AI supercharges phishing: automated attacks and identity scams overwhelm defenses in 2026

The gist
AI-fueled phishing and identity scams have exploded in scale and sophistication, overwhelming traditional defenses and putting every organization’s digital front door at risk.
What to know
- AI-powered phishing attacks surged 449% in 2025, with groups like Scattered Spider impersonating major brands and causing hundreds of millions in losses.
- Subscription-based phishing-as-a-service kits like EvilTokens and Kali365 fueled a staggering 1,380% spike in Microsoft 365 account attacks, making cybercrime accessible to anyone with $250 and a Telegram account.
- Standard defenses have failed—organizations now rely on continuous employee training, phish-resistant MFA, and advanced behavioral detection to stand a chance against AI-driven identity threats.
AI Turns Phishing Personal
AI-driven attacks now mimic individual voices, brands, and internal jargon in real time, making phishing indistinguishable from genuine communication and rendering traditional red flags obsolete.
The year 2025 marked a dramatic escalation in AI-enhanced phishing and social engineering, with KnowBe4's report revealing a staggering 449% increase in AI-powered vishing attacks and a 67% surge in the abuse of legitimate platforms. Cybercriminal groups like Scattered Spider capitalized on these advances, orchestrating breaches of major retailers such as M&S, Co-Op, and Harrods, then leveraging AI to impersonate these brands in sophisticated phishing campaigns that inflicted hundreds of millions in damages. This surge underscored a shift from rudimentary phishing to highly targeted, brand-centric attacks powered by AI's ability to mimic trusted entities and bypass conventional defenses.
AI transformed social engineering from a labor-intensive craft into an industrialized operation capable of generating thousands of hyper-personalized phishing lures in the time it once took to craft a single message. Large Language Models (LLMs) now scrape public data—from LinkedIn profiles to company announcements—to build detailed persona graphs, enabling attackers to produce grammatically flawless, contextually rich messages that reference specific projects, colleagues, or internal jargon. This evolution renders traditional phishing indicators obsolete, as AI-generated content can engage victims in real-time, mimicking individual communication styles and even handling objections through interactive 'ChatOps Phishing' bots that guide victims step-by-step toward compromise.
By early 2026, AI-enhanced voice phishing campaigns had matured into highly targeted, identity-centric operations exemplified by the ShinyHunters group’s abuse of Okta SSO services. These attackers registered approximately 150 custom domains mimicking company help desks and MFA portals with near-perfect fidelity, enabling them to steal credentials and register their own MFA devices to maintain persistent network access. The integration of AI voice cloning further supercharged vishing scams, allowing attackers to convincingly impersonate executives and bypass instinctive trust barriers, as highlighted by experts emphasizing the need for policy-driven verification processes empowering employees to independently validate suspicious requests.
AI-driven localization and multilingual phishing kits have expanded the reach and sophistication of phishing ecosystems, as seen in the massive 'Ghost Stadium' fraud operation during the FIFA World Cup. This campaign employed pixel-perfect clones in over eleven languages and multiple Chinese dialects, leveraging Meta’s advertising infrastructure to drive traffic. Concurrently, Chinese-language phishing-as-a-service platforms evolved into real-time MFA interception systems, enabling attackers to instantly capture OTP codes and provision payment cards into attacker-controlled digital wallets. These developments illustrate how AI not only automates and personalizes attacks but also integrates multi-modal deception and real-time fraud capabilities across global, culturally nuanced landscapes.
Identity: The New Battleground
Cybercriminals have shifted from stealing passwords to hijacking digital identities, exploiting OAuth permissions and multi-channel deepfakes to silently infiltrate cloud accounts and corporate networks.
By late 2025, attackers had pivoted from traditional credential theft to targeting identity as the primary attack surface, exploiting OAuth over-permissioning and session token theft to gain excessive cloud account access. This evolution was amplified by AI-driven social engineering that automated persona profiling and mimicked organizational communication styles, enabling attackers to bypass conventional defenses by impersonating trusted colleagues across platforms like Slack, Teams, and Jira. Multi-channel tactics, including chatbots and deepfake voicemails, further deepened the deception, making identity compromise a stealthy and potent vector.
The emergence of device code phishing attacks in early 2026 marked a dramatic escalation in OAuth abuse, with campaigns exploiting legitimate Microsoft authentication flows to capture tokens rather than passwords. Tools like the EvilTokens phishing kit and later the AI-powered Kali365 platform democratized this attack method, enabling even low-skilled criminals to bypass multifactor authentication by tricking victims into entering attacker-generated device codes on real Microsoft login pages. This token-centric approach grants persistent access without triggering MFA prompts, representing a fundamental shift in attack methodology and challenging traditional security models.
