A significant phishing campaign employed SVG attachments masked as voicemail notifications to deliver malicious JavaScript. Detected by INKY, this operation targeted over 26,000 messages across 5,527 organizations from June 1 to August 4, 2026. Key findings revealed that 95% of emails spoofed the recipients' own domains, resulting in many being misclassified as non-spam by Microsoft’s native filters.
The reports illustrated the effectiveness of using internal sender impersonation, personalized content, and deceptive file types, making it challenging for conventional email defenses to detect such threats.