How AI Is Used in Phishing Attacks: LLM-Generated Emails, Voice Cloning, and Deepfake Video That Bypass Traditional Defenses

Key takeaways
- AI is used in phishing to automate reconnaissance, content generation, and multi-channel delivery, collapsing the cost of a convincing attack from hours to minutes.
- AI-generated spear-phishing emails achieve a 54% click-through rate, compared to 12% for generic, non-personalized phishing, while increasing profitability for cybercriminals by up to 50 times.
- Voice cloning and deepfake video extend AI-powered phishing beyond email, allowing attackers to impersonate executives on live phone calls and video conferences.
- Multi-channel campaigns that combine email, voice, and video overcome the trust heuristics employees rely on.
- Continuous, simulation-driven security awareness training that covers email, voice, SMS, and deepfake video is the most effective defense against AI-powered phishing.
Understanding how AI is used in phishing attacks is essential for any security leader: attackers now deploy large language models, voice cloning, and deepfake video to automate and personalize deception at a scale that renders traditional defenses obsolete. This article maps the full AI phishing toolkit, spanning every attack channel and the technology stack behind it.
Attackers jailbreak legitimate LLMs, purchase purpose-built criminal models like WormGPT and FraudGPT on underground forums, and combine AI-generated emails, synthetic voice calls, and deepfake video conferences into coordinated multi-channel campaigns that exploit trust across email, voice, and video.
The numbers are stark: AI-generated spear-phishing emails now achieve a 54% click-through rate compared to just 12% for generic, non-personalized phishing, increasing profitability for attackers by up to 50 times for larger audiences.
This article explains exactly how each AI phishing technique works, which technical and human defensive measures actually reduce the risk, and why continuous, simulation-driven security awareness training has become the critical countermeasure against AI-powered social engineering.
Understanding how AI is used in phishing attacks is essential for any security leader... After reading, you will understand exactly how each AI phishing technique works, which technical and human defensive measures actually reduce the risk, and why continuous, simulation-driven security awareness training has become the critical countermeasure against AI-powered social engineering.

What Is AI-Powered Phishing and How Does It Differ from Traditional Phishing
AI-powered phishing is the use of generative AI, large language models, voice synthesis, and deepfake technology to automate, personalize, and scale phishing attacks beyond what human attackers alone can achieve. It transforms phishing from a manual, template-dependent craft into an industrialized operation where thousands of individually tailored attacks launch in the time it once took to compose a single fraudulent email.
Unlike traditional phishing, which relied on generic lures and detectable errors, AI-powered phishing leverages open-source intelligence (OSINT) to craft psychologically calibrated messages that reference real relationships, recent transactions, and personal context, making them functionally indistinguishable from legitimate communication.
That explosion did not come from more attackers working harder. It came from attackers working smarter, with machines doing the heavy lifting of research, composition, and delivery across multiple channels simultaneously.
Traditional Phishing vs. AI-Powered Phishing: A Side-by-Side Comparison
To understand the gap between legacy phishing and its AI-driven successor, it helps to examine five dimensions where the asymmetry is most pronounced.
Personalization depth. Traditional phishing inserted a name, a company, or a generic title into a template. AI-powered phishing mines OSINT sources, LinkedIn bios, earnings call transcripts, social media accounts, public filings, to construct messages that reference the recipient's actual colleagues, recent projects, and even the tone used in internal communications.
A finance director does not receive "Dear Employee, verify your account." They receive what appears to be a follow-up from the CFO about an invoice discussed in a meeting that actually happened last Tuesday.
Scale. A skilled human attacker might craft a few dozen convincing spear-phishing emails per day. An AI-assisted attacker can generate thousands of unique, personalized messages in the same window.
Quality and linguistic polish. Traditional phishing emails were notorious for spelling errors, awkward grammar, and culturally tone-deaf phrasing, the "Nigerian prince" template that security awareness training taught employees to spot. AI-generated phishing is grammatically flawless, culturally calibrated, and stylistically consistent with the impersonated sender's actual communication patterns.
A 2025 systematic review published in the MDPI journal AI found that generative AI enables phishing content with persuasive effectiveness approaching human-written social engineering, while exceeding human output in speed by orders of magnitude.
Channel coverage. Traditional phishing operated overwhelmingly through email. AI-powered phishing spans email, voice calls with cloned executive speech, SMS messages that continue multi-channel narratives, and real-time deepfake video conversations. An attack might begin with an email from a vendor, escalate through a vishing call that sounds exactly like the head of procurement, and culminate in a video conference where every participant is synthetic.
Detection evasion. Traditional phishing left fingerprints: suspicious sender domains, mismatched URLs, generic greetings, and linguistic errors that both humans and automated filters learned to flag. AI-generated phishing produces messages with no mechanical tells. The sender address may be spoofed with precision. The language mirrors the impersonated individual's actual diction. The request references legitimate, verifiable context.
Security tools built to pattern-match against known-bad templates face a moving target that changes with every generation.
The Pre-AI Phishing Era: From AOHell to Template-Based Attacks
Phishing did not begin with ChatGPT. Its lineage stretches back three decades, and understanding that arc makes the AI inflection point sharper.
The first recognizable phishing attacks emerged in 1995 on America Online, where a program called AOHell enabled users to steal credentials by posing as AOL employees in chat rooms and instant messages. Attackers would message users claiming there was a billing problem, request their password, and use the captured credentials for fraud or harassment.
The technique was crude, text-based, one-to-one, and dependent on the attacker's ability to talk convincingly in real time, but the core social engineering logic was already in place.
The release of the ILOVEYOU worm in May 2000 marked phishing's transition to automated mass distribution. The worm arrived as an email attachment masquerading as a love letter. When opened, it overwrote files and forwarded itself to every contact in the victim's Outlook address book. It reached an estimated 45 million users within days and caused billions of dollars in damage.
For the first time, phishing demonstrated that automated emotional manipulation, curiosity, affection, fear, could spread faster than any manual attack ever could.
The 2010s brought phishing into the template era. Cybercriminals built reusable kits: pre-designed Bank of America password reset pages, fake Dropbox share notifications, bogus FedEx delivery alerts. These templates were mass-deployed with minimal customization. Attackers swapped logos, changed URLs, and blasted millions of recipients. The economics were volume-driven; if 0.1% of targets clicked, the campaign paid for itself.
Security awareness training in this era taught employees to spot bad grammar, check URLs, and hover over links. These rules worked because the attacks were static enough to be pattern-matched.
What defined the pre AI era was a hard limit on scale. Phishing quality and personalization were constrained by human effort. An attacker who wanted to impersonate a specific CEO convincingly had to study that CEO's writing style manually, craft each email individually, and manage responses personally. The result was a natural bottleneck. Sophisticated spear phishing was high-cost and low-volume. Bulk phishing was cheap but crude. The two categories rarely overlapped.
What Makes AI Phishing Fundamentally Different
AI has not simply improved phishing. It has erased the bottleneck that separated high-effort spear phishing from low-effort bulk phishing, creating a new category where personalized, convincing attacks deploy at mass scale. That represents a paradigm shift rather than an incremental upgrade.
