Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Generative AI is making it easier for attackers to produce targeted, convincing phishing at scale, but it has not made email security a problem that AI can solve alone. Organizations need layered defenses: email and activity monitoring, identity controls, well-practiced response procedures, and users who know to question unexpected support requests and authorization prompts. Microsoft reported a 54% click-through rate for AI-automated phishing emails versus 12% for standard attempts in its 2025 report; those are Microsoft’s observed rates, not a universal benchmark for every campaign or organization.

How is generative AI changing email security?

AI can help an attacker tailor a message, improve its wording, and produce more variations with less effort. That raises the potential scale and quality of phishing, but it does not mean every phishing email is AI-generated—or that AI is required for a successful attack. The U.S. Government Accountability Office (GAO) describes the broader risk: “paired generative AI systems could autonomously create and deliver phishing emails.” It also cautions that “Even with safeguards in place, no current generative AI systems are immune to such misuse.”

Microsoft’s Digital Defense Report 2025 reported a 54% click-through rate for AI-automated phishing emails and 12% for standard attempts—4.5 times higher in that report’s comparison. These are publisher-reported observations in Microsoft’s study context, not rates that organizations should expect from their own users or a prediction for any particular campaign.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Separate FBI Internet Crime Complaint Center (IC3) figures offer context about AI-related crime, but not email phishing specifically. The FBI reported 22,364 AI-related complaints and nearly $893 million in losses for 2025 data in April 2026. The same reporting put losses from all cyber-enabled crimes at nearly $21 billion. Neither figure is an email-only total, and they should not be read as a measure of how much phishing uses generative AI.

Can AI-generated phishing bypass email filters?

A convincing message may be harder for a person or a filter to identify by appearance alone, especially if it uses plausible wording and context. But the available evidence does not establish how often AI-generated phishing bypasses filters or that AI automatically defeats them. Filtering remains useful; it should be one layer in a system that also looks for suspicious identity activity, authorization events, and changes made after delivery.

Look beyond grammar and spelling

Awkward wording can still be a warning sign, but polished grammar is not proof that a message is legitimate. Users and security teams should pay attention to the request and its context: an unexpected support contact, a request to approve access, or a prompt to enter a code can be more important than whether the text reads naturally.

Rank #2
Securing Email with Email Security Appliance 300-720 SESA Study Guide Flashcards
  • Pass the Securing Email with Email Security Appliance 300-720 SESA with updated flashcards packed with detailed content aligned to the latest exam blueprint. Cover all core topics without the overload found in lengthy study guides. Get 300+ Securing Email with Email Security Appliance 300-720 SESA flashcards on 8-1/2″ x 11″ perforated card stock.

Recognize attacks that unfold in stages

Microsoft describes email bombing as a way to overwhelm a target with newsletters or service sign-ups, potentially burying security alerts, MFA prompts, password resets, fraud notices, or transaction messages. The flood can be followed by a fake IT-support contact and an attempt to persuade the target to install a remote access tool. Treating each event as an unrelated nuisance can obscure the sequence; correlating the inbox flood, support contact, and later activity can help reveal it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How can phishing lead to Microsoft 365 account takeover?

The FBI’s May 21, 2026, Kali365 alert describes a device-code phishing flow that can steal access without asking for a victim’s password. An attacker impersonates a trusted cloud or document service and directs the target to enter a device code on a legitimate Microsoft verification page. The victim may believe they are authorizing access to a document, while the attacker captures OAuth access and refresh tokens.

Rank #3
Securing Email with Email Security Appliance Study Guide Flashcards
  • Pass the Securing Email with Email Security Appliance with updated flashcards packed with detailed content aligned to the latest exam blueprint. Cover all core topics without the overload found in lengthy study guides. Get 300+ Securing Email with Email Security Appliance flashcards on 8-1/2″ x 11″ perforated card stock.

According to the FBI, stolen tokens can enable persistent access to Microsoft 365 services such as Outlook, Teams, and OneDrive without another password or MFA challenge. This is why a legitimate verification page does not, by itself, make an unexpected authorization request safe: the key question is whether the user initiated and understands the sign-in or access flow.

How are companies using AI to detect phishing?

AI can be part of a defensive system that helps analyze messages and surface suspicious activity, but it should not be treated as a standalone phishing detector. A useful defense also considers what happens across email, identity, and collaboration services—for example, whether a suspicious message is followed by an unusual authorization, an inbox-rule change, or other account activity. The cited sources do not establish which commercial product performs best or provide a controlled comparison of vendor detection rates.

