SYMANTEC logged a sharp resurgence in SVG phishing attacks in August 2026, with 26,433 malicious SVG files blocked. The firm notes that this spike follows a quiet first half of the year and places SVGs among the top three malicious attachment types now seen in the wild. Over the past year, Symantec records 222,226 SVG-related detections, with a 60% drop from October 2025 to June 2026 and a 142% rise in August, suggesting a format rotation rather than a sustained retreat. The majority of detections continue to come from the US, UK and the Netherlands, accounting for about 82% of activity.
What makes SVGs so dangerous is their nature: SVG files are XML-based, parsed as images by many email rules but executed as documents by browsers. Attackers embed login forms, redirects or malware directly in the SVG, sometimes using svg-smuggling to reconstruct malicious archives in memory or simply steering victims to malicious sites. Techniques to bypass filters include labeling SVGs as plain text or generating unique files for each send, complicating hash-based detection.
INKY (Kaseya) also highlighted voicemail-themed campaigns that spoof content-type checks and even the recipient’s own domain. No single actor is blamed; instead, Symantec describes a broad, commodity threat with regional patterns, including campaigns in Latin America that deploy remote access trojans such as AsyncRAT, Remcos and DCRat.
Defence remains layered: block or quarantine inbound SVG attachments, inspect content rather than extensions, filter web traffic, guard against domain spoofing, and train staff to be wary of image attachments tied to voicemails or invoices. The report cautions that the figures are a floor, not a ceiling, and that attackers continue to evolve their methods.