DarkScout

AI-Generated Phishing: Why the Old Warning Signs Don’t Work Anymore

nikhil
16 min read 21 Jul 26
Share :
AI-Generated Phishing: Why the Old Warning Signs Don’t Work Anymore

In December 2025, AI-generated phishing jumped from 4 percent to 56 percent of all reported phishing attacks in a single month, according to Hoxhunt’s 2026 Phishing Trends Report. That is not a gradual shift. That is an industry-wide changeover happening in real time.

The emails behind that surge do not look like phishing used to. No broken English, no generic “Dear Customer” greeting, no mismatched sender domain glaring back at you. In controlled testing, AI-generated spear phishing achieved a 54 percent click-through rate, statistically matching phishing written by human experts and running well above the roughly 12 percent baseline for generic phishing. IBM’s research adds another layer to the picture, finding that AI now plays a role in roughly 1 in 6 breaches, most often for phishing content and deepfake impersonation.

Everyone was trained to look for typos and awkward phrasing. That training is now actively counterproductive, because those are exactly the cues AI-generated phishing eliminates.

This guide breaks down how attackers are actually building these emails, the specific attack types this technology has enabled, why multi-factor authentication alone no longer guarantees safety, and what to do if you suspect you have already been targeted.

What Makes Phishing “AI-Generated”

AI-generated phishing is a phishing message, whether email, text, voice, or video, created or substantially refined using generative AI tools rather than written entirely by hand. The goal has not changed. Trick someone into clicking a link, handing over credentials, or approving a fraudulent transaction. What changed is the quality and speed of the deception.

A large language model can write flawless, contextually accurate, brand-specific email copy in seconds. It can pull tone, phrasing, and formatting cues from a company’s actual public communications and mirror them convincingly. What used to take a skilled attacker hours of manual writing and research now takes minutes, and it no longer requires the attacker to be a fluent English speaker or a talented copywriter at all.

How Attackers Actually Build These Attacks

The process behind a modern AI-generated phishing campaign follows a fairly consistent pipeline, and understanding each stage makes the resulting email far less mysterious.

1. Automated reconnaissance

AI tools scrape public sources like LinkedIn, company websites, press releases, and social media to build a detailed profile of a target, including their role, recent projects, coworkers, and communication style, all without a human analyst doing the research manually.

2. Personalized content generation

That research feeds directly into an LLM prompt, which generates an email referencing real details, a specific vendor relationship, a recent invoice, a coworker’s name, tuned to sound exactly like something the target would expect to receive. Our broader guide to AI-powered cyberattacks covers how this same automation is reshaping attack techniques well beyond phishing alone.

3. Translation and localization

AI removes the language barrier that used to make foreign-origin phishing easy to spot. A campaign can now be fluently localized into dozens of languages simultaneously, each version grammatically clean and culturally appropriate.

4. Automated testing and iteration

Some campaigns run rapid A/B testing on subject lines and phrasing, using click and open data to refine future messages the same way legitimate marketing teams optimize email campaigns, just aimed at deception instead of conversion.

5. Voice and video synthesis

For higher value targets, attackers increasingly pair the written lure with a synthetic voice or video clip cloned from publicly available audio, used to add urgency or false legitimacy to a request, such as a fake executive voicemail confirming a wire transfer.

Why Old Detection Training Stopped Working

Most phishing awareness training for the past decade centered on a specific set of visual and linguistic red flags. That training assumed the attacker was working with limited time, limited language skills, or a template pulled from a phishing kit. AI-generated phishing removes almost every one of those assumptions at once.

  • Spelling and grammar errors, once one of the most reliable tells, are essentially gone.
  • Generic greetings like “Dear Customer” have been replaced with real names and specific, accurate context pulled from actual research on the target.
  • Mismatched formatting and off-brand tone have been replaced with copy that closely mirrors a company’s actual internal communication style.
  • Broken or unnatural phrasing from non-native speakers has disappeared, since AI can localize a lure into fluent, natural language instantly.

The honest conclusion is not comforting. Training employees to look for the old cues now actively works against them, since scanning for mistakes that no longer exist creates false confidence in emails that deserve just as much scrutiny as ever.

Types of AI-Generated Phishing

Types of AI-Generated Phishing

AI has not created entirely new categories of social engineering so much as it has dramatically upgraded the execution of existing ones.

