July 23, 2026
How AI Is Changing Phishing Attacks And Why Your Team Isn’t Ready
The phishing email that hit a Hong Kong finance worker in 2024 was indistinguishable from a real video call with his CFO. It cost the…

By Satya
9 min read
The phishing email that hit a Hong Kong finance worker in 2024 was indistinguishable from a real video call with his CFO. It cost the company $25 million. Your awareness training didn't prepare your team for this.
In January 2024, a finance worker at a multinational firm in Hong Kong received a message asking him to join a video call.
On the call were people he recognised. His CFO. Several colleagues. They discussed a confidential transaction and asked him to transfer funds to specified accounts. He did.
He transferred $25 million.
None of the people on the call were real.
Every face he saw — including his CFO's — was a deepfake. Every voice was AI-generated. The entire video conference was fabricated using publicly available footage of the real employees, processed through AI tools that reconstructed their faces and voices in real time.
He wasn't tricked by a suspicious email with a grammatical error. He wasn't caught by a generic phishing template. He was tricked by a live, interactive, AI-generated recreation of people he personally knew and trusted.
This is where phishing is in 2026.
Not where it was in 2019. Not where your security awareness training was built for. Not where your current email filters are calibrated to catch.
Here. Now. At a level of sophistication that most organisations haven't begun to address.
What Phishing Used to Be
To understand why your defences are failing, it helps to understand what they were designed to stop.
Traditional phishing — the kind that shaped a decade of security awareness training — operated on a simple economic model. Attackers sent massive volumes of generic emails to undifferentiated lists of targets. The emails were cheap to produce, largely identical, and relied on volume rather than precision. Hit a million inboxes and even a 0.01% success rate yielded a hundred victims.
The defenses built against this model made sense. Train employees to spot the signs of low-effort phishing: grammatical errors, generic salutations, urgent calls to action, mismatched sender addresses, suspicious links. Build email filters to catch known malicious patterns. Block dangerous file attachments.
For a decade, this worked reasonably well against the attacks it was designed to stop.
The problem is that the attacks it was designed to stop no longer dominate the threat landscape.
What Changed — and Why AI Is the Cause
Generative AI has done something to phishing that changes its fundamental economics: it has made mass personalisation possible.
Personalised phishing — where attackers research a specific target and craft an attack tailored to them — has existed for years. It's called spear phishing, and it was always more effective than generic phishing. The problem was cost. Crafting a genuinely convincing personalised attack required hours of human research per target. Which meant spear phishing was reserved for high-value targets: senior executives, financial controllers, people with system access or wire transfer authority.
AI eliminates that constraint.
An AI system can now:
Scrape a target's LinkedIn profile, their public posts, their company's website, press releases, and annual report — in seconds.
Cross-reference any previous data breaches where their email and associated information appeared.
Analyse their writing style from publicly available communications.
Generate a personalised phishing email that references their specific role, recent projects, colleagues by name, and internal company language — in their target's own voice if needed.
Do this for thousands of targets simultaneously.
The attack that previously required a skilled human analyst spending four hours per target now runs at industrial scale. The economics of spear phishing have collapsed. What was reserved for the C-suite is now available for every employee with a company email address.
The Four Attack Patterns You Need to Understand
AI hasn't created one new type of phishing. It has supercharged four distinct attack patterns that your team needs to understand — because each one defeats a different layer of your current defences.
Pattern 1: Hyper-Personalised Email Spear Phishing
This is the evolution of traditional phishing, and it's where most organisations are already losing.
The tell-tale signs your training teaches employees to spot — generic greetings, odd phrasing, implausible requests — are gone. An AI-generated spear phishing email addressed to your accounts payable manager might reference:
The specific ERP system your company uses. A real vendor relationship, sourced from a public contract notice or LinkedIn post. The name of their actual line manager, found in three seconds on your website. Correct internal approval language, inferred from your published procurement policies.
The email asks them to update banking details for an upcoming payment run. It looks like internal process. It uses their name. It cites a real vendor. It arrives from a domain that is one character off your actual domain.
According to IBM's 2024 Cost of a Data Breach Report, phishing remains the most common initial attack vector for enterprise breaches — and the cost per breach where phishing was the entry point averaged $4.88 million.
