September 20, 2026
AI Didn’t Kill Phishing – It Industrialized It
A ₹500 coupon fooled 60% of employees — and that was before AI got involved.

By Mohit Yadav
5 min read
If you ask most people what the biggest cybersecurity risk is, they'll say hackers, malware, or some genius breaking into a server. Honestly, the biggest risk is much simpler than that: it's people. A person clicking a link they shouldn't have, or typing their password into a page that looked legit but wasn't. And lately, this kind of mistake has gotten a lot harder to avoid – because the fake messages tricking people have gotten a lot better. Let's talk about why.
What is phishing, in simple terms?
Phishing is basically a scam message pretending to be from someone you trust – your bank, your company, a delivery service – asking you to click a link, log in, or share some information. It's the same trick as a scam phone call, just sent over email, WhatsApp, or text instead.
It's not some fancy hacking. There's no code being broken. The attacker is just trying to fool a person into handing something over willingly – a password, an OTP, access to a system.
A test we ran, and what it showed
At an organization I worked at, we ran a phishing test on our own employees – basically sending a fake phishing email on purpose, just to see how many people would fall for it.
The email offered a ₹500 Myntra coupon. All you had to do was "log in" to claim it.
More than 60% of employees not only clicked the link but also entered their actual corporate credentials into the fake login page.
That's more than half the company, and there was nothing fancy about this email – no AI, no personalization, just a decent-looking offer. It tells you something important: this isn't about people being careless or not smart enough. A good offer, a bit of curiosity, and a login page that looks real is often all it takes. Now think about what happens when AI is the one writing that email instead of us.
So what's actually changed because of AI?
Before AI tools became common, making a really convincing phishing email took effort. Someone had to research the target, figure out how that company talks, write something that sounds natural, and avoid typos or awkward phrasing – the stuff that usually gives a scam away.
Because that took time, attackers had to pick: send a cheap, generic scam to a lot of people (weak, but free), or spend real effort crafting one really good message for one important target, like a company's finance head.
AI removed that trade-off. Now, an attacker can get an AI tool to write hundreds of well-written, personalized messages in seconds – each one sounding natural, each one tailored to a specific person. The typos and weird phrasing that used to be red flags are mostly gone.
This isn't just a feeling – researchers are seeing it too. Microsoft's own threat research has talked about phishing shifting from something that took real manual effort into something that's now automated and scalable. There's also a widely cited industry report showing a sharp rise in AI-driven phishing recently, with finance and insurance among the hardest-hit sectors – which makes sense, since that's where the money and sensitive data are.
You can literally buy phishing kits now
Here's the part that surprises people: you don't even need to know how to hack anymore. There are ready-made "phishing kits" being sold online – tools that write the fake messages, dodge spam filters, and send everything out for you.
Some underground phishing kits now come with AI capabilities built in, allowing even low-skilled attackers to launch convincing campaigns at scale. Someone with zero technical skill could buy this and start running scams the same day.
That's really what "AI industrialized phishing" means. Something that used to need a skilled person doing it by hand can now be mass-produced by anyone with a bit of money.
The new tricks: fake voices and fake video
A few tricks that used to be too expensive for most attackers are now cheap and common.
Cloned voices – a short audio clip of someone (from a podcast, a YouTube video, even a voicemail) is enough for AI to fake their voice convincingly. This is how people get scam calls that sound exactly like their company's CEO asking for an urgent money transfer.
Fake video calls – there have already been real cases where an entire video call, including the "people" on it, turned out to be AI fakes. Real money was transferred because of it. "I saw them, I heard them" isn't a safe way to verify anymore.
Messages that know a lot about you – AI can quickly pull together your job, your recent projects, how you write, all from what's publicly available, and use it to make a message feel personal. That level of detail used to be the sign of a serious, targeted attack. Now it's just normal.
Why training alone won't fix this
The usual advice is: train people to spot bad grammar, weird email addresses, and urgent-sounding requests. That's still useful, but it was built for scams that had obvious flaws.
AI-made phishing is specifically good at removing those flaws. Remember, our basic ₹500 coupon test – no AI involved – still fooled over 60% of people. Now imagine that same test, except the email is perfectly written and personalized just for you. Training helps, but it was never going to get everyone to zero mistakes, and attackers only need it to work sometimes.
Organizations often invest heavily in technology controls while underestimating the human element. Under modern privacy and data protection frameworks, a successful phishing attack can quickly escalate from a security incident into a regulatory, financial, and reputational problem.
What actually helps
• Verify big requests separately. If someone asks for money or a password over email or a call, confirm it through a different, already-known contact – not a number given in that same message.
• Don't fully trust voice or video alone anymore. If something feels off, double-check some other way.
• Keep running phishing tests regularly, like our coupon test – not to blame people, but to actually know where the gaps are.
• Use detection tools built for this, since old spam filters that look for typos won't catch AI-written messages coming from clean-looking sources.
Bottom Line
Phishing has always been a human problem disguised as a technical one.AI didn't invent social engineering. It simply gave attackers a faster assembly line.The same psychological triggers that convinced employees to claim a ₹500 coupon are now being amplified by AI-generated emails, cloned voices, and deepfake videos.
In cybersecurity, trust remains essential. But in the age of AI, trust increasingly needs verification.