{"id":25450,"date":"2025-11-25T09:25:10","date_gmt":"2025-11-25T17:25:10","guid":{"rendered":"https:\/\/www.optery.com\/?p=25450"},"modified":"2026-03-31T09:30:25","modified_gmt":"2026-03-31T16:30:25","slug":"new-phishing-methods-evade-email-defenses","status":"publish","type":"post","link":"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/","title":{"rendered":"New Phishing Methods Evade Email Defenses as Social Engineering Dominates Initial Access"},"content":{"rendered":"\n<div class=\"wp-block-group text-center is-layout-constrained wp-block-group-is-layout-constrained\">\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"200\" height=\"200\" data-attachment-id=\"24512\" data-permalink=\"https:\/\/www.optery.com\/agentic-ai-phishing-and-proactive-defense\/1748020056365-4\/\" data-orig-file=\"https:\/\/www.optery.com\/wp-content\/uploads\/2025\/05\/1748020056365-3.png\" data-orig-size=\"200,200\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"\" data-image-description=\"&lt;p&gt;The Optery Dispatch&lt;\/p&gt;\n\" data-image-caption=\"\" data-large-file=\"https:\/\/www.optery.com\/wp-content\/uploads\/2025\/05\/1748020056365-3.png\" src=\"https:\/\/www.optery.com\/wp-content\/uploads\/2025\/05\/1748020056365-3.png\" alt=\"The Optery Dispatch\" class=\"wp-image-24512\" srcset=\"https:\/\/www.optery.com\/wp-content\/uploads\/2025\/05\/1748020056365-3.png 200w, https:\/\/www.optery.com\/wp-content\/uploads\/2025\/05\/1748020056365-3-150x150.png 150w, https:\/\/www.optery.com\/wp-content\/uploads\/2025\/05\/1748020056365-3-24x25.png 24w, https:\/\/www.optery.com\/wp-content\/uploads\/2025\/05\/1748020056365-3-48x49.png 48w, https:\/\/www.optery.com\/wp-content\/uploads\/2025\/05\/1748020056365-3-82x82.png 82w, https:\/\/www.optery.com\/wp-content\/uploads\/2025\/05\/1748020056365-3-164x164.png 164w, https:\/\/www.optery.com\/wp-content\/uploads\/2025\/05\/1748020056365-3-64x64.png 64w\" sizes=\"(max-width: 200px) 100vw, 200px\" \/><\/figure>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ember1213\">Welcome to&nbsp;<em>The Optery Dispatch<\/em>&nbsp;\u2014 a newsletter delivering the latest insights on threat intelligence and proactive cybersecurity strategy. In Issue #7, published November 25, 2025, we cover:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Microsoft\u2019s new Digital Defense Report shows ClickFix as the leading initial-access technique, underscoring how social engineering continues to outpace traditional defenses.<\/li>\n\n\n\n<li>A new phishing platform called Quantum Route Redirect automates credential theft campaigns and evades multiple layers of email security.<\/li>\n\n\n\n<li>DoorDash discloses a breach resulting from social engineering that exposed contact information of some of its customers, Dashers, and merchants.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"ember3729\">Microsoft\u2019s Digital Defense Report 2025 shows social engineering techniques dominating initial access methods, accounting for 89% of observed attacks<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><span class=\"text-blue\">ClickFix has become a go-to initial access method which traditional phishing protections don\u2019t catch<\/span><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to Microsoft\u2019s new Digital Defense Report 2025, ClickFix topped the list of initial access methods observed by Microsoft Defender Experts over the past year. ClickFix is a social engineering technique that deceives users into copying and running malicious commands, disguised as \u201cfixes,\u201d CAPTCHA checks, or IT support prompts, directly in Windows Run, Terminal, or PowerShell.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With just a few keystrokes, attackers can deliver infostealers, remote-access Trojans, or worms, enabling credential theft and persistent access. ClickFix attacks are delivered via phishing, malvertising, and drive-by compromises, most of which impersonate legitimate brands and organizations. The report notes that traditional phishing protections won\u2019t catch ClickFix.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To defend against ClickFix, Microsoft recommends implementing the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u201cTeach users that pasting commands from unknown sources is as risky as clicking suspicious links.\u201d<\/li>\n\n\n\n<li>\u201cEnable PowerShell logging and use Constrained Language Mode to limit abuse.\u201d<\/li>\n\n\n\n<li>\u201cWatch for unusual clipboard activity followed by shell launches (cmd.exe, powershell.exe).\u201d<\/li>\n\n\n\n<li>\u201cDisable clipboard access and scripting in untrusted zones.\u201d<\/li>\n\n\n\n<li>\u201cCorrelate clipboard usage with downstream execution patterns to catch suspicious flows.\u201d<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Of confirmed incidents escalated to Microsoft Defender Experts, where the initial access vector could be definitively determined, ClickFix accounted for 47% of intrusions, phishing for 35%, password spray for 10%, and drive-by compromise\/SEO poisoning for 7%.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Adding together the methods of ClickFix, traditional phishing, and drive-by compromise\/SEO poisoning, social engineering drove 89% of all attacks in Microsoft\u2019s confirmed initial-access dataset.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Other findings<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Across the broader threat landscape, the report highlights that malware families such as Lumma Stealer, RedLine, Vidar, Atomic Stealer, and Raccoon Stealer, once considered post-exploitation tools, are now being used as first-stage payloads. These infostealers are typically delivered through malvertising, SEO poisoning, cracked software, and social engineering techniques like ClickFix, and are designed to collect credentials, browser session tokens, and system context data at scale. Microsoft notes that these infections can escalate into enterprise-wide intrusions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft additionally observed an uptick in device code phishing, where attackers abuse the device code authentication flow to obtain access and refresh tokens that can grant account access and support persistent or lateral movement as long as the token remains valid.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Email bombing, when an attacker floods a target\u2019s inbox with hundreds or thousands of subscription emails, is described in the report as a particularly effective social-engineering tactic being used to obscure important alerts such as MFA prompts, password resets, fraud alerts, and transaction notifications, or to create confusion that attackers can exploit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Across the report, Microsoft emphasizes \u201cadversaries aren\u2019t breaking in\u2014they\u2019re logging in.\u201d MFA continues to be essential, though attackers are continuing to find new ways to circumvent it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To reduce the number of social engineering attempts organizations must defend against, minimizing exposed employee PII wherever possible helps prevent attackers from being able to identify and target employees with their lures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Read the full report for more insights:&nbsp;<a href=\"https:\/\/www.microsoft.com\/en-us\/corporate-responsibility\/cybersecurity\/microsoft-digital-defense-report-2025\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Digital Defense Report 2025 | Microsoft<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"ember3740\">Quantum Route Redirect: A New Phishing Kit That Can Defeat Traditional Defenses<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ember3741\"><strong><span class=\"text-blue\">Powerful new phishing tool that can bypass multiple layers of security now targeting Microsoft 365 users<\/span><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">KnowBe4 researchers have identified a new phishing tool called \u201cQuantum Route Redirect\u201d (QRR), and it marks another step in the industrialization of social engineering.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The QRR kit comes with prebuilt phishing domains, brand-spoofing templates (DocuSign, payroll, payment notices, missed voicemail messages), and QR-code \u201cquishing\u201d support. Instead of attackers building their own infrastructure, QRR lets them launch large-scale credential-theft campaigns with minimal technical skill.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The platform\u2019s biggest advantage is its automated traffic-routing engine. When the phishing link is activated, either by a security scanner or by an employee, QRR analyzes the request and determines whether it came from a bot or a real user.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Scanners are sent to harmless websites, making the email appear safe, while real users are redirected to convincing fake Microsoft 365 login pages designed to capture their credentials. This bot-vs-human filtering enables QRR to slip past Microsoft Exchange Online Protection, secure email gateways, integrated cloud email security tools, and even some web application firewalls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">KnowBe4 has identified roughly 1,000 domains hosting QRR, with victims in 90 countries; 76% of affected users are in the United States. The tool includes a dashboard with browser fingerprinting, VPN\/proxy detection, analytics, and real-time statistics.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cUnfortunately, we believe the technology behind Quantum Route Redirect is here to stay and will likely increase in use as cybercriminals look to evade URL scanning technologies,\u201d KnowBe4 noted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As these turnkey kits spread, organizations should expect an increase in business-email\u2013style lures, quishing attempts, and credential-harvesting campaigns.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Despite its sophistication, QRR still depends on one constant: attackers need personal information about employees to choose targets, shape believable lures, and increase success rates. Even the most advanced phishing kits can\u2019t operate effectively without accurate contact details and job roles.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Minimizing that exposed PII remains one of the few steps organizations can take to meaningfully disrupt targeting before a phishing kit ever reaches an inbox.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Learn more:&nbsp;<a href=\"https:\/\/blog.knowbe4.com\/quantum-route-redirect-anonymous-tool-streamlining-global-phishing-attack?utm_campaign=13550123-The%20Optery%20Dispatch%20-%20Newsletter%2FNurture&amp;utm_source=hs_email&amp;utm_medium=email&amp;_hsenc=p2ANqtz-8WbrkJZDCtG0GlSTnXAH-5OoGKtRpRD5ya-H3PeRNGgXQDgbRg3JN9ZZ6CGSGZiKfgTfsH\" target=\"_blank\" rel=\"noreferrer noopener\">Quantum Route Redirect: Anonymous Tool Streamlining Global Phishing Attack<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.techradar.com\/pro\/security\/microsoft-365-users-targeted-by-major-new-phishing-operation-heres-how-to-stay-safe?utm_source=chatgpt.com&amp;_hsenc=p2ANqtz-8WbrkJZDCtG0GlSTnXAH-5OoGKtRpRD5ya-H3PeRNGgXQDgbRg3JN9ZZ6CGSGZiKfgTfsH\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft 365 users targeted by major new phishing operation \u2013 here\u2019s how to stay safe | TechRadar<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"ember3752\">DoorDash Breach Exposes Contact Information After Social Engineering Attack<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ember3753\"><strong><span class=\"text-blue\">Breach shows that basic contact details remain a valuable data type for attackers<\/span><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">DoorDash has confirmed a new data breach following a successful social engineering attack against an employee, allowing an unauthorized actor to access internal systems in late October.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to the company, the attacker obtained contact information which may have included names, email addresses, phone numbers, and physical addresses belonging to customers, Dashers, and merchants. DoorDash emphasized that no SSNs, payment data, or passwords were accessed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On November 12, DoorDash began notifying those affected. The notice states that \u2018no sensitive data was accessed\u2019. Commentators and security experts quickly took issue with the characterization of this data as \u2018non-sensitive,\u2019 as attackers rely on contact data for social engineering, impersonation, credential harvesting, account takeovers, and fraud. It is the same category of data that was undoubtedly needed to conduct the social engineering attack that breached DoorDash.