The volume of these attacks is rising sharply. SlashNext's 2023 State of Phishing report documented a 4,151% increase in malicious phishing emails in the twelve months following the release of generative AI tools. That number has continued to climb.
Pattern 2: Voice Cloning and Vishing
Your employees are trained to be suspicious of email. They are not trained to be suspicious of phone calls from voices they recognise.
AI voice cloning technology has reached a level where a convincing replica of a person's voice can be generated from as little as three seconds of audio. Public audio is everywhere — earnings calls, podcast appearances, YouTube interviews, company announcements, LinkedIn video posts.
The attack pattern: an attacker clones the voice of a known authority — a CEO, a CFO, an IT manager — and calls an employee with an urgent request. Verify your credentials. Approve this transfer. Reset this password. The voice sounds exactly right. The urgency feels real. The employee complies.
This variant is sometimes called vishing (voice phishing), and it has moved from theoretical to documented. Multiple enterprises reported targeted voice-cloning attacks throughout 2024 and 2025, with financial services and legal firms among the most frequently targeted.
The defense your team has against this attack is: zero. No existing security awareness module adequately prepares employees to be suspicious of a phone call that sounds exactly like their direct manager.
Pattern 3: Deepfake Video Calls
The Hong Kong incident at the opening of this piece is not an isolated case. It is the leading edge of an attack pattern that will become more common as deepfake generation becomes faster and cheaper.
The economics of real-time deepfake video calls are still relatively demanding in 2026 — they require moderate hardware and some technical capability. But they are no longer nation-state-level attacks. They are within reach of sophisticated criminal organisations, and the capabilities are improving faster than most security practitioners realise.
What makes this attack pattern particularly dangerous is that it defeats the verification instinct. Employees are taught: if you're uncertain, call the person directly and verify. Deepfake video calls exploit exactly that verification step — the "call" IS the attack.
For large financial transactions, sensitive data access, or credential changes, verification via a known channel is no longer sufficient when that channel itself can be faked.
Pattern 4: AI-Powered Business Email Compromise
Business Email Compromise (BEC) — where attackers impersonate executives or trusted third parties to authorise fraudulent transactions — has been the highest-value category of cybercrime for several years. The FBI's Internet Crime Complaint Center reported $2.9 billion in BEC losses in 2023 alone.
AI has made BEC attacks dramatically more scalable and more convincing.
Traditionally, a BEC attack required monitoring a target organisation's email communications (usually through a prior compromise) to understand internal language, approval processes, and relationships before crafting a convincing impersonation. AI now allows attackers to infer all of this from public sources — with enough accuracy to fool employees who have no reason to be suspicious of an email that perfectly mimics how their CFO actually writes.
The AI doesn't just generate the email. It can run multiple simultaneous BEC campaigns, adapt messaging based on responses, and generate follow-up communications that maintain the impersonation across a multi-email thread.
Why Your Current Training Is the Wrong Solution to the Wrong Problem
Security awareness training as it currently exists in most organisations, was designed to teach pattern recognition: if an email looks like this, treat it as suspicious.
AI phishing attacks are specifically designed to not look like anything suspicious.
This is not a training failure in the sense that your employees haven't learned the lessons. It is a structural failure: the lessons were built for a threat model that no longer describes the primary attack surface.
Three specific problems:
The annual training cycle problem. Most organisations run security awareness training once or twice a year. The AI threat landscape is evolving monthly. An annual training session in January does not prepare employees for attack patterns that were first documented in September.
The simulated phishing problem. Many organisations test employees with simulated phishing campaigns — sending fake phishing emails to see who clicks. This is useful training against generic phishing. Against AI-personalised attacks, it provides false confidence. If your simulated phishing emails look like 2021-era generic phishing, passing the test tells you nothing about whether employees would resist a 2026 AI-personalised attack.
The binary suspicion problem. Training teaches employees to either trust or distrust a communication. AI attacks collapse this binary by producing communications that are genuinely indistinguishable from legitimate ones. Asking employees to "be suspicious" of an email that references their actual manager by name, their actual project, and their actual approval process is asking them to distrust legitimate communications too — which creates its own operational problems.
