Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issuesVolume 342, Issue 2IT Vendor NewsKnowBe4

Phishing Campaign Targets Employees With Malicious SVG Files

KnowBe4, Friday, September 11th, 2026

SVG images carrying embedded JavaScript have become a rapidly growing phishing delivery method.

INKY researchers documented a large phishing campaign delivering SVG image files containing malicious JavaScript, part of a sharp increase in SVG abuse over the past year.

SVG is effective for attackers because it is treated as an image by users and often by mail filtering, yet it is an XML format that can carry executable script. Organizations should check whether their mail gateway inspects SVG content or merely classifies it by type, since the latter is the gap the campaign exploits.

more →  ·  More from KnowBe4 →