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This breach is the latest in a series of security events for DoorDash. In 2019, the company reported a breach that exposed data belonging to roughly five million customers, Dashers, and merchants. Another breach followed in August 2022, linked to the same threat actors behind the 0ktapus campaign.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">DoorDash users should be alert to unsolicited messages\/phishing attempts that appear to come from DoorDash. Affected users should change their passwords and enable MFA, as attackers commonly pair exposed email addresses with breach-repository data to identify and crack credentials.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The compromise of personal devices via the exploitation of personal contact data can extend to work accounts when those devices are used for corporate access or MFA.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This breach is a reminder that contact information is sensitive, attackers treat it as valuable, and organizations must minimize its exposure in order to reduce their risk of breaches.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Read more:&nbsp;<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/doordash-hit-by-new-data-breach-in-october-exposing-user-information\/?utm_campaign=13550123-The%20Optery%20Dispatch%20-%20Newsletter%2FNurture&amp;utm_source=hs_email&amp;utm_medium=email&amp;_hsenc=p2ANqtz-8WbrkJZDCtG0GlSTnXAH-5OoGKtRpRD5ya-H3PeRNGgXQDgbRg3JN9ZZ6CGSGZiKfgTfsH\" target=\"_blank\" rel=\"noreferrer noopener\">DoorDash hit by new data breach in October exposing user information<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;<\/p>\n\n\n<p><!-- \/wp:post-content --><\/p>\n<p><!-- wp:paragraph --><\/p>\n<p><strong>Thanks for reading! Want us to write about something specific? <\/strong><a href=\"https:\/\/share.hsforms.com\/1WaLDYEywQqKs9wqQESC_nwnwt3v\" target=\"_blank\" rel=\"noopener\"><strong>Submit a topic or idea.<\/strong><\/a><\/p>\n<p><!-- \/wp:paragraph --><\/p>\n<p><!-- wp:paragraph --><\/p>\n<p id=\"ember1719\">If you\u2019re looking to reduce your organization\u2019s exposed PII and prevent phishing, voice and messaging scams, credential theft, and other PII-based threats, Optery can help. Get started here: <a href=\"https:\/\/www.optery.com\/business\/\"><strong>Optery for business<\/strong><\/a><\/p>\n<p><!-- \/wp:paragraph --><\/p>\n<p><!-- wp:paragraph --><\/p>\n<p><!-- \/wp:paragraph --><\/p>\n<p><!-- wp:paragraph --><\/p>\n<p><strong>Subscribe to receive future editions of <a href=\"https:\/\/www.optery.com\/dispatch-newsletter\/\">The Optery Dispatch<\/a><\/strong><\/p>\n<p><!-- \/wp:paragraph --><\/p>\n<p><!-- wp:html --><\/p>\n<p><script src=\"https:\/\/js.hsforms.net\/forms\/embed\/40161883.js\" defer><\/script><\/p>\n<div class=\"hs-form-frame\" data-region=\"na1\" data-form-id=\"612f4b24-f200-4076-bdba-bcc1b6b13d75\" data-portal-id=\"40161883\">\u00a0<\/div>\n<p><!-- \/wp:html --><\/p>\n<p><!-- wp:paragraph --><\/p>\n<p><!-- \/wp:paragraph --><\/p>\n<p><!-- wp:paragraph --><\/p>\n<p><!-- \/wp:paragraph --><\/p>","protected":false},"excerpt":{"rendered":"<p>Welcome to&nbsp;The Optery Dispatch&nbsp;\u2014 a newsletter delivering the latest insights on threat intelligence and proactive cybersecurity strategy. In Issue #7, published November 25, 2025, we cover: Microsoft\u2019s Digital Defense Report 2025 shows social engineering techniques dominating initial access methods, accounting for 89% of observed attacks ClickFix has become a go-to initial access method which traditional<a href=\"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/\">Continue reading <span class=\"sr-only\">&#8220;New Phishing Methods Evade Email Defenses as Social Engineering Dominates Initial Access&#8221;<\/span><\/a><\/p>\n","protected":false},"author":37,"featured_media":25453,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[691,1],"tags":[750,261,650,754,658,248,748,749,140,752,751,753,296],"class_list":["post-25450","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-dispatch-newsletter","category-blog","tag-clickfix","tag-credential-theft","tag-doordash","tag-doordash-breach","tag-malvertising","tag-mfa","tag-microsoft","tag-microsoft-digital-defense-report","tag-phishing","tag-phishing-kit","tag-quantom-route-redirect","tag-seo-poisoning","tag-social-engineering"],"acf":{"related_urls":[{"url":"https:\/\/www.optery.com\/comcast-red-canary-emerging-phishing-tradecraft\/","title":"Dispatch #6: Comcast and Red Canary Highlight Recurring and Emerging Phishing Tradecraft"},{"url":"https:\/\/www.optery.com\/salesforce-social-engineering-ai-threats\/","title":"Dispatch #5: Salesforce Breaches, Social Engineering & Agentic AI Threats"},{"url":"https:\/\/www.optery.com\/data-brokers\/","title":"Optery Data Broker Directory"},{"url":"https:\/\/www.optery.com\/security-pro-personal-data-removal-guide\/","title":"Guide to Enterprise Data Removal Service"},{"url":"https:\/\/www.optery.com\/pii-removal-for-executives-is-not-enough\/","title":"PII Removal for Execs is Not Enough"},{"url":"https:\/\/www.optery.com\/reducing-spam-texts-and-calls\/","title":"Why You Get So Many Spam Texts and Calls, and What You Can Actually Do About It"},{"url":"https:\/\/www.optery.com\/optery-vs-deleteme-vs-incogni-analysis-by-cybersecurity-expert\/","title":"Optery vs. DeleteMe vs. Incogni \u2013 Cybersecurity Expert Names Optery the Clear Winner"},{"url":"https:\/\/www.optery.com\/optery-ceo-lawrence-gentilello-data-diva-podcast\/","title":"Optery CEO Lawrence Gentilello Joins Debbie Reynolds on \u201cThe Data Diva\u201d Talks Privacy Podcast"},{"url":"https:\/\/www.optery.com\/cisa-fbi-cnmf-confirm-data-broker-threat\/","title":"Joint CISA\/FBI\/CNMF Advisory Is Confirms Use of Commercial Data Brokers to Target Organizations"},{"url":"https:\/\/www.optery.com\/optery-wins-2025-fortress-cybersecurity-award-for-privacy-enhancing-technologies\/","title":"Optery Wins 2025 Fortress Cybersecurity Award for Privacy Enhancing Technologies"}],"schema_input_mode":false,"custom_json_code":"","post_featured":[],"post_bg":[],"testimonial_source":"","testimonial_customer_name":"","testimonial_quote":"","testimonial_image":"","custom_footer":"footer2","custom_header":25370,"hide_notification":[],"sign_up_banner_page_other":["other"],"sign_up_banner_page_title":"<p>Ready to <span style=\"color: #6ef7d3;\">safeguard <\/span>your employees&#8217; data?<\/p>\n","sign_up_banner_page_text":"See why Optery is the leader in enterprise-grade personal data removal.","sign_up_banner_page_button":{"title":"Request a Demo","url":"https:\/\/share.hsforms.com\/1FY2GQMI4T0KppwNRRnxmegnwt3v","target":""}},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>New Phishing Methods Evade Email Defenses as Social Engineering Dominates Initial Access - Optery<\/title>\n<meta name=\"description\" content=\"New phishing tool called \u201cQuantum Route Redirect\u201d that evades email defenses as social engineering dominates initial access.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New Phishing Methods Evade Email Defenses as Social Engineering Dominates Initial Access\" \/>\n<meta property=\"og:description\" content=\"New phishing tool called \u201cQuantum Route Redirect\u201d that evades email defenses as social engineering dominates initial access.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/\" \/>\n<meta property=\"og:site_name\" content=\"Optery\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Optery\/\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-25T17:25:10+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-03-31T16:30:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.optery.com\/wp-content\/uploads\/2025\/12\/Dispatch-7.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Sara\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:description\" content=\"FBI issues FLASH alert on Salesforce breaches by UNC6040 and UNC6395 using vishing and stolen OAuth tokens, LevelBlue data shows BEC and social engineering behind 96% of incidents, and Anthropic\u2019s latest report reveals how agentic AI is enabling single operators to run breaches end-to-end.\" \/>\n<meta name=\"twitter:creator\" content=\"@Optery\" \/>\n<meta name=\"twitter:site\" content=\"@Optery\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sara\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.optery.com\\\/new-phishing-methods-evade-email-defenses\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.optery.com\\\/new-phishing-methods-evade-email-defenses\\\/\"},\"author\":{\"name\":\"Sara\",\"@id\":\"https:\\\/\\\/www.optery.com\\\/#\\\/schema\\\/person\\\/d325cf6ab36a80db7bf197541907ef14\"},\"headline\":\"New Phishing Methods Evade Email Defenses as Social Engineering Dominates Initial Access\",\"datePublished\":\"2025-11-25T17:25:10+00:00\",\"dateModified\":\"2026-03-31T16:30:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.optery.com\\\/new-phishing-methods-evade-email-defenses\\\/\"},\"wordCount\":1335,\"publisher\":{\"@id\":\"https:\\\/\\\/www.optery.