While corporate endpoints like laptops and servers usually receive the lion's share of security investment, smartphones have quietly turned into one of the most targeted entry points for enterprise compromise.
The 2026 Mobile Security Report from cybersecurity provider Pradeo highlights this exact shift. Drawing from aggregated field data across protected enterprise devices over the past 12 months, the report outlines a stark reality: mobile threats are growing in both volume and technical sophistication, while traditional security frameworks lag behind.
According to ENISA (The European Union Agency for Cybersecurity) data cited in the report, mobile attacks now represent the leading incident vector in Europe, accounting for 42% of all identified cyberattacks. Pradeo's own telemetry paints a picture of constant pressure on individual devices.
-
360 security events per device: The average professional smartphone encountered 360 security events per year (up from 342 in 2023).
-
120 moderate and 10 severe threats: Devices faced an average of 120 moderate threats requiring admin attention, and 10 severe, confirmed attacks requiring immediate blocking per year.
-
Application load explosions: The average professional device now hosts 370 installed applications, 80% of which are personal or unapproved apps introduced via Bring Your Own Device (BYOD) environments or unmanaged downloads.
-
Phishing click rates: Devices face an average of 288 phishing attempts annually across SMS, email, and messaging channels. Users click on these malicious links 45% of the time.
The primary mobile threat vectors, according to the report's data, is applications at 67%, network/fishing at 30%, and OS level issues at 3%.
There are four core trends shaping mobile security.
1. Applications remain the #1 attack vector
Applications account for 67% of all mobile security incidents. Threats are no longer limited to explicit malware; vulnerabilities in legitimate apps are a massive liability. Pradeo found that an average application contains seven vulnerabilities, with 18% of apps being vulnerable to code injection.
Furthermore, official app stores no longer offer absolute safety. Attacks like SparkCat demonstrated how malicious SDKs embedded in legitimate apps can slip past Google Play and Apple App Store controls. Another campaign uncovered 77 malicious applications on Google Play that racked up more than 19 million downloads before being removed.
2. The evolution of mobile phishing: quishing & smishing
Phishing remains the starting point for nearly 60% of successful European cyberattacks.
-
Smishing industrialization: SMS phishing makes up 55% of all mobile phishing. Global groups like Smishing Triad targeted more than 121 countries using 194,000+ domains, while attackers in the UK deployed localized "SMS blasters" (fake 2G base stations) to broadcast fraudulent texts directly to nearby phones.
-
Quishing (QR code phishing): Attackers are increasingly shifting to QR codes embedded in PDFs or physical spaces (like parking meters) to bypass traditional email filters. Advanced campaigns now use "split" or "layered" QR codes—fragmenting images so automated scanners miss them, while the mobile camera easily assembles the link.
3. "Legal" data leaks and intrusive apps
A major blind spot identified in the report is intrusive applications: legitimate, widely-used consumer apps (e.g., social, shopping, or fitness apps) that collect excessive background data.
-
42% of applications on a typical professional mobile device are classified as intrusive.
-
More than 60% of mobile apps exhibit excessive data exploitation practices.
Through embedded advertising and analytics SDKs, these apps gather location metrics and device identifiers that can be bought and pieced together. High-profile investigations highlighted how location data from fitness apps (like Strava) or retail apps exposed the sensitive movements of journalists, military personnel, and world leaders without any traditional system breach.
4. Artificial intelligence: dual-use disruption
AI is accelerating both offense and defense.
-
Offense: ENISA reports more than 80% of phishing emails incorporate AI techniques to generate highly convincing, context-aware lures. Attackers are also leveraging local AI models in malware—such as the PromptLock ransomware—to dynamically adapt behavior on-device and evade API tracking.
-
Defense: Machine learning algorithms allow defense tools to correlate micro-anomalies across applications, network traffic, and permissions to identify stealthy, zero-day behaviors before damage occurs.
Looking ahead, Pradeo outlines key operational shifts for enterprise environments.
-
Phone numbers as critical single points of failure: As organizations phase out passwords, phone numbers are becoming primary identity keys. This increases susceptibility to SIM-swapping attacks designed to intercept 2FA codes and authentication alerts.
-
The mobile Zero Trust blind spot: Traditional Zero Trust architecture focuses heavily on corporate laptops and network perimeters. Without continuous device-level telemetry on smartphones, mobile devices will remain an open back door into corporate identity systems.
-
Regulatory pressure: Regulations like GDPR, NIS2, DORA, and the Cyber Resilience Act mean data leakage via third-party mobile SDKs or unencrypted connections can constitute direct compliance breaches—even without a classic cyberattack.
Which organizations are most at risk?
Does industry type matter? Yes and no.
-
Public Sector & Critical Infrastructure: These entities remain priority targets. Because central IT networks in government and defense are heavily fortified, state-sponsored and opportunistic actors are shifting toward targeting the personal mobile usage of employees (messaging apps, location data, transit usage) to gain secondary access.
-
Financial Services & Healthcare: Heavily targeted due to direct monetization pathways (via specialized banking trojans like Herodotus or Crocodilus) and strict regulatory frameworks like DORA.
-
Every BYOD-friendly enterprise: Industry aside, any organization that allows employees to access corporate email, Slack, or databases on personal smartphones faces equal exposure. The mix of personal app density (370 apps/device) with enterprise access creates an unmanaged attack surface.
To address the growing risks outlined in the report, CISOs and IT teams should focus on four core operational steps.
1. Shift from manual review to automated MTD
With hundreds of events per device annually, manual triage is impossible. Organizations need a dedicated Mobile Threat Defense (MTD) solution that automates threat detection and remediation in real time at the device level.
2. Continuous application vetting and SDK visibility
Do not assume store approval equals safety. Implement automated security auditing for both internal enterprise apps and third-party commercial applications installed on devices to catch rogue SDKs, excessive permissions, and hidden data exfiltration.
3. Integrate mobile telemetry into your SOC
Mobile security shouldn't exist in a silo. Feed mobile device health, network connection events, and application behaviors directly into your Security Operations Center (SOC) and SIEM/XDR platforms to ensure mobile endpoints are factored into threat hunting.
4. Implement on-device phishing defenses
Because mobile phishing spans SMS, messaging apps, QR codes, and email, traditional email gateways aren't enough. Deploy on-device protections capable of inspecting network traffic and blocking malicious URLs regardless of which application delivered the link.
RELATED: New data from YouMail show U.S. consumers received 4.35 billion robocalls in July. It's the highest monthly total since July 2025, and volume is now more than 15% above the multi-year low hit last October. More than 2 billion of July's robocalls were telemarketing or scams, now making up nearly half of all robocall traffic.
A few standouts from the index:
-
Telemarketing and scam calls jumped nearly 6% in July alone, now representing almost half of all robocalls. Legitimate notifications and payment reminders declined.
-
Scams using fake "pre-approved personal loan" messages generated more than 40 million calls in July, spoofed across thousands of different numbers.

