AI Is Making Phishing Harder to Spot. Here’s What Changed.
For years, spotting a phishing email was almost intuitive - bad grammar, a generic "Dear Customer," a link that didn't quite match the sender's domain. Those tells are disappearing. Generative AI has given attackers the ability to write flawless, personalized messages in minutes, clone a colleague's voice from a few seconds of audio, and build fake login pages that are nearly indistinguishable from the real thing. For businesses in New York City, Westchester, Connecticut, and Los Angeles, this isn't a future risk. It's already showing up in inboxes right now.
The Numbers Behind the Shift
The scale of the change is well documented. Hoxhunt's 2026 Phishing Trends Report found that AI-assisted attacks jumped from just 4% of all reported phishing in November 2025 to 56% in December, a 14-fold increase in a single month, driven by criminals using generative AI to mass-produce convincing lures with little effort. That share has since settled at around 40%, meaning roughly four in ten phishing attempts hitting inboxes today are AI-generated.
The FBI is tracking this too. The FBI's Internet Crime Complaint Center (IC3) logged 803 phishing complaints with a confirmed AI connection in 2025, totaling $10.3 million in AI-attributed losses, and dedicated its first-ever AI-specific section of its annual report to the trend. Separately, IBM's X-Force 2026 research found that generative AI has cut the time it takes to craft a convincing phishing email from around 16 hours down to about 5 minutes, roughly a 200x jump in attacker productivity.
The effectiveness gap is the part that should concern every business owner. In a controlled study comparing AI-automated spear phishing to human-written campaigns, AI-generated emails reached a 54% click-through rate, statistically identical to phishing written by experienced human attackers, and far above the roughly 12% baseline for generic phishing. One caveat worth noting: some widely circulated figures in this space, like the claim that 82.6% of phishing emails now contain AI-generated elements, trace back to vendor roundups rather than a single transparent, named methodology, so they're best treated as directional industry signals rather than precise measurements. Even accounting for that, the direction is consistent across every source: AI-written phishing is closing the gap with the best human-crafted attacks, fast.
It's Not Just Email Anymore
Text and voice have become just as dangerous. Voice phishing (vishing) surged 442% from the first half to the second half of 2024, according to CrowdStrike's 2025 Global Threat Report, making it the fastest-growing attack vector that year. A 2026 Sagiss survey found that 64% of respondents believe an AI-generated message could convincingly impersonate a co-worker well enough to fool them.
The risk isn't hypothetical. In 2024, an employee at British engineering firm Arup was convinced to transfer $25 million after joining a video call where every other person on the call, including someone appearing to be the CFO, was an AI-generated deepfake. The employee had actually suspected the initial email was a phishing attempt, but the "live" video call overrode that instinct. That's the exact scenario security teams now have to plan for: attackers no longer need just a convincing email, they can back it up with a convincing voice or face.
Why Small and Midsize Businesses Are Especially Exposed
Larger enterprises typically have layered defenses in place already - security operations centers, dedicated incident response teams, enterprise-grade filtering, and the budget to keep all of it current. Small and midsize businesses without a dedicated security team tend to absorb a disproportionate share of the damage instead. That's the gap we spend most of our time closing for clients.
What Actually Still Works
The good news is that the fundamentals of phishing defense haven't changed, they've just gotten more important:
- Verify before you act. If an email, text, or even a phone call asks for a wire transfer, credential reset, or sensitive data, confirm it through a separate, known channel, ideally a phone call to a number you already have on file, not one provided in the message itself.
- Never enter credentials from a link in an email. Navigate to the site directly instead. This one habit defeats the large majority of credential-harvesting attempts, AI-written or not.
- Treat "urgent" and "confidential" as red flags, not green lights. Attackers, human or AI, still rely on urgency and pressure to short-circuit good judgment. Security awareness training that keeps this front of mind has been shown to cut phishing susceptibility by roughly 86% within a year.
- Report anything that feels slightly off, even if it looks legitimate. The faster a suspicious message gets reported, the faster it can be blocked for everyone else in the company.
- Don't rely on writing quality as your filter anymore. Train your team, and yourself, to focus on the request being made, not how polished the message sounds.
What We Do for Red Key Clients
Phishing defense isn't a single tool, it's a layered system: email filtering tuned to catch AI-generated lures, ongoing simulated phishing campaigns so your team practices spotting real threats in a safe environment, multi-factor authentication so a stolen password alone isn't enough to get an attacker in, and a documented incident response plan so everyone knows exactly what to do in the first ten minutes of a suspected breach. As AI tools get folded into more of the software your team already uses, we also help clients think through AI governance, so adopting tools like Claude, ChatGPT, or Copilot doesn't accidentally open a new door for attackers.
If you're not sure how your team would hold up against an AI-written phishing attempt today, that's worth finding out before an attacker tests it for you.