The first difference is automation of the entire kill chain. AI tools handle reconnaissance, scraping and synthesizing OSINT from dozens of sources, along with content generation, delivery across multiple channels, and response handling, engaging victims in real-time conversation to deepen the deception. Each of these functions previously required a human specialist. Now a single operator with access to generative AI tools can run campaigns that once demanded a team.
The second and more consequential difference is that AI opens attack surfaces traditional phishing never touched. Synthetic voice cloning, accessible through consumer-grade tools, lets attackers impersonate a CEO's voice on a phone call with enough fidelity that employees comply with urgent wire-transfer requests. Real-time deepfake video takes that further.
Voice phishing and deepfake video attacks bypass every email security control an organization has deployed.
The third shift is emotional intelligence. Traditional phishing exploited two emotions, fear and greed, with all the subtlety of a hammer. AI-powered phishing reads the target's digital footprint and selects the emotional trigger most likely to produce compliance. A new hire gets an urgent message from "HR" about onboarding paperwork.
A recently promoted manager receives congratulations from the "CEO" with a link to "review the announcement draft." These are not random impersonations. They are data-driven applications of social psychology, executed by machines that never tire and never make spelling mistakes.
"Gone are the days of the 'Prince of Nigeria' emails that presented broken, nearly unreadable English to try to convince would-be victims to send their life savings," said Chris Steffen, research director at Enterprise Management Associates, in CNBC reporting on the AI phishing surge. "Instead, the emails are extremely convincing and legitimate sounding, often mimicking the styles of those that the bad guys are impersonating."
The implication for security leaders is that the old playbook, training employees to spot bad grammar, verify suspicious links, and report obvious impersonations, addresses a threat landscape that no longer exists. Defending against AI-powered phishing requires phishing simulations that replicate the same multi-channel, AI-generated attack methods adversaries are already using.
Training that only covers email phishing leaves employees exposed to the voice call, the SMS follow-up, and the deepfake video that complete the modern attack chain.
The AI Phishing Toolkit: LLMs, Dark LLMs, and Automated Reconnaissance
Attackers use AI in phishing because the economics of social engineering have inverted. What once demanded 16 hours of skilled labor now takes five minutes with a jailbroken language model. Purpose-built criminal LLMs strip away every ethical guardrail that legitimate providers install.
The result is a three-tier toolkit: jailbroken commercial models, underground dark LLMs sold as subscription services, and AI reconnaissance engines that infer deeply personal details from public social media text, each lowering the cost of a successful attack while raising its precision.
How Attackers Jailbreak Legitimate LLMs for Phishing Content
The guardrails on commercial language models are real but permeable. OpenAI, Anthropic, and Google have invested heavily in alignment techniques that refuse malicious prompts. Attackers have developed systematic prompt engineering patterns that route around these defenses by framing requests as legitimate business tasks.
IBM X-Force's research team, led by Chief People Hacker Stephanie Carruthers, documented exactly how thin these defenses are. The team used five sequential prompts to extract a fully weaponized phishing email from ChatGPT. First, they asked the model to identify the top concerns of employees in a target industry, healthcare, producing career advancement, job stability, and fulfilling work as priority anxieties.
Second, they instructed the model to apply specific social engineering techniques: trust, authority, and social proof. Third, they layered in marketing tactics including personalization and calls to action. Fourth, they directed the model to impersonate an internal HR manager. The fifth prompt asked ChatGPT to assemble everything into the email itself.
The output was convincing enough that two of the three organizations originally signed up for the study withdrew after reviewing the AI-generated phish, expecting it to be too effective to test against their employees.
The productivity delta is what makes this dangerous at scale. Carruthers and her team typically spend 16 hours on OSINT collection, pretext development, and email drafting for a single phishing campaign. The AI-generated version was ready in five minutes.
"I have nearly a decade of social engineering experience, crafted hundreds of phishing emails and even I found the AI-generated phishing emails to be fairly persuasive," Carruthers wrote in the IBM X-Force findings. The human-crafted email still won the A/B test, but by a margin she described as "nail-bitingly close."
Today's jailbreak landscape has evolved well beyond simple prompt engineering. Attackers use role-playing frameworks that cast the model as a security researcher running authorized red-team exercises. They chain multiple models together, using one to generate benign-sounding seed text and another to extend it into malicious territory. Some techniques exploit the model's tendency to continue patterns, feeding it legitimate marketing copy then pivoting mid-generation to phishing content.
Guardrails update, but the cat-and-mouse dynamic heavily favors attackers who can iterate on jailbreak prompts faster than model providers can patch them.
Dark LLMs: WormGPT, FraudGPT, and the Criminal AI Underground
If jailbreaking legitimate models is a workaround, dark LLMs are the direct route. These are language models purpose-built or fine-tuned for cybercrime, trained on malware corpora and phishing datasets with no refusal filters whatsoever. They are sold openly on criminal forums as subscription services, often with customer support and feature roadmaps that mimic legitimate SaaS businesses.
WormGPT, one of the earliest and most widely documented examples, was built on the open-source GPT-J architecture and trained specifically on malware-related data. It produces grammatically flawless phishing emails across multiple languages, maintains session memory for multi-message conversation chains, and generates obfuscated malicious code on demand. FraudGPT followed, specializing in business email compromise (BEC) scenarios and scam page generation.
PoisonGPT, a proof-of-concept model demonstrated by security researchers, showed how a supply-chain attack could maliciously modify a model to spread disinformation when deployed.
Threat actors no longer need to train LLMs; they strip the safety layers from publicly available ones and package the result for sale.
The pricing model reinforces this industrialization. Dark LLM subscriptions range from $30 to $200 per month depending on capabilities, putting enterprise-grade phishing automation within reach of low-skill actors. Some vendors offer lifetime licenses, free trial tiers, and affiliate programs that reward customer referrals. The ecosystem mirrors the legitimate SaaS market in structure while serving the opposite purpose: a criminal mirror economy where the product is victimization at scale.
AI-Powered Reconnaissance: How LLMs Infer Personal Details for Hyper-Personalized Attacks
The most underappreciated weapon in the AI phishing toolkit is reconnaissance. Before an attacker sends a single message, they need to know who they are targeting and what will make that person comply. LLMs have turned this phase from manual research into automated inference, extracting personal details that the target never explicitly disclosed.
A 2024 study by ETH Zurich researchers published at ICLR demonstrated that large language models can infer personal attributes from anonymized social media text with startling accuracy. The models achieved up to 85% accuracy for top-1 attribute predictions and 95.8% across the top three results, approaching human performance at a fraction of the time and cost.
From posts that contained no names, no locations, and no explicit demographic markers, the models identified income brackets, age ranges, relationship status, and mental health indicators from linguistic patterns left behind in everyday writing.
This capability rewrites the reconnaissance playbook. An attacker can feed a target's public LinkedIn posts, Reddit comments, or Twitter history into an LLM and receive a probabilistic dossier: likely location, estimated income, probable family structure, professional anxieties, hobbies, and travel patterns. None of this information was written down anywhere.
It was inferred from the space between the words: regional dialect markers, complaint patterns, time-of-day posting rhythms, and thousands of other subtle signals that a human analyst might miss entirely.
