AI phishing costs soar as defenses scramble

The Hacker News ↗

The gist

AI-fueled phishing is outpacing defenses, driving up security team costs and unleashing a wave of sophisticated, near-undetectable scams.

What to know

  • By mid-2026, AI-powered phishing has driven security analyst costs up 13.6% to nearly $52,000 annually, even as incident resolution sped up by 16%.
  • Attackers exploit AI hallucinations to register thousands of plausible but fake domains (phantom squatting), with Unit 42 uncovering 13,000 malicious URLs and 250,000 vulnerable domains.
  • A staggering 95.2% of phishing attempts now hide in encrypted TLS traffic and use advanced evasion tactics, forcing defenders to adopt Zero Trust, deep TLS inspection, and integrated identity-email security frameworks.

AI Drives Analyst Overload

AI-fueled phishing campaigns have overwhelmed security teams with relentless, highly personalized attacks and deepfake threats, pushing analyst workloads and costs to record highs despite faster response times.

By mid-2026, the financial strain of phishing on security teams has escalated sharply, with costs per analyst rising 13.6% to nearly $52,000 annually since the public debut of ChatGPT. This increase persists despite improved operational efficiencies—security teams now resolve phishing emails 16% faster and at 12% lower cost per incident—because AI-driven attackers have dramatically amplified both the volume and sophistication of their campaigns. The average phishing workload has ballooned to consume 36.5% of security team hours, up from 33.5% in 2022, underscoring how AI's acceleration of attack frequency outpaces defensive gains.

Generative AI has revolutionized phishing economics by slashing the time and cost required to craft personalized attacks, which were once labor-intensive and restricted to high-value targets. Now, attackers can deploy tailored campaigns across entire organizations within minutes, leveraging AI to rapidly test and adapt tactics to evade detection. This dynamic, automated approach overwhelms traditional detect-investigate-respond models, with 40% of security professionals anticipating worsening pressures as AI tools continue to evolve.

Deepfake technology has emerged as a particularly disruptive frontier in AI-driven phishing, with 62.5% of surveyed security experts reporting immediate operational impacts from these attacks. Deepfake voice and video phishing rank highest among emerging threats for their extreme impact, presenting novel challenges that traditional defenses are ill-equipped to handle and forcing security teams to rethink verification and response strategies in an era where seeing and hearing is no longer believing.

Sources
IT Brief New Zealand

Phantom Squatting: Hallucinated Havoc

Attackers are mass-registering AI-hallucinated domain names before defenses can react, weaponizing language model quirks to launch undetectable phishing and malware campaigns at scale.

Phantom squatting, a novel cyberattack technique identified by Palo Alto Networks' Unit 42 in mid-2026, exploits the consistent hallucinations of AI language models that generate plausible but non-existent domain names. Attackers preemptively register these AI-generated fake domains, which initially lack any reputation or presence in threat feeds, allowing them to bypass traditional security filters and launch phishing and malware campaigns before defenses can react. For instance, within weeks of Unit 42 predicting a hallucinated postal service domain, attackers registered it and deployed the Montana Empire phishing kit, illustrating the real-world impact of this emerging threat.

The predictability of AI hallucinated domains stems from the language models’ inherent patterns, which often produce the same fake domains across different systems when prompted with identical queries like 'What's the official website for company X?'. This consistency enables attackers to anticipate and register these phantom domains en masse—Unit 42 uncovered approximately 13,000 malicious URLs and about 250,000 unregistered AI-generated domains ripe for exploitation. This phenomenon extends the concept of slopsquatting from software package names to web domains, marking a broader evolution where AI-generated outputs become exploitable inputs in the cyber threat landscape.

The rise of phantom squatting significantly expands the attack surface for cyber adversaries, as every new large language model deployment introduces fresh hallucinated domains that can be weaponized, posing severe risks to software supply chains and digital trust. Researchers warn that because AI models are trained on human-authored corpora, they naturally fabricate plausible-sounding domains, creating a continuously growing pool of vulnerable targets. To counter this, Unit 42 recommends proactive defense strategies such as mapping likely hallucinated domains and registering them preemptively, alongside vigilant monitoring of domain registration streams to detect and disrupt attacks before they materialize.

Sources

Phishing Hides in Plain Sight

Sophisticated attackers are embedding malicious content in encrypted traffic and camouflaging payloads with advanced text and CSS tricks, rendering traditional and AI-based email filters nearly blind.

By mid-2026, attackers have dramatically shifted their phishing strategies to exploit encrypted TLS traffic, with Zscaler research revealing that 95.2% of phishing attempts now hide within such encrypted sessions. This evolution effectively blindsides traditional and AI-based email security systems that lack robust deep TLS inspection capabilities, allowing malicious content to slip through undetected under the cloak of encryption.

Concurrently, cybercriminals have refined text salting techniques since at least April 2026, as documented by Barracuda researchers who uncovered over one million phishing attacks leveraging this method. By embedding malicious payloads within benign-looking retail-themed text, attackers dilute suspicious keywords, thereby deceiving both conventional and AI-powered email defenses that rely on keyword detection and content analysis.

