Still the Single Biggest Way Attackers Get In

Phishing remains the most-reported cybercrime category to the FBI's Internet Crime Complaint Center for the third consecutive year, with over 191,000 complaints in 2025 alone - more than any other type of cybercrime tracked. It initiates roughly 16% of all data breaches, according to Verizon's 2026 Data Breach Investigations Report, and phishing-related breaches now cost organisations an average of $4.8 million each. Beyond direct phishing, its close relative Business Email Compromise - where an attacker impersonates a trusted executive or vendor to redirect a payment - generated over $3 billion in reported US losses in 2025 alone, averaging nearly $123,000 per successful incident.

What Actually Changed

The defining shift in 2025-2026 is speed and quality, both driven by generative AI. Creating a convincing phishing email has gone from a multi-hour task requiring some writing skill to roughly five minutes, according to IBM's X-Force research - and the results show it: an estimated 82.6% of phishing emails now contain AI-generated content, and AI-crafted phishing attempts achieve click-through rates roughly 4.5 times higher than traditional, manually written ones. Voice phishing - AI-generated phone calls designed to extract credentials or authorise payments - increased over 440% in a recent two-year period, and deepfake-related incidents grew by roughly 680% year over year.

Why the Old Spotting Tricks Don't Work Anymore

For years, the standard phishing advice centred on spotting tells: broken grammar, generic greetings, obviously fake logos, mismatched sender addresses. AI has quietly eliminated most of these signals. Grammar is now flawless by default. Messages can be personalised using details scraped from social media or previous data breaches, referencing a recipient's actual job title, recent purchases, or colleagues by name - a level of tailoring that used to require a skilled, targeted attacker and can now be automated at scale, cheaply, against thousands of recipients simultaneously.

Where Attacks Are Actually Landing

A significant and often overlooked share of phishing - more than half by some tracking estimates - now originates from already-compromised legitimate accounts rather than obviously fake ones, meaning a phishing email might genuinely arrive from a real colleague's real, hacked account, making sender verification alone an unreliable defence. Supply chain phishing - attacks that come through a trusted third-party vendor or partner rather than directly - accounts for a meaningful share of incidents at large organisations, exploiting the trust extended to known business relationships.

What Actually Works Now

Security researchers are consistent that no single defence stops modern phishing - layered protection matters more than ever. Phishing-resistant multi-factor authentication, particularly passkeys or hardware security keys rather than SMS codes, defeats even sophisticated real-time interception attacks that can otherwise bypass traditional two-factor authentication. Independently verifying unusual requests - calling a colleague or vendor on a known number rather than replying to the email or trusting caller ID - remains effective precisely because it doesn't rely on spotting a tell in the message itself. And organisations running regular phishing-simulation training report meaningfully lower click rates over time, suggesting that awareness training, done consistently rather than as a one-off, genuinely helps even against increasingly convincing AI-generated attempts.

The Individual-Level Takeaway

For everyday users, the most reliable shift in mindset is this: stop trying to "spot" a phishing email by how it looks, since AI has made that increasingly unreliable, and instead treat any unexpected request involving money, credentials, or sensitive information as worth independently verifying through a separate channel - regardless of how legitimate the message appears. That single habit change matters more now than any specific red flag checklist, precisely because the checklist keeps getting shorter as AI closes the gaps that used to give scams away.