The awareness training isn't useless. But it cannot be your primary defense against AI phishing. It has to move from being the main layer to being a single layer in a deeper stack.
What Organisations That Are Adapting Are Actually Doing
The organisations I've seen respond most effectively to AI-enhanced phishing threats have made one fundamental shift in their mental model:
They stopped asking "does this communication look legitimate?" and started asking "does this communication require verification regardless of how legitimate it looks?"
In practice, this translates into several concrete changes:
Process controls for high-stakes actions, not just suspicious ones. Any request to transfer funds, change banking details, reset credentials, or grant system access requires a verification step that is completely independent of the original communication channel. If the request came via email, verification happens via phone to a known number — not a number in the email. If the request came via phone, verification happens via a second channel. If it came via video call, verification happens via a pre-agreed out-of-band signal.
This sounds like friction. It is friction. It is also the only defense that works against an attack that can perfectly mimic any communication channel.
Zero-trust for financial transactions. Multiple independent approvals required for any transaction above a defined threshold. No single employee, regardless of seniority, can authorise a significant transaction based on a single communication — even if that communication appears to come from the CEO.
AI-assisted detection tools. Email security platforms have increasingly moved toward behavioural analysis rather than content pattern matching. Instead of flagging emails that look suspicious, they flag emails whose metadata, sending patterns, or contextual signals are anomalous — even when the content looks perfectly legitimate. Tools like Proofpoint, Abnormal Security, and Darktrace have specifically developed AI-based detection that can identify AI-generated phishing attempts at the infrastructure level rather than the content level.
Regular, realistic simulation. The most effective organisations are running phishing simulations that use AI-generated, personalised attacks — not generic templates. If your employees never encounter a convincing personalised attack in training, they have no muscle memory for the real thing.
Voice and video verification protocols. For any audio or video communication requesting a sensitive action, a pre-agreed verification protocol — a code word, a challenge question, a separate confirmation message — that cannot be replicated by an AI system with no prior relationship with the target.
The Piece Nobody Wants to Say Out Loud
Here it is: the security awareness training budget your organisation spent last year produced an organisation that is better prepared for 2019's phishing threats.
That's not nothing. 2019-era phishing still exists, and employees who click on obvious phishing emails are still a real problem.
But it is not sufficient. And in most organisations, the gap between what the training addresses and what the current threat landscape looks like is wide enough to drive a $25 million wire transfer through.
The uncomfortable truth is that some attacks — specifically well-resourced, AI-enhanced deepfake video calls — are currently nearly impossible to defend against at the individual employee level. The defense has to be at the process level: making it structurally impossible for any single person to approve high-stakes actions based on any single communication, regardless of how legitimate it appears.
Your employees cannot be trained to resist an attack they cannot identify. Your processes can be designed so that identification is irrelevant — so that the consequences of a successful deception are contained even when the deception works.
That is the mental model shift most organisations haven't made yet.
Where to Start
If you're a security leader reading this, three things worth doing this quarter:
Audit your current phishing simulations. Are they using AI-personalised attacks or generic templates? If generic, they are measuring the wrong thing.
Map your high-risk transaction processes. Which processes in your organisation could result in significant financial or data loss if a single employee was deceived? For each one, ask: does our current process require independent verification regardless of how legitimate the request appears? If not, it should.
Brief your non-technical leadership. The CFO, the CEO, the board — they are the people whose identities are most likely to be cloned in a deepfake or voice attack. They need to understand that an employee receiving a video call that looks like them is not being protected by their own communication. A protocol for out-of-band verification of sensitive requests from senior leadership is not paranoia. In 2026, it is basic operational security.
The Hong Kong finance worker who transferred $25 million was not careless. He was not untrained. He did what every employee is taught to do when uncertain: he got on a call and saw the faces of people he knew.
The lesson isn't that employees need better training.
The lesson is that some attacks have moved beyond what training can prevent — and that means the defence has to move beyond training too.
I write weekly about AI, Cybersecurity, and the gap between what organisations say they're doing with technology and what's actually happening. No vendor sponsorships. No hype.
→ More on Medium: pvdssatya.medium.com