Rank #4
Sophos XGS 108 (Gen2) Network Security Appliance with 1 Year Xstream Protection (XX108Z12ZZPCUS) | 6 x 2.5 GE Ports + 1 SFP | Next-Gen Protection, SD-WAN, Secure VPN, Centralized Management
  • XGS 108 with 1 Year Xstream Protection - Next-generation firewall appliance with Xstream Protection subscription providing zero-day defense, cloud sandboxing, email filtering, intrusion prevention, and advanced reporting, managed through Sophos Central for unified policies and reporting.
  • 6 x 2.5 GE copper ports and 1 SFP fiber port, supporting up to 12.5 Gbps firewall performance for growing business networks.
  • Zero day protection with cloud sandboxing, email filtering, and advanced reporting for full enterprise coverage.
  • TLS inspection and next generation intrusion prevention block hidden threats in encrypted traffic and stop sophisticated attacks.
  • Includes Xstream Protection – Advanced security bundle with zero-day protection, cloud sandboxing, email filtering, and automated threat response, providing full coverage against the most sophisticated cyberattacks.

When assessing a service, compare its coverage and operating requirements rather than relying on a general claim that it “uses AI.” Ask how it fits your environment and how analysts can investigate a detection:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Platform and deployment: Confirm compatibility with the organization’s email platform and understand how the service is deployed.
  • Coverage: Check whether it addresses email, identity, collaboration tools, and post-delivery response—not just message screening.
  • Account-compromise signals: Ask whether it can help identify suspicious OAuth authorization, inbox-rule changes, and impersonation alongside suspicious messages.
  • Identity administration: Verify what controls it provides or supports for device-code authentication and conditional access.
  • Investigation workflow: Evaluate false-positive handling, employee reporting, and the context available to responders.
  • Data and operations: Review data handling, retention, privacy, and the staffing or process changes the service requires.
  • Evidence: Look for independent evaluations with transparent methods. Vendor marketing claims are not equivalent to controlled comparative results.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should organizations do about AI-powered phishing?

Start with controls that limit the consequences of a successful lure, then make sure employees and responders can identify and connect suspicious events. The FBI’s device-code recommendations apply to the specific flow in its Kali365 alert; organizations should assess their legitimate dependencies before changing authentication policy.

Best Value
Sophos XGS 88W (Gen2) Wireless Security Appliance with 1 Year Xstream Protection (XY88ZZ12ZZPCUS) | 4 x 2.5 GE Ports | Built-in Wi-Fi 6, SD-WAN, Secure VPN, Central Cloud Management
  • XGS 88W with 1 Year Xstream Protection - Next-generation firewall appliance with Xstream Protection subscription providing zero-day defense, cloud sandboxing, email filtering, intrusion prevention, and advanced reporting, managed through Sophos Central for unified policies and reporting.
  • Built in Wi Fi 6 with 4 x 2.5 GE copper ports, delivering up to 9.9 Gbps firewall performance for secure wired and wireless networks.
  • Zero day protection with cloud sandboxing, email filtering, and advanced reporting for full enterprise coverage.
  • TLS inspection and next generation intrusion prevention block hidden threats in encrypted traffic and stop sophisticated attacks.
  • Includes Xstream Protection – Advanced security bundle with zero-day protection, cloud sandboxing, email filtering, and automated threat response, providing full coverage against the most sophisticated cyberattacks.

1. Review device-code authentication and conditional access

For the FBI-described device-code scenario, the agency advises organizations to consider restricting or blocking device-code flow. It recommends auditing legitimate dependencies before applying a restriction, blocking authentication transfer policies, and avoiding lockout of emergency accounts. The FBI’s wording is direct: “Restricting device code flow to limit or block device authentication codes can help prevent or limit this style of attack.” Adapt these controls to business needs and test their effect on legitimate sign-ins.

2. Connect email and identity events

Monitor for related events as a sequence, rather than relying only on a verdict assigned to one message. Microsoft recommends correlating activity around email bombing, fake support contact, and remote access tool installation. Its report also recommends filtering inbox floods and controlling external Teams exposure.

3. Prepare users for unexpected support and authorization requests

Microsoft recommends educating employees about fake IT-support scams. Make the reporting route clear, and teach staff to pause when an unsolicited support contact asks them to install a tool, enter a device code, or approve access. An unexpected prompt should be verified through a trusted channel rather than through contact details or links in the message.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Limit and monitor remote management tools

Microsoft recommends limiting the use of remote monitoring and management tools. Organizations should know which tools are authorized and have a process for investigating an installation or use that follows a suspicious support interaction.

5. Treat defenses as ongoing work

GAO characterizes malicious use of generative AI as an evolving problem and says safeguards and defenses require continuous development and resources. A filter, training session, or policy update is not a permanent solution: review controls and response procedures as threats and business requirements change.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.