For years, the advice for spotting a scam email was almost comforting. Look for the bad grammar, the weird phrasing, the too-good-to-be-true urgency. Those tells worked because the attackers were often working in a second language, at volume, with no time to polish.
Generative AI erased every one of those tells. The phishing email that lands in your finance manager's inbox now is fluent, personalised, correctly branded, and references a real project by name. The voice on the phone authorising a payment sounds exactly like your CEO because it is a clone of your CEO's voice. This is the uncomfortable centre of cybersecurity in 2026: the same technology making your team more productive is making the people attacking your team dramatically more dangerous.
How the attacks changed
The shift isn't that new kinds of attacks appeared. It's that the old ones got supercharged. AI took the friction out of deception, and deception is most of what attackers do.
Four things got much worse, fast:
- Phishing at scale. Generative AI writes convincing, tailored messages by the thousand, each one personalised to the target. The result is that roughly 82.6% of phishing in 2026 is AI-driven, and the old "spot the typo" advice is now useless.
- Deepfake voice and video. Attackers clone a voice or face and impersonate an executive on a call or video, authorising fraudulent transfers in real time. In one study, 26% of executives targeted by deepfake scams said the attacker's goal was to trigger an unauthorised transfer.
- Synthetic identities. AI generates entire fake personas, complete with believable profiles, used for fraud and opening accounts that don't belong to anyone real.
- Speed and volume. What used to take a skilled attacker days now takes minutes. The economics of attacking flipped, and that means more attempts against more targets, including small ones.
The fear is widespread and, for once, justified. A Cobalt survey found 97% of cybersecurity professionals worry their organisation will face an AI-driven incident, and 93% expect to see daily AI attacks. Industry reporting noted a 118% jump in AI-driven phishing and deepfake activity. This is not a future problem.
Why the old playbook falls short
The reason this is genuinely hard is that most security awareness training was built to catch clumsy fakes. "Check for spelling mistakes" and "does the sender address look odd" are advice for a world where fakes were obviously fake. When the email is flawless and the voice is perfect, you cannot ask a human to eyeball their way to safety anymore.
The other problem is emotional. These attacks are engineered to push exactly the right psychological button: urgency from the boss, a vendor with a plausible invoice, a colleague who needs a favour right now. The polish plus the pressure is what gets people. So the defense has to change shape too.
The defenses that actually hold up
Here's the more hopeful half of the story. AI cuts both ways, and defenders have real tools. The strongest posture combines technology, process, and people, because no single layer is enough on its own.
| Layer | What it does | Why it matters now |
|---|---|---|
| Adaptive email filtering | AI that learns from the newest attack patterns | Catches AI-written phishing that rule-based filters miss |
| Phishing-resistant MFA | Hardware security keys, not just SMS codes | A stolen password or cloned voice can't defeat a physical key |
| Identity and endpoint monitoring | Flags unusual logins and device behaviour | Spots the breach even when the lure succeeded |
| Human awareness training | Teaches out-of-band verification habits | The last line when the fake is technically perfect |
Two of those deserve extra emphasis, because they're where most real breaches are won or lost.
Phishing-resistant MFA is the single highest-value move. If your logins require a hardware security key rather than a text-message code, a stolen password becomes almost worthless, and no cloned voice can talk its way past a physical device. It's not glamorous and it's not expensive, and it stops a huge share of attacks cold.
The verification habit beats every fake. The one rule that defeats deepfakes is deceptively simple: any request involving money or access gets verified through a second, separate channel. The "CEO" calls asking for an urgent transfer? You hang up and call back on the known number. The vendor emails new bank details? You confirm by phone using the contact you already had. Deepfakes are convincing in the moment they control. They fall apart the second you step outside that channel.
A practical checklist for a normal business
You don't need an enterprise security team to be meaningfully safer. If you run a small or mid-sized business, this is the list that matters:
- Turn on phishing-resistant MFA everywhere you can, starting with email, banking, and admin accounts.
- Write down a verification rule for money and access requests, and make sure everyone knows it: second channel, always, no exceptions for "urgency."
- Use AI-powered email filtering that updates with new attack patterns rather than static rules.
- Train your people on the new reality, that fakes are now flawless, so the defense is process and verification, not spotting typos.
- Monitor for the odd login, so a successful lure doesn't quietly become a month-long breach.
None of these are expensive. All of them are more effective than hoping your team will eyeball a perfect fake and somehow know.
The bottom line
Generative AI didn't invent fraud, it industrialised it. The lures are flawless now, the voices are real, and the volume is relentless. But the response isn't to panic, it's to stop relying on human suspicion of sloppy fakes and start relying on things that work regardless of how good the fake is: hardware-backed logins, out-of-band verification, adaptive filtering, and a team that's been told the truth about what they're up against.
The organisations that get breached in 2026 won't be the ones that lacked expensive tools. They'll be the ones still training their people to look for typos. Update the playbook, and most of this threat becomes manageable.