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.optery.com\\\/new-phishing-methods-evade-email-defenses\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.optery.com\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/Dispatch-7.png\",\"keywords\":[\"ClickFix\",\"credential theft\",\"DoorDash\",\"DoorDash Breach\",\"malvertising\",\"MFA\",\"Microsoft\",\"Microsoft Digital Defense Report\",\"phishing\",\"Phishing Kit\",\"Quantom Route Redirect\",\"seo poisoning\",\"Social Engineering\"],\"articleSection\":[\"NEWSLETTER\",\"OPTERY BLOG\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.optery.com\\\/new-phishing-methods-evade-email-defenses\\\/\",\"url\":\"https:\\\/\\\/www.optery.com\\\/new-phishing-methods-evade-email-defenses\\\/\",\"name\":\"New Phishing Methods Evade Email Defenses as Social Engineering Dominates Initial Access - Optery\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.optery.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.optery.com\\\/new-phishing-methods-evade-email-defenses\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.optery.com\\\/new-phishing-methods-evade-email-defenses\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.optery.com\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/Dispatch-7.png\",\"datePublished\":\"2025-11-25T17:25:10+00:00\",\"dateModified\":\"2026-03-31T16:30:25+00:00\",\"description\":\"New phishing tool called \u201cQuantum Route Redirect\u201d that evades email defenses as social engineering dominates initial access.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.optery.com\\\/new-phishing-methods-evade-email-defenses\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.optery.com\\\/new-phishing-methods-evade-email-defenses\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.optery.com\\\/new-phishing-methods-evade-email-defenses\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.optery.com\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/Dispatch-7.png\",\"contentUrl\":\"https:\\\/\\\/www.optery.com\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/Dispatch-7.png\",\"width\":1280,\"height\":720,\"caption\":\"The Optery Dispatch - Issue # 7\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.optery.com\\\/new-phishing-methods-evade-email-defenses\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.optery.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"New Phishing Methods Evade Email Defenses as Social Engineering Dominates Initial Access\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.optery.com\\\/#website\",\"url\":\"https:\\\/\\\/www.optery.com\\\/\",\"name\":\"Optery\",\"description\":\"Opt Out of Dozens of Data Brokers all in One Place\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.optery.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.optery.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.optery.com\\\/#organization\",\"name\":\"Optery Inc\",\"url\":\"https:\\\/\\\/www.optery.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.optery.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.optery.com\\\/wp-content\\\/uploads\\\/2022\\\/09\\\/optery-logo-3.svg\",\"contentUrl\":\"https:\\\/\\\/www.optery.com\\\/wp-content\\\/uploads\\\/2022\\\/09\\\/optery-logo-3.svg\",\"width\":111,\"height\":26,\"caption\":\"Optery Inc\"},\"image\":{\"@id\":\"https:\\\/\\\/www.optery.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Optery\\\/\",\"https:\\\/\\\/x.com\\\/Optery\",\"https:\\\/\\\/www.youtube.com\\\/optery\",\"https:\\\/\\\/www.reddit.com\\\/r\\\/optery\"],\"description\":\"Optery is an automated data removal service designed to help individuals, families, and businesses find and remove their personal information\u2014such as home address, phone number, and email\u2014from hundreds of data broker and people-search websites that publish or sell such details online.\",\"email\":\"support@optery.com\",\"legalName\":\"Optery, Inc.