AI Security & Cyber Threats · AI-Generated Phishing & Social Engineering
Are AI generated phishing attacks increasing the volume of scams companies see
Yes — security researchers have documented a genuine increase in phishing volume attributable to AI, since generative tools let attackers produce large numbers of personalized, well-written attempts far faster than manual scam creation ever allowed.
Key takeaways
- AI has measurably lowered the cost and time required to produce a convincing phishing attempt.
- This has translated into documented increases in phishing volume that security teams track.
- Personalization at scale, not just volume, is the more significant shift.
- Detection tools have had to adapt in parallel to keep pace with the increased volume.
A Documented, Measurable Increase
Security researchers and threat intelligence firms have documented a genuine increase in phishing volume attributable to generative AI, since these tools let attackers produce large numbers of grammatically flawless, contextually plausible attempts far faster than manual scam-writing ever allowed, at a fraction of the time and skill it used to require.
Why Personalization Matters More Than Raw Volume
The more significant shift isn’t just quantity — it’s that AI lets attackers cheaply personalize each attempt using scraped public information about a specific target, a level of tailoring that previously required meaningful manual research per victim, making a targeted attempt look genuinely credible rather than obviously generic.
How This Changes the Economics of Scamming
Because AI collapses the time and skill required to produce a convincing, personalized attempt, it lowers the barrier to entry for less-skilