Skip to main content

Beyond Takedowns: Brand Protection in 2026

13 min read

Beyond takedowns cover: a disruption loop showing discovery, verification, evidence, immediate containment and enforcement, with tiles reading AI lures, QR phishing, PhaaS churn and recycle rate.

TL;DR — Phishing in 2026 is not an email problem with a removal step bolted on; it is a fast-rotating brand-abuse operation. Generative AI has removed the spelling-mistake tells, QR codes carry attacks off the managed desktop onto unmanaged phones, and phishing-as-a-service lets an operator replace a suspended domain in minutes. A program built only on "find it, report it, wait" loses that race by design. This is the operating model that replaces it: continuous discovery, containment before removal, infrastructure-level disruption, and metrics that measure customer protection rather than ticket volume.

About this analysis. This is a PhishEye Threat Research briefing for security, fraud, and brand leaders. The figures cited come from Microsoft's Email threat landscape, the APWG Phishing Activity Trends Report, and KnowBe4's threat research, as compiled in our 2026 phishing trends report. The two operational examples are drawn from our own published case studies and are linked to source.

The scenario that breaks the takedown model

A customer gets an SMS that appears to come from their bank, warning of a suspicious transaction and offering a QR code for "quick verification." They scan it with their phone. The page that loads is a faithful copy of the bank's mobile login. They enter their credentials, then the one-time passcode.

The account is drained inside two hours. The security team spots the domain a couple of hours after that and files an abuse report. The registrar suspends it the next day — by which time the operator has rotated to fresh lookalike domains, moved the campaign into social media DMs, and started on the next batch of recipients.

Nothing in that sequence is exotic. It is the ordinary shape of a 2026 campaign, and it exposes the flaw in treating phishing as a queue of individual removals: the asset you took down was never the operation. It was one disposable instance of it.

What the numbers actually say

Three independent datasets converge on the same picture. Volume is up — APWG counted 971,181 attacks in Q1 2026, a 13.8% rise. Credential theft is now almost the entire game: Microsoft attributes 94% of email attacks to it. And the attacks are overwhelmingly machine-assisted, with KnowBe4 putting 85.8% of the phishing it observed as AI-driven.

Two shifts matter most for brand owners.

Delivery has moved to formats that scanners struggle with. Microsoft found 78% of email threats were link-based, and HTML, PDF, and SVG files together carry 78% of malicious payloads — precisely because those formats can smuggle scripts, redirects, and QR codes past inspection while looking like routine business documents.

Quishing is the clearest growth story of the year. Microsoft recorded QR-code phishing volume climbing 146% over a single quarter. KnowBe4, measuring differently, put links-including-QR at 60% of what it saw. The measurement methods differ; the direction does not.

Why QR codes are a structural problem, not just a new lure

Quishing works because it moves the victim across a control boundary mid-attack.

The email arrives on a corporate desktop behind a mail gateway, endpoint protection, and a filtering proxy. The QR code itself is an image — there is no URL for the gateway to rate. The user then scans it with a personal phone, where the browser hides most of the address bar, the device is outside MDM, and none of the corporate controls apply. The attack completes entirely in the unmonitored half of that journey.

That is why "train users to check the URL" fails here. On a phone, there is often no URL to check. The defensive weight has to shift to controls that do not depend on the victim's judgement: monitoring where your own QR campaigns resolve, expanding shortened links before delivery, enforcing safe browsing through MDM, and telling customers plainly that a QR code is not proof of authenticity.

AI changed the economics, not the physics

Generative AI collapsed the cost of producing a convincing lure. Fluent localized copy, accurate brand graphics, and a cloned checkout page are now minutes of work rather than days. The practical consequence is that the advice a generation of awareness training was built on — look for bad grammar, odd phrasing, blurry logos — no longer separates real from fake.

What AI did not change is the infrastructure the campaign has to stand on. An operator still has to register a domain, obtain a certificate, host content somewhere, and receive the stolen data at an endpoint they control. Those artifacts are observable, and they are where detection has migrated: certificate transparency logs, registration patterns, hosting fingerprints, page structure, and the collector endpoint behind the form.

