Connect with us

Business & Technology

Phishing falls as attackers turn to AI & encryption

Published

on


Zscaler has published its ThreatLabz 2026 Phishing and Initial Access Report, which shows phishing volumes fell while attacks became more targeted and effective.

Phishing activity declined 20% year on year in both 2024 and 2025 as tighter email and identity controls pushed attackers towards more selective campaigns, according to the report. It also found that 95.2% of phishing attempts were delivered through encrypted traffic, while 87% of all blocked malicious activity used encryption.

The shift points to a change in how attackers seek initial access. Rather than relying on broad, high-volume campaigns, the research describes a move towards fewer but more convincing attempts, including AI-generated websites and tools designed to hijack active user sessions.

In the UK, the study ranks the country second behind the US as a location for phishing infrastructure and hosting. It also places the UK fourth among the most targeted countries, behind Germany, India and the US.

AI and phishing

ThreatLabz identified 413,524 AI-generated site instances during the period covered by the research. Of those, 37,447, or 9.06%, were flagged as malicious.

Tools including Manus AI, Blackbox AI and Lovable AI are being used to create phishing pages that resemble legitimate corporate sites and customer workflows, the report says. It adds that these pages can be produced much faster than through manual development, making it easier for attackers to run targeted campaigns at scale.

Brand imitation remained a central tactic. Microsoft and Google were the most copied brands in phishing attacks, reflecting a continued focus on enterprise identity systems and account credentials.

Another finding centres on efforts to bypass multi-factor authentication. The research cites kits such as BlackForce, which it says are being used to take over active sessions in real time after users have logged in.

Sector targets

The services sector saw the sharpest increase in activity among the industries tracked in the report. Attacks against the sector rose 65.5% year on year, increasing from 330.9 million to 547.7 million hits.

Attackers were exploiting routine trust-based exchanges in billing, onboarding, renewals and support, according to Zscaler. Manufacturing and government also remained significant targets for email phishing, with government hits up 50% as attackers sought high-value intelligence.

Geographically, the US remained the leading target for email phishing attacks. Brazil recorded a 2,522% rise in phishing hosting, making it one of the top five global sources identified in the research.

Encrypted traffic

The report places heavy emphasis on encrypted traffic as a concealment method. By routing phishing content and other malicious activity through HTTPS and other encrypted channels, attackers can blend in with routine web traffic and make detection harder for organisations that do not inspect that traffic closely.

The findings suggest this is no longer a niche tactic. According to the study, encryption has become the default route for a large share of malicious activity, not just phishing.

Separate telemetry in the report points to large-scale hostile scanning before compromise. Data collected from decoys recorded 89.9 million hostile interactions from 1.37 million unique attacker IPs over six months.

This activity included attempts to probe collaboration platforms, identity systems and exposed services to identify weak points before an intrusion attempt. The report also says cloud infrastructure has become a main source of reconnaissance, with more than 121,000 distinct AWS-hosted IP addresses logged probing customer environments.

Using public cloud systems for scanning and credential validation can complicate response efforts because the traffic often originates from infrastructure more commonly associated with legitimate business services. That makes attribution and filtering more difficult for defenders.

The methodology states that the research drew on more than 500 trillion daily signals from Zscaler’s cloud platform and data gathered between January and December 2025, with deception telemetry collected between October 2025 and March 2026.

Deepen Desai, Chief Security Officer at Zscaler, said the changes reflected an adjustment in attacker behaviour rather than any retreat. “We are witnessing a strategic recalibration in the way adversaries approach initial access,” said Desai. “The decline in raw phishing volume isn’t a sign of retreat; it’s a sign of evolution. Attackers are trading quantity for quality, using GenAI to eliminate traditional ‘tells’ like poor grammar and generic lures. With 95% of phishing now hiding in encrypted traffic, organizations can no longer afford to leave their TLS traffic uninspected. A Zero Trust architecture is the only way to break the attack chain, from discovery to data exfiltration.”



Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Business & Technology

Thames Valley drivers face highest fuel prices in the UK

Published

on


The soaring prices come after the start of the Iran war in the end of February, with diesel now at 205.9p per litre at Membury services in Berkshire, and unleaded petrol reaching 185p per litre.

Some drivers are reducing their journeys due to the unaffordable fuel prices.

The Government has frozen fuel duty in an effort to alleviate the burden, while motoring groups advise shopping around for the best deals.

Simon Williams, head of policy at the RAC, commented on the situation: “Fuel prices continued to rise over the weekend with petrol climbing to a new Iran War high of 160.85p and diesel going back over 180p, something drivers haven’t seen since 9 June.

“Unleaded has now risen more than 10p a litre – 7 per cent – since bottoming out at 150.59p on 6 July while diesel is up 16p (15.8p) a litre, or 10 per cent, almost fully reversing June’s 16.6p reduction, which was the biggest monthly drop on record.

“Positively for petrol car drivers, RAC analysis of wholesale fuel data shows prices at the pump should begin to stabilise this week.

READ MORE: Oxford University Ebola vaccine trial gets only five volunteers

A40 closed Westbound due to two crashesSome drivers are reducing their journeys due to the unaffordable fuel prices. (Image: Ed Nix)

“But the news for those who rely on diesel, including many businesses, is worrying as it looks set to carry on rising, possibly reaching 185p in the next week or so.”

The rise in fuel prices coincides with the summer holiday season, when more than 20 million UK drivers are expected to hit the roads this week.

The AA is advising motorists to use price comparison apps powered by the Government’s Fuel Finder service to “beat the higher prices.”

The increase in prices has led to record numbers of forecourt drive-offs.

Forecourt Eye, a fuel theft prevention company, reported a 20 per cent increase in incidents of fuel taken without payment in the five months following the conflict’s onset on February 28, compared to the previous five months.

