The use of artificial intelligence (AI) by cybercriminals is transforming phishing attacks, making them more sophisticated and harder to detect. According to a Kaspersky study, 49% of organisations reported an increase in cyberattacks, with phishing being the most common threat.
AI has allowed cybercriminals to personalise phishing emails, creating messages tailored to an individual’s role and interests. By leveraging publicly available data, such as social media or company websites, attackers can craft highly convincing emails, often mimicking internal communications from executives.
Furthermore, deepfake technology is being used to create realistic audio and video impersonations, making attacks even more credible. In one instance, a deepfake was used to convince an employee to transfer US$25.6 million.
Traditional email filters are also struggling to keep up. AI can manipulate email scripts to bypass security software, refining attacks in real time to improve success rates. This makes even experienced employees more vulnerable to these increasingly sophisticated tactics.
To combat AI-driven phishing, organisations need to adopt a multi-layered cybersecurity approach, combining regular AI-focused awareness training, advanced security tools, and a zero-trust security model to limit potential damage.
4o mini






