email-dominated threat surface to a multi-channel one has specific, reinforcing causes — and they're still accelerating.
Email security actually worked
Two decades of gateway scanning, DMARC, DKIM, and anomaly detection made email the most defended surface. Attackers moved to surfaces without those defences.
Other channels aren't screened
Social DMs, WhatsApp, SMS, and Teams chat travel over infrastructure that doesn't inspect content. A LinkedIn DM from a real account looks legitimate by design.
AI collapsed personalisation cost
Scrape a LinkedIn profile, clone a voice from three seconds of audio, generate a personalised approach at near-zero cost. AI-generated spear phishing reportedly achieves far higher click rates than human-written lures.
Mobile is least monitored
Smaller screens hide URL previews. Most organisations have far less security telemetry on the employee phone than on the employee laptop.
The fifth force: collaboration tools were never designed with anti-phishing as a primary control. Threat actors are increasingly using Teams and Slack for initial access and delivery — inside environments people treat as inherently trusted.
What to take into your next risk conversation
One in three is the floor, not the ceiling
Voice is up 442%. QR phishing is up 400%. The share of attacks arriving outside email isn't stabilising — it's still climbing.
Australian data supports the same conclusion
ASD's ACSC records social engineering in 60% of incidents and places SMS on equal footing with email for malware delivery.
Critical infrastructure is the live case study
A major Australian operator was breached via help-desk vishing in 2025. The July 2025 joint government advisory confirms the pattern.
Architecture determines what a program can teach
Email-gateway platforms were built for one channel. Human-led, intelligence-driven programs can cover six — because the channel isn't the constraint.
Is your awareness program training on every channel — or just email?
Click or Flick Corporate simulates phishing across SMS, voice, LinkedIn, and QR codes — not just the inbox. If your program was designed around email and hasn't been rebuilt for the channel landscape of 2026, that's worth a conversation.