AI phishing uses trust to bypass defenses

The Hacker News

The gist

AI-powered phishing has turned trust into cybersecurity’s Achilles’ heel, fueling an industrial-scale crimewave that outsmarts traditional defenses and exploits the very systems meant to keep us safe.

What to know

  • AI-driven phishing attacks, including vishing and hyper-personalized lures, skyrocketed 449% by 2026 and routinely bypass legacy security tools.
  • Attackers now automate OAuth abuse, MFA theft, and real-time phishing-as-a-service—breaching over 700 organizations including Salesforce and Microsoft 365 environments.
  • Major breaches like NYC Health + Hospitals and ShinyHunters’ campaigns show the new frontline isn’t software flaws—it’s the manipulation of trusted identities and third-party access.

AI Supercharges Phishing Tactics

Phishing attacks have become hyper-personalized, multi-modal, and nearly undetectable as AI enables deepfake voices, real-time chatbots, and targeted lures that outsmart both employees and legacy defenses.

By 2025, AI-driven social engineering fundamentally transformed phishing attacks from manual, artisanal efforts into industrialized, large-scale operations characterized by unprecedented speed, scale, and sophistication. KnowBe4’s 2025 Phishing Threat Trends Report highlighted a staggering 449% surge in AI-powered voice phishing (vishing) attacks alongside a 67% increase in abuse of legitimate platforms, signaling attackers’ shift toward hijacking trusted communication channels and timing campaigns around seasonal events like tax deadlines to maximize impact.

Large Language Models (LLMs) and generative AI enabled hyper-personalized phishing lures that reference specific projects, colleagues, and company announcements, making attacks alarmingly believable and grammatically flawless. This AI capability extended beyond email to multi-modal tactics including deepfake voice snippets, video impersonations, and interactive chatbots—such as the novel 'ChatOps Phishing'—which guide victims through compromising actions in real time, rendering traditional phishing indicators obsolete and defenses increasingly ineffective.

By early 2026, threat actors like UNC6671 exemplified the evolution of AI-powered social engineering by targeting enterprise employees on personal phones with sophisticated vishing campaigns that impersonated IT help desks and leveraged adversary-in-the-middle infrastructure to intercept credentials and MFA tokens. These attacks, focusing heavily on financial, legal, and professional sectors, shifted the threat model from network breaches to large-scale identity fraud, enabling lateral movement across SaaS ecosystems and resulting in ransom demands exceeding $10 million.

The Levi Strauss social engineering breach in mid-2026 underscored the ongoing rise of AI-enhanced tactics such as vishing and adversary-in-the-middle phishing portals that exploit human trust rather than technical vulnerabilities. The company’s rapid containment and engagement of cybersecurity experts reflect an early organizational response to this evolving threat landscape, which continues to escalate across sectors including retail and cargo theft, where attackers increasingly flood inboxes with AI-generated phishing emails and impersonate internal accounts to fraudulently book high-value loads.

Sources
PR Newswire - Consumer TechnologyToxSec - AI and CybersecurityIT Brief New ZealandPYMNTSPYMNTSThe Hacker News

Identity Systems Under Siege

Attackers now weaponize OAuth, SSO, and shared mailboxes—turning trusted identity platforms into persistent backdoors and exploiting help desks to hijack credentials at scale.

By early 2026, attackers had refined their exploitation of trusted identity systems beyond traditional vulnerabilities, leveraging sophisticated social engineering techniques such as the 'consent fix attack' and targeted voice phishing campaigns to manipulate OAuth flows and Single Sign-On (SSO) platforms like Microsoft and Okta. Groups like ShinyHunters registered hundreds of deceptive domains mimicking legitimate MFA and help desk sites, enabling them to capture multifactor authentication credentials and register their own MFA devices, effectively turning SSO into a single point of failure that grants persistent, stealthy access across corporate environments.

