Phishing Campaign Targets Employees With Malicious SVG Files
KnowBe4, Friday, September 11th, 2026
SVG images carrying embedded JavaScript have become a rapidly growing phishing delivery method.
INKY researchers documented a large phishing campaign delivering SVG image files containing malicious JavaScript, part of a sharp increase in SVG abuse over the past year.
SVG is effective for attackers because it is treated as an image by users and often by mail filtering, yet it is an XML format that can carry executable script. Organizations should check whether their mail gateway inspects SVG content or merely classifies it by type, since the latter is the gap the campaign exploits.