We see this repeatedly in our own casework. In the IronToll campaign, a single reported URL unrolled into a 90+ domain phishing-as-a-service operation because the kit reused recognisable infrastructure. The lure was polished; the plumbing was not.

Detection, takedown, and brand protection are three different things

These get used interchangeably in vendor material, and the conflation is the source of a lot of wasted spend.

  • Detection finds a suspicious asset.
  • Takedown persuades a registrar, host, or platform to remove it. It is one enforcement tactic.
  • Brand protection is the surrounding programme: monitoring, verification, containment, enforcement, customer communication, and follow-up.

A programme that has bought only detection generates alerts nobody can action. A programme that has bought only takedowns is perpetually reacting to yesterday. The value sits in the connective tissue between them — which is what a phishing takedown service is actually for.

Containment beats removal on the clock that matters

This is the single most useful mental shift available to a defender.

Formal removal is slow because it depends on someone else: a registrar's abuse desk, a hosting provider's ticket queue, a platform's trust-and-safety review. Realistically that is hours at best and days at worst. We have documented cases where the provider's own reporting pipeline is the bottleneck — Cloudflare's abuse-report API returning 401 to legitimate reporters is a live example of takedown infrastructure working against the people using it.

Meanwhile, the controls you own move in minutes: pushing the URL to your mail filter, blocking it at the proxy and SMS firewall, submitting to Safe Browsing and SmartScreen, and warning customers on the channel they were contacted through.

So a mature programme runs two clocks:

  • Time to customer protection — first detection to the point where users can no longer reach the page. This is the number that maps to prevented losses.
  • Time to verified removal — first detection to confirmed suspension. This still matters, but it is largely outside your control.

Optimising only the second while ignoring the first is how programmes end up with excellent takedown statistics and unchanged fraud losses.

The operating model

Continuous brand protection lifecycle: discovery, verification, evidence, immediate containment, enforcement, and post-takedown monitoring that loops back on reappearanceFrom linear removal to a continuous disruption loop1. Continuous discoveryweb · email · social · apps · CT logs2. Verificationmalicious vs. partner vs. fan page3. Evidence capturescreenshots · WHOIS · source4. Containment NOWfilters · proxy · SMS · blocklistsminutes — you control this5. Enforcementregistrar · host · platform · paymentshours to days — they control this6. Post-takedown watchnameservers · kit fingerprintsdid it come back?reappears — re-enforce on the same caseSteps 4 and 5 run in parallel, not in sequence. Waiting for removal before protecting usersis what turns a four-hour incident into a four-day one.A closed case is one that stayed closed for 30 days — not one with a suspension email.
Figure 1. The disruption loop. The critical design choice is running containment (step 4) in parallel with enforcement (step 5), because only one of those two clocks is yours.

The five capabilities that make this work:

  1. Continuous discovery across web, email, social, app stores, ads, and certificate transparency — not just your own domain portfolio.
  2. High-confidence verification that separates genuine abuse from partners, resellers, and fan accounts, because a program that cries wolf gets ignored.
  3. Automated evidence capture at the moment of detection: timestamped screenshots, WHOIS, hosting, and page source, taken before the operator adds cloaking or pulls the page.
  4. Multi-party enforcement through established abuse channels — and, where the fraud is monetised, the payment processor as well as the host.
  5. Post-takedown monitoring that treats reappearance as the same case rather than a new ticket.

Two examples from our own casework

Infrastructure beats whack-a-mole. Our Grand Egyptian Museum investigation began with a handful of fake ticket domains. Rather than reporting them one by one, we pivoted on a single exposed origin server and unrolled 188 domains impersonating around 40 attractions across more than 10 countries, all running on a handful of shared hosts. Reporting the domains individually would have been endless; mapping the hosting collapsed the operation into a small number of enforcement targets.

The kit is the fingerprint. In IronToll, one live phishing URL led to a 90+ domain government-impersonation PhaaS campaign built on a shared kit that harvested credentials and live SMS one-time passcodes. Because every deployment reused identifiable kit artifacts, new domains could be attributed to the same operator as they appeared — which is exactly what post-takedown monitoring is for.