The exploitation of shared mailboxes and trusted internal communication channels further illustrates how attackers bypass perimeter defenses by impersonating trusted insiders, as seen in a healthcare payroll heist where social engineering convinced help desk staff to reset passwords and MFA for a shared mailbox account. Operating within the organization's trusted environment, attackers evade detection by security tools that view such activity as legitimate internal user behavior, underscoring the paradigm shift toward identity as the new security perimeter.

From mid-2025 through mid-2026, the ShinyHunters campaign exemplified the industrial-scale abuse of OAuth trust relationships in Salesforce environments, where attackers combined vishing calls impersonating IT support with stolen OAuth tokens from compromised third-party vendors like Salesloft Drift and Gainsight. This multi-pronged approach allowed them to bypass MFA, maintain persistent access, and exfiltrate vast amounts of CRM data across over 700 organizations without triggering traditional sign-in alerts, revealing critical gaps in monitoring OAuth consent and third-party integrations as Microsoft responded by enhancing Defender for Cloud Apps with real-time telemetry and OAuth scope visibility.

The broader evolution in 2026 highlights a strategic shift where attackers no longer 'break in' through software flaws but instead 'log in' by weaponizing trust embedded in identity systems, SaaS platforms, and legitimate third-party tools. This includes abusing OAuth flows, cloud APIs, and enterprise AI assistants to gain persistent access while evading detection, as noted by Devon Ackerman who emphasized the failure lies in visibility rather than traditional controls. Compromised identities, shared mailboxes, and delegated access enable attackers to operate stealthily across hybrid environments, with AI accelerating data discovery, making continuous monitoring and governance of trust relationships an essential security imperative.

Sources

Phishing Goes Industrial

Cloud-powered automation and AI have transformed phishing into a professionalized, scalable operation, using open redirects, fake interfaces, and real-time malware delivery to overwhelm users and evade detection.

By late 2025, phishing attacks had evolved into highly automated and industrialized operations, leveraging cloud services and advanced automation to scale trust exploitation. VIPRE's Q3 2025 Email Threat Report highlighted that 80% of phishing campaigns exploited open redirects targeting major platforms like Outlook and Gmail, while attackers employed techniques such as commercial clutter and list bombing to desensitize users. These campaigns increasingly utilized cloud-based APIs and platforms, including Apple's TestFlight for malware distribution and the Fetch API for data exfiltration, illustrating a shift from opportunistic attacks to professionalized, cloud-powered infrastructures.

The ClickFix phishing campaign, emerging in November 2025, epitomizes the industrialization and automation of trust exploitation through sophisticated phishing kits and real-time deception platforms. Targeting Booking.com partners and macOS users, attackers combined social engineering elements like fake Cloudflare verification popups, instructional videos, and countdown timers with advanced malware such as Shemos Infostealer and PureRAT. This campaign’s ongoing profitability and evolution—including fake blue screens of death and exploitation of Microsoft Teams guest access—underscore the professionalization of trust-based attacks and their adaptability within enterprise and hospitality sectors.

By early 2026, attackers harnessed AI and cloud technologies to automate personalized social engineering at scale, exemplified by sophisticated phishing attacks mimicking Zoom interfaces. These AI-generated JavaScript attacks simulated real Zoom meetings and update prompts, tricking victims into installing remote management software that granted attackers full device control. Such campaigns integrated real-time deception with automated infection mechanisms, compressing initial access timelines from days to minutes and bypassing multi-factor authentication, signaling a new era of rapid, industrialized trust exploitation that exploits the speed gap between adoption and security validation.

By mid-2026, phishing-as-a-service platforms like LogoKit advanced into real-time deception ecosystems, dynamically generating highly personalized phishing pages using legitimate cloud services such as Thum.io and Clearbit to replicate corporate login environments. This automation extended globally with multilingual support across languages including English, German, Chinese, and Korean, while credential theft was streamlined by sending data directly to Telegram bots, enhancing stealth and resilience. These developments, alongside AI-driven localization and live MFA interception dashboards, reflect the full industrialization and professionalization of trust exploitation, where attackers operate with the precision and scale of legitimate enterprises.

