Verizon 2026 DBIR

The attack moved to the phone. Most defenses didn't.

For the first time, the industry's most-cited breach report named a finding that didn't exist before: Mobile-centric Social Engineering. Here's what the data says — and what to do about it.

Verizon's 2026 DBIR found mobile phishing via text and voice succeeds 40% more often than email, and 41% of social-engineering breaches now reach beyond the inbox. The attack moved to the phone. Most defenses didn't.

40%

Higher success rate for mobile phishing (text & voice) than email

~8 days

Between SMS phishing campaigns at a large org (48/year)

41%

Of social-engineering breaches now use a vector other than email

62%

Of breaches involve the human element

Source: Verizon 2026 Data Breach Investigations Report.

Four things the report makes clear

Verizon named your blind spot. On its own letterhead.

Text and voice now out-convert email

Median click rate on mobile-centric vectors runs about 2%, versus 1.4% for email — a 40% higher success rate. Fifteen years of inbox training didn't transfer to the phone.

A new SMS campaign every ~8 days

Large orgs saw a median of 48 SMS-based phishing campaigns in a year — 12 a year at smaller orgs. Smishing isn't an edge case; it's a standing weather pattern.

The inbox is no longer the front door

41% of social-engineering breaches now use a vector other than email, and about a quarter of social attack vectors arrive via social media or phones.

The measured data came only from managed devices

Verizon could only count those SMS attacks because the devices were managed. It flags employees on unmanaged personal phones as a “risky gap in your visibility.” That gap is BYOD.

Verizon's own SMS attack data came only from managed devices — the report flags employees on unmanaged personal phones as a “risky gap in your visibility.”

Why the stack misses it

Every layer you own stops before the message.

Every layer you already own stops at a boundary the attacker walks right past. The message is the last mile — and it's the one nobody else covers.

Email security (SEG)
Stops at:The inbox
Doesn't see SMS, iMessage, WhatsApp, or DMs at all
EDR / XDR
Stops at:The managed endpoint
No agent on the messaging layer; nothing on a personal phone
SWG / SSE
Stops at:Traffic routed through the gateway
A personal iPhone on cellular never routes through it — and it has to decrypt TLS to see anything
SmishAlert
Stops at:The message, before the tap
Any iPhone, managed or BYOD, blocked upstream — without reading message content

What to do about it

Screen at the message layer. Prevent · Capture · Prove.

You can't train your way out of a vector that beats email by 40%. The defensible move is detection and blocking at the message layer — which is exactly how SmishAlert is built.

Prevent

Block the smish before the tap.

iOS · managed and BYOD

Inline blocking of unknown-sender messages on iOS, before they reach the tap. The moment an attack is fingerprinted anywhere — any tenant, any device, any channel — it becomes an automatic block on every iPhone in the network.

  • On-device filtering of unknown-sender SMS and iMessage via Apple's Message Filtering extension
  • Runs on any iPhone — company-managed or personal (BYOD) — with no MDM required to protect the device
  • Cross-tenant intelligence: the first phone to see it is the last one that has to
Capture

Nothing gets through invisibly.

Android, WhatsApp, iMessage, social DMs

Where we can't block, employees report suspicious messages in a tap. Those reports don't sit in a queue — they're correlated into named campaigns and they feed the fingerprint database that hardens iOS blocking for everyone.

  • One-tap reporting across Android, WhatsApp, iMessage, and social DMs
  • Fingerprint-grade correlation clusters lookalike reports into named campaigns
  • Report-only is the honest boundary — and the network's early-warning system
Prove

An audit-grade record of everything.

SIEM · API · executive readout

Every block and every report becomes a defensible record — executive impersonation, payroll and HR fraud, credential harvesting, vendor impersonation — streamed to your SIEM and available over API.

  • Board-ready executive reporting on what was blocked and what was captured
  • SIEM/SOAR routing and API access for teams that want signal in their stack
  • The system of record beneath prevention — governance, not the headline

Every attack one employee reports makes the whole network safer — automatically.

FAQ

Verizon 2026 DBIR — FAQ

What is Mobile-centric Social Engineering in the 2026 DBIR?

It's a new finding category in Verizon's 2026 Data Breach Investigations Report covering social engineering that arrives by text and voice rather than email. The report found these mobile vectors succeed about 40% more often than email, validating smishing as a distinct, measurable threat category. SmishAlert is purpose-built for exactly this vector.

How much more effective is mobile phishing than email, according to Verizon?

The 2026 DBIR reports a roughly 2% median click rate on mobile-centric vectors versus 1.4% for email — about a 40% higher success rate. It also found 41% of social-engineering breaches now use a vector other than email.

Why does the DBIR matter for BYOD and personal phones?

Verizon's SMS attack data came only from managed devices, and the report explicitly calls unmanaged personal phones a 'risky gap in your visibility.' SmishAlert closes that gap: its iOS filtering runs on any iPhone, managed or personal, and never reads message content.

How does SmishAlert address the DBIR's mobile finding?

SmishAlert blocks unknown-sender smishing on iOS before the tap, captures every attempt it can't block across other channels, and proves it in an audit-grade record. Start with a 30-day exposure pilot for a defensible measurement of your own workforce exposure.

Measure it on your own workforce

See what the DBIR describes, in your own numbers.

A 30-day exposure pilot turns the industry's headline into a defensible measurement of your workforce — with the known-bad blocked on iOS before the tap.

Or take the 2-minute self-evaluation — no email required.