What is modern phishing in 2026? Modern phishing is no longer defined by obvious errors – poor grammar, generic attachments, or suspicious sender addresses. It is defined by believable business context, compressed attacker preparation time, and process manipulation that targets money, identity, or approvals. According to Verizon DBIR 2024, the human element was present in 68% of breaches. The FBI’s Internet Crime Complaint Center reported USD 2.9 billion in Business Email Compromise (BEC) losses in 2023 alone – making it one of the most financially damaging forms of cybercrime (FBI IC3 2023).
Phishing in 2025 – at a glance:
- IBM X-Force 2023: an AI-generated phishing e-mail takes approximately five minutes to prepare; a human-crafted version takes around 16 hours – attacker preparation time has collapsed to a coffee break
- FBI IC3 2023: USD 2.9 billion in BEC losses in the United States alone – the highest-value phishing variant, requiring no malware
- Verizon DBIR 2024: the human element was present in 68% of breaches
- McKinsey Global Survey, May 2024: 65% of organisations were regularly using generative AI in at least one business function – the environment itself now makes AI-generated communication feel normal
- Red Sift 2025: approximately 81.2% of Fortune 500 companies have DMARC in place – but DMARC does not stop spear phishing sent from lookalike domains or compromised legitimate accounts
- Microsoft Security 2025: MFA blocks more than 99% of automated account-compromise attacks – but BEC often uses no malware and can bypass MFA by targeting process, not technology
- The Hong Kong deepfake case, early 2024: a staff member authorised transfers of approximately HKD 200 million (roughly USD 25 million) after a video call featuring AI-generated synthetic executives (Hong Kong Police / widely reported Arup case, 2024)
Table of Contents
How has phishing changed between 2019 and 2026?
In 2019, many executives pictured phishing as a clumsy scam e-mail with awkward grammar, a random attachment, and a sender address that looked wrong from the first glance. Those attacks still exist – but they no longer define the problem.
A convincing phishing e-mail can now be generated in minutes, tailored to a recipient’s job title, recent travel, suppliers, or public LinkedIn activity, and written in the same tone that person encounters every day. IBM X-Force found that a human-crafted phishing e-mail took a team approximately 16 hours to prepare, while the AI-generated version was built in around five minutes with five prompts (IBM X-Force, 2023).
The other change is context. In 2019, attackers blasted generic e-mails and waited for a careless click. In 2026, they do lightweight reconnaissance first – corporate websites, staff biographies, conference appearances, procurement portals, or the CFO’s recent press interview – and build a message around a real business event. Staff therefore need to be trained to inspect process signals, not just language signals: Is this request bypassing a normal approval path? Is the sender using the expected channel? Is the urgency artificial? Does this make sense in the context of current projects?
What is Business Email Compromise (BEC) and why does it generate billions in losses?
BEC is the highest-value phishing variant for a simple reason: it targets judgement, not software. The FBI IC3 reported USD 2.9 billion in BEC losses in 2023, making it one of the most financially damaging forms of cyber-enabled crime (FBI IC3 2023).
A typical BEC campaign is slower and quieter than commodity phishing. Attackers begin with credential theft, mailbox access, or public-source reconnaissance. Then they watch – learning who approves payments, how invoices are phrased, which law firms appear in signature blocks, which supplier names recur, and whether the finance team confirms changes by phone. Then comes the moment: a known vendor changes bank details, the “CEO” e-mails the finance director asking for a discreet transfer, or a plausible invoice arrives during an executive absence.
BEC bypasses many technical controls because it often uses legitimate or lookalike accounts rather than malware payloads. DMARC, DKIM, and SPF help reduce direct domain impersonation – but BEC can use a subtly different domain, a compromised supplier account, or a genuine internal account that has already been taken over.
The fix: Treat BEC as a business-process attack with e-mail as the delivery channel. Require out-of-band confirmation for all payment instruction changes and all requests to modify banking details. A phone call to a known registered number – not a reply to the suspicious e-mail – is the control that stops BEC.
How are deepfake audio and video being used in phishing fraud?
The clearest demonstration of AI-generated content used in attacks is deepfake fraud. Hong Kong authorities reported in June 2024 that a staff member had joined a group video conference in which familiar executives appeared to be present – the conference was fabricated using deepfake technology, and the victim authorised transfers totalling approximately HKD 200 million (roughly USD 25 million) (Hong Kong Police / widely reported Arup case, 2024).
