Phishers have gone automated. KnowBe4’s latest report shows 86% of attacks over the past six months relied on artificial intelligence, up from 80% in 2024 and 84% last year. That’s according to the company’s Phishing Threat Trends Report Volume Seven, which analyzed campaigns from more than 3,000 unique threat actors. The shift marks a turning point. Criminals once labored over crude lures. Now AI handles the heavy lifting, crafting messages that mimic legitimate ones with eerie precision.
Jack Chapman, KnowBe4’s SVP of threat intelligence, puts it bluntly. “The inbox is no longer the only front line for coordinated social engineering attacks,” he said. Businesses lean on collaboration tools for daily work. Attackers noticed. They’ve piled on, hitting calendars and chat apps alongside email. Calendar invite phishing jumped 49% in the period studied. Microsoft Teams attacks rose 41%, often posing as IT support to snag credentials. And reverse proxies—tools that hijack Microsoft 365 sessions—surged 139%.
These aren’t isolated spikes. Internal impersonation appeared in 30% of first-quarter attacks from those threat actors. Picture a fake note from your boss, routed through Teams, urging a quick password reset. AI makes it personal. It scans public profiles, pulls job details, weaves in urgency. Detection grows harder. Traditional filters snag obvious fakes. But these? They blend in.
The numbers stack up elsewhere. Hoxhunt’s Phishing Trends Report logged a 14-fold surge in AI-generated attacks by December 2025, hitting 56% of all reported incidents. That momentum carried into this year. Mika Aalto, Hoxhunt’s co-founder and CEO, warned, “Our research shows that AI-generated phishing went from a trickle to a flood almost overnight.” Kaseya echoed the alarm in a recent analysis, noting 83% of phishing emails incorporate AI content, with 40% of business email compromise attacks using generative models. Dave Baggett, Kaseya’s SVP of security suite, observed, “Attackers can now produce highly convincing messages at scale, which means the traditional signals security tools relied on for years—bad grammar, suspicious domains, obvious links—are disappearing.”
Volume tells another story. StationX compiles data showing 3.4 billion phishing emails flood inboxes daily—39,000 per second. Of those tracked from late 2024 into early 2025, 82.6% bore AI hallmarks, per sources like Keepnet Labs and VIPRE. Click rates for AI spear-phishing hit 54%, dwarfing the 12% for standard lures. IBM pegs 37% of breaches to AI-generated phishing. FBI figures clock cybercrime losses at $20.87 billion last year, with phishing the top complaint.
But email’s not the lone battlefield anymore. Smishing—texts turned traps—makes up 35% of attacks, up 40% year-over-year. Vishing, those voice scams, exploded 442% in the latter half of 2024, fueled by AI audio clones from mere seconds of target speech. QR codes in phishing? Up 400% since 2023. Business email compromise alone racked up $2.77 billion in verified U.S. losses in 2024, averaging $129,000 per case.
AI lowers barriers. Phishing-as-a-service kits automate everything: recon, lure generation, delivery. What took experts hours now scales to thousands per minute, at pennies per pop. Microsoft research finds AI phishing 4.5 times more effective than handmade efforts. No wonder global losses top $25 billion annually—$17,700 a minute.
Defenders scramble. Training slashes click rates from 33% to under 5%, KnowBe4 data shows—an 85% drop. Yet attackers adapt. Chapman again: “Social engineering is becoming more targeted, making it more difficult to discern what is legitimate versus what is malicious.” Holistic defenses emerge. Behavioral analytics flag odd patterns in Teams chats or calendar adds. Real-time intelligence spots multi-channel chains: email primes, then Teams closes.
And the pace quickens. Cofense blocked a malicious email every 19 seconds last year, double the prior rate. APWG tallied 4.8 million attacks in 2024, a record 20% jump. Financial firms and SaaS platforms draw half the fire.
So what’s next? Secure the humans. And the AI agents they use. Chapman stresses both. Tools must evolve beyond filters to parse intent, context. Employees report in 28 minutes on average. Attackers exploit 27 minutes before that. Close the gap with triage systems, like Doppel’s new AI-powered Phishing Triage, which classifies reports in seconds. But vigilance stays key. Hover over links. Verify voices. Question calendars. AI phishers bet on haste. Don’t play their game.


WebProNews is an iEntry Publication