\",\"foundingDate\":\"2020-08-19\",\"numberOfEmployees\":{\"@type\":\"QuantitativeValue\",\"minValue\":\"11\",\"maxValue\":\"50\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.optery.com\\\/#\\\/schema\\\/person\\\/d325cf6ab36a80db7bf197541907ef14\",\"name\":\"Sara\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.optery.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/optery-heather-1-96x96.png\",\"url\":\"https:\\\/\\\/www.optery.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/optery-heather-1-96x96.png\",\"contentUrl\":\"https:\\\/\\\/www.optery.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/optery-heather-1-96x96.png\",\"caption\":\"Sara\"},\"description\":\"Sara is an award-winning marketing leader in the cybersecurity and GRC spaces. Before joining Optery to lead their B2B marketing function, she was at the helm of marketing for a privacy-focused cybersecurity startup, a multinational organization, and a creative agency. She blends strategy, technology, and creativity to boost brand stories, fuel growth, and create sustained and measurable demand. Known for steering high-impact projects with a data-driven approach, Sara also regularly publishes content on cybersecurity, privacy, and related risk topics.\",\"url\":\"https:\\\/\\\/www.optery.com\\\/author\\\/sara\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"New Phishing Methods Evade Email Defenses as Social Engineering Dominates Initial Access - Optery","description":"New phishing tool called \u201cQuantum Route Redirect\u201d that evades email defenses as social engineering dominates initial access.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/","og_locale":"en_US","og_type":"article","og_title":"New Phishing Methods Evade Email Defenses as Social Engineering Dominates Initial Access","og_description":"New phishing tool called \u201cQuantum Route Redirect\u201d that evades email defenses as social engineering dominates initial access.","og_url":"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/","og_site_name":"Optery","article_publisher":"https:\/\/www.facebook.com\/Optery\/","article_published_time":"2025-11-25T17:25:10+00:00","article_modified_time":"2026-03-31T16:30:25+00:00","og_image":[{"width":1280,"height":720,"url":"https:\/\/www.optery.com\/wp-content\/uploads\/2025\/12\/Dispatch-7.png","type":"image\/png"}],"author":"Sara","twitter_card":"summary_large_image","twitter_description":"FBI issues FLASH alert on Salesforce breaches by UNC6040 and UNC6395 using vishing and stolen OAuth tokens, LevelBlue data shows BEC and social engineering behind 96% of incidents, and Anthropic\u2019s latest report reveals how agentic AI is enabling single operators to run breaches end-to-end.","twitter_creator":"@Optery","twitter_site":"@Optery","twitter_misc":{"Written by":"Sara","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/#article","isPartOf":{"@id":"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/"},"author":{"name":"Sara","@id":"https:\/\/www.optery.com\/#\/schema\/person\/d325cf6ab36a80db7bf197541907ef14"},"headline":"New Phishing Methods Evade Email Defenses as Social Engineering Dominates Initial Access","datePublished":"2025-11-25T17:25:10+00:00","dateModified":"2026-03-31T16:30:25+00:00","mainEntityOfPage":{"@id":"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/"},"wordCount":1335,"publisher":{"@id":"https:\/\/www.optery.com\/#organization"},"image":{"@id":"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/#primaryimage"},"thumbnailUrl":"https:\/\/www.optery.com\/wp-content\/uploads\/2025\/12\/Dispatch-7.png","keywords":["ClickFix","credential theft","DoorDash","DoorDash Breach","malvertising","MFA","Microsoft","Microsoft Digital Defense Report","phishing","Phishing Kit","Quantom Route Redirect","seo poisoning","Social Engineering"],"articleSection":["NEWSLETTER","OPTERY BLOG"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/","url":"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/","name":"New Phishing Methods Evade Email Defenses as Social Engineering Dominates Initial Access - Optery","isPartOf":{"@id":"https:\/\/www.optery.