This edition of Techstep Pulse covers the developments that shaped mobility and security in August 2026. Three areas stand out: phishing campaigns that hijack a login session while it is happening rather than stealing credentials for later, a foldable device generation that is finding genuine business demand for the first time, and a growing recognition among European businesses of how much of their operation depends on infrastructure they do not control. Together, they describe an environment where the decisions organisations have been able to postpone, about authentication, about devices, about where their data sits, are becoming harder to leave open.

Phishing moves from stealing passwords to hijacking sessions
Research from CTM360, a cyber threat intelligence firm, found that phishing targeting the insurance industry has shifted from harvesting credentials for later use to real-time account hijacking. Attackers now submit a victim's details to the legitimate portal the moment they are entered on a fake site, and if multi-factor authentication is required, the fake site asks for that code immediately too, according to CTM360's report. The researchers identified a dedicated phishing platform, dubbed the InsureOTP kit, that lets attackers monitor sessions and handle one-time codes through a backend dashboard, often tied into messaging bots. These campaigns increasingly start through sponsored search ads rather than email, leading victims to convincing replica sites hosted on legitimate cloud platforms.
A separate campaign is targeting Signal, the encrypted messaging app, with the specific goal of stealing users' backup recovery keys. According to research from Pradeo, a mobile security firm, the scam begins with a message impersonating Signal Support, manufacturing urgency around a supposed synchronisation error, and asking the victim to copy and paste their recovery key. Signal has confirmed its support team will never proactively ask for a PIN, verification code, or backup recovery key, but the campaign relies on the trust people place in the app's encryption to lower their guard.
For a business, both campaigns work the same way. Verification steps that used to stop credential theft, a password change, an MFA prompt, a recovery key, no longer stop an attacker who is present in the transaction as it happens. Employees can do everything right by their usual training and still hand over access, because the attack is built to look exactly like the real process.
This changes what user awareness training needs to cover. Spotting a suspicious link is no longer enough if the destination looks and behaves like the genuine service, down to the MFA prompt. Detection increasingly needs to happen at the device and network level, flagging unusual app behaviour or connections to newly registered domains, rather than relying on people to notice something is wrong mid-session.
Insurance portals and personal messaging apps are very different targets, but the underlying technique is the same. Attackers have industrialised the moment of authentication itself. That is a broader signal for any organisation managing devices that access sensitive systems: the assumption that MFA alone is a sufficient barrier needs revisiting.
This is where on-device detection earns its place alongside user training. A tool like Essentials MTD is built to flag exactly this kind of anomaly, unexpected data requests, connections to newly registered domains, behaviour that does not match a legitimate session, before an employee has to spot it themselves.
See how Essentials MTD can help:
Why this matters: Real-time phishing defeats defences built around spotting bad links or stolen passwords after the fact. Treating unusual authentication patterns, not just suspicious emails, as a signal worth monitoring is becoming necessary rather than optional.
Foldables move from novelty to a real B2B option
Samsung has launched its newest generation of foldable devices, positioning them more deliberately for business use than previous generations. The pitch centres on combining two device categories into one: a large screen and increased workspace for multitasking, paired with the portability of a phone, aimed specifically at executives, sales teams, and consultants who currently carry both a phone and a tablet.
Early demand suggests the positioning is landing. The lineup hit its European pre-order target in just eleven days, with pre-orders in key European markets up between 20% and 70% year on year compared to the previous generation. Samsung has since added an extra million units to its production run after demand outpaced its internal forecasts.
For a fleet manager, foldables have been a hard category to justify at scale, interesting on paper, but historically priced and positioned as a novelty rather than a working tool. This generation's demand numbers suggest a segment large enough to actually plan around, even if it stays a minority of a fleet rather than a default device.
That said, the realistic use case is narrow by design. This isn't shaping up to be a high-volume replacement for standard smartphone fleets, the way mainstream flagship lines are. It's a premium option for roles where the extra screen real estate solves a genuine problem, field sales reps who need to show product catalogues or contracts on the spot, consultants presenting on the move, or executives who want to cut down on carrying two devices. Provisioning a small, well-defined cohort of foldables alongside a standard fleet is a different exercise than a full device refresh, and worth planning for separately rather than treating as an edge case to handle later.
The broader signal here is about how device categories mature. A form factor that started as an engineering showcase is now backed by real B2B purchasing intent, which means it's worth having an opinion on it in fleet strategy, rather than waiting until requests start arriving from individual departments.
Why this matters: Foldables are moving from experimental to genuinely purchasable for specific roles. Organisations that decide now where a foldable does and doesn't make sense will be better placed than those improvising a policy after the first request lands.
.png?width=1440&height=480&name=Images-3%20(4).png)
Europe weighs sovereignty as fears of a US tech "kill switch" grow
A study from Proton found that close to 75% of European businesses are concerned that a government-imposed "kill switch" could cut off access to US cloud and digital services with little warning, according to reporting from TechRadar Pro. Surveying 1,500 businesses across the UK, France, and Germany, the study found that more than half could not survive a single business day without their primary US-based digital infrastructure, and that respondents ranked this risk on par with a serious ransomware attack.
The concern is feeding a broader push toward what is being called "tech sovereignty," organisations looking for European alternatives for email, productivity tools, and cloud storage so they are less exposed to decisions made outside their control. It is not yet reshaping procurement at scale, but the direction is worth tracking for any organisation weighing cloud versus on-premise infrastructure, or reviewing where its critical data and services are hosted.
For organisations managing devices, this ties back to a question worth asking regardless of geopolitics: how much visibility and control do you actually have over where your fleet's data lives, and how quickly could you adapt if that changed. Businesses that already run flexible, cloud or on-premise infrastructure are better placed to adjust than those locked into a single provider by default. Techstep's own look at mobile endpoint security and governance goes into what that kind of control actually requires in practice, regardless of where the underlying infrastructure sits.
Why this matters: Dependence on a single provider or region is an operational risk, not just a political talking point. Understanding where data and services actually sit, and how easily that could change, is worth revisiting even outside a crisis.
Together, this month's stories point to the same underlying shift: mobility decisions are becoming less about a single default device or provider, and more about deliberate choices, which form factor for which role, which infrastructure for which risk tolerance, which authentication assumptions still hold. Attackers are getting closer to the moment of trust itself, whether that is a login session or a support message, while fleet and infrastructure strategy both reward organisations that plan ahead rather than react. And as more organisations start to ask where their data actually lives and who controls access to it, that same discipline extends to device strategy as well.
.png?width=720&height=240&name=Images-1%20(7).png)