Sources
PR Newswire - Business TechnologyCyberWire DailySANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)Security Weekly - A CRA ResourceCISO Talk by James AzarCISO Talk by James Azar

Breaches Exploit Human Trust

Major incidents like the NYC Health + Hospitals and ShinyHunters breaches reveal that attackers increasingly 'log in' via third-party and vendor trust relationships, bypassing technical barriers through social engineering and stale credentials.

The landscape of high-impact breaches in 2026 has been dominated by attackers exploiting trust relationships rather than technical vulnerabilities, with social engineering and third-party vendor compromises serving as primary intrusion vectors. Notably, the NYC Health + Hospitals breach exposed biometric data of 1.8 million individuals through a third-party vendor, underscoring the devastating consequences of supply chain compromises on enterprise security. As PKWARE® analysis highlights, "attackers did not break in; they logged in," emphasizing that human factors and inherited vendor access are critical weak points in modern defenses.

The ShinyHunters group orchestrated a sustained and sophisticated campaign from mid-2025 through mid-2026, leveraging OAuth abuse and stale credentials to exfiltrate data at scale from SaaS platforms such as Salesforce and Microsoft 365. Their tactics included voice phishing employees to authorize malicious connected applications disguised as legitimate Salesforce tools, stealing OAuth tokens from compromised vendors like Salesloft Drift, and exploiting misconfigured guest access on Salesforce Experience Cloud. This multi-pronged approach allowed them to bypass MFA and traditional authentication monitoring, as Microsoft noted that "sign-in and authentication monitoring barely registers" such trusted OAuth traffic, enabling persistent, stealthy access across over 700 organizations including Cloudflare, Zscaler, and Palo Alto Networks.

The exploitation of stale credentials and weak access lifecycle governance has been a critical enabler of these breaches, allowing attackers to maintain long-term access and move laterally across cloud environments. For example, the Klue breach was traced to a pilot credential active for four years, facilitating the Icarus group's access to data from nearly 200 enterprise customers. Such incidents highlight the urgent need for enforcing credential expiration policies, rigorous helpdesk identity verification, and persistent data-centric encryption, as perimeter defenses alone proved insufficient when data was readable immediately upon exfiltration.

By early 2026, the UNC6671 group—linked to ShinyHunters—evolved a high-tempo extortion operation exploiting OAuth abuse and stale credentials through vishing attacks targeting personal phones. This approach tricks employees into approving malicious OAuth consents, enabling attackers to bypass individual SaaS application compromises and move laterally across entire SaaS ecosystems with a single authenticated session. CrowdStrike emphasized that "by abusing the trust relationship between the IdP and connected services," attackers can deploy automated scripts to exfiltrate data from platforms like Microsoft 365 and Okta, demonstrating the severe operational and financial risks posed by trust exploitation in enterprise environments.

Sources

Defense Shifts to Identity

Traditional prevention is failing as organizations pivot to layered, adaptive defenses—prioritizing behavioral detection, zero trust, and real-time identity monitoring to counter relentless trust exploitation.

By late 2025, defense strategies against AI-driven phishing attacks had evolved into a sophisticated layered approach that integrates people, processes, and technology. Signature-based detection was declared obsolete as AI-generated phishing variations proliferated, prompting organizations to adopt Just-in-Time Micro-Drills for continuous, realistic employee training and implement out-of-band verification alongside easy phishing reporting mechanisms to empower employees as active defenders. Technological measures shifted toward behavioral anomaly detection and phish-resistant MFA methods like FIDO2/passkeys, emphasizing the need to identify and respond dynamically to attack processes rather than static payloads.

By early 2026, the cybersecurity community recognized that prevention alone was insufficient; real-time detection and response became paramount with identity positioned as the frontline defense. Resilience against industrialized trust exploitation hinged on continuous monitoring, adaptive defenses, and strategic awareness, while fundamental controls such as identity governance, supply chain validation, segmentation, and rapid patching emerged as urgent imperatives. This shift was underscored by reports from Sophos and Red Canary showing identity-related root causes surpassing non-identity causes since 2022 and an 850% year-over-year surge in identity threat detections, respectively, signaling that identity had become the new perimeter in cybersecurity.