Highly targeted voice phishing campaigns, such as those by the ShinyHunters and Mutant Spider groups, exploited identity-centric vulnerabilities by impersonating IT support to manipulate MFA resets and register malicious devices within corporate networks. These attacks leveraged Okta SSO and Microsoft Teams to gain persistent, privileged access, underscoring the risks of single sign-on systems as single points of failure. As Adam Meyers of CrowdStrike observes, attackers increasingly exploit human factors—calling help desks to reset MFA—rather than relying on zero-day exploits, signaling a structural shift toward social engineering that undermines traditional perimeter defenses.
Security leaders widely recognize identity-based attacks as the foremost threat, with 90% citing them as their top concern by early 2026. The interconnectedness of supply chains and shared mailboxes amplifies risk, as a single compromised identity can enable stealthy insider-like access and privilege escalation without triggering alarms. Defensive strategies now emphasize least privilege, conditional access policies, physical token authentication, and behavioral baselining, while also advocating for restricting device code authentication flows where feasible. Platforms like Doppel are emerging to combat AI-enhanced social engineering by dismantling cross-channel impersonation campaigns and building organizational resilience.
Phishing-as-a-Service Goes Mainstream
Subscription-based AI phishing kits like EvilTokens and Kali365 have industrialized cybercrime, letting even novices launch hyper-personalized, multi-vector attacks for the price of a streaming service.
By early 2026, subscription-based phishing-as-a-service platforms like EvilTokens and Kali365 have revolutionized the cybercrime landscape by democratizing access to sophisticated phishing tools that were once the domain of highly skilled attackers. These platforms integrate AI-generated lures, automated workflows, and multi-tenant ecosystems, enabling even low-skilled cybercriminals to launch complex, highly personalized campaigns at scale. For instance, EvilTokens reported a staggering 1,380% increase in AI-enabled phishing attacks in early 2026, while Kali365, available for as little as $250 per month via Telegram, offers turnkey solutions including 33 Microsoft service impersonation templates, real-time dashboards, and OAuth token capture capabilities that bypass multifactor authentication, as highlighted in FBI warnings and security firm analyses.
These phishing kits employ advanced technological innovations such as realistic SaaS-themed lures exploiting trusted services like Microsoft Office and DocuSign, anti-bot protections, cloud hosting, and sophisticated evasion techniques including seven-layer anti-analysis systems and XOR-encrypted payloads. By leveraging generative AI, platforms like EvilTokens and Kali365 personalize phishing messages at an industrial scale, ensuring no two lures are identical across hundreds of incidents, which significantly enhances victim engagement and attack success rates. This industrialization of phishing operations has been described by Huntress CEO Kyle Hanslovan as lowering the technical barrier so drastically that 'you just don't have to know this,' effectively turning cybercrime into a tech startup-like ecosystem.
The emergence of multi-tenant phishing ecosystems such as ARToken and EvilTokens marks a significant escalation in the scale and sophistication of cybercrime infrastructure. These platforms offer extensive post-compromise toolkits accessible through user-friendly React-based dashboards, exposing over 80 API endpoints for operations ranging from device code phishing to business email compromise and SharePoint exfiltration. With subscription models priced between $600 and $1,500 and additional tools like standalone browsers for stealth, these ecosystems democratize cyberattack capabilities globally, targeting specific professional roles by exploiting legitimate vendor relationships and trusted domains to bypass detection, as confirmed by Microsoft and security researchers.
BEC Scams Exploit Trust Chains
Modern Business Email Compromise attacks weaponize AI and insider reconnaissance to manipulate real business relationships, bypassing technical controls and blending seamlessly into legitimate workflows.
By mid-2026, Business Email Compromise (BEC) attacks had transformed into highly targeted, multi-stage operations that exploit trusted business relationships and processes without relying on traditional malicious artifacts like malware or suspicious links. These sophisticated scams often impersonate executives or vendors using legitimate domains and real email histories, rendering conventional email authentication methods such as SPF, DKIM, and DMARC insufficient for detection. The subtlety lies in anomalies like altered payment details or unusual invoice requests, which demand advanced behavioral baselining and relationship intelligence to identify deviations in communication patterns and workflows.
The operational complexity of modern BEC schemes has escalated with attackers conducting deep organizational reconnaissance, mapping internal structures, financial privileges, and vendor communications to craft convincing fraudulent requests. AI-powered tools have further lowered the barrier for threat actors, enhancing scam quality and personalization while accelerating the learning curve. As noted in early 2026 forum discussions by actors like Bigjack, timing, urgency, and embedding fraudulent requests within legitimate email threads are critical tactics to evade detection and pressure targets, sometimes supplemented by specialized call centers designed to coerce victims into finalizing payments.
