How can you identify a phishing attack and prevent your team from falling victim to the scam?
Learn to recognize the signs of a phishing attack, understand how artificial intelligence has transformed the sophistication of these scams, and discover how to prepare your team to react methodically to suspicious messages.
Phishing is no longer just that email with poorly written Portuguese, a strange sender, and an improbable promise. By 2026, a large portion of the messages arriving in the inboxes of Brazilian employees will be written using language models, adapted to the recipient's context, and sent from carefully chosen domains to go unnoticed by technical filters. According to research by KnowBe4 cited in a phishing statistics report published in 2026 , 82,6% of current phishing emails contain some type of AI-generated content, and versions produced with the aid of generative models achieve click-through rates 4,5 times higher than traditional ones.
Brazil occupies an uncomfortable position in this scenario. According to a survey by the Association for the Defense of Personal and Consumer Data (ADDP), published in a report by Correio Braziliense in November 2025 , the country ranks second globally in cyberattacks, with approximately 700 million attempts per year, equivalent to 1.379 attacks per minute. Between January and September 2025 alone, 1,5 million specific cases of phishing were registered, in addition to scams via WhatsApp and fake call centers that share the same social engineering logic.
In this article, you will understand what characterizes a phishing attack today, what the main types are, what signs allow you to identify a suspicious message, and how to structure a security culture that reduces the likelihood of your team falling for the scam.
What characterizes a phishing attack?
Phishing is a social engineering attack that uses electronic communication to trick the victim into performing an action that compromises the company's security. This action could include entering credentials on a fake page, approving a transfer to an unauthorized account, downloading a malicious attachment, clicking on a link that installs malware, or revealing sensitive information such as authentication codes, customer data, or internal documents.
What distinguishes phishing from other threats is that the vulnerability exploited is not in software or hardware, but in human behavior. No patch can fix the decision of an employee who, under urgent pressure, clicks on a link from a seemingly trustworthy sender. According to the Brasscom cybersecurity report analyzed by Duranium in December 2025 , 85% of phishing incidents mapped in Brazil resulted in data breaches, and the average cost of a breach reached US$1,36 million in 2024, an increase of 11,5% compared to the previous year.
How has phishing evolved with artificial intelligence?
The widespread adoption of generative AI has changed three practical aspects of attack. The first is the quality of language. Texts in fluent Portuguese, without grammatical errors, with correct industry terminology and a tone appropriate to the supposedly represented sender. The second is personalization. Language models process public information about the company and the employee, including LinkedIn profile, recent news, and social media mentions, producing messages that cite real projects, real colleagues, and contexts that increase credibility.
The third is expansion to multiple channels. The attack begins with a well-crafted email but evolves into a voice call with cloning based on three-second audio samples, a Teams or Zoom meeting with real-time video deepfake, or a WhatsApp message using the executive's photo and voice. According to data compiled by a publication on deepfakes in Business Email Compromise in March 2026 , the proportion of BEC attacks using voice, video, or text deepfake increased from less than 5% in 2023 to 40% in the first quarter of 2026, with average losses per incident exceeding US$4,1 million.
The main types of phishing scams targeting Brazilian companies.
Phishing is not a single category. It's a portfolio of techniques that share the same deceptive logic, applied across different channels and formats.
Mass email phishing: This is the oldest and still the most widespread method. Generic messages are sent to large lists, impersonating banks, government agencies, or well-known companies, with a link to a fake page that captures credentials.
Spear phishing: an attack targeted at an individual or small group, personalized with specific information about the victim. Much more effective than mass phishing and increasingly common among medium and large companies.
Business Email Compromise (BEC): a type of attack where the attacker impersonates an executive, supplier, or partner to induce bank transfers, alteration of payment details, or the sending of confidential information. According to statistics compiled by Bright Defense, approximately 78% of BEC messages are attempts at impersonation, and 82% of these attempts impersonate a CEO or other executive.
Smishing: phishing via SMS, with messages that simulate bank alerts, notifications from the Internal Revenue Service, delivery notices, or registration confirmations, usually with a shortened link.