The rise of zero trust and conditional access frameworks became essential responses to attackers leveraging legitimate credentials for lateral movement within networks, as highlighted in 2026 analyses. Conditional access policies enable an allow-list approach that flags deviations in user behavior, operating systems, or IP ranges as suspicious, thereby enhancing detection capabilities. Attackers’ exploitation of identity chains in hybrid environments, facilitated by AI-driven scalability, further emphasized the necessity for continuous identity governance and real-time monitoring to detect and disrupt lateral movements before high-value targets are compromised.

By mid-2026, experts like Joel Moses illuminated how attackers increasingly exploit trust relationships rather than breaching identity mechanisms directly, using tactics such as MFA fatigue, session token theft, and malicious application consent. This exploitation spans cloud and on-premises environments, creating attack paths that demand continuous identity governance, periodic third-party access reviews, and layered defenses including number matching and FIDO2 keys. Furthermore, modern defense strategies expanded to continuously validate all trusted control planes—security consoles, identity platforms, and network gateways—while integrating communication as a core incident response component to counteract attackers’ leverage over public narratives, as evidenced by high-profile breaches like Levi Strauss & Co., where social engineering bypassed traditional technical controls.

Sources
ToxSec - AI and CybersecurityCISO Talk by James AzarN2K NetworksN2K NetworksHNCISO Talk by James Azar

Trust Is the New Attack Surface

Attackers exploit trusted systems, integrations, and AI assistants—targeting the very relationships and platforms that organizations rely on—forcing defenders to treat trust as a dynamic vulnerability requiring continuous governance.

By mid-2026, the cybersecurity landscape had fundamentally shifted from focusing on isolated system vulnerabilities to grappling with the erosion of trust across entire ecosystems, including Domain Controllers, AI assistants, and software supply chains. Attackers increasingly exploit trusted relationships rather than breaking security directly, targeting critical infrastructure components like VPNs, SD-WAN controllers, and AI platforms that were never architected to withstand sustained adversarial pressure. As a result, defenders must prioritize understanding which trusted systems adversaries value most, recognizing that trust exploitation now drives the majority of major breaches.

The rapid adoption of AI, cloud-native development, and interconnected SaaS ecosystems has expanded the attack surface dramatically, introducing new vulnerabilities in AI model proxies, orchestration frameworks, and cloud APIs. Organizations often extend trust through integrations, developer tools, and third-party services without applying equivalent governance, creating architectural weaknesses that attackers exploit by inheriting trust rather than circumventing controls. This broadening of trust exploitation now encompasses not only user credentials but also email authentication, cloud entitlements, AI gateways, and non-human identities, demanding continuous validation and governance beyond traditional IT assets.

Modern cyberattacks frequently leverage legitimate identities and approved tools to bypass traditional defenses like endpoint detection and multi-factor authentication, operating within trusted channels such as cloud APIs, identity platforms, and enterprise AI assistants. This abuse of trust is compounded by critical visibility gaps into how these legitimate technologies are weaponized, making continuous monitoring of SaaS telemetry, browser activity, and identity usage essential. Security leaders must therefore reconceptualize trust from a business enabler to a dynamic attack surface requiring rigorous, ongoing governance and enhanced communication strategies to counteract attackers’ narrative control during incidents.

Supply chain security has evolved into a pivotal battleground for trust exploitation, with recent compromises involving widely used maintainers, CI/CD infrastructure, and VPN delivery pipelines illustrating how trust relationships extend far beyond software bills of materials. Defenders face the challenge of expanding visibility and governance to detect when trusted infrastructure or identities begin behaving maliciously, as traditional methods focused on blocking malicious endpoints no longer suffice. This necessitates treating every control plane—security consoles, identity platforms, development infrastructure—with the same rigorous monitoring, segmentation, and validation as production workloads to effectively manage the largest emerging attack surface: trust itself.

Sources

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.