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/#primaryimage"},"image":{"@id":"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/#primaryimage"},"thumbnailUrl":"https:\/\/www.optery.com\/wp-content\/uploads\/2025\/12\/Dispatch-7.png","datePublished":"2025-11-25T17:25:10+00:00","dateModified":"2026-03-31T16:30:25+00:00","description":"New phishing tool called \u201cQuantum Route Redirect\u201d that evades email defenses as social engineering dominates initial access.","breadcrumb":{"@id":"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/#primaryimage","url":"https:\/\/www.optery.com\/wp-content\/uploads\/2025\/12\/Dispatch-7.png","contentUrl":"https:\/\/www.optery.com\/wp-content\/uploads\/2025\/12\/Dispatch-7.png","width":1280,"height":720,"caption":"The Optery Dispatch - Issue # 7"},{"@type":"BreadcrumbList","@id":"https:\/\/www.optery.com\/new-phishing-methods-evade-email-defenses\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.optery.com\/"},{"@type":"ListItem","position":2,"name":"New Phishing Methods Evade Email Defenses as Social Engineering Dominates Initial Access"}]},{"@type":"WebSite","@id":"https:\/\/www.optery.com\/#website","url":"https:\/\/www.optery.com\/","name":"Optery","description":"Opt Out of Dozens of Data Brokers all in One Place","publisher":{"@id":"https:\/\/www.optery.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.optery.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.optery.com\/#organization","name":"Optery Inc","url":"https:\/\/www.optery.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.optery.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.optery.com\/wp-content\/uploads\/2022\/09\/optery-logo-3.svg","contentUrl":"https:\/\/www.optery.com\/wp-content\/uploads\/2022\/09\/optery-logo-3.svg","width":111,"height":26,"caption":"Optery Inc"},"image":{"@id":"https:\/\/www.optery.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Optery\/","https:\/\/x.com\/Optery","https:\/\/www.youtube.com\/optery","https:\/\/www.reddit.com\/r\/optery"],"description":"Optery is an automated data removal service designed to help individuals, families, and businesses find and remove their personal information\u2014such as home address, phone number, and email\u2014from hundreds of data broker and people-search websites that publish or sell such details online.","email":"support@optery.com","legalName":"Optery, Inc.","foundingDate":"2020-08-19","numberOfEmployees":{"@type":"QuantitativeValue","minValue":"11","maxValue":"50"}},{"@type":"Person","@id":"https:\/\/www.optery.com\/#\/schema\/person\/d325cf6ab36a80db7bf197541907ef14","name":"Sara","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.optery.com\/wp-content\/uploads\/2024\/02\/optery-heather-1-96x96.png","url":"https:\/\/www.optery.com\/wp-content\/uploads\/2024\/02\/optery-heather-1-96x96.png","contentUrl":"https:\/\/www.optery.com\/wp-content\/uploads\/2024\/02\/optery-heather-1-96x96.png","caption":"Sara"},"description":"Sara is an award-winning marketing leader in the cybersecurity and GRC spaces. Before joining Optery to lead their B2B marketing function, she was at the helm of marketing for a privacy-focused cybersecurity startup, a multinational organization, and a creative agency. She blends strategy, technology, and creativity to boost brand stories, fuel growth, and create sustained and measurable demand. Known for steering high-impact projects with a data-driven approach, Sara also regularly publishes content on cybersecurity, privacy, and related risk topics.","url":"https:\/\/www.optery.com\/author\/sara\/"}]}},"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/www.optery.com\/wp-content\/uploads\/2025\/12\/Dispatch-7.png","_links":{"self":[{"href":"https:\/\/www.optery.com\/wp-json\/wp\/v2\/posts\/25450","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.optery.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.optery.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.optery.com\/wp-json\/wp\/v2\/users\/37"}],"replies":[{"embeddable":true,"href":"https:\/\/www.optery.com\/wp-json\/wp\/v2\/comments?post=25450"}],"version-history":[{"count":27,"href":"https:\/\/www.optery.com\/wp-json\/wp\/v2\/posts\/25450\/revisions"}],"predecessor-version":[{"id":26167,"href":"https:\/\/www.optery.com\/wp-json\/wp\/v2\/posts\/25450\/revisions\/26167"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.optery.com\/wp-json\/wp\/v2\/media\/25453"}],"wp:attachment":[{"href":"https:\/\/www.optery.com\/wp-json\/wp\/v2\/media?parent=25450"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.optery.com\/wp-json\/wp\/v2\/categories?post=25450"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.optery.com\/wp-json\/wp\/v2\/tags?post=25450"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}