Published on August 8, 2026 · The mitza.es team

Phishing remains, year after year, the most common attack vector against businesses in Spain: INCIBE logged 25,133 cases in 2025, out of more than 45,000 online fraud incidents, within a total of 122,223 cybersecurity incidents handled (26% more than the previous year). What's new in 2026 isn't phishing itself, but how artificial intelligence has changed its effectiveness.
Why AI-generated phishing is different
Phishing emails written with generative AI achieve click-through rates more than four times higher than their human-written equivalents. The reason is simple: AI removes the grammar and tone mistakes that used to give a scam away, and it lets attackers personalize a message from a victim's public data in seconds — work that used to take hours per target.
Deepfakes: from curiosity to corporate fraud
Deepfake fraud generated €929 million in losses worldwide in 2025, three times more than in 2024. In Spain, 23% of companies have already suffered some kind of deepfake fraud attempt, and a BEC-style scam (impersonating an executive's email or voice) using a CEO deepfake costs an average of €600,000 when successful. In February 2026, Spain's Civil Guard warned about fake AI-generated profiles impersonating real officers, and Google pulled a fraudulent ad that used the image of TV host Pablo Motos to promote a fictional investment.
What Europol is warning about for the rest of the year
Europol's IOCTA 2026 report notes that artificial intelligence, automation and specialized criminal infrastructure are expanding the scale of cybercrime: they let attackers operate at volume, personalize messages en masse, and cover their tracks more effectively. It's the same logic behind the rise in cases INCIBE is recording in Spain.
Practical measures for an SME
- Verify any urgent request for payment or a change of bank details through a second channel, even if it appears to come from a known executive.
- Train your team to spot phishing signals, even when the text is well written.
- Apply multi-factor authentication on email, banking and critical access points.
- Set up a clear verification protocol before executing transfers or sensitive changes.
Strengthening the basics before it happens
These figures connect directly with the rise in ransomware we've seen this year in Spain, and with the minimum security obligations already set out by the NIS2 directive for companies within its scope. If you want to know where your company stands, our IT maintenance service includes a basic security review, and for a more complete diagnosis you can request a tailored audit.