THREAT TRENDSAUGUST 14, 2026By Nate Medeiros, CEO & Founder

AI Phishing Attacks: The Trends We Are Seeing in 2026

Phishing volume is down, click rates are up, and the attack toolkit now sells for the price of a laptop bag. Here is what the industry data says about where AI phishing is heading and what it means for defenders.

Key takeaway

Phishing volume is falling while click rates climb: attackers are sending fewer, better messages. Over 80% of phishing emails now show signs of AI-generated content, polymorphic attacks defeat signature filters, and complete AI attack kits sell for a few hundred dollars. Defenses have to assume every lure is fluent and personalized.

An AI chip producing a stream of personalized phishing emails that fan out to many different recipients

Ask a security team what has changed about phishing over the past two years and you will hear a version of the same answer: the bad emails got good.

The misspelled subject lines, the awkward greetings, the prince with a wire transfer problem, those are disappearing from the data. In their place is something harder to fight: fluent, personalized, professional-looking messages that arrive in smaller numbers, on more channels, and land far more often. AI phishing attacks have moved from a novelty demonstrated at conferences to the default way phishing is done.

This post looks at what the industry data actually shows heading through 2026: the trends we are seeing in the market, where attacks are growing, and what it means for the people defending against them. If you want a primer on what AI phishing is and how it works, start with our AI phishing guide. This is the field report.

Trend 1: Fewer Phishing Emails, Far Better Ones

Here is the number that surprises people: total phishing volume is going down.

Zscaler's ThreatLabz research shows phishing hits peaked at over 2 billion in 2023 and have since declined nearly 20% year over year, two years in a row. If your only metric were volume, you might conclude the problem is shrinking.

It is not. It is recalibrating. Stronger email controls and platform-level enforcement have made mass spray-and-pray campaigns less profitable, so attackers are sending fewer, more targeted lures that blend into real business workflows. In the same research window, phishing aimed at the services sector grew 65.5% year over year, and attacks on government targets grew 50%. Attackers are trading volume for precision, and AI is what makes precision cheap.

The takeaway for defenders is uncomfortable: fewer alerts does not mean less risk. The attacks that remain are the ones engineered to get through.

Trend 2: AI Is No Longer the Exception. It Is the Baseline.

In 2023, AI-written phishing was a prediction. In 2026, it is the water everything swims in.

  • KnowBe4's Phishing Threat Trends research found that 82.6% of analyzed phishing emails now show signs of AI-generated content, and its most recent reporting puts AI involvement in phishing attacks at over 85%.
  • Polymorphic phishing, where every recipient gets a slightly different, fully unique message that defeats signature-based filters, rose from 56.9% of attacks in 2024 to 67.3% this year.
  • IBM researchers demonstrated that an AI system could build a complete, convincing phishing campaign in about 5 minutes with 5 prompts. The same task took experienced human red-teamers roughly 16 hours.

And the quality shows up where it matters most to attackers: the click.

Bar chart showing AI-generated spear phishing achieves a 54 percent click-through rate versus 12 percent for generic human-written phishing

Research published in Harvard Business Review found AI-automated spear phishing achieved a 54% click-through rate, matching the performance of expert human attackers, against roughly 12% for generic lures. The same research found AI cut campaign costs by more than 95%. Expert-level attacks at commodity prices is the whole story of this era in one sentence.

Personalization has gone industrial. Reconnaissance that once required an analyst reading LinkedIn profiles is now automated: public documents, social media, and previously leaked data get compiled into accurate personal profiles, and each target receives a message built for them specifically. The economics that once reserved spear phishing for executives now apply to everyone in the org chart, which is why the person staring down a convincing request is no longer just the CFO.

Trend 3: The Tooling Is Productized and for Sale

A trend that gets less attention than deepfakes but arguably matters more: the AI attack stack has become a product category.

On criminal marketplaces, purpose-built tools like FraudGPT sell for a few hundred dollars, and more capable kits like Xanthorox AI go for around three thousand. These are not jailbroken chatbots; they are packaged services with features, updates, and customer support. An attacker with no technical skill and no writing ability can now run campaigns that would have required a team a few years ago.

The infrastructure side is industrializing too. Zscaler's researchers identified more than 413,000 AI-generated website instances in their most recent reporting period and flagged roughly 9% as malicious. Mainstream AI site builders are being repurposed as phishing-page factories, producing high-fidelity fake login pages and fake apps in minutes. When a phishing site gets taken down, the replacement is a prompt away.

This is why defenders increasingly describe the problem in economic terms. Detection and takedown still matter, but they are now racing an adversary whose marginal cost per attack is close to zero.