The practical outcome for spear phishing is devastating. An email that references the target's actual neighborhood, mentions a conference they attended two years ago, and mirrors the writing style of their actual manager is not just more convincing. It renders traditional red flags like "check the sender address" nearly irrelevant.
The victim sees authenticity everywhere. The ETH Zurich research team showed that even text processed through state-of-the-art anonymization tools remained vulnerable to inference attacks, because LLMs capture linguistic cues that anonymizers are not designed to strip. Organizations that rely on employees keeping personal details offline are operating under a false sense of privacy. The models reconstruct what was never explicitly shared.
The combination of these three capabilities, jailbroken content generation, purpose-built criminal models, and automated personal inference, represents a step change in phishing economics. Attackers can now generate personalized, grammatically perfect, psychologically calibrated phishing content for thousands of targets simultaneously, informed by private details inferred from public data.
Defending against this stack requires phishing simulations that match the same sophistication: multi-channel, AI-generated, and informed by the OSINT exposure profiles that attackers are already exploiting.
AI Voice Cloning and Vishing: Synthetic Voice Attacks
Voice cloning is one of the clearest examples of how AI is used in phishing beyond email: attackers need as little as 3 to 10 seconds of a target's voice to build a weapon.
They harvest audio from LinkedIn video posts, YouTube conference talks, earnings call recordings, podcast interviews, and outgoing voicemail greetings. That sample feeds into AI models that generate synthetic speech replicating the speaker's tone, cadence, and emotional inflection with precision that defeats human detection.
The cloned voice then places live phone calls to employees, impersonating executives to authorize wire transfers or IT support to extract credentials. Because the brain treats a familiar voice as proof of identity, victims comply before suspicion can surface.

1. How AI Voice Cloning Works for Phishing
Voice cloning starts with open-source intelligence (OSINT). Attackers scrape audio from sources most executives never consider a security risk. Three seconds of clean audio is sufficient for modern voice synthesis engines to build a workable clone. Ten seconds produces a replica that matches pitch, pacing, breath patterns, and the micro-inflections that signal authority or urgency.
The technical process is trivial. Platforms like ElevenLabs offer instant voice cloning through a web interface for as little as $5 per month, the same tool used to create the fake Joe Biden robocall that reached tens of thousands of New Hampshire voters in January 2024. Open-source models eliminate the cost barrier entirely.
An attacker uploads a short audio clip, types the desired script, and downloads a synthetic audio file that is indistinguishable from the original speaker to the human ear.
Attackers then use caller ID spoofing to make the incoming call appear to originate from the executive's actual number. The victim sees a familiar name, hears a familiar voice making an urgent but routine-sounding request, and complies. The psychological mechanism exploits a cognitive shortcut humans have relied on throughout history: a familiar voice is treated as proof of the speaker’s identity.
A 2025 study published in Scientific Reports by researchers at UC Berkeley found that participants perceived an AI-cloned voice as belonging to the same identity as its real counterpart approximately 80% of the time. They correctly identified a voice as AI-generated only about 60% of the time, barely above chance.
The study used ElevenLabs' instant voice cloning API, the same commercially available tool attackers deploy, across 220 unique speakers. "Generally speaking, people are poorly equipped to identify AI-generated voice clones, both in terms of identity matching and naturalness," the researchers concluded. Even when participants were explicitly told to judge whether a voice was real or synthetic, they could not do so consistently.
2. The UK Energy Firm CEO AI Voice Cloning Scam
The first widely reported AI voice cloning attack set the template thousands of copycat operations would follow. In March 2019, the CEO of a UK-based energy firm received a phone call from what sounded exactly like his parent company's chief executive. Same German accent. Same melodic cadence. Same subtle authority in every syllable.
The caller said an urgent payment of €220,000 (approximately $243,000) needed to reach a Hungarian supplier within the hour. The CEO recognized the voice and authorized the transfer immediately.
The money routed through accounts in Hungary and Mexico before disappearing. The CEO later told investigators he complied not just because of what was said, but because the "melody" of his boss's voice was unmistakable. It was not. The voice belonged to an AI model trained on samples harvested from the parent CEO's public speaking appearances.
The attack followed a multi-stage sequence now standard in vishing operations. Attackers conducted reconnaissance on the parent company's leadership, identifying the German CEO as the ideal impersonation target based on his authority and public audio footprint. They called the UK subsidiary CEO directly using spoofed caller ID matching the parent CEO's number.
The cloned voice delivered the demand with natural urgency and followed up with emails referencing the call to reinforce legitimacy. After the first transfer succeeded, the attackers called back claiming the reimbursement had not arrived and demanded a second transfer. That follow-up call finally triggered suspicion.
3. AI-powered scam call centers: industrial-scale voice phishing
Voice cloning has moved beyond one-off attacks into industrialized operations. Criminal enterprises now operate fully automated call centers that combine synthetic voices with large language model (LLM)-driven conversation scripts, enabling thousands of simultaneous vishing calls with minimal human involvement. A single operator can oversee dozens of AI-driven conversations at once, intervening only when a victim shows signs of compliance or resistance.
These systems work in real time. When a target answers the phone, an LLM processes their responses, selects the optimal reply from a script tree trained on successful fraud patterns, and feeds the text into a cloned voice engine that speaks it aloud with natural pacing and emotional inflection.
If the victim objects, the AI either coaches the human operator or adjusts its own script to overcome the specific objection, usually by escalating urgency or invoking authority.
The economics are punishing. A legacy vishing scam required a fluent speaker of the target's language, hours of manual dialing, and a low success rate that limited profitability. An AI call center eliminates labor costs, operates 24/7, speaks dozens of languages, and never fatigues or deviates from the script. The UC Berkeley research team warned that longer, unscripted conversations may reduce detection further.
Listeners performed worse with longer clips because synthetic speech becomes harder to distinguish from real speech as the sample length increases.
Every employee in an organization, from accounts payable to the C-suite, is reachable by a synthetic voice that sounds exactly like someone they trust. Policy documents alone cannot defend against this. Employees need to hear a cloned voice in a controlled simulation, feel the instinct to comply, and learn to pause and verify through a second channel before acting.
That experience cannot be taught in a slide deck. Multi-channel phishing simulations that include synthetic voice attacks give teams the visceral detection instinct no written policy can provide, and the same verification habits carry directly into the next vector attackers are already scaling: deepfake video.
Deepfake Video Phishing: When Seeing Is No Longer Believing
Deepfake video phishing, one of the most advanced examples of how AI is used in phishing, collapses the one sensory defense employees have relied on for decades: the belief that seeing a face and hearing a voice confirms a person’s identity. Attackers who deploy real-time face-swapping, lip-sync generation, and AI-cloned voices on video calls render that assumption obsolete, enabling wire fraud, credential theft, and network access at a scale no email-based phishing campaign could achieve.
Gen Threat Labs detected 159,378 unique deepfake video scam attempts in Q4 2025 alone, while the number of deepfake files circulating online reached an estimated 8 million in 2025, up from roughly 500,000 in 2023, according to the UK government.

How Deepfake Phishing Attacks Work
Deepfake video phishing exploits a vulnerability that sits deeper than any software flaw: the human brain's hardwired trust in visual and auditory evidence. The technical barrier to exploiting that vulnerability has collapsed.
