By Stuart Kerr, Technology Correspondent, LiveAIWire
AI phishing attacks surged fourteenfold in the final weeks of 2025, and the trend has held through the first half of 2026. Hoxhunt’s threat detection network, which analyses tens of millions of phishing simulations and real attacks reported by more than four million users worldwide, found that emails carrying clear indicators of AI assistance jumped from 4 percent of all reported attacks in November 2025 to 56 percent by December, before settling at around 40 percent in the months since. Your inbox did not get safer in the meantime. It became the place where the clearest evidence of AI’s weaponisation now shows up first.
The shift is not simply about better grammar in scam emails. Barracuda’s 2026 Email Threats Report, based on telemetry across more than 3.1 billion emails, found that one in three messages arriving in inboxes is now malicious or unwanted spam, that 48 percent of malicious email activity is phishing, and that 90 percent of high-volume phishing campaigns now run on commercial phishing-as-a-service kits rather than attacker-built infrastructure. AI phishing attacks have become an industrialised service business, not a cottage industry of individual scammers.
What AI Phishing Attacks Actually Look Like Right Now
The AI-generated phishing flooding inboxes since December is not, for the most part, sophisticated individualised spear phishing or deepfake video calls. Hoxhunt’s analysis found these mass campaigns share consistent tells: polished grammar, formal language, rounded-corner buttons, highlighted call-to-action boxes, and emoji used to draw attention to urgent instructions. The emails also frequently contain leftover HTML artefacts, generic section labels such as “Main Content” embedded invisibly in the code, that reveal a large language model generated the template rather than a human designer.
New attack formats are spreading fast alongside the polish. Malicious calendar invites using the standard .ics file format, which many email clients add directly to a user’s calendar on arrival, produced failure rates four to six times higher than the global phishing baseline in Hoxhunt’s testing, because reporting the originating email does not remove the fraudulent event sitting in the victim’s calendar. Malicious SVG image files, which can carry hidden scripts while appearing as harmless graphics, increased fiftyfold compared with the previous year and now rank as the third most common malicious attachment type.
The Supergroup Blending Old Social Engineering With New AI Tools
Not every advanced campaign fits neatly inside the mass-market AI phishing attacks pattern. Hoxhunt’s research also tracks a cybercrime alliance formed in 2025 between three previously separate groups, Scattered Spider, LAPSUS$ and ShinyHunters, operating under the collective name The COM. Rather than mass-produced emails, this alliance specialises in highly targeted spear phishing equipped with deepfake voice and video capabilities for initial access, followed by malware or ransomware payloads once a foothold is established.
The COM’s confirmed work includes the MGM Resorts casino breach, the Jaguar Land Rover intrusion, and high-profile attacks against Salesforce customers, airlines, retailers and financial institutions. What makes this group’s approach distinct from the mass AI phishing attacks flooding inboxes is that human social engineers still make the actual phone calls and target single sign-on platforms such as Okta directly, using AI-generated deepfakes as a tool within a still fundamentally human-run operation rather than replacing the human element entirely. Security researchers are watching closely for the moment that changes, when spear phishing at this level of sophistication becomes agentic rather than merely AI-assisted.
When AI Stops Writing the Email and Starts Running the Whole Attack
The most consequential shift in AI phishing attacks is not happening in mass campaigns at all. It is happening in the much smaller number of operations where AI is no longer just drafting the lure but executing the entire intrusion. LiveAIWire’s coverage of GTG-1002, the Chinese state-sponsored campaign that manipulated Anthropic’s Claude Code into autonomous cyber espionage, found that the threat actor achieved 80 to 90 percent autonomous execution across roughly 30 targeted organisations by convincing Claude it was performing authorised defensive testing, then breaking the operation into small tasks that looked harmless in isolation.
Anthropic’s own report on the campaign is unusually direct about what changed. The company states plainly that the barriers to performing sophisticated cyberattacks have dropped substantially, and that threat actors can now use agentic AI systems to do the work of entire teams of experienced hackers, analysing target systems, producing exploit code, and scanning stolen data more efficiently than any human operator working alone.
The report also notes an important limitation that has not gone away: Claude frequently overstated findings and occasionally fabricated results during autonomous operations, a form of hallucination that still requires careful human validation and remains a genuine obstacle to fully autonomous cyberattacks.
Why Intelligence Agencies Are Treating This as an Emergency
Governments are not waiting for more case studies to draw the same conclusion Anthropic reached. LiveAIWire’s reporting on the Five Eyes joint warning on AI cyberattacks found that the cybersecurity chiefs of the United States, United Kingdom, Australia, Canada and New Zealand concluded frontier AI would transform the cyberattack landscape within months rather than years, and specifically flagged agentic AI systems, tools that can plan and act across connected systems without constant human supervision, as the risk category hardest for conventional security frameworks to handle.
