AI-Driven Phishing Attacks Bypass Email Filters, Land in Inboxes
## Cybersecurity: AI-Driven Phishing Attacks
Cybersecurity: AI-Driven Phishing Attacks
AI-generated phishing is increasingly affecting email security, with a rise in attacks bypassing filters and reaching users' inboxes, although AI-generated emails are still a minority in overall phishing incidents.
Human factors play a significant role in breaches, with 68% involving people and 80–95% starting with phishing, making social engineering a prevalent breach vector.
The advent of generative AI has led to a substantial increase in phishing activity, with reports indicating a more than 4,000% rise attributed to tools like ChatGPT and similar language models. These models generate context-aware emails at scale, eliminating the spelling errors and awkward phrasing that users have been trained to identify as suspicious.
Economic incentives are substantial, as the average cost of a phishing-related breach is about $4.88 million, marking the largest year-over-year increase in breach costs since the pandemic.
The 2025 Phishing Trends Report offers a reference for the global incidence of real malicious clicks and phishing attacks that bypass email filters. The report highlights that training employees to identify and report social engineering attacks can lead to a sixfold improvement within six months, reducing phishing incidents per organization by 86%.
For attackers, AI reduces the effort and expertise needed while maintaining high payoffs, contributing to the rise of business email compromise (BEC), credential harvesting, and multi-channel phishing (e.g., email, SMS, collaboration tools).
The 2025 Phishing Trends Report offers a reference for the global incidence of real malicious clicks and phishing attacks that bypass email filters.
Data from Hoxhunt’s 2025 Phishing Trends indicates a sharp increase since 2022 in phishing attacks that bypass email filters, with nearly a 50% rise in such incidents, although growth slowed in 2024 as filters adapted. The report identifies a $1.2 million cost difference between breaches identified and contained before or after 200 days of initiation.
Detection engines still mainly rely on static indicators such as domains, URLs, and attachment types, while attackers increasingly exploit trusted infrastructure like reputable file-sharing platforms and HTTPS-secured pages to appear legitimate.
AI enables attackers to subtly vary content and structure, creating polymorphic phishing waves where each email differs slightly, reducing the effectiveness of signature-based detection and complicating reputation-based blocking.
Despite advancements, analysis of numerous malicious phishing emails shows that fewer than 5% of phishing emails bypassing filters in 2024 were confidently identified as AI-written, suggesting that traditional phishing kits and methods remain prevalent.
Organizations can counter AI-generated phishing by:
Enhancing the inbox as part of the detection surface with easy client reporting and efficient SOC workflows. Implementing adaptive, role-aware phishing simulations that reflect real attacker themes. Continuously tuning email defenses for AI-driven and multi-channel campaigns, focusing on behavioral indicators and anomalies. Tracking metrics such as reporting rate, failure rate, and dwell time as primary indicators of human risk, beyond compliance completion.
While AI has shifted the advantage towards phishers, combining technology with behavior-based training and high-velocity reporting can significantly reduce the number of incidents initiated by phishing attacks.
Based on reporting by GBHackers.
