Phishing is back at the top because attackers no longer need custom code to steal Exchange credentials. The standard response still treats phishing as a lure problem, but this case shows the real shift: no-code AI builders can now generate convincing OWA login pages and wire stolen credentials to external storage with almost no technical effort.
Cisco Talos said phishing accounted for over a third of initial-access engagements in Q1 2026, with public administration and health care tied as the most targeted sectors at 24 percent each. Talos also documented the first confirmed use of Softr in a phishing engagement, where attackers built a page that mimicked Microsoft Exchange and Outlook Web Access and used form templates and vibe coding features to collect credentials.
The risk is not just better-looking phishing. It is faster, cheaper credential harvesting that can be repeated at scale by less skilled actors, and the same no-code tooling can keep lowering the barrier as adoption grows.