The surge in pump prices due to the war has driven the value of stolen fuel up by 48 per cent over the same period, reaching an estimated daily average of £194,000 across the UK’s 8,359 forecourts.

Gordon Balmer, executive director of the Petrol Retailers Association, noted that its members are “reporting increasing levels of abuse and aggression towards colleagues who are simply doing their jobs and have no influence over the price displayed on the forecourt”.

The Government has postponed its planned September 2026 increase to fuel duty until the end of the year due to rising pump prices.

Originally introduced by the Conservatives in 2022 following Russia’s invasion of Ukraine, the 5p reduction was set to end in September 2026.





Source link

Continue Reading

Business & Technology

Scran launches cooking app for neurodivergent users

Published

on



SOFIAH NICHOLE SALIVIO

News Editor

Scran has launched an iOS and Android cooking app for neurodivergent users. Developed in Edinburgh by founders with backgrounds in technology and accessibility, it aims to change how recipes are presented to reduce the mental effort involved in cooking.

Users can import recipes from websites, social media, photos and cookbooks. The app then restructures them into shorter, more explicit steps.

Its launch comes amid growing attention on digital products designed around accessibility needs rather than adapted later. The founders said common recipe formats can be hard to follow because preparation is often buried in later instructions, ingredient quantities are separated from method steps, and longer directions require repeated rereading.

Scran moves preparation tasks to the start of a recipe, places ingredient amounts within each step and breaks longer directions into smaller actions that users can tick off as they cook. It also includes serving-size adjustments, aisle-sorted shopping lists, measurement conversion, larger text, dark mode and dyslexia-friendly fonts.

Scran was created by Grant Macgregor and Jonny Kirkaldy, an Edinburgh-based couple who said they have spent 15 years designing digital products, including accessibility work for neurodivergent users. The app was built with input from home cooks, including people with ADHD, dyslexia and autism.

During a four-month pilot, 200 people tested the product and their feedback shaped how recipes are imported, simplified and followed. Scran said the app recorded a 30% week-four retention rate during the trial, while a voluntary follow-up survey found that 32 of 36 respondents said it made cooking from recipes easier. Of those, 19 said it was much easier and 13 said it was somewhat easier.

Inclusive Design

The founders say the central issue is cognitive load. Rather than offering a standard recipe database, the app focuses on changing the structure of recipe instructions so each task is clearer and easier to complete in sequence.

“Standard recipe formats assume everyone processes information the same way. We’ve heard from so many people who blame themselves when a recipe trips them up, when really it’s the recipe that’s failing them. We want to give people the confidence to cook whatever they want to,” said Jonny Kirkaldy, co-founder of Scran.

Scran uses artificial intelligence to import and simplify recipes, but the wider proposition rests on design rules created through research with neurodivergent cooks. The founders said the system is intended to create more consistent step-by-step instructions across different recipe sources.

The app enters a crowded market for meal planning and recipe tools, but it targets a narrower user group with a specific accessibility problem. That may help explain the pilot’s retention figures, which Scran cites as evidence of demand for a simpler way to follow recipes.

Consumer apps aimed at accessibility needs have often focused on reading, communication or mobility. Cooking has received less attention, even though recipe formats combine several common pain points at once, including dense text, task switching, sequencing and working memory demands.

One tester described the effect of restructuring steps into single actions.

“This app is life-changing. Having the steps broken down into single actions makes my life so much easier and less overwhelming. I want to enjoy cooking and the app does the hard bit for me!” said Sofia.

Commercial Model

Scran is self-funded and is launching with a subscription model after a free trial period. The service is priced at £29.99 a year or £4.99 a month, putting it in line with many paid productivity and lifestyle apps rather than free recipe platforms supported by advertising.

That pricing suggests the founders are betting users will pay for a tool that solves a practical problem rather than for access to recipes alone. The pilot’s retention and survey data will be watched as an early indicator of whether accessibility-led consumer software can sustain paid subscriptions in a competitive app market.

Macgregor said the project was built around a specific use case rather than broad claims about technology.

“For us, technology is at its best when it solves a specific, real-world accessibility issue. By combining inclusive design, a supportive app experience and ongoing community feedback, we’ve built something that can help more people stay on track, feel confident and enjoy cooking more,” said Grant Macgregor.



Source link

Continue Reading

Business & Technology

Company not liable for death of worker during Storm Eunice

Published

on


Jack Bristow, 23, from Sutton Courtenay, died after a tree fell on his truck while he was working in Hampshire.

He suffered a catastrophic head injury and was pronounced dead at the scene. He left behind his son, Harvey, who was one at the time.

Mr Bristow and driver Callum Smith had left Hooke Highways Limited’s Watlington depot at about 7.55am to remove traffic management equipment across the South East that could have been blown away in severe winds.

Jack Bristow , 23, died working in Storm Eunice in 2022 (Image: Unknown)

They were travelling back to Oxfordshire on Old Odiham Road when the accident happened at about 11.43am.

His parents, Teresa White and Gary Bristow, brought a claim against the company, arguing it had breached its duty of care by sending him to work during a Met Office Red Warning for extremely strong winds.

However, Judge Irena Sabic KC dismissed the claim, saying the risk of death while travelling as part of the assignment “was not reasonably foreseeable”.

She warned against “setting a novel standard of care” by which negligence could be established against an employer.

In her judgment, she said: “My view is that the precautions that the Claimants say should reasonably have been taken are not practicable or realistic. The risk of this horrific accident occurring was simply not foreseeable.”

Expressing sympathy for Mr Bristow’s relatives, the judge said he had been described as “hard working, caring, witty and completely devoted to his son”.

The family’s separate claim against landowner Davis Meisels, from whose land the tree fell, will be determined in due course.





Source link

Continue Reading

Trending