1. AI-written spear phishing and BEC

Highly targeted emails referencing real names, projects, and vendor relationships, often impersonating an executive or a trusted supplier to request a wire transfer or sensitive data. Our full breakdown of business email compromise covers how this specific attack type has consistently generated some of the largest reported financial losses of any social engineering technique.

2. Deepfake voice and video impersonation

Synthetic audio or video cloned from a real executive’s publicly available voice or footage, used to add urgency to a fraudulent request. This tactic has moved from rare and expensive to increasingly accessible as voice cloning tools have become cheaper and require less source material to produce convincing results.

3. AI-assisted ClickFix attacks

A social engineering technique using a fake CAPTCHA or browser error message to trick a user into pasting and running malicious code themselves. AI helps generate the convincing pretext text and page design at scale. Our explainer on the ClickFix attack covers exactly how this technique tricks users into bypassing their own security software.

4. AI-generated quishing

QR code phishing paired with an AI-written pretext, commonly disguised as a parking notice, a delivery failure, or a multifactor re-enrollment request, designed to move the victim off a monitored device and onto their personal phone where fewer security controls apply.

5. Multi-channel AI campaigns

Increasingly, a single campaign coordinates an email, a text message, and sometimes a phone call together, each generated and personalized by AI to reinforce the same false narrative from multiple directions at once.

Real-World Examples

These are not hypothetical scenarios. Each of the cases below has been publicly reported and confirmed.

Arup, $25 million lost to a deepfake video call

In February 2024, a finance employee at the global engineering firm Arup joined a video conference call believing he was speaking with the company’s CFO and several senior colleagues. Every person on that call was an AI-generated deepfake. The employee authorized 15 separate transactions totaling roughly $25 million to accounts controlled by the attackers before the fraud was discovered, as first confirmed by CNN’s reporting on the incident.

WPP, a cloned CEO voice targeting a senior executive

In 2024, attackers impersonated WPP CEO Mark Read, combining a cloned voice with a fake WhatsApp account using his photo to contact a senior executive at the company directly, according to coverage of the attempted scam. The attempt relied on the same building blocks covered earlier in this guide: research on a real executive, a convincing synthetic voice, and a channel employees are used to trusting.

Ferrari, a deepfake attempt that was actually caught

Not every case ends in a loss. In July 2024, a Ferrari executive received WhatsApp messages appearing to come from CEO Benedetto Vigna, followed by a phone call using an AI-cloned voice that closely matched his accent and speech pattern. As detailed in MIT Sloan Management Review’s account of the incident, the executive grew suspicious and asked a question referencing a personal detail the real CEO had mentioned days earlier. The caller could not answer and ended the call immediately. This case is worth including precisely because it shows that out-of-band, personal verification is still one of the most reliable defenses available, even against a highly convincing deepfake.

A mass-scale campaign targeting small accounting firms

Not every AI-generated attack targets a single high-value executive. One documented 2024 campaign, analyzed in a review of AI phishing risk, used AI to generate customized tax deadline reminder emails sent to roughly 800 small accounting firms, each referencing that specific firm’s state registration details and recent public filings. The campaign reportedly achieved a 27 percent click rate, showing that AI-driven personalization at scale works just as well against small businesses as it does against a single enterprise target.

Why MFA Alone No Longer Stops It

For years, the standard advice after any phishing warning was simple: turn on multi-factor authentication. That advice still matters, but it is no longer sufficient on its own, and the reason is worth understanding clearly.

  • Adversary-in-the-middle phishing kits sit between the victim and the real login page, capturing the session token generated after a legitimate MFA approval rather than trying to steal the password and code separately. The victim believes they logged in normally, MFA and all, while the attacker silently captures the authenticated session behind the scenes.
  • A majority of successfully compromised accounts in recent AI-driven campaigns actually had MFA enabled at the time of the breach, according to recent industry reporting, which is exactly why “just turn on MFA” is no longer the complete answer it once was.
  • Push notification fatigue compounds the problem further. Attackers combine an AI-generated pretext with repeated MFA push requests, waiting for a distracted or annoyed user to approve one by mistake. Our guide to push bombing covers exactly how this specific tactic works and why volume alone can defeat an otherwise well-configured MFA setup.