Real-time face-swapping tools, powered by open-source models like DeepFaceLab and FaceSwap, allow an attacker to map their own facial movements onto a target's likeness during a live video call. The model tracks the attacker's expressions, head position, and eye movement frame by frame, then renders the impersonated face onto the video stream with enough fidelity to pass on standard conferencing resolution.
Lip-sync generation synchronizes mouth movements to any audio input the attacker provides, whether spoken live or generated through voice cloning. The result is a composite that looks, moves, and speaks like the executive being impersonated.
Rather than face-swapping alone, attackers can now generate an entirely synthetic persona, head, torso, gestures, and background, on commodity hardware. Gaming GPUs, widely available for under $1,000, provide the parallel processing power needed to run inference at livestream frame rates. The computational infrastructure that once required a studio budget now fits on a desk.
The data requirements are disturbingly minimal. Publicly available video from conference talks, LinkedIn posts, company all-hands recordings, earnings calls, and media interviews provides attackers with the clean, front-facing, well-lit footage that deepfake models train on most effectively.
The agency advises employers to ask candidates to wave a hand in front of their face during video interviews, a motion that can cause AI-generated video filters to glitch, and to require candidates to point their camera out a window to verify claimed locations.
Voice cloning compounds the threat. Tools like ElevenLabs and open-source alternatives can generate a convincing voice clone from as little as three seconds of source audio. Earnings calls, podcast appearances, and even voicemail greetings supply that material. When an attacker pairs a cloned voice with a real-time face-swapped video feed, the resulting impersonation becomes extraordinarily difficult to detect through a screen.
Organizations that rely on static, email-only phishing simulations leave employees unprepared for this multi-sensory attack vector.
The Arup $25.6 Million AI Deepfake Video Phishing Scam
The attack on Arup, disclosed in February 2024, remains the largest known deepfake phishing loss and the definitive case study in how this threat vector operates. The sequence was methodical, multi-channel, and devastatingly effective.
It began with a phishing email. A finance employee in Arup's Hong Kong office received a message purportedly from the company's UK-based chief financial officer, referencing a confidential transaction that required immediate execution. The employee was suspicious. The email had the hallmarks of a phishing attempt. But the message directed him to join a video conference call to discuss the matter.
On that call, the employee saw and heard his CFO. He also saw other colleagues he recognized. Every participant on the screen was a deepfake. Hong Kong police senior superintendent Baron Chan Shun-ching later confirmed: "(In the) multi-person video conference, it turns out that everyone [he saw] was fake," according to CNN's reporting on the police briefing.
The attackers had used publicly available video and audio of the company's executives, conference recordings, media appearances, and internal communications to build convincing synthetic replicas of multiple staff members simultaneously.
The visual and auditory evidence on that video call overrode the employee's initial skepticism. Seeing faces he knew, hearing voices he trusted, and receiving instructions consistent with the earlier email, he authorized 15 separate wire transfers totaling approximately $200 million Hong Kong dollars, or $25.6 million USD. The fraud was discovered only when the employee later checked with Arup's head office.
"This happens more frequently than people realize," Rob Greig, Arup's Chief Information Officer, told the World Economic Forum in a 2025 interview about the attack. The Arup case crystallizes why deepfake video phishing is categorically different from traditional phishing. Email phishing asks an employee to ignore a red flag. Deepfake video phishing removes the red flag entirely by manufacturing the evidence the employee has been trained to trust most.
Every existing verification instinct, "I saw them," "I heard their voice," "other colleagues were there too," becomes a liability.
AI Deepfake Job Candidates and DPRK IT Worker Infiltration
The same deepfake technology that steals millions through impersonation on video calls also enables a slower, more insidious form of infiltration: North Korean operatives posing as remote IT workers to penetrate U.S. companies.
The mechanics are systematic. Operatives associated with the Democratic People's Republic of Korea (DPRK) use stolen or fabricated U.S. identities paired with AI-generated headshots and deepfake video to pass remote job interviews.
A July 2025 FBI alert detailed how these workers use U.S.-based facilitators, some witting and some unwitting, who provide domestic mailing addresses for company laptops, set up bank accounts to receive salaries, and in some cases attend initial video interviews on the operative's behalf.
Once hired, the worker installs remote access software on the company-issued device, granting North Korean handlers unrestricted access to corporate networks.
The threat is threefold. First, salary theft: wages funneled back to Pyongyang directly fund North Korea's weapons programs in violation of U.S. and UN sanctions. Second, data exfiltration: once inside a corporate network, these operatives extract source code, customer data, and proprietary systems. Third, persistent access: the compromised device and credentials become a long-term beachhead for follow-on intrusions.
The FBI's guidance emphasizes that third-party IT contractors face additional vulnerability, since they bypass the direct hiring scrutiny that internal HR processes provide.
Organizations that rely on fully remote hiring without in-person identity verification face a structural exposure gap. When an HR manager cannot physically confirm that the person on screen matches the identity on file, deepfake video converts the hiring pipeline itself into an attack surface. Some U.S. companies have begun requiring fingerprinting or in-person drug testing specifically to close this gap.
For organizations that cannot mandate physical presence, the FBI recommends mandated video calls with unobscured backgrounds, location verification challenges, and hand-wave tests designed to disrupt real-time AI filters. These countermeasures, unthinkable just a few years ago, now define the baseline for secure remote hiring.
Multi-Channel AI Attack Campaigns: Coordinated Assaults Across Email, Voice, and Video
Multi-channel campaigns reveal how AI is used in phishing at its most coordinated: attackers exploit a cognitive shortcut every human relies on. When an email, a voice call, and a video conference all deliver the same urgent request from the same executive, the brain treats that consistency as proof of legitimacy. This is not theoretical.
The Multi-Channel AI Attack Chain
The progression follows a deliberate architecture designed to make each channel reinforce the next. Attackers do not simply throw multiple messages at a target. They sequence them so that each interaction resolves doubt created by the previous one.
It begins with AI-driven open-source intelligence (OSINT) reconnaissance. Automated tools scrape LinkedIn profiles, earnings call transcripts, conference videos, and social media activity to map reporting structures, communication patterns, and executive speech cadences. Within hours, an attacker knows who reports to whom, how the CFO phrases requests, and where a given employee sits in the approval chain.
From that intelligence, the attacker generates an AI-crafted spear phishing email: grammatically flawless, contextually relevant, and framed as urgent. This email establishes the premise of a confidential transaction requiring immediate action. The tone mimics the executive's known style, and the request references real projects surfaced during OSINT reconnaissance.
If the target hesitates, the second channel activates. An AI-cloned voice call, generated from as little as three seconds of publicly available audio, arrives within minutes. According to McAfee research (2024), three seconds of source audio produces a voice clone with 85% accuracy. The voice is the executive's. The urgency is consistent with the email.
The caller references the "message just sent" and presses for confirmation. The employee who was initially suspicious now has corroborating evidence from a second, seemingly independent channel.
The third stage is the kill shot. A deepfake video call places the executive, along with other "colleagues," on screen in real time. Multiple participants nod, contribute, and reinforce the request.