The emergence of platforms like ARToken and its affiliate EvilTokens epitomizes the evolution of BEC into AI-enhanced, multi-channel exploit ecosystems. Unlike simple phishing kits, ARToken functions as a full BEC-as-a-service environment, featuring advanced inbox rule manipulation, shared access links, and a sophisticated seven-layer anti-analysis system to evade detection. Cisco Talos reported a staggering 1,380% increase in EvilTokens attacks targeting Microsoft 365 accounts in early 2026, leveraging AI-augmented pipelines that chain Groq-hosted Llama models and GPT-4o-mini to generate tailored phishing scenarios exploiting genuine vendor relationships and trusted business processes.
Multi-channel exploitation strategies have grown increasingly intricate, with attackers leveraging legitimate Microsoft 365 SharePoint URLs linked to attacker-controlled look-alike tenants to bypass security filters and boost success rates. This tactic, confirmed by Microsoft and analyzed by Sekoia in early 2026, demonstrates how threat actors integrate AI-driven phishing with trusted platforms to create seamless, believable attack chains. The rapid evolution of these AI-powered, identity-centric BEC campaigns underscores the urgent need for integrated cloud email security platforms that analyze internal mail flow, communication cadence, and post-delivery behavior beyond legacy gateway models.
Defenses Shift to Identity Layers
Organizations now fight AI-powered phishing with dynamic, identity-centric security—combining behavioral analytics, strict access policies, and micro-drills to outpace attackers who exploit both technology and human trust.
By late 2025, cybersecurity defense strategies had decisively shifted toward a layered, identity-centric model that integrates people, processes, and technology to counter AI-driven phishing and identity-based attacks. This approach emphasizes continuous, realistic employee training through Just-in-Time Micro-Drills and clear verification policies to build a resilient human firewall, while technologically enforcing phish-resistant MFA protocols like FIDO2/passkeys and behavior-based anomaly detection. As traditional signature-based detection became obsolete against AI’s infinite phishing variations, organizations adopted dynamic, behavior-focused security postures that monitor attack processes rather than static payloads, exemplified by integrated monitoring of OAuth app approvals and out-of-band verification for sensitive requests.
By November 2025, defending against sophisticated identity-centric threats such as Scattered Spider required moving beyond perimeter defenses to comprehensive identity and SaaS posture assessments combined with identity threat detection and response technologies. CISOs were urged to achieve exhaustive identity visibility—discovering and classifying all human, machine, API, AI, and vendor identities across environments—and to harden identity posture through continuous configuration audits, privilege reduction, and threat-informed risk prioritization. Behavior-based threat detection became essential, leveraging runtime anomaly detection, cross-system telemetry aggregation, and advanced detection rules like the 1,500+ from Permiso’s P0 Labs to identify subtle identity-based attack patterns.
Entering 2026, organizations fortified defenses against emerging threats such as device code phishing and AI-powered voice cloning by implementing strict conditional access policies that whitelist approved apps, users, and IP ranges, alongside policy-driven verification requiring secondary human confirmation for sensitive transactions. Employee training evolved to emphasize understanding the social engineering mechanics behind novel attack vectors rather than mere URL recognition, empowering staff to question even high-ranking executives’ requests. This holistic approach recognized that filtering alone was insufficient, as illustrated by the rise of AI-driven ‘ChatOps Phishing’ and vishing attacks where low-tech delivery met high-tech persuasion, necessitating integrated monitoring and layered identity-centric defenses.
By mid-2026, identity-centric defense matured further with the adoption of advanced authentication protocols like FIDO physical key tokens and biometrics, despite privacy concerns, alongside principles of least privilege and conditional access to minimize attack surfaces. Security platforms such as Sublime Security enhanced detection rules to uncover sophisticated phishing tactics exploiting legitimate cloud services and evasion techniques, analyzing social engineering patterns and expanding brand impersonation detection across all senders. Meanwhile, the FBI and cybersecurity agencies warned of MFA bypasses via OAuth device code abuse (e.g., Kali365 phishing-as-a-service), underscoring the critical need for timely patching, insider threat monitoring, and removing internet exposure of vulnerable infrastructure. Manufacturing sectors, hit hard by a 47x surge in credential leaks in April 2025, exemplify the urgency for integrated monitoring across IT, OT, human, and supply chain layers to detect multi-stage identity-focused attacks leveraging trusted platforms and social media.
Modern email security paradigms have evolved by June 2026 from static content filtering to sophisticated, identity-centric frameworks that analyze communication relationships, behavioral baselines, and business workflows. Identity-centric email security (ICES) platforms monitor internal mail flow, mailbox relationships, and post-delivery behavior to detect subtle anomalies that traditional gateway models miss. Dynamic detection techniques such as URL detonation, browser interaction analysis, and redirect-chain reconstruction are now critical to counter trusted-cloud phishing hosted on legitimate platforms, reflecting a comprehensive layered defense approach necessary to combat increasingly automated and identity-focused cybercrime ecosystems.