Vishing: voice phishing, including calls from fake call centers, imposter technical support, and increasingly, deepfakes of executives' voices requesting urgent action.
Quishing: phishing via QR Code, where the printed code or code sent by email directs the victim to a fake page. Because the QR code does not allow visual inspection of the address before clicking, this method bypasses several technical filters.
Adversary-in-the-Middle (AiTM): an attack in which phishing captures not only the password but also the post-authentication session cookie, allowing the attacker to bypass multifactor authentication based on codes or notifications.

Signs that indicate a phishing attack
Even with all the sophistication available today, almost all phishing attacks carry identifying signals. Some are technical and others are behavioral, and it's worthwhile to train your team to recognize both groups.
Sender's domain slightly altered.
It's common to find subtle substitutions such as replacing "m" with "rn", using domains very similar to the legitimate one, or sending from subdomains that don't belong to the real organization. Hovering the mouse over the sender's name before clicking remains one of the most effective checks.
Artificial sense of urgency
Phrases like “act immediately,” “your account will be blocked in two hours,” and “response needed today” exist to shift the recipient from reflective mode to reactive mode. Legitimate executives rarely pressure their team to execute transfers or reveal information in minutes, without room for verification.
Discrepancy between link text and actual address.
A link displayed as www.bancolegítimo.com.br may point to a completely different address. It's always possible to verify the actual destination by hovering your mouse over the link, whether on a desktop or when viewing the link details on mobile devices.
Unusual request from a known channel.
A request for an urgent change of supplier bank details, a CEO's request for immediate payment to a new account, a purchase order for employee gift vouchers. Any unusual action, even from a recognizable sender, warrants verification through an alternative channel.
Unexpected attachments or links
Documents, spreadsheets, or PDFs that arrive without prior context, or with vague context such as "see attached" and "check the document," require caution. The same applies to links that require immediate login to corporate services.
Visual elements almost correct.
Slightly distorted logo, non-standard colors, font different from that normally used by the sender, inconsistent formatting. Sophisticated attacks correct these details, but they still frequently slip through.
Confidentiality request
Messages that instruct the recipient not to discuss with colleagues, not to involve the finance team, or not to follow usual procedures are among the strongest indicators of a BEC attempt. Our articles on the most common security mistakes that put companies at risk of attacks provide additional context on behavioral patterns that increase corporate exposure.
How to prepare your team to avoid falling for the scam.
Reducing the success rate of phishing attacks in your company requires a combination of technical controls, processes, and ongoing training. None of these elements work in isolation.
Multifactor authentication resistant to phishing.
SMS-based or application-based MFA remains superior to password-only methods, but can be circumvented by AiTM-type attacks that capture the code along with the credential. Phishing-resistant methods, based on physical cryptographic keys (FIDO2 standard) or device-linked biometrics, significantly raise the attack barrier.
Updated technical filters
Email gateways with behavioral analytics, domain reputation checking, attachment sandboxing, and click-through URL inspection substantially reduce the volume of emails reaching the user. Proper SPF, DKIM, and DMARC configurations on your own domain also make it harder for attackers to impersonate your company in attacks against third parties.
Double-checking processes for sensitive actions
Any transfer above a certain value, change of supplier bank details, creation of a new beneficiary, or urgent payment should require confirmation through an alternative channel before execution. If the request came via email, confirmation should be by phone. If it came via WhatsApp, confirmation should be in person or via official email. The technique of two confirmations through different channels, advocated by digital fraud experts in Brazil, eliminates most BEC scams.
Continuous training and simulations
Annual security training is insufficient. Companies with the best results combine initial training, simulated phishing campaigns throughout the year, and recurring communication about new phishing methods. The goal is not to punish the employee who clicks on a simulation, but to identify the points that need reinforcement in communication.
A culture of guilt-free reporting.
Employees need a clear and accessible channel to report suspicious messages, and they need to know that reporting is always the right thing to do, even when the suspicion is unjustified. Environments where fear of reprimand inhibits reporting multiply the time it takes to detect real attacks.