Both cases make the same point: the leverage is at the infrastructure layer, not the individual URL.

Metrics: what to stop reporting, and what to report instead

Takedown counts are the most commonly reported brand-protection metric and one of the least informative. A rising count can equally mean your defences improved or that an operator decided to target you harder this quarter. It cannot distinguish the two.

Stop reporting this Report this instead Why it is better
Takedown requests submitted Time to customer protection Measures when users stopped being exposed, not when paperwork was filed
Domains suspended Time to verified removal Confirmed outcome rather than submitted intent
Raw alert volume Containment rate Share of threats blocked or warned on before formal removal
False-positive count Recycle / disruption rate Share of removed assets that do not return on new infrastructure within 30 days
Customer exposure avoided Estimated victim interactions prevented, the number finance actually understands

The recycle rate is the one most programmes are missing, and it is the one that tells you whether you disrupted an operation or merely inconvenienced it.

Where compliance enters the picture

Brand protection is increasingly load-bearing for regulatory obligations, which is what moves it from a marketing line item to a security function with a budget.

Disclosure regimes such as the SEC's cybersecurity rules and the EU's DORA compress the time available to understand and report an incident, and GDPR obliges you to notify affected individuals when personal data is exposed. When a credential-harvesting site impersonating your login page is active, the questions that follow are evidentiary: when did it appear, when was it detected, when were customers protected, how many were exposed, and what did you do about it.

An enforcement workflow that captures timestamped evidence as a matter of routine answers those questions from records. One that does not turns every incident into an archaeology project under a statutory deadline. That, rather than the logo, is the strongest budget argument available.

What to do next

The goal is not to remove every fraudulent asset. It is to shorten the window in which each one can reach a customer, and to raise the cost of standing the next one up.

  • Widen discovery beyond domains. Social, app stores, ads, and paste sites are where a growing share of impersonation now lives. Our social media and fake app guide covers those channels specifically.
  • Decouple containment from removal. Get blocking and customer warnings onto a path you control, running in parallel with the abuse report rather than after it.
  • Instrument the two clocks. Time to customer protection and time to verified removal, reported separately. See our takedown metrics guide for the full set.
  • Treat reappearance as the same case. Track nameservers and kit fingerprints after closure; measure the recycle rate.
  • Address QR explicitly. Monitor your own campaign destinations, expand shortened links, enforce mobile safe browsing, and tell customers a QR code proves nothing.
  • Align the teams before the incident. Security, fraud, legal, and marketing need one playbook and one owner, agreed while nothing is on fire.

If you want the mechanics of the enforcement half specifically — evidence standards, escalation paths, and what to do when a provider stalls — that is covered on our phishing takedown service page and in the step-by-step how to take down a phishing website walkthrough.

FAQ

Is takedown still worth doing if attackers just rotate? Yes, but as one tactic rather than the whole strategy. Removal permanently retires that asset and raises the operator's cost. It simply cannot be the only thing standing between a live phishing page and your customers, because you do not control its timing.

What is the single most valuable metric to start with? Time to customer protection: first detection to the point where users can no longer reach the page. It is the metric that most closely tracks prevented losses, and unlike removal time it measures something you control.

Why is QR phishing so much harder to stop? It crosses a control boundary mid-attack. The email is inspected on a managed desktop where the QR code is just an image with no URL to rate, then the victim scans it with an unmanaged phone where the address bar is truncated and corporate controls do not apply.

Has AI made phishing undetectable? No. It removed the language and design tells that awareness training relied on, but the campaign still needs domains, certificates, hosting, and a collector endpoint. Detection has moved to those infrastructure signals.

Who should own brand protection? Usually security operations, with defined hand-offs to fraud, legal, and marketing. The failure mode is ownership sitting with a team that can detect but cannot enforce, or with one that can enforce but never sees the alerts.

Sources


About the authors

PhishEye Threat Research analyzes phishing, brand-impersonation, and takedown operations for defenders. The statistics in this briefing are drawn from published Microsoft, APWG, and KnowBe4 research as compiled in our 2026 trends report; the operational examples are our own first-hand investigations, linked to the full write-ups.