AI phishing 4 min read

AI phishing: why it will define cybersecurity in 2026

Published on EBM Solution

An artificial intelligence system generating convincing phishing messages at scale

AI phishing is turning a familiar scam into a sophisticated, industrial-scale threat. Artificial intelligence is fuelling the shift, and the defences that worked for years are struggling to keep up.

The new era of AI phishing

The cybersecurity landscape is going through a radical transformation. Phishing has always been one of the most widespread attacks; artificial intelligence has given it a powerful accelerator that is reshaping its reach and effectiveness.

An experiment run by Reuters with Harvard revealed an alarming reality: using simple AI chatbots such as ChatGPT, Grok and DeepSeek, researchers created perfect phishing emails with a single command. When those emails were sent to 108 volunteers, 11% clicked the malicious links. That figure is only the tip of a threat redefining the rules of digital security.

How AI phishing works

The first factor making AI phishing so dangerous is the democratisation of attack tools. Dark web platforms such as Lighthouse and Lucid offer phishing kits by subscription, letting even inexperienced criminals launch sophisticated campaigns. The numbers are striking: 17,500 phishing domains generated across 74 countries, hundreds of global brands targeted, and 30 seconds to create cloned login portals indistinguishable from the originals. Whether the target is Okta, Google or Microsoft, criminals can now replicate almost any interface in real time, removing the barriers to entry for cybercrime.

Generative AI has also removed the main warning sign of traditional phishing: generic, badly written emails. Modern AI tools analyse LinkedIn profiles to personalise messages, use data from past breaches to build credible context, imitate the specific communication style of the target company and generate thousands of variants in seconds. The result is messages that match the real business context closely, deceiving even the most attentive employees.

The third frontier is deepfake phishing. Over the last ten years, attacks based on this technology have increased by 1,000%. Criminals can now impersonate CEOs and executives on Zoom calls, clone relatives' voices on WhatsApp and create fake but apparently authentic Teams meetings. This evolution makes it practically impossible to distinguish a legitimate communication from a sophisticated attack.

Why traditional defences are no longer enough

Detection systems based on digital signatures, the pillar of traditional email security, prove ineffective against AI phishing. Attackers can rotate infrastructure continuously, vary domains and subject lines, and evade static checks with ease. Once a phishing email reaches the inbox, responsibility falls entirely on the employee, and even well-trained staff can make mistakes when faced with such convincing messages.

More than sophistication, it is the scale of attacks that represents the true threat. Criminals can launch thousands of new domains and cloned sites in a few hours. Even when one wave is neutralised, another quickly replaces it, guaranteeing a constant flow of fresh threats. It is the perfect storm generated by AI: an enemy that requires completely new strategies.

Effective AI phishing detection strategies

The first line of defence requires equally advanced technology. Natural Language Processing (NLP) models trained on legitimate communication patterns can identify subtle deviations in tone and structure, analyse linguistic anomalies invisible to the human eye, detect contextual inconsistencies in messages and continuously update detection parameters. These systems go beyond static filters, adapting dynamically to new attack techniques.

No automation can fully replace human vigilance. Security awareness training remains fundamental, but it has to evolve. Modern simulations replicate real campaigns specific to a sector, personalise scenarios based on the employee's role, go beyond spotting grammatical errors and build muscle memory for instinctive reporting. The goal is to prepare employees for the exact attacks they are likely to face, not to test them.

User and Entity Behaviour Analytics (UEBA) systems represent the last line against AI phishing. Even when an attack gets past perimeter defences, UEBA monitors anomalous user activity, detects logins from unexpected locations, identifies suspicious changes to mailboxes and alerts defenders in real time about potential intrusions. This multi-level strategy ensures that a successful phishing attempt does not turn into a full compromise of the infrastructure.

The future of cybersecurity: preparing for 2026

AI is pushing phishing to levels that can easily overwhelm or bypass traditional defences. Looking ahead to 2026, organisations need to prioritise AI-based detection that evolves as fast as the threats, continuous monitoring of all network and user activity, realistic training through constantly updated simulations, and a multi-level approach combining technology and human readiness. Success will depend on balancing advanced technology with human readiness. Organisations that find that balance will be more resilient as AI phishing continues to evolve.

Even commerce is moving inside content, where content marketing that turned into a storefront changes how audiences meet products.

Have a project in mind?

Do you know where to start?

The goal is to pin down the problem, the priorities and the timing.

Book a first call

Frequently asked questions

How can I recognise an AI-generated phishing email?

AI phishing emails are extremely hard to distinguish from legitimate ones. They no longer show obvious grammatical errors and use accurate business context. The key is always to verify unusual requests through alternative channels, even when they appear to come from reliable sources.

Is my company safe if it has updated antispam filters?

No. Traditional antispam filters rely on static patterns that AI phishing can easily evade. You need machine-learning solutions that adapt dynamically to new threats.

What does an AI phishing attack cost my company?

The average cost of a data breach caused by phishing ranges from tens of thousands to millions of euros, including data loss, operational disruption, reputational damage and regulatory sanctions. Prevention is increasingly cheaper than remediation.

Are deepfakes really a real threat?

Yes. Deepfake attacks have grown by 1,000% over the last decade and are among the most insidious forms of AI phishing, particularly effective in business email compromise.

Sources

Reuters, investigation with Harvard on AI-generated phishing emails and click rates: https://www.reuters.com/investigates/special-report/ai-chatbots-cyber/

Netcraft, inside the Lighthouse and Lucid PhaaS campaigns targeting 316 global brands: https://www.netcraft.com/blog/inside-the-lighthouse-and-lucid-phaas-campaigns-targeting-316-global-brands

The Hacker News, 17,500 phishing domains target 316 global brands: https://thehackernews.com/2025/09/17500-phishing-domains-target-316.html

Keepnet Labs, deepfake statistics and trends: https://keepnetlabs.com/blog/deepfake-statistics-and-trends

AI News, why AI phishing detection will define cybersecurity in 2026: https://www.artificialintelligence-news.com/news/why-ai-phishing-detection-will-define-cybersecurity-in-2026/