Governance over public company data
Corporate profiles on LinkedIn, press releases, and social media content provide raw material for spear phishing. This doesn't mean ceasing communication altogether, but rather reviewing what is publicly available regarding approval structures, decision-making hierarchies, and internal processes.

What to do when the click has already happened?
Even with training and controls, the click will eventually happen. The difference between a manageable incident and a crisis usually lies in what occurs in the first few minutes.
If an employee entered credentials on a suspicious page, the password should be changed immediately and active sessions terminated on all platforms. If MFA is in effect, it is necessary to check if any unknown devices have been linked to the account and revoke suspicious access.
If the employee downloaded or ran an attachment, the device should be isolated from the network before any further action. Remaining connected can allow for the lateral spread of malware. The IT team or security partner needs to be contacted to analyze the device and assess signs of compromise elsewhere in the environment.
If the incident involved the execution of a transfer or the sending of sensitive data, the banking channels and affected areas need to be notified immediately. In cases of fraud via Pix (Brazil's instant payment system), Joint Resolution No. 6 of the Central Bank establishes protocols between institutions to attempt to retain and recover funds within short timeframes. For larger incidents, our content on what to do if your company is a victim of a ransomware attack delves deeper into how to structure the response in the first few hours.
Frequently asked questions about phishing attacks
Many questions arise when IT managers and area leaders begin to structure phishing protection in their companies. The questions below frequently come up in conversations with clients who have faced incidents or want to reduce the likelihood of them happening. The answers have been organized to support both technical decisions and alignment between IT, security, and business areas, and can serve as an initial reference before a more in-depth analysis of your operation's security posture.
My antivirus and email filter aren't enough against phishing?
They reduce the volume of attacks that arrive, but they don't eliminate them. Modern attacks use newly created domains, attachments with evasion techniques, and pages hosted on legitimate services like Google Docs or Canva, making reputation-based blocking difficult. According to market data, approximately 55% of phishing pages in 2026 will use valid SSL certificates, which negates the old rule of trusting only HTTPS sites. Technical filters are essential layers, but they need to be combined with training and processes.
Does phishing only affect large companies?
No. Small and medium-sized enterprises are frequent targets precisely because they possess valuable assets with lower security maturity. According to the CISO Advisor Census 2026, 9 out of 10 small and medium-sized Brazilian companies suffered at least one attempted attack via WhatsApp Web or corporate email in 2025. Many criminals prefer this size because incident response tends to be slower and less structured.
How does WhatsApp fit into corporate phishing strategies?
WhatsApp is currently one of the most effective vectors for social engineering in Brazil. Fake executives create contacts with photos and messages that mimic the company leader, requesting urgent gift card purchases, money transfers, or the sending of internal documents. Companies that use WhatsApp as a professional channel need to establish clear rules about what topics can and cannot be discussed there, and train employees to be suspicious of any contact from an unknown number, even if the photo and name seem familiar.
Is it worth running simulated phishing campaigns in my company?
Yes, provided they are well executed. Simulated campaigns show, with objective data, which areas and which types of messages generate the most clicks. They help guide future training and track the evolution of human risk over time. The common mistake is using these campaigns to punish employees, which generates fear and reduces future reporting. The purpose should always be educational, with the click treated as an opportunity for reinforcement, not as a personal failing.
Is multifactor authentication enough to block phishing?
It greatly reduces, but does not completely eliminate, the risk. SMS-based or application code-based MFA can be circumvented by Adversary-in-the-Middle attacks, which capture the second factor at the moment the user types it on the fake page. Phishing-resistant MFA, based on physical cryptographic keys or device-linked biometrics, is significantly more effective. Where possible, this method should be the standard for privileged access and sensitive areas.
Protect your team with those who understand the Brazilian landscape.
With 22 years of experience, Ayko supports Brazilian companies in implementing comprehensive cybersecurity strategies, combining technical controls, access policies, continuous monitoring, and team training. Our approach begins with a careful analysis of the environment and the specific threats affecting each sector, considering the national context in which we operate.
If your company wants to reduce its exposure to phishing attacks and build a security culture that supports its operations, contact our experts and discover how to transform prevention into a competitive advantage.