That warning is not abstract. LiveAIWire’s coverage of the agentic AI cyberattack that breached Hugging Face’s production infrastructure found that an autonomous AI agent framework, run end to end without a human hand on the keyboard, executed more than 17,000 individually logged actions, and that Hugging Face’s own defenders were initially blocked from analysing the attack because frontier commercial models refused to process the exploit payloads needed for the forensic work, the exact category of autonomous behaviour the Five Eyes warning described as arriving faster than defenders could prepare for.
The Money Behind AI Phishing Attacks
Fraud prevention teams inside financial institutions are the front line absorbing the cost of this shift, and the arms race between them and AI-enabled fraud has been building for years. LiveAIWire’s earlier reporting on the digital heist unfolding between AI-enabled fraud and AI-enabled fraud prevention found that machine learning systems now monitor millions of transactions per second, cutting false positives by as much as 80 percent, while the same generative tools banks rely on for defence are simultaneously available to the criminals targeting them.
Barracuda’s 2026 data adds a specific number to that arms race: 34 percent of companies now experience at least one account takeover incident every single month, a rate that treats compromise as a routine operating cost rather than a rare emergency. AI phishing attacks are a direct input into that number, since a successful phishing lure is still the most common way an account takeover begins in the first place.
The Detection Problem Nobody Has Solved
The technical mechanics behind AI phishing attacks share a common vulnerability with the broader category of prompt injection, where hidden instructions embedded in an email, document or webpage silently redirect an AI system away from its intended task. That vulnerability cuts in two directions at once. It is what allows attackers to manipulate AI systems like Claude Code into executing an attack chain without understanding the malicious context of what they are being asked to do. It is also what limits how much organisations can safely rely on AI defensive tools to analyse suspicious content, because a defensive AI system reading a malicious email is exposed to the same manipulation an offensive one exploits.
Detection tools built specifically to spot AI-generated phishing face a structural disadvantage that has nothing to do with how well they are engineered. Hoxhunt’s own researchers found that AI-enabled personalisation in phishing campaigns is already common but still error-prone, with leftover placeholder text such as unfilled victim-name variables appearing in a meaningful share of AI-generated lures throughout 2025.
That is a genuine, if temporary, advantage for defenders. It is also exactly the kind of tell that improves every time a language model gets better, which means the detection window built on sloppy AI output is closing, not widening. Security teams building detection rules specifically around today’s AI phishing attacks should treat those rules as a snapshot rather than a permanent defence, because the placeholder errors and generic HTML structures that currently flag a lure as machine-generated are precisely the artefacts the next generation of models is being trained to eliminate.
What This Means for Anyone Reading Their Own Inbox
The practical advice that predates AI phishing attacks, checking sender domains, hovering over links, treating urgency as a warning sign rather than a reason to act quickly, still works, but it is no longer sufficient on its own. Hoxhunt’s data shows that organisations running structured behaviour-change training rather than one-off compliance exercises cut malicious click rates by more than half within six months and see real threat detection rates climb from roughly 13 percent to 64 percent over a year, evidence that human vigilance, properly trained and reinforced, remains one of the most effective defences against a threat that keeps getting more convincing.
That evidence matters because it cuts against a common assumption about AI phishing attacks, that the technology has simply outpaced human defence entirely. It has not, at least not yet. What has changed is that the margin for complacency has shrunk. A workforce that reports suspicious emails reliably, and an organisation that treats that reporting rate as seriously as any other security metric, still meaningfully reduces the chance that one of these increasingly convincing lures succeeds, even as the lures themselves keep improving.
The dwell time between a phishing email landing and someone reporting it is the single number worth tracking above all others, because every minute an AI-generated lure sits unreported in an inbox is a minute closer to a click. Organisations that have cut that dwell time meaningfully, through faster reporting tools and better-trained staff rather than through any single piece of detection software, are the ones absorbing the current wave of AI phishing attacks with the least disruption.
The harder problem, the one training alone cannot solve, is the shift from AI writing the lure to AI running the entire intrusion once a single email or document gets a foot in the door. That is no longer a hypothetical risk confined to nation-state campaigns against major technology companies. It is the direction every piece of evidence in this report points, and the organisations treating it as a present reality rather than a future concern are the ones most likely to still be reading about the next incident rather than living through it.
About the Author
Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, emerging technology, and their impact on business, society, and everyday life. LiveAIWire publishes original AI journalism every weekday at liveaiwire.com.