Generative AI has fundamentally altered the economics and effectiveness of phishing attacks. According to multiple industry reports compiled in early 2025, approximately 40% of business email compromise (BEC) emails are now AI-generated, and nearly 90% of CISOs identify AI-driven attacks as a major threat to their organizations, per Trellix research.
Scale, Speed, and Sophistication
The Vanta State of Trust Report, surveying 2,500 business and IT leaders globally, found that nearly three-quarters believe AI threats are outpacing their ability to manage them. Half of companies report an uptick in AI-generated phishing, malware, and identity fraud. The acceleration is driven by LLMs' ability to generate contextually appropriate, grammatically perfect social engineering content in any language — eliminating the telltale signs that historically helped users identify phishing attempts.
What was once reserved for sophisticated threat actors is now accessible to entry-level cybercriminals. AI tools can scrape a target's LinkedIn profile, corporate website, and social media presence, then generate hyper-personalized spear-phishing emails that reference specific projects, colleagues, and internal terminology. Attackers no longer launch massive generic campaigns — they design targeted, credible, and contextual attacks at scale.
The Multi-Modal Threat
AI-powered attacks increasingly combine multiple channels. A typical campaign now begins with a BEC email from what appears to be a trusted executive, escalates to a deepfake voice call to build urgency, and may culminate in a video conference with AI-generated avatars to authorize fraudulent transfers. This multi-modal approach exploits the human tendency to trust layered confirmations.
Forrester analyst Paddy Harrington predicts that in 2026, offensive autonomous and agentic AI will emerge as a mainstream threat, with attackers deploying fully automated phishing, lateral movement, and exploit chains. The gap between detection and response continues to widen: 72% of security decision-makers say risk has never been higher (up from 55% in 2024), while 56% experience threat activity at least once a week.
Defenders should implement AI-powered email security that analyzes behavioral patterns and semantic intent rather than relying solely on signature-based detection, enforce strict verification protocols for all financial transactions, and invest in continuous security awareness training that specifically addresses AI-generated threats.