Security1 distinct publisher3 min readPublished
Verizon's 2026 DBIR puts mobile phishing simulation click rates 40% above email. Most of those attempts never reach a security team, because the report button, the gateway and the triage queue all sit in the inbox.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The mechanism in Keepnet's own description is a sequencing problem. Email primes the target. An SMS follows, claiming urgency. Then the voice call closes [12]. Email is asynchronous, so the target can pause and check with a colleague. The SMS and the call are synchronous, and by the vendor's framing the target has seconds [12]. User reporting is an asynchronous control. It works best on the leg of the attack the attacker has already stopped depending on.
Check the arithmetic before anyone builds a budget case out of this release. Verizon's 40% is relative and comes from simulations: mobile median click rate against email median click rate [3]. The Microsoft 2025 Digital Defense Report figure quoted in the same announcement is absolute: 54% click-through for AI-automated phishing against 12% for standard attempts, which the release calls a 4.5x multiplier [7]. Different bases. Apply Verizon's 40% to Microsoft's 12% baseline and you get 16.8%, well short of 54% [13]. One number measures the channel, the other measures the automation, and a slide that adds them is wrong.
The receiving end is where the launch is thin. The app is free to anyone on the App Store, and Keepnet says organizations can roll it out across a workforce [1]. Routing reported events into an incident workflow exists only for Keepnet customers [2]. Android is described as next on the roadmap [1]. An organization with a mixed fleet can therefore instrument its iPhones and tell everyone else to keep screenshotting. The announcement also does not say how the app captures a suspicious message or call record on iOS [14], which is the detail that decides whether one-tap is literal or a copy-paste with better branding.
The number worth carrying into a budget conversation is the FBI's. IC3's 2025 report counted $798 million in smishing and vishing losses from government impersonation alone, and per the release this was the first time those losses were measured as their own category [11]. A category is how loss data turns into a line item. Mandiant's M-Trends 2026, also cited, puts voice phishing in more than 60% of phishing-related incident response engagements [9], which is consistent with what responders have handled since MGM Resorts in 2023 and through Scattered Spider's April 2025 intrusions at Marks & Spencer and Co-op, estimated in the release at £270m to £440m in combined damage [8].
ENISA's 2025 Threat Landscape, quoted in the same announcement, puts roughly 60% of initial access at phishing and more than 80% of observed social engineering as already AI-supported [6]. That is the supply-side reason help desk and finance queues are first-touch surfaces [10]: the caller sounds right, in the target's language, at volume, and the cost per attempt keeps falling.
The DBIR makes the coverage point itself, naming WhatsApp, social media and personal email as channels where most corporate security tooling provides none [5]. Vendors do sell mobile report buttons. The gap is that 80% of organizations have already seen mobile phishing attempts while the telemetry, the gateway and the queue remain email-shaped [4], which means the click rate an awareness program reports each quarter describes the channel that clicks less [3].
Ranked by verification strength, evidence, and original report placement.
For Keepnet customers, reported events land in Keepnet Incident Responder, where security teams handle them in the same workflow as email phishing reports.
80% of organizations have experienced mobile phishing attempts (Verizon Mobile Security Index 2025), most of those incidents never reach security teams, and the corporate report button, the secure gateway and the incident pipeline still live entirely in the email layer.
Keepnet launched a free SMS/Call Reporter app that turns a suspicious SMS or phone call into a one-tap report; anyone can download it for personal protection and organizations can roll it out across their workforce; it is available on the Apple App Store now, with an Android release next on the roadmap.
The 2026 Verizon Data Breach Investigations Report states that mobile-based phishing simulations show "an increase of 40% in the median click rate" compared with email simulations (p. 50), and that higher click rates make mobile devices the new favorite target because defenders have gotten better at spotting phishing emails.
The 2026 DBIR records that criminals are using messaging channels other than corporate email to reach employees, such as WhatsApp, social media and personal email accounts, all platforms where most corporate cybersecurity solutions do not provide coverage.
ENISA's 2025 Threat Landscape reports that roughly 60% of initial access begins with phishing and that more than 80% of observed social engineering activity is already AI-supported.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
October moves NIS2 from transposition into enforcement across the EU1 distinct publisher
invest
Attackers talked their way into Point72, Citadel and Millennium with cloned voices1 distinct publisher
security
Attackers stopped fighting MFA and started phoning the service desk1 distinct publisher
product
Pennsylvania's Snap case makes an App Store questionnaire the alleged lie1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Cited outside, unexamined inside
The borrowed numbers are unusually disciplined for a launch item: Verizon's DBIR quoted at p. 50, the FBI's IC3 report at p. 4, ENISA, Microsoft and Mandiant each named. The product they surround is unexamined. Help Net Security reproduces Keepnet's account of one-tap reporting, verdicts in seconds and a privacy-first architecture with no independent test, and the piece never explains how an iOS app comes to hold the suspicious message or call in the first place. One dollar range — the £270-440 million retail figure — arrives with no source at all.
Shipped, otherwise unmeasured
One dated fact about uptake exists: the app was on the Apple App Store on 2 September 2026. No downloads, no pilot, no named organisation, no Android build yet. The half that matters to security teams — reports flowing into Incident Responder — is available only to existing Keepnet customers, a population the announcement never sizes.
Real gap, asserted closure
The problem side of this story is well documented; the closing of it is not. Verizon, ENISA, Mandiant and the FBI all carry weight on mobile-channel risk, while everything about the remedy is a vendor describing a day-old app. Two of the borrowed figures also pull against each other when stacked: Verizon's 40% is a relative lift on phishing simulations, Microsoft's 54%-versus-12% is an absolute rate on AI-automated attacks, and 40% applied to a 12% base gives 16.8% — nowhere near 54%. Read as one escalating curve, they overstate what either report found.
Vendor announcement, end to end
Keepnet sells the pipeline the free app feeds, so every cited report does double duty: establishing the mobile blind spot and establishing Incident Responder as where it should close. The competitive geometry — consumer apps stop at scam detection, enterprise mobile defence stops at malware, we sit between — is the vendor's own map of the market, published with no second party available to draw it differently.
One outlet, one voice
Single publisher, single document, no corroboration — any apparent agreement would be one source echoing itself. Confidence divides cleanly: the third-party statistics are checkable at page level and likely to hold, while nothing about the app's behaviour has been touched by anyone outside the company that built it.