This case breaks a common executive assumption: “Our people would never authorise a transfer based on an e-mail.” Perhaps not. But they may authorise it after a video call with familiar faces, a credible script, and pressure framed as a confidential corporate transaction. Deepfake fraud weaponises trust in richer channels — the very thing many executives treat as safer than e-mail.
Verification for large payments should therefore rely on known-number callbacks, dual approval, and process discipline — not on how convincing a face or voice appears. For executive assistants and HR teams, QR-code phishing and cloud-document invitations should be included in simulations, as those channels are now common enough that a programme focused only on e-mail attachments and login links is behind the threat.
What actually reduces phishing susceptibility across an organisation?
A mature anti-phishing programme combines people controls with technical controls and measures both. The most important elements are:
- Frequent role-specific simulations rather than one annual exercise. Monthly simulations with increasing realism (internal branding, thread-hijack scenarios, cloud-share invitations, vendor fraud, QR code phishing) generally outperform once-a-year campaigns.
- Easy reporting mechanisms that make it frictionless to flag suspicious e-mails. Mature programmes aim to raise reporting rates far above click rates – because reporting is the cultural metric that shortens attacker dwell time.
- Reward reporting, not just recognition. The right culture celebrates “I was not sure, so I reported it” rather than only acknowledging perfect recognition.
- DMARC, DKIM, and SPF deployed and enforced – Red Sift reported Fortune 500 DMARC readiness at approximately 81.2% in 2025. Essential, but not sufficient on their own.
- MFA universal for high-risk access. Microsoft Security confirms MFA blocks more than 99% of automated account-compromise attacks. Use phishing-resistant methods where possible for privileged accounts.
- Role-aligned controls. Finance, HR, executive assistants, procurement, payroll, and customer-facing teams see different attack patterns. A generic training programme misses that reality.
Learn more about phishing simulation and awareness training.
How should you measure your phishing programme’s effectiveness?
Boards often receive the wrong metric first – the click rate. Click rate matters, but on its own it can be misleading. A more useful board pack includes four measures:
| Metric | Why it matters | Healthy direction of travel |
|---|---|---|
| Simulation click rate (by campaign complexity) | Shows whether employees still engage with realistic lures | Down over time, especially on higher-complexity campaigns |
| Reporting rate | Measures whether employees act as a detection layer | Up over time; ideally much higher than click rate |
| Time-to-report | Shows how quickly security gains visibility of live campaigns | Down over time; minutes beat hours |
| Complexity progression | Prevents overfitting to simplistic simulations | Up over time without major regression in reporting |
FAQ
What is spear phishing and how does it differ from regular phishing?
Spear phishing is a targeted phishing attempt built around a specific person, role, or business context. Regular phishing is broader and more generic. Spear phishing is harder to detect because it uses real business context, believable authority, and personalised language – making it difficult to distinguish from legitimate communication under time pressure.
What is Business Email Compromise (BEC)?
BEC is a fraud technique in which attackers impersonate or compromise a trusted e-mail account to manipulate payments, invoices, payroll, or sensitive data flows. It often involves no malware at all and can bypass many traditional e-mail controls – making it the most financially damaging form of cybercrime per the FBI IC3.
How do you prevent phishing attacks in a company?
Reduce phishing risk through layered controls: realistic and frequent awareness training, easy suspicious-e-mail reporting, strong e-mail authentication (DMARC/DKIM/SPF), MFA for high-risk access, and business-process verification for payments and account changes.
What is the most effective phishing awareness training?
The most effective programmes are continuous rather than annual, role-specific rather than generic, and designed to reward reporting rather than punish mistakes. Monthly simulations and micro-learning generally outperform once-a-year awareness campaigns.
How often should companies run phishing simulations?
For most mid-market firms, monthly is a sensible baseline. Higher-risk teams — finance, payroll, executive support — may justify more frequent role-specific simulations tied to real attack patterns.
What is DMARC and does it prevent phishing?
DMARC is an e-mail authentication and policy framework that helps organisations prevent direct spoofing of their domains. It is important but does not stop all phishing – attackers can still use lookalike domains, compromised accounts, or non-e-mail channels such as SMS, voice calls, and video.
Phishing defence assessment – free programme review
Patronusec helps organisations benchmark phishing resilience with realistic simulations, role-based awareness training, and reporting metrics that boards can actually use.
Book a no-commitment call with our team.