Trend 4: Phishing Has Left the Inbox

The fastest-growing phishing channels right now are not email at all.

Horizontal bar chart showing year-over-year growth of 442 percent in vishing, 400 percent in QR code phishing, 40 percent in smishing, and 38 percent in audio deepfakes in phishing emails

CrowdStrike documented a 442% surge in voice phishing in the second half of 2024, driven in part by AI voice cloning that makes a convincing phone call as easy to produce as a convincing email. QR code phishing has roughly quintupled as attackers push victims from screened corporate email onto unscreened personal phones. KnowBe4 measured a 38% rise in audio attachments inside phishing emails this year, many carrying cloned voices built with commodity tools.

Phishing attacks converging on one employee from five channels at once: email, text message, voice call, QR code, and a deepfake video call

The high end of this trend is the synthetic executive. The landmark case remains the Arup incident, where a finance employee wired $25 million after a video call in which every other participant was AI-generated. Since then the pattern has spread downmarket: researchers have documented campaigns using cloned executive voice memos against regional bank treasury teams, and in mid-2026 a subsidiary of Capillary Technologies disclosed losing roughly 3 million euros to attackers using cloned voices and forged signatures over a weekend. The FBI has warned publicly that AI-generated voice messages are being used to impersonate senior US government officials.

The common thread: attacks are converging on the person, not the platform. Email security, however good, only sees one of these channels.

And Increasingly, the Attack Starts in the Browser Itself

Some of the fastest-growing social engineering techniques are not categorically phishing at all. No message gets delivered, no link gets filtered. The deception happens entirely inside the browser:

Browser window filled with social engineering traps: a fake verification checkbox, a fake login popup, and a malicious download, with a fishing hook dangling above them
  • Fake verification prompts (ClickFix). A page displays what looks like a CAPTCHA or an error fix and walks the user through pasting a command that compromises their own machine. ESET researchers measured a surge of over 500% in the first half of 2025, making it the second most common attack vector they track, behind only phishing itself.
  • Browser-in-the-browser attacks. A pixel-perfect fake "Sign in with Microsoft" or "Sign in with Google" popup is drawn inside the page, complete with a spoofed address bar, harvesting credentials without ever leaving the attacker's site.
  • Malvertising and SEO poisoning. Paid search ads and manipulated results impersonate trusted brands, so the victim arrives at a fake login or download page from a Google search, confident because they navigated there themselves.
  • Fake browser update overlays. A compromised legitimate website tells the visitor their browser is out of date and serves malware as the "update," a technique that has quietly remained one of the most common malware delivery methods for years.
  • Adversary-in-the-middle kits. Tools like Evilginx and Tycoon 2FA proxy the real login page and steal the session token after the user authenticates, defeating MFA inside the browser itself.

Every one of these plays out in the one place traditional defenses cannot see: the open browser tab, at the moment a person decides to trust what is on the screen. Email gateways never see the fake CAPTCHA. MFA does not stop a stolen session. The browser is where the deception happens, where the decision happens, and where the compromise happens, which is exactly why it is where protection has to live. We covered this shift in depth in Phishing Doesn't End at the Inbox.

What This Means for Defenders

Put the four trends together and a clear picture emerges. Attacks are fewer but better. AI writing is the norm, so the old tells are gone. The tooling is cheap and packaged, so the attacker population is growing. And the delivery channels have multiplied past what email gateways can see.

Three practical conclusions follow:

  • Stop training people to spot typos. The classic red flags are actively misleading now, because the most dangerous messages are the cleanest ones. Training has to shift toward verifying requests through known channels and recognizing pressure tactics, and simulations need to look like modern attacks, not recycled templates from 2019.
  • Assume some lures will land, and protect the moment after the click. When a 54% click rate is achievable at scale, prevention cannot end at the inbox. Real-time protection in the browser, at the point where someone is about to enter credentials on a fake page, is the layer that turns a successful lure into a non-event.
  • Measure behavior, not completions. If attacks adapt continuously, a once-a-year training certificate says nothing about current risk. Human risk management means tracking how people actually respond to realistic attempts and letting that drive what happens next.

The Bottom Line

The market data all points the same direction: AI has not just made phishing better, it has changed what kind of problem phishing is. It used to be a filtering problem with a human backstop. It is becoming a human problem with a filtering front door, and the organizations adjusting to that reality first are the ones that will be hardest to breach.

For a deeper look at how these attacks work and how to build a defense, read our full guide to AI phishing, or assess your organization’s risk to see how SavvyShield protects employees at the moment of decision.