If You Think You’ve Already Been Targeted

The instinct after a suspicious email is to worry about the message itself. The more important question is what happened after, especially if a link was clicked or credentials were entered anywhere.

Check whether any credentials were actually submitted to a fake login page, since that is the moment real exposure begins regardless of how convincing the original email looked. If a password or session token was entered anywhere unfamiliar, treat it as compromised immediately rather than waiting for confirmation. Stolen credentials and session data from successful phishing attempts routinely end up circulating through the same channels as other stolen data, packaged and sold the same way as the credentials described in our guide to what a stealer log actually contains.

Reset the password on the affected account immediately, and do the same for any other account using the same or a similar password. Report the incident internally right away rather than staying quiet out of embarrassment, since a fast report gives your security team a real chance to contain the damage before it spreads further.

How to Defend Against AI-Generated Phishing

Effective defense now requires layering technical controls with a fundamentally updated approach to training, since neither one alone is enough against AI-generated lures.

  • Update phishing training to reflect reality. Stop teaching employees to hunt for typos and generic greetings. Teach them to verify unusual requests through a second channel instead, regardless of how polished or personalized the message looks.
  • Deploy phishing-resistant authentication where possible. FIDO2-based passkeys and hardware security keys are significantly more resistant to adversary-in-the-middle attacks than password-and-code combinations, since the cryptographic handshake is bound to the legitimate site.
  • Verify high-stakes requests out of band. Any request involving a wire transfer, credential reset, or sensitive data should be confirmed through a phone call or a separate, already-trusted communication channel, not by replying to the original message.
  • Use AI-aware email security tooling. Traditional filters built around known bad senders and obvious red flags increasingly miss AI-generated content. Our roundup of email threat intelligence tools covers which platforms are actually built to catch behavioral and contextual anomalies rather than just known indicators. Our broader guide to email security covers the layered approach this threat now demands.
  • Monitor for credential exposure continuously. Even a well-trained, well-protected organization will eventually have someone fall for a convincing enough lure. Catching the resulting exposure quickly is what limits the damage.

What Detection Tools Can and Cannot Do

Honest limitations matter here, since plenty of vendors imply AI-aware detection tools solve this problem completely. They do not.

What detection tools can do?

They can catch known attack infrastructure, flag unusual sending patterns, and surface behavioral anomalies that differ from a user’s normal communication history. Our overview of AI threat detection covers where these tools are genuinely strong at scale.

What detection tools cannot do?

They generally cannot guarantee detection of a genuinely novel, well-researched, single-target spear phishing attempt sent from previously unused infrastructure, since AI-generated content is specifically designed to blend in with legitimate communication patterns. A determined, well-resourced attacker targeting one specific person can still slip through even a strong detection stack.

This is exactly why layered defense matters more now than it did before. No single control, whether it is training, email filtering, or MFA, is sufficient on its own against an attack designed specifically to defeat the assumptions each of those controls was originally built around.

Conclusion

AI has not invented a new form of social engineering. It has removed the friction, cost, and skill requirements that used to limit how convincing and how frequent phishing attacks could be. The result is a threat that looks less like the phishing emails from five years ago and more like a genuine, well-researched message from someone you actually know.

The old advice to check for typos and generic greetings is no longer just insufficient; it is actively misleading. What matters now is verifying unusual requests through a second channel, adopting phishing-resistant authentication where it is available, and assuming that even a well-trained team will eventually be targeted by something convincing enough to work.

If a credential has already been exposed through a successful phishing attempt, finding out fast matters more than anything else. DarkScout’s email exposure scanner checks whether your organization’s addresses already appear in known breach and stealer log data, so a phishing incident gets caught and contained before it turns into a much larger one.

Frequently Asked Questions

What is AI-generated phishing?
AI-generated phishing is a cyberattack that uses artificial intelligence to create highly convincing phishing emails, text messages, voice calls, or videos designed to steal credentials, financial information, or sensitive data.
How is AI-generated phishing different from traditional phishing?
Can AI create convincing phishing emails?
What are the most common AI phishing attacks?
Does multi-factor authentication (MFA) stop AI-generated phishing?
How can businesses protect themselves from AI-generated phishing?
What should I do if I clicked an AI phishing email?
Can AI-generated phishing use deepfake voices and videos?
How do attackers personalize AI phishing emails?
Can AI-generated phishing be detected?
Scroll to Top