These text salting tactics are further enhanced through sophisticated CSS and font manipulation strategies—such as 'clip-path: inset(100%)', 'text-indent: -9999px', and zero font size—that invisibly mask harmful text from security tools while keeping it perceptible to the human eye. This dual-layered concealment effectively disrupts signature-based filters and AI models alike, as attackers exploit the gap between raw source code and user-visible content, complicating detection efforts.

To counter these advanced evasion techniques, modern email security solutions must pivot from analyzing raw email source code to scrutinizing the actual content rendered to users. This shift is critical because, as highlighted in July 2026 analyses, AI systems can be misled by hidden-content manipulations that distort their interpretation of email intent and risk, underscoring the need for security tools that replicate the user's visual experience to effectively unmask concealed threats.

Sources

Detection Rules Get Smarter

Defenders now blend linguistic intelligence, metadata analysis, and behavioral detection to catch advanced impersonation scams that abuse trusted brands, QR codes, and document formats.

By mid-2026, detection rules have evolved significantly to counter increasingly sophisticated phishing and brand impersonation tactics, leveraging advanced technologies such as Natural Language Understanding (NLU) and YARA signature matching. These enhancements enable precise identification of malicious campaigns targeting trusted entities like Canada Revenue Agency, QuickBooks, and Adobe Sign, while also uncovering evasive techniques including recipient-specific QR codes, obfuscated URLs, and invisible Unicode characters designed to bypass filters. Notably, the integration of metadata and structural analysis across PDFs, DOCX, and image files has allowed defenders to detect anomalies in fonts, EXIF data, and object hashes, effectively exposing programmatically generated malicious documents and fake invoices that underpin Business Email Compromise (BEC) schemes.

Detection capabilities have expanded beyond static signatures to include dynamic behavioral and contextual analysis, targeting the abuse of trusted infrastructure such as Google Cloud Storage, Cloudflare tunnels, and JustPaste.it. This shift addresses attackers’ growing use of legitimate services to mask phishing landing pages and redirectors, thereby circumventing traditional reputation-based filters. Additionally, sophisticated detection rules now identify failed personalization attempts and tracking placeholders in bulk phishing emails, revealing automated campaigns with poorly rendered payloads that betray their malicious origins.

The defense landscape has also embraced comprehensive sender authentication enhancements, with stricter DMARC validation and expanded keyword and display name matching to thwart impersonation of major platforms including OpenAI, Microsoft Teams, McAfee, and Proofpoint. Coupled with NLU-driven analysis of social engineering and service abuse patterns, these measures effectively detect complex scams such as ChatGPT brand impersonation, callback frauds using settime.io, executive coaching impersonations, and romance scams routed through free email providers. This multi-layered approach reflects a maturation in detection strategies, blending linguistic intelligence with metadata scrutiny to stay ahead of evolving phishing threats.

Sources
Detections DigestDetections DigestDetections DigestDetections Digest

Zero Trust or Bust

Modern phishing defense hinges on integrated identity-email security and aggressive infrastructure disruption, as attackers rotate domains and exploit trusted cloud services faster than legacy takedowns can keep up.

By mid-2026, cybersecurity defenses have undergone a fundamental transformation, moving away from static perimeter and content-based filtering toward integrated identity-email security frameworks and Zero Trust architectures. Zscaler’s research highlights that with 95% of phishing attacks now concealed within encrypted TLS traffic, organizations can no longer afford to bypass TLS inspection, as only Zero Trust models can effectively sever the attack chain from initial discovery to data exfiltration. This evolution also embraces behavioral analysis and relationship intelligence, recognizing that modern phishing exploits legitimate business workflows rather than just malicious emails, thus demanding a nuanced understanding of identity context and communication patterns.

Simultaneously, defenders face an urgent imperative to disrupt phishing infrastructures rapidly, as adversaries leverage AI to spawn hundreds of thousands of high-fidelity phishing sites and deploy sophisticated kits like BlackForce that hijack active sessions and bypass multi-factor authentication in real time. ThreatLabz’s identification of over 413,000 AI-generated phishing instances, with nearly 10% explicitly malicious, underscores the scale and precision of these threats. Traditional URL takedown approaches are now obsolete, as attackers treat phishing as a resilient infrastructure problem—swiftly rotating domains, hosting, and redirect chains to maintain campaigns, often outpacing defenders who take days to respond.

Consequently, effective phishing defense in 2026 demands a holistic strategy that integrates identity-email security, Zero Trust architectures, comprehensive TLS inspection, and dynamic disruption of phishing infrastructure rather than relying solely on URL takedowns. Modern Integrated Communication and Email Security (ICES) platforms enable defenders to monitor internal mail flows, mailbox relationships, and communication cadence, detecting anomalies that legacy gateways miss. Moreover, addressing trusted-cloud phishing scenarios requires dynamic post-engagement analysis beyond reputation-based controls, as attackers exploit legitimate services to bypass traditional defenses. As one analysis puts it, the challenge for CISOs is no longer merely identifying phishing sites but understanding and dismantling the underlying infrastructure before adversaries redeploy elsewhere.

Sources

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.