Monetization takes the form that matches the target's access: wire transfers for finance employees, credential theft for IT staff, or system access for engineers with infrastructure privileges.
As the FBI's San Francisco field office warned in May 2024, cybercriminals are increasingly using AI to generate convincing multi-channel social engineering campaigns that exploit trust across communication platforms.
The Bureau noted that these techniques are becoming more accessible and harder to detect with each passing quarter.
How Cross-Channel Trust Transference Makes AI Phishing More Dangerous
Humans rely on multi-channel consistency as a trust heuristic. It is one of the most deeply embedded verification mechanisms that exists. When an email, a phone call, and a video appearance all deliver the same message, the brain concludes the request is authentic because fabricating consistency across three separate channels feels impossibly difficult. For most of human history, it was.
AI has broken that assumption. Generating a convincing email, a cloned voice, and a real-time deepfake video no longer requires a nation-state budget or weeks of production. Off-the-shelf tools can produce all three from publicly available data in under an hour. The attack does not need to be perfect in any single channel. It needs only to be good enough across all three that the consistency heuristic overrides isolated doubts.
This is what makes the multi-channel approach qualitatively different from traditional phishing. A suspicious email alone might get reported. But that same email followed by a familiar voice on the phone and a familiar face on video short-circuits the reporting reflex. The employee stops treating the interaction as a potential threat and starts treating it as an unusual but legitimate executive request.
Security awareness training built for the single-channel era, checking for bad grammar, hovering over links, and avoiding attachments, offers no protection against an attack that arrives across email, voice, and video with perfect consistency. Employees must be trained to recognize that consistency is now a weapon and that verification through a completely separate, pre-established channel is the only reliable defense.
The Real-World Impact and Economics of AI-Powered Phishing
The profitability to launch a hyper-personalized spear-phishing campaign has increased by up to 50 times for larger audiences. The financial damage continues to climb. The FBI's Internet Crime Complaint Center documented $20.9 billion in total cybercrime losses in 2025, per the 2025 IC3 Annual Report released in April 2026, the highest figure ever recorded, up from $16.6 billion in 2024.
Pindrop's analysis found AI-driven fraud specifically surged 1,210% in 2025, far outpacing the growth in non-AI fraud during the same period. The math is grim and one-directional: attacks are getting cheaper to produce, harder to detect, and exponentially more damaging.
Financial Losses from AI-Powered Phishing
Business email compromise, a category now turbocharged by AI-generated content, has been a consistent multi-billion-dollar problem. The IC3 recorded BEC losses of over $3 billion in 2025 alone, and cumulative BEC losses across the last decade, between 2013 and 2023, approached $55.5 billion.
The damage concentrates unevenly across industries. Healthcare organizations face a distinct combination of high-value data and under-resourced security teams. One major U.S. healthcare provider experienced over 15,000 unique bot fraud calls targeting patient accounts and HSA/FSA funds during summer 2025 alone, according to Pindrop's telemetry data. In retail, AI-powered return fraud surged 330% in just two months among major retailers, with attackers deploying bots that systematically exploit return policies through thousands of low-dollar transactions engineered to stay below fraud-detection thresholds.
Financial services firms, already the most-targeted sector for phishing, confront the added burden of AI voice cloning that can replicate an account holder's speech patterns from as little as three seconds of publicly available audio.
Click-Through Rates: Why AI Phishing Outperforms Human Attacks
The performance gap between AI-generated and traditional phishing is no longer marginal. It is a chasm. A 2024 controlled human study published on arXiv evaluated GPT-4o and Claude 3.5 Sonnet against human phishing experts across 101 participants. The control group, receiving generic phishing emails, recorded a 12% click-through rate. Human-expert-crafted emails achieved 54%. Fully AI-automated emails also hit 54%, statistically identical to the experts. AI with a human-in-the-loop reached 56%.
Personalization drives this fourfold performance gap. The same study found that 40% of AI-phishing recipients specifically cited personalization as the reason they trusted the message, compared to 0% in the control group and roughly 20% in the human-expert group.
The AI systems achieved 88% accuracy when building target profiles from open-source intelligence, scraping LinkedIn, corporate websites, and social media to produce dossiers that were accurate and useful in nearly nine out of ten cases. Only 4% of AI-generated profiles contained any inaccurate information.
The cost economics make this performance differential catastrophic. The researchers replicated the manual process of OSINT gathering and email crafting and found it took an average of 34 minutes per target: 23 minutes for reconnaissance and 10 minutes for writing. The AI-automated equivalent took 2 minutes and 41 seconds, with much of that time spent on optional human-in-the-loop review.
This is the structural shift that makes AI-powered phishing a rapidly escalating threat. Traditional spear phishing was a high-skill, high-cost attack reserved for well-resourced adversaries targeting high-value individuals. AI has democratized it. A single threat actor with access to a large language model can now generate 10,000 unique, OSINT-personalized phishing emails at near-zero marginal cost. The economic barrier that protected all but the most valuable targets has been eliminated.
SMBs vs. Enterprises: How AI Phishing Impacts Organizations Differently
Enterprises and small-to-medium businesses face AI-powered phishing from opposite ends of a lopsided playing field, and both are losing ground.
Large enterprises typically maintain security operations centers, dedicated anti-phishing teams, and layered defenses that include email security gateways, endpoint detection, and security awareness training programs. What they also have is an enormous attack surface. A Fortune 500 company might employ 50,000 people, each with a LinkedIn profile, corporate headshot, conference-speaking history, and social media presence.
That sprawling digital footprint can be mined by AI reconnaissance tools in seconds. The more employees an organization has, the more doors exist for an AI-generated phishing email to find someone distracted, stressed, or rushed enough to click. Even a 1% click-through rate across 50,000 employees means 500 potential compromises.
SMBs face the inverse problem. Their attack surface is smaller. A 50-person accounting firm or a 200-employee manufacturing plant has fewer entry points. But their defenses are proportionally weaker still. The majority of SMBs lack any dedicated cybersecurity staff. Security awareness training, if it exists at all, often consists of an annual compliance video.
These organizations are now targeted with the same AI-generated phishing attacks that enterprises face. But they have none of the detection infrastructure, incident response capacity, or security awareness culture to absorb the blow.
The consequences scale differently but are equally devastating. An enterprise might weather a single $500,000 wire fraud attempt as a line-item loss. For an SMB, that same amount represents potentially business-ending damage. The post-breach costs are what smaller organizations cannot survive. Forensic investigation, regulatory notification, legal liability, and reputation repair consume resources they simply do not have.
IBM's 2025 Cost of a Data Breach Report found the average breach cost across all organizations was $4.44 million, a figure that already exceeds the annual revenue of many SMBs before factoring in the operational disruption that follows.
Every organization, regardless of size, faces the same attack sophistication. What differs is only the capacity to detect it, respond to it, and survive it.
Nation-State Actors and Organized Crime Using AI Phishing
Nation-state threat actors and transnational organized crime groups have operationalized AI phishing at scale because artificial intelligence eliminates the single biggest constraint on social engineering: the need for skilled human operators to maintain convincing, persistent conversations across languages and time zones.
