Researchers Flag Logistics-Themed Phishing Ahead of Holiday Shipping Peak

Researchers at EfficientIP say security teams should watch for delivery and logistics-themed phishing lures heading into the holiday shipping season. The warning follows a first half of 2026 in which the sector’s share of phishing detections more than tripled. Logistics and delivery brands accounted for 13.6% of detections in the period, up from 4.0% in the second half of 2025, according to the company’s H1 2026 DNS Threat Intelligence Report (https://efficientip.com/resources/dga-overlooked-malware-indicator-h1-2026/). The increase moved the sector from seventh to third among phishing targets, behind online and cloud services, which led with 27.7% of detections.
Phishing as a whole declined over the same period. Total phishing hits fell 10% from the prior half to 2.48 billion, which means the logistics and delivery figure reflects a rising share within a shrinking category. The report attributes much of the rise to a single campaign impersonating parcel delivery brand Mondial Relay that emerged in the final days of June. EfficientIP also began detecting additional types of phishing pages during the half, delivery and banking lures among them.
Across all categories, EfficientIP counted 13.85 billion threat-signal hits in the first half of 2026, a 24% increase from 11.18 billion in the second half of 2025. Malware nearly doubled over the same period to 3.84 billion hits, moving from fourth to first among threat categories with 27.7% of total volume. Average daily malware activity fell from a November 2025 high of 14.4 million hits to 8.0 million in January, then rose to 16.2 million in March and 32.6 million in April. It stayed between 29 million and 32 million hits per day through June.
The findings come from more than 150 billion DNS transactions EfficientIP analyzes each day. The domain name system translates web addresses into the numeric addresses networks use, and most connections a device makes to a domain, malicious or legitimate, begin with a DNS lookup.
The report tracks the order in which DNS signals moved ahead of the April peak. Activity tied to domain-generation algorithms (DGAs), which malware uses to produce large volumes of domain names for reaching its command-and-control servers, rose 24.2% month over month in February. In March and April, hits on domains first observed within the previous seven days rose 56.8% and 92.1%, moving in step with malicious activity, which increased 73.1% and 86.8% in those months. EfficientIP treats the February DGA increase as a sign that attacker infrastructure was being assembled before the surge. The report also cautions against assuming that a change in one signal causes a change in another.
Karim Hossen, R&D manager and CISO at EfficientIP, said in the release that suspicious DNS activity “can reveal its infrastructure weeks before an attack unfolds,” leaving defenders time to investigate.
Of the five DGA families the report profiles, three were first observed during the half. One of them, Unmasked, relied on domains whose registrations had expired by June 2026. Devices continued to query those domains anyway, with daily matches reaching 46,041 on June 30, the highest count among the families EfficientIP tracks.
