72% of cybersecurity incidents in Spanish SMBs in 2025 started with an email, a phone call, or a WhatsApp message — not a sophisticated exploit. The most dangerous attack vector for your company in 2026 is not technical: it is someone on your team trusting something they should not. This article explains exactly how these attacks work today and why standard controls fail to stop them.
Why phishing remains the number one vector in Spanish SMBs
According to INCIBE's 2024 Cybersecurity Balance, Spanish SMBs faced over 83,000 managed incidents, with phishing and online fraud as the dominant categories. The critical insight most companies miss is that attackers have migrated to channels where filters don't reach: phone calls, WhatsApp Business, LinkedIn, and third-party suppliers with legitimate system access. An attacker impersonating a payroll provider does not need to bypass any firewall. They only need one person in accounting to be under pressure on a busy Tuesday afternoon. The attack is organizational, not technical.
of European organizations that suffered a successful phishing incident in 2024 had active cybersecurity training programs. Source: ENISA Threat Landscape 2024.
The counterintuitive finding that most IT managers find uncomfortable: companies that completed cybersecurity training in the past year show click rates on phishing simulations only 12% lower than those with no training at all. The problem is not the training itself — it is that employees are trained to detect generic phishing (spelling errors, unknown senders, excessive urgency) while real 2026 attacks display none of these signals. AI-generated spear phishing against an SMB procurement manager includes the correct name, a reference to a real order, the exact tone of their usual supplier, and a link to a payment portal with a valid SSL certificate. None of the red flags taught in standard courses are present.
Five concrete actions to reduce exposure in 2026
- Implement secondary-channel verification for any IBAN change or urgent transfer request — call back on a known number, never the one that called you.
- Enable DMARC in reject mode on all corporate domains, including unused brand domains that could be spoofed.
- Run contextualized phishing simulations twice a year using scenarios that mimic your actual suppliers, not generic red-flag emails.
- Document and audit all third-party supplier access to internal systems: which systems, from which IPs, with which credentials, and with activity logging.
- Search LinkedIn, your corporate website, and YouTube for publicly available information about your company's structure and suppliers — this is what attackers use before calling.
Want to know exactly where an attacker would enter your company today? Blurtek runs phishing and social engineering exposure assessments for Spanish SMBs. No jargon, no overselling. Contact the Blurtek team.
Solicitar diagnóstico