Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Generative AI is making phishing cheaper, faster and more convincing, but it has not made every scam flawless or proved that AI caused a worldwide increase in phishing. Criminals can use models to draft and translate lures, tailor messages to targets, create synthetic voices and video, and automate parts of social engineering. The strongest evidence shows an amplifier of established impersonation and credential-theft tactics—not a measured global percentage of phishing that is AI-generated.

How is AI being used in phishing?

AI helps operators remove time-consuming steps from a familiar attack chain. A criminal can generate an initial message, produce variants for different audiences, translate them, adjust tone after a reply and support a larger targeting operation. The FBI says criminals use AI-generated text for social engineering, spear phishing and financial-fraud schemes because it can appear believable and overcome common warning signs (FBI IC3, December 3, 2024).

Writing and editing the lure

Models can produce polished messages in natural language, correct grammar, imitate a business style and create multiple subject lines or calls to action. That matters because awkward wording and spelling errors have traditionally been useful clues. Good prose does not prove legitimacy, however: an authentic-looking message can still direct you to a fraudulent site or request a secret.

Personalization and translation

AI can adapt a lure to a role, language, industry or current event. This supports both broad campaigns and more targeted spear phishing. It can also help an operator answer questions in a conversation, making a scam feel less like a one-off email and more like a genuine exchange.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Scaling delivery and experimentation

Automation lets criminals generate and test many variants rather than manually writing each one. The Australian Signals Directorate’s Australian Cyber Security Centre describes social engineering as a longstanding threat that is becoming easier to use at scale, in part because of AI technologies (Annual Cyber Threat Report 2024–2025).

Can AI create more than email text?

Yes. Official advisories describe a broader set of synthetic-media and automation capabilities. Singapore’s Cyber Security Agency says threat actors can generate convincing phishing lures at scale, produce realistic voice clones and video deepfakes, and develop tools intended to bypass multi-factor authentication (CSA press release, 2026).

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Images: fabricated invoices, profile photographs, identity documents or branded graphics can support an impersonation.
  • Voice: a cloned voice may be used in a phone call or voice message that appears to come from an executive or family member.
  • Video: a deepfake can add apparent authority to a request for money, credentials or urgent action.
  • Chatbots: fraudulent sites can use automated conversation to answer objections and keep a target engaged.

These techniques do not all appear in every campaign. They are additional tools around the same goals: persuading someone to disclose information, transfer money, install software or approve an access request.

Is AI creating a new kind of phishing?

Mostly, it is strengthening old methods. Impersonation, urgency, credential theft and confidence schemes predate generative models. A UK government assessment forecast that, by 2025, generative AI would be more likely to amplify existing risks than create wholly new ones, while sharply increasing the speed and scale of some threats (UK Government risk assessment). That statement is a dated forecast, not a current measurement of all phishing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

A 2026 U.S. Government Accountability Office summary cites an academic study estimating that generative AI could reduce malicious users’ costs of conducting phishing attacks by more than 95% (GAO, Science & Tech Spotlight: Malicious Use Of Generative AI). This is a study estimate, not evidence that real-world campaign costs universally fell by that amount or that attack volume rose accordingly.

What do the reported numbers actually show?

Available figures describe different places, periods and reporting systems. They cannot be combined into a global AI-phishing rate.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Source and measure Reported figure What it means
Singapore CSA, 2025 Approximately 4,800 phishing attempts, down 21% from about 6,100 in 2024 A national reported-attempt count for that year; it does not identify which attempts used AI.
ASD/ACSC, FY2024–25 Phishing recorded in 60% of incidents handled A share of the agency’s incident caseload, not population-wide prevalence or a global rate.
Singapore CSA, 2023 Approximately 4,100 reports, down 52% from 8,500 in 2022 and about 30% above 2021 A local year-over-year series. CSA said the decline differed from a global trend it associated partly with generative-AI chatbots, but the release did not prove AI caused that trend.

None of these sources establishes what proportion of worldwide phishing is AI-generated. Keep three questions separate: what AI can do, where authorities have observed it being used, and how common it is across all campaigns.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Are AI phishing scams harder to spot?

They can remove some obvious clues, especially poor grammar, unnatural translation and repetitive copy. Synthetic voice, video and realistic branding can also make a request feel familiar. But AI does not make a message automatically trustworthy, and writing style alone is not a reliable detection test.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Use the request and the channel as evidence. Unexpected urgency, a demand for passwords or one-time codes, a new payment destination, a link whose domain does not match the claimed organization, or instructions to bypass normal approval are warning signs whether a human or a model wrote the message. Verify through a separately sourced phone number or website, not through contact details in the message.

How can I recognize and report a phishing message?

Before responding

  1. Pause when a message creates pressure, secrecy or an unusual financial or account request.
  2. Check the sender address, reply-to address, destination domain and attachment before opening anything.
  3. Contact the person or organization through a known channel and ask whether the request is genuine.
  4. Do not provide passwords, authentication codes, payment details or remote access in response to an unsolicited message.

If you suspect social engineering

The Australian Cyber Security Centre advises targets not to engage, not to delete or forward the communication, and to report it immediately to their organization’s cyber-security or IT support team. Preserve the original message and relevant headers where possible so investigators can examine it (ASD/ACSC Annual Cyber Threat Report 2024–2025).

If money or personal information was lost

Contact your bank or payment provider promptly, secure affected accounts and retain transaction and message records. In the United States, the FBI’s Internet Crime Complaint Center asks financial-fraud victims to file a report with available details (FBI IC3 advisory). Elsewhere, use your national cybercrime or fraud-reporting service and your organization’s incident process.

What this means for organizations

Controls designed around misspellings or obvious bulk mail are no longer enough. Organizations should combine technical filtering with phishing-resistant authentication where feasible, strong payment and account-change verification, least-privilege access, rapid reporting channels and regular awareness exercises. Training should teach employees to verify context and requests, not to rely on spotting a particular “AI writing style.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The practical conclusion is narrower than the headline sometimes suggests: AI gives familiar phishing operations more reach and adaptability, while defenders still have opportunities to interrupt the request, verify the person behind it and contain a compromised account.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.