S&P 5005,842.10 0.42%
NASDAQ19,210.55 0.88%
NVDA1,184.22 2.41%
MSFT478.90 0.88%
GOOGL210.11 1.12%
META612.50 0.34%
AAPL239.80 0.21%
AMZN248.66 1.40%
AVGO1,902.40 3.12%
TSLA298.10 1.05%
BTC98,420 1.88%
ETH4,210 2.24%
10Y4.18% 0.02%
DXY104.12 0.18%
S&P 5005,842.10 0.42%
NASDAQ19,210.55 0.88%
NVDA1,184.22 2.41%
MSFT478.90 0.88%
GOOGL210.11 1.12%
META612.50 0.34%
AAPL239.80 0.21%
AMZN248.66 1.40%
AVGO1,902.40 3.12%
TSLA298.10 1.05%
BTC98,420 1.88%
ETH4,210 2.24%
10Y4.18% 0.02%
DXY104.12 0.18%
Back to homepage
AI & Cybersecurity

AI-Driven Phishing Surges: What U.S. Companies Must Do Today

Cybercriminals are using large language models to craft hyper-personalized lures and voice deepfakes. Defenders can fight back, but speed and strategy matter.

P
Pedro Marini
July 28, 2026 · 4 min read
AI-Driven Phishing Surges: What U.S. Companies Must Do Today

Illustration by IMF Alpha editorial · Reviewed by Pedro Marini

Listen to this article
AI narration · ~4 min
Tickers mentioned
MSFT+1.20%GOOGL+0.80%CRWD-0.50%PANW+2.30%FTNT-1.10%

The new phishing playbook is written by AI. Over the past year security teams have shifted from blocking mass spam to chasing hyper-targeted social engineering produced with large language models. The result: fewer obvious typos, richer context, and messages that sound like they come from someone you actually know. It looks like a familiar scam, but it feels like a colleague.

Why this matters now

  • Precision is replacing volume. Attackers no longer spray-and-pray. AI makes it cheap to stitch together public records, scrape social posts, and produce tailored messages at scale. That raises click-through rates and dials down the noisy signals defenders used to rely on.
  • Voice and video deepfakes are back in the mix. Phone fraud gains a sharper edge when a synthetic voice can imitate an executive or a vendor. A CEO-sounding call asking for an urgent wire transfer stops being implausible.
  • Signatures are less reliable. Behavioral tricks and generative mutations let malware change its indicators; legacy signature-based defenses miss a growing share of attacks.

A short history

Phishing evolved in waves. Early scams were obvious and easy to ignore. By the 2010s the focus shifted to credential theft and business email compromise. Now AI accelerates personalization and removes much of the manual grunt work. Think of it moving from a mass-market postcard to a bespoke letter that even mentions your dog.

Where vendors fit in

Defenders are adapting. Endpoint detection and cloud email gateways are adding model-driven anomaly detection and adversarial training. But beware the hype. An AI label is not a guarantee — models have blind spots, and attackers probe those gaps quickly. What’s interesting is how fast vendor claims outpace independent validation.

What enterprise leaders should do this week

  • Treat phishing as a systems problem, not only training. Combine strong MFA, conditional access, and strict approval workflows for financial requests.
  • Harden identity and privileges. Apply least-privilege, audit service accounts, and operate on the assumption that credentials will be phished sooner or later.
  • Use AI for detection — carefully. Prefer models that surface anomalies and explain why, rather than black-box yes/no answers. Always pair AI alerts with human analysts and clear escalation paths.
  • Run a tabletop for voice-deepfake scenarios. Simulate an executive-impersonation call and rehearse verification steps with finance and HR until they become second nature.
  • Measure meaningful signal, not just clicks. Track near-misses, time-to-contain, and the chain of actions that led to an incident, not only phishing click rates.

A dissenting note

Some security professionals say the panic is overblown. Most campaigns still rely on simple hooks and easy targets. AI-driven sophistication exists, but only in a subset of attacks. Still, even a small bump in success rates against high-payoff targets — finance, legal, procurement — changes the risk equation dramatically.

Market implications

Vendors that combine behavioral telemetry with models you can interrogate will build trust and win share. Expect M&A and partnership activity as legacy network vendors bolt on generative-model detection. Keep an eye on major cloud and endpoint players as they roll out new detection features; their moves will signal where the market is headed.

A practical takeaway

AI amplifies both attack capability and defensive tooling. Right now attackers have a tempo advantage — they can iterate faster. Companies that focus on identity hygiene, hardened workflows, and cautious, explainable model use will blunt most of the damage. Speed and judgement, more than raw budget, will decide who gets hurt and who weathers this wave.

Advertisement
Continue reading

Related coverage

The IMF Brief · Daily Newsletter

The AI economy, decoded before the open.

Five minutes. One email. The signal cutting through the noise at the intersection of artificial intelligence and Wall Street. Free, forever.

Join 184,000+ readers · No spam · Unsubscribe anytime