
Phishing testing in the age of AI-generated scams
15 September 2026
For years, the advice on spotting a phishing email was fairly simple: look for the spelling mistakes, the odd phrasing, the sender address that's almost right but not quite. That advice is now largely useless, and the data backs that up plainly. Microsoft's Digital Defense Report found AI-generated phishing emails get clicked 54% of the time, compared with 12% for manually written ones, and that AI-generated spear-phishing began outperforming expert human red-teamers for the first time in early 2025. Separately, CybelAngel's analysis found over 80% of phishing emails detected recently used AI generation, up more than 50% year on year.
If your last phishing simulation used the old templates, the misspelled "urgent invoice" email, the generic "your password expires today" link, it's testing a threat that's mostly gone. Here's what's actually changed, and what testing needs to look like now.
Why the old signals stopped working
AI tools removed the two things that used to give phishing away: bad grammar and generic phrasing. A modern phishing email can be personalised, well written, and reference real names, real deals, or real internal projects, because the attacker had an AI tool draft it after scraping publicly available information about your business. Voice cloning has done the same thing to phone-based fraud. There are now documented cases of finance staff receiving calls that convincingly mimicked an executive's voice, authorising a wire transfer that turned out to be entirely fraudulent.
Why financial services firms are a specific target
Attackers aren't spraying these attempts evenly across every employee. Darktrace's telemetry across financial sector clients found nearly 30% of phishing attempts were aimed specifically at executives and finance staff with payment authority, not the general workforce. That's a deliberate choice: a hedge fund, family office or insurer typically has fewer formal verification layers around a large wire transfer than a retail bank does, and the people who can authorise one are identifiable from a LinkedIn profile in minutes.
The gap between the threat and the defence
According to the AFP's 2026 Payments Fraud and Control Survey, only 17% of organisations affected by payments fraud in the past year had deployed AI-aware defences. Most businesses are still running detection built for the old, sloppier version of phishing. That gap matters more now than it used to, because the attacks have got harder to spot with the naked eye, at exactly the moment defences haven't caught up.
New phishing-as-a-service operations are making this worse still. One recent example, tracked by researchers under the name BigBear 2.0, has targeted hundreds of organisations across more than 40 countries, stealing thousands of credentials including cases where standard MFA was bypassed entirely, by intercepting the session itself rather than trying to guess a password. Standard MFA, a text message code or an app-based one-time code, doesn't stop this kind of attack, because the attacker is sitting invisibly between the victim and the real login page, capturing the session as it happens.
What phishing testing actually needs to look like now
A once-a-year test using a generic template tells you very little about whether your team can spot a targeted, well-written, AI-assisted attempt. What actually holds up:
- Simulations that mirror real tactics: personalised spear-phishing referencing plausible internal detail, not a generic template
- Multi-channel tests, not just email, since real attacks increasingly combine email, text and phone calls in sequence
- Mandatory out-of-band verification for any payment or bank detail change, a callback to a known number, regardless of how convincing the request looks or sounds
- Phishing-resistant authentication (hardware keys or passkeys) for anyone with payment authority, rather than SMS or app-based codes
- Training aimed specifically at the people attackers are actually targeting, finance staff, executive assistants, principals, rather than a single generic company-wide module
Where we come in
We run phishing simulations that reflect current attacker tactics, not templated ones from a few years ago, and help clients move payment-authority staff onto phishing-resistant authentication. If your last test still used the obvious misspelled email, it's worth finding out how your team handles something that actually sounds like it's from someone they know.