40% of Business Email Compromise Now AI-Generated: How LLMs Are Supercharging Phishing at Scale

Published

Generative AI has fundamentally altered the economics and effectiveness of phishing attacks. According to multiple industry reports compiled in early 2025, approximately 40% of business email compromise (BEC) emails are now AI-generated, and nearly 90% of CISOs identify AI-driven attacks as a major threat to their organizations, per Trellix research.

Scale, Speed, and Sophistication

The Vanta State of Trust Report, surveying 2,500 business and IT leaders globally, found that nearly three-quarters believe AI threats are outpacing their ability to manage them. Half of companies report an uptick in AI-generated phishing, malware, and identity fraud. The acceleration is driven by LLMs' ability to generate contextually appropriate, grammatically perfect social engineering content in any language — eliminating the telltale signs that historically helped users identify phishing attempts.

What was once reserved for sophisticated threat actors is now accessible to entry-level cybercriminals. AI tools can scrape a target's LinkedIn profile, corporate website, and social media presence, then generate hyper-personalized spear-phishing emails that reference specific projects, colleagues, and internal terminology. Attackers no longer launch massive generic campaigns — they design targeted, credible, and contextual attacks at scale.

The Multi-Modal Threat

AI-powered attacks increasingly combine multiple channels. A typical campaign now begins with a BEC email from what appears to be a trusted executive, escalates to a deepfake voice call to build urgency, and may culminate in a video conference with AI-generated avatars to authorize fraudulent transfers. This multi-modal approach exploits the human tendency to trust layered confirmations.

Forrester analyst Paddy Harrington predicts that in 2026, offensive autonomous and agentic AI will emerge as a mainstream threat, with attackers deploying fully automated phishing, lateral movement, and exploit chains. The gap between detection and response continues to widen: 72% of security decision-makers say risk has never been higher (up from 55% in 2024), while 56% experience threat activity at least once a week.

Defenders should implement AI-powered email security that analyzes behavioral patterns and semantic intent rather than relying solely on signature-based detection, enforce strict verification protocols for all financial transactions, and invest in continuous security awareness training that specifically addresses AI-generated threats.

Read the full analysis on IntelFusions