SVG phishing email attacks are bypassing enterprise email security gateways by hiding JavaScript inside image files and exploiting a deprecated ECMAScript MIME type that most scanners do not flag. SANS Internet Storm Center researcher Xavier Mertens documented the active campaign on June 2, 2026, and identified three specific configuration steps that block the attack.