Phishing is a form of social engineering, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) says. The scale is striking: the FBI's Internet Crime Complaint Center logged 193,407 phishing and spoofing complaints in 2024, with reported losses of $70,013,036. Generative AI has removed the two classic consumer red flags, security researchers warn, making messages harder to spot and pushing defenders toward technical controls such as multi-factor authentication and platform-level removals. That shift matters because technical defences can blunt campaigns quickly: research shows multi-factor authentication blocks a large share of account-compromise attempts in studied scenarios, and national reporting services have driven widespread scam takedowns.
CISA splits phishing attacks into two core tactics.
How the attacks reach victims
CISA describes two simple but effective methods. First is credential theft, where victims are sent links to pages that impersonate legitimate logins. Those fake pages harvest usernames, passwords and sometimes one-time codes. Second is malware deployment, where a link or attachment delivers software that infects a device and opens persistent access for an attacker.
Those mechanics aren't confined to email. Security guides and incident reports through 2024 and 2025 show the same playbook repeated across short message service, voice calls and workplace collaboration platforms. The median time for a target to click a phishing link is about 21 seconds, and the median time to submit data on a fraudulent form is 28 seconds. That speed explains why a single message can be enough to launch a breach chain.
At scale, attackers mix simple broad campaigns with highly tailored efforts. Open-source reconnaissance on social media, corporate websites and data-dump archives feeds both spray-and-pray operations and spear-phishing that's customised to an individual or role.
Business email compromise variants remain a high-value play for financially motivated actors.
Industry analysis shows why those campaigns work: phishers exploit emotional levers such as authority, urgency, fear and greed to prompt immediate action from recipients. The combination of tight timing and emotional pressure explains why training alone has limits.
AI changes the calculus and what to do about it
Dexpose warns that generative AI has removed the two most reliable warning signs people were trained to recognise, making modern phishing messages far harder to distinguish from legitimate communications.
Recent security guidance notes the same shift. Conversational models can produce near-perfect grammar, contextual detail and a tone that matches the impersonated person.
Where poor writing and generic phrasing once flagged scams, attackers now use models to craft messages that read like genuine correspondence. That change has pushed defenders to emphasise technical controls and verification workflows over simple user training alone.
Technical defences still matter and show measurable impact. Microsoft research cited in industry summaries found multi-factor authentication blocked a large share of account-compromise attempts in the studied scenarios. Industry breach reports also place phishing as a routine initial access vector: the Verizon 2025 Data Breach Investigations Report recorded phishing in 15 percent of analysed breaches, and IBM's Cost of a Data Breach Report attributes roughly 16 percent of breaches to phishing.
Platform and service-level responses add another layer. The United Kingdom's National Cyber Security Centre Suspicious Email Reporting Service has processed millions of reports and led to widespread scam takedowns, showing how large-scale reporting can interrupt active campaigns. Those takedowns don't stop every attack, but they remove infrastructure and blunt the reach of live campaigns quickly.
Authorities and vendors converge on a layered mitigation approach. Organisations are advised to require strong authentication, monitor and block look-alike domains, harden email gateways, apply robust endpoint detection and implement verification policies for financial or credential-change requests. For individuals, guidance remains practical: verify unexpected requests through a separate channel, avoid clicking links in unsolicited messages and treat requests for credentials or one-time codes as red flags.
The material surveyed did not show any single regulatory rollout or dated policy change. Instead the record shows continuing operational activity in reporting, detection and vendor research rather than a single industry-wide update. That operational tempo means defenders are iterating on tools and playbooks while attackers refine targeting and automation.
For organisations, the new reality is clear: training that focused on spotting clumsy language and obvious scams is no longer enough. Technical controls, verification processes and cooperative takedowns have become the critical lines of defence. For individuals, the best immediate habit is a simple one: pause, verify, and treat any unexpected request for credentials or codes as a signal to check twice.
Related Articles
- Election breach and $300,000 legal bill pressure minister
- New York subpoena sparks multi-state probe of OpenAI
- Google sues to halt AI-powered SMS scam that hit hundreds of thousands
Multi-factor authentication remains the clearest, proven defence: studies and industry reports show it blocks a large share of phishing-driven account compromises. Organisations should make MFA mandatory and pair it with verification workflows and platform partnerships to remove scam infrastructure quickly. Originally reported by sqmagazine.co.uk.
This article was created with AI assistance.