The 21 second breach: why phishing defence now fails after the click

by Black Hat Middle East and Africa
on
The 21 second breach: why phishing defence now fails after the click

We used to fight the phishing fight before the click. If people could spot the lure and move on without clicking the link, everything would be OK. But recent reports from Zscaler ThreatLabz and ANY.RUN show that this model of defence isn’t enough anymore. Because the danger can now begin after the click – in encrypted web sessions and at a speed that leaves security teams with very little time to respond.

The click isn’t the main event 

Zscaler's 2026 research into phishing and initial access highlights just how much phishing has evolved. In 2025, 87% of blocked malicious activity was delivered over HTTPS, while 95.2% of all blocked phishing attempts (around 1.2 billion hits) travelled through encrypted channels.

The implication is that now, phishing can lead to compromise through encrypted web sessions, making malicious activity far harder to distinguish from legitimate traffic.

Many organisations still focus phishing defences on the inbox. Email security filters malicious messages, awareness training encourages users not to click, and multi-factor authentication (MFA) provides another layer of protection.

But a growing number of phishing campaigns use adversary-in-the-middle techniques and session interception to bypass traditional credential-based defences. Rather than simply stealing passwords, attackers are increasingly targeting authenticated sessions themselves.

ANY.RUN's Q1 2026 risk research backs up this trend. Sneaky2FA detections increased by 76.8%, while EvilProxy activity grew by 17.7% – demonstrating continued investment in phishing kits designed to defeat MFA.

Twenty-one seconds changes the equation

According to ANY.RUN’s report, the median time to living-off-the-land execution was just 16 seconds, while the median time to persistence was 21 seconds.

That leaves very little time for security teams to investigate before an attacker has established a foothold. And this fundamentally changes what phishing defence means. If attackers can move from initial access to native Windows tools within seconds and establish persistence less than half a minute later, traditional post-click investigation will probably happen too late.

ANY.RUN also recorded a 17.4% increase in PowerShell abuse and a 58.4% rise in JavaScript-based LOLBAS activity. So rather than relying solely on bespoke malware, attackers are exploiting legitimate administrative tools that blend into everyday system activity – which makes detecting malicious behaviour significantly more difficult, and reduces the window available for defenders to respond.

So what can you do? 

  • Look beyond the inbox. As phishing increasingly operates through encrypted traffic, organisations need visibility into web sessions, identity activity and abnormal authentication behaviour – not just malicious emails.
  • Strengthen identity protection. MFA is still essential, but phishing-resistant authentication, conditional access policies and session monitoring are becoming equally important as attackers target authenticated sessions.
  • Automate containment wherever you can. With attackers establishing persistence in a median of 21 seconds, these findings suggest organisations should prioritise automated containment alongside faster detection and response.

The real phishing challenge now lies in what happens immediately after someone has clicked a malicious link. Organisations may now have just a few seconds to detect, contain and interrupt an attack before initial access becomes a far more serious compromise.

 

Learn from the world’s leading cybersecurity practitioners at Black Hat MEA 2026, and implement tools and processes to protect against evolving threats. Register now.

Share on

Join newsletter

Join the newsletter to receive the latest updates in your inbox.


Follow us


Topics

Sign up for more like this.

Join the newsletter to receive the latest updates in your inbox.

Related articles