We analyzed nearly 89,000 phishing emails from Q3 2026. Templated AI phishing moved onto compromised accounts and now gets past native filters as often as targeted spear phishing.
Free report. Q3 2026.
Full findings, the technical deep dive, and five sanitized case studies.
Free · Sent to your inbox
88,968
phishing emails analyzed in Q3 2026
38x
more of it sent from compromised accounts
1.4x
more likely to get past native filters
Built by the team behind Google Safe Browsing and reCAPTCHA. Backed by Battery Ventures, Accel and Foundation Capital.












Full findings, the technical deep dive, and five sanitized case studies from Q3 2026.
The 90% figure is measured by Aegis in customer environments, compared with rule-based filtering.
How the data was collected, and what you get.
88,968 phishing emails observed between July 1 and September 1, 2026, compared with Q2 2026. Each email is sorted into one of three groups: human-written, AI spear phishing, and templated AI phishing.
Mass phishing written with AI from a template and sent to many people at once, as opposed to AI spear phishing written for one target. It grew from 0.5% to 5.8% of confirmed phishing between Q2 and Q3.
The classification is probabilistic, based on features we can observe in each message. The report's methodology section explains how it works and where its limits are.
The full findings, a technical deep dive with evasion, DMARC, timing and brand breakdowns by group, and five sanitized case studies.
Fill in the form at the top of this page and we will email you the report. It is free.
Yes. Connect Microsoft 365 or Google Workspace by API, with no MX change, and Aegis runs in monitoring mode next to your current stack. Book a demo to get started.
Connect a tenant, run in monitoring mode, and compare against what your current stack delivered.
Five-minute connect · monitoring mode · disconnect any time without touching mail routing