AI allows a single operator to run dozens of emotionally intelligent conversations simultaneously, transforming what was once a labor-intensive craft into a repeatable, automated fraud production line, though the technology still produces detectable artifacts that defenders can exploit today.
Forest Blizzard, DPRK, and State-Sponsored AI Phishing
Russian-aligned Forest Blizzard (APT28) and North Korean cyber units have integrated AI into their phishing operations across the full attack lifecycle, from reconnaissance to content generation to identity fabrication. These groups now use large language models to scrape open-source intelligence (OSINT) on targets, generate culturally fluent spear phishing lures in multiple languages, and eliminate the grammatical errors that once made state-sponsored phishing emails detectable.
In July 2025, Ukraine's CERT-UA documented APT28 deploying LAMEHUG malware that used the Qwen2.5-Coder AI model to automate malicious command generation, confirming that state-sponsored actors have moved from experimentation to operational AI integration. The operational payoff is straightforward: AI reduces the per-target cost of personalized phishing to near zero, enabling nation-state campaigns to scale from hundreds to tens of thousands of targets without proportionally increasing headcount.
The most audacious state-sponsored AI phishing program is North Korea's IT worker infiltration scheme, which combines AI-generated resumes, synthetic video interviews, and real-time deepfake identity verification to place operatives inside Western companies.
These operatives use AI-generated profile photos, LLM-tailored employment histories, and live deepfake technology during video interviews to defeat standard hiring verification. Once inside an organization, they gain access to internal systems, source code, and sensitive data, turning a phishing operation into a persistent insider threat. Multichannel phishing simulation platforms that test employees across email, voice, and video are the only training approach that mirrors how these state-sponsored campaigns actually operate.
AI Romance Scams, Pig Butchering, and Synthetic Identity Fraud
Large language models have enabled romantic fraud at industrial scale. Where human-run romance scams required operators to sustain weeks or months of emotionally engaging conversation with each victim individually, AI now allows a single scammer to maintain simultaneous intimate relationships with hundreds of targets. The FBI reported that victims in its San Antonio Division alone lost more than $28 million to confidence and romance scams in 2025, nearly doubling the $15.8 million lost in 2024.
Criminal actors deploy AI to generate realistic photos, eliminate grammatical errors that once betrayed scam messages, and produce emotionally persuasive narratives that adapt to each victim's responses in real time, all while maintaining the illusion of a genuine, attentive partner.
Pig butchering schemes, named for the practice of fattening victims with trust before slaughtering their finances, have evolved into the same AI-driven architecture. After weeks of relationship-building, victims are directed to fraudulent cryptocurrency investment platforms displaying fabricated profits. When withdrawal is attempted, it is denied and contact severed.
In parallel, synthetic identity fraud has emerged as a distinct criminal product: AI combines real stolen data from breaches with fabricated employment histories, education credentials, and credit profiles to create identities that pass KYC verification and credit checks.
The same LLM infrastructure that powers romance scams also generates the supporting documentation, reference letters, and digital footprint needed to make each synthetic persona survive verification. What connects all of these operations is the same enabling technology: AI that manufactures trust at a scale no human criminal organization could achieve alone.
That same industrial scale is what makes simulation-based defense, where employees face realistic AI-generated attacks before real ones arrive, the only training model fast enough to keep pace.
Detection and Defensive Measures Against AI-Powered Phishing
Defending against AI-powered phishing demands layered technical controls that address the attack at multiple points, AI-content detection deployed where it adds value and not where it creates false confidence, and a fundamental rethinking of why employees fall for these attacks. Begin with technical defenses that shrink the attack surface, then evaluate AI detection tools for what they can and cannot deliver operationally.
Finally, use the NIST Phish Scale framework to understand why AI-generated phishing succeeds at rates legacy tools were never designed to handle, and restructure detection strategy around context rather than cues.
How AI-Based Email Filtering Works Against Generated Phishing
AI-based email filtering is the first meaningful upgrade to perimeter defense in years. Unlike signature-based filters that match against known-bad domains or keyword patterns, modern AI-driven filters analyze semantic patterns, linguistic structure, and the relationship between an email's content and its claimed sender. An AI-generated phishing email impersonating a CFO uses fluent, contextually appropriate language that signature-based filters miss entirely.
Semantic analysis tools detect when an email's tone, vocabulary, and internal logic deviate from the patterns established across genuine internal communications.
A 2025 study published in Expert Systems with Applications evaluated 63 AI-generated phishing emails created with GPT-4o and found that major email services exhibited significant detection gaps. AI-generated phishing bypassed legacy filters at rates that make single-layer email defense obsolete. The limitation is real: no email filter catches everything, and a sophisticated attacker who mimics internal communication style closely enough can still slip through.
Browser security extensions add a second layer by detecting phishing pages in real time. They analyze URL structures, page composition, and behavioral signals that indicate credential harvesting. These tools work at the point of interaction, when an employee clicks a link and lands on a page, rather than at the gateway.
Their value increases against AI-generated phishing because AI can produce login pages that are pixel-perfect replicas of legitimate services, complete with dynamically generated branding and personalized error messages. Browser extensions that compare the rendered page against known templates and detect anomalous form behavior can block the credential harvest even after the email has been delivered and clicked.
The weakness: extensions only protect browsers where they are installed, leaving mobile apps, SMS links, and voice-based attacks uncovered.
Phishing-resistant multifactor authentication stops credential harvesting at its endpoint. FIDO2, passkeys, and hardware tokens use public key cryptography and origin binding. The authenticator responds only when it recognizes the legitimate domain. If the site is spoofed, the authenticator stays silent and there is nothing for the attacker to capture.
Even when an employee enters their credentials into a convincing AI-generated phishing page, the attacker cannot use those credentials because the cryptographic handshake requires the physical device and the correct domain. Passkeys eliminate passwords entirely, removing the primary target of most phishing campaigns. The operational reality: deploying phishing-resistant MFA across an enterprise takes time, and legacy applications that do not support FIDO2 protocols create coverage gaps attackers actively exploit.
Network detection and response (NDR) tools identify anomalous communication patterns that signal a phishing attack in progress. When an employee's account begins sending emails to unusual external domains, accessing atypical resources, or exhibiting command-and-control beaconing patterns, NDR tools flag the behavior. This is a post-delivery safety net. It does not prevent the initial phishing email from arriving, but it can detect the compromise before lateral movement occurs.
Against AI-powered phishing, where the initial message looks normal, NDR's reliance on behavioral anomalies rather than content signatures provides a detection layer that content-based tools cannot replicate. The honest assessment: NDR generates alerts that require triage, and security teams already drowning in false positives may struggle to respond before damage is done.
No single technical control catches everything. Defense against AI phishing requires all four layers operating simultaneously. The gaps between them are where attackers succeed, and closing those gaps is what separates organizations that detect compromise early from those that learn about it from a third party.
What AI-Content Detection Tools Can and Cannot Do
AI-content detection tools, including watermarking, AI-text classifiers, and deepfake detection, promise to identify machine-generated content before it reaches employees. In practice, their operational utility is constrained by false positives and false negatives that make them unreliable as standalone decision engines.
AI-text classifiers such as GPTZero, ZeroGPT, and Corrector App analyze writing for patterns like low perplexity and uniform sentence structure that indicate machine generation. A 2025 study in Neurosurgical Review evaluated 1,000 texts across three detectors and found that while they achieved area-under-the-curve scores between 0.75 and 1.00 in distinguishing AI-generated from human-authored content, none achieved 100% reliability.
The Corrector detector assigned AI likelihood scores above 50% to 30.4% of known human-authored articles. These false positives carry operational consequences: flagging legitimate executive communications as AI-generated erodes trust in the detection system and creates alert fatigue. False negatives are equally problematic. AI-generated phishing emails that score below detection thresholds reach inboxes with a false sense of security.
Deepfake detection tools face similar structural challenges. They analyze videos and audio for artifacts, irregular blinking patterns, inconsistent lighting, and spectral anomalies in voice synthesis. The generation models improve faster than the detection models. Watermarking standards like C2PA provide cryptographic provenance for media files, verifying whether content originated from a specific device or editing tool, but they require adoption across the entire content creation ecosystem to be effective.
An attacker generating deepfake video for a targeted phishing campaign will not voluntarily watermark their output.
Open-source tools exist. The Deepfake Detection Challenge dataset and associated models remain available, but most require significant machine learning expertise to deploy and tune. They produce probability scores, not verdicts, and the security team must decide what threshold triggers an alert. For most organizations, AI-content detection functions best as a triage aid rather than an automated gate.
Human analysts still need to assess flagged content, and employees still need the training to recognize manipulation cues that tools miss. Phishing simulations that expose employees to AI-generated attacks in a controlled environment build the human detection layer that software alone cannot provide.
Why AI Phishing Succeeds: The NIST Phish Scale Framework
The NIST Phish Scale, developed by researchers at the National Institute of Standards and Technology, provides a rigorous, widely used framework for understanding why certain phishing emails succeed and others fail. It evaluates phishing detection difficulty along two axes: message cues and user context.
Message cues are the observable characteristics of the phishing email itself. Spelling errors, grammatical mistakes, urgent language, impersonation of a known contact, and technical indicators like mismatched URLs or suspicious attachments. Legacy phishing detection, both human and automated, relied heavily on these cues. A misspelled subject line, a generic greeting, or a mismatched sender domain triggered suspicion.
User context encompasses the recipient's workload, their expectations about receiving similar communications, how closely the phishing email aligns with their actual job duties, and their prior exposure to similar attacks. The NIST researchers found that user context was the lens through which all cues were interpreted.
An employee processing invoices who receives a payment request during quarter-end close is operating in a context that makes detection far harder than a generic credential phish arriving on a slow Tuesday.
AI-generated phishing systematically dismantles the cue-based detection model. Grammar errors disappear. Urgency is calibrated to sound reasonable rather than hysterical. Impersonation becomes precise. The AI generates emails that match the executive's actual writing style, reference real projects, and arrive at contextually plausible moments. The message cues that NIST identified as detection signals are exactly what AI eliminates.
What remains is user context, and AI attackers exploit this by timing campaigns around known business cycles and targeting roles where the request aligns with normal duties.
This demands a fundamentally different detection paradigm. Organizations cannot train employees to spot cues that no longer exist. Instead, the NIST Phish Scale framework points toward contextual defenses: verification protocols that function regardless of message quality, role-specific simulation training that exposes employees to AI-generated attacks in their actual work contexts, and a security culture where unusual requests trigger a second-channel confirmation by default rather than by exception.
When cues vanish, context becomes the only reliable signal, and building a workforce that verifies by reflex is the defensive measure that AI cannot out-engineer.
Regulatory and Framework Responses to AI-Powered Phishing
Regulators, standards bodies, and insurers are moving to address AI-powered phishing, and the pace of their response is accelerating. AI-powered attacks exploit a gap that existing frameworks were never designed for: synthetic media, automated reconnaissance, and machine-generated social engineering. Three distinct fronts, federal guidance, state-level enforcement, and the MITRE ATT&CK framework, are now reshaping what compliance teams must track and what controls organizations must implement.
NIST IR 8596 and Federal AI Security Guidance
In December 2025, NIST released the preliminary draft of NIST IR 8596, the Cybersecurity Framework Profile for Artificial Intelligence, extending CSF 2.0 with three AI-specific focus areas: Secure, Defend, and Thwart. The Thwart function directly addresses AI-powered phishing by building organizational resilience against AI-enabled threat vectors.
It is an explicit recognition that traditional controls were not architected for attacks where adversaries use large language models for reconnaissance, content generation, and impersonation at scale.
The profile maps AI-specific risks to familiar CSF categories rather than replacing existing standards. For legal and compliance teams, this document is already functioning as an emerging benchmark for reasonable AI security practices, one that will influence regulatory expectations, contractual standards, and vendor risk assessments even before it moves from draft to final.
Organizations that integrate the Thwart function's guidance into their security awareness and phishing simulation programs now position themselves ahead of the compliance curve.
FTC Enforcement, State AI Laws, and the Regulatory Trajectory
The Federal Trade Commission launched Operation AI Comply in September 2024, making explicit that "there is no AI exemption from the laws on the books." The enforcement action, which has continued into 2026 under new leadership, uses existing consumer protection authority to pursue AI-enabled fraud, including schemes where generative AI tools facilitate phishing, impersonation, and deception.
FTC leadership has consistently framed AI as an accelerant to existing harms rather than a separate regulatory category requiring new statutes.
Meanwhile, states have built a fragmented but rapidly expanding patchwork of AI-specific laws. Since 2022, 46 states have enacted deepfake legislation, and the federal TAKE IT DOWN Act became law in May 2025, criminalizing non-consensual AI-generated intimate imagery. California's AI Transparency Act (SB 942), effective August 2026, mandates watermarking and latent disclosure requirements for generative AI outputs.
For compliance teams, the operational challenge is clear: a multi-state organization must track and reconcile overlapping, occasionally conflicting, state-level AI obligations while the FTC applies uniform federal enforcement pressure through existing consumer protection law.
MITRE ATT&CK Mapping for AI-Powered Phishing Techniques
The MITRE ATT&CK framework now formally recognizes AI as a distinct adversarial capability through sub-technique T1588.007, "Obtain Capabilities: Artificial Intelligence," under the Resource Development tactic. This sub-technique captures how adversaries acquire and use generative AI tools to conduct reconnaissance, draft phishing content in multiple languages, generate deepfake audio and video for impersonation, and automate malicious script creation.
Once the adversary has obtained AI capabilities, the attack flows through well-established tactics: Reconnaissance (TA0043), where LLMs accelerate open-source intelligence (OSINT) gathering on targets, into Initial Access (TA0001) via phishing (T1566) or phishing for information (T1598). The AI-specific sub-technique does not create new tactics. It acknowledges that AI supercharges the speed, scale, and sophistication of existing ones.
Detection remains difficult because much of the AI-assisted reconnaissance and content generation occurs outside the target's visibility. Security teams should map their detection strategies to the downstream techniques that AI enables, specifically phishing, credential harvesting, and impersonation, rather than attempting to detect AI use itself.
Cyber Insurance Underwriters Tighten Policies for AI Phishing Claims
Cyber insurance carriers are responding to AI-powered phishing with heightened scrutiny, new exclusions, and mandatory control requirements. A 2026 Wiley analysis of the cyber insurance market found that insurers are likely to implement form exclusions or impose sublimits specifically for AI-related losses, even as courts debate whether losses from AI-driven social engineering constitute "direct" losses under existing computer fraud coverage.
Organizations that cannot evidence security awareness training covering AI-specific threats, including deepfake and voice-cloning simulations, face tougher renewal terms. The message from underwriters is clear: AI phishing readiness is no longer a differentiator. It is becoming a prerequisite for coverage.
Compliance teams that treat these emerging requirements as checkbox exercises will find their organizations exposed, not just to regulatory risk, but to coverage gaps that surface precisely when a breach occurs.
How Security Awareness Programs Are Adapting to AI-Powered Phishing
Annual security awareness training was built for an era when phishing meant misspelled emails with generic greetings and suspicious links. AI-generated attacks have eliminated most of the telltale signs those programs taught employees to detect. By early 2025, AI-powered phishing represented more than 80% of all observed social engineering activity worldwide, according to the European Union Agency for Cybersecurity (ENISA).
A controlled study from late 2024 found that AI-generated phishing emails match the 54% click-through rate of human expert campaigns, both far outpacing generic phishing, as language models continue to improve.
Why traditional annual security awareness training fails against AI phishing
The fundamental architecture of legacy security awareness training is mismatched against AI-powered threats. Compliance-driven programs operate on annual cycles with static slide decks, generic phishing templates, and a completion-checkbox mentality. Employees learn to spot simple scams and misspelled URLs, patterns that large language models have made obsolete overnight. AI-generated phishing emails now eliminate the grammatical errors and awkward phrasing that legacy training modules treat as primary detection signals.
The result is training that teaches employees to look for artifacts attackers stopped leaving behind two years ago.
The channel gap is equally dangerous. Traditional SAT programs simulate email phishing exclusively, while vishing calls and deepfake video conference impersonations have become operational attack vectors.
An employee trained to scrutinize email headers has no framework for evaluating a phone call that perfectly mimics their CFO's voice or a video call where every participant is an AI-generated synthetic persona. The training does not map to the threat surface.
How continuous, simulation-driven programs build AI-phishing resilience
Modern security awareness programs replace the annual training model with continuous, simulation-driven cycles that mirror the velocity of AI-enabled attacks. Instead of one-size-fits-all modules, employees receive multi-channel simulations across email, voice, SMS, and deepfake video that replicate the exact tactics attackers are using this quarter, not last year. When an employee fails a simulation, automated microlearning triggers immediately, closing the knowledge gap while the experience is still fresh.
This approach builds what researchers call inoculation: controlled exposure to realistic attack scenarios that trains the brain to pause and verify before complying. Finance teams practice spotting invoice fraud across email, voice, and video channels. IT staff rehearse credential-reset attempts delivered through SMS and phone calls.
The training cadence is continuous because the attacks are continuous. The simulation library updates as fast as the threat landscape shifts.
The role of human risk scoring in measuring defense against AI-powered phishing attacks
Human risk scoring transforms security awareness from an attendance-based metric into a quantifiable defense signal. Training completion percentages tell a security leader whether employees sat through a module. They reveal nothing about whether those employees would actually resist an AI-generated attack. A human risk score aggregates simulation performance across every channel, alongside open-source intelligence (OSINT) exposure data, credential breach history, and real-world phishing reporting behavior into a single dynamic metric.
This scoring layer gives CISOs and boards something annual compliance reports never could: a trend line showing whether the organization is becoming more or less resistant to AI-powered social engineering over time. The IBM 2025 Cost of a Data Breach Report identified phishing as the most common initial attack vector, involved in 16% of all breaches.
The only defensible measurement framework is one that tracks actual behavioral change at the individual, department, and organization level rather than seat time in a training module. Closing that gap demands a fundamentally different approach to what the organization measures and how it defines a prepared workforce.
Frequently Asked Questions About AI-Powered Phishing
Can ChatGPT be used to create phishing emails?
Yes. IBM X-Force researchers demonstrated that ChatGPT can generate highly convincing phishing emails in just five minutes using only five simple prompts. The AI-generated email nearly matched the click-through rate of one crafted by human experts over 16 hours, as documented in IBM's AI vs. human deceit research. Generative AI eliminates the grammatical errors and awkward phrasing that employees and spam filters have traditionally relied on as detection cues.
Attackers routinely jailbreak ChatGPT and other LLMs to produce phishing content at scale, bypassing guardrails with prompt engineering techniques. The barrier to entry has collapsed. A single operator with no fluent language skills can now generate dozens of culturally nuanced, personalized phishing emails in under an hour.
How do AI-powered phishing attacks bypass multi-factor authentication?
AI-powered phishing bypasses MFA primarily through adversary-in-the-middle (AiTM) attacks that use reverse proxy servers to intercept both credentials and session tokens in real time. When an employee clicks an AI-generated phishing link and reaches a fake login page that perfectly mimics the real service, the attacker's proxy relays credentials to the legitimate site and captures the session cookie returned after MFA is completed.
As Cisco Talos explains in its state-of-the-art phishing analysis, that stolen session token grants authenticated access without ever needing the MFA code. AI amplifies this threat by generating undetectable fake login portals and crafting the personalized email lures that deliver victims to them. Only phishing-resistant MFA standards such as FIDO2 and hardware security keys prevent this attack vector.
What was the largest financial loss from an AI deepfake phishing attack?
The largest confirmed financial loss from an AI deepfake phishing attack is $25.6 million, stolen from engineering firm Arup in early 2024. As CNN reported, attackers used deepfake technology to impersonate the CFO and senior executives during a video conference call. A finance employee, convinced they were speaking with genuine leadership, authorized 15 wire transfers totaling 200 million Hong Kong dollars.
The attack fused AI-generated phishing emails that established initial contact with real-time deepfake video that sealed the deception. Hong Kong police confirmed the scam required only publicly available video footage to train the deepfake models. No internal breach was necessary.
The Arup case proves that when attackers combine AI-generated content with deepfake video, the only reliable defense is a workforce trained to question every unusual request, no matter how convincingly it arrives.
How AI-Powered Simulations Prepare Teams for the Phishing Threats Email Filters Miss
AI-generated phishing emails now evade traditional email filters at staggering rates, landing in inboxes with flawless grammar, personalized details, and urgent calls to action. Adaptive Security's multichannel phishing simulations train employees to recognize and report these advanced threats across email, voice, and SMS, the exact channels where real attacks land. Take a self-guided tour to see how AI-powered simulations build the detection reflexes that email filters alone cannot provide.
As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.
Get started with Adaptive Security
Related articles

Thread Hijacking Phishing: How Cyberattackers Exploit Trusted Email Conversations and How Organizations Can Stop Them

How Phishing Works: A Complete Guide to Phishing Attack Types, Mechanics, Detection, and Organizational Defense

Phishing Email Examples: How to Recognize, Report, and Defend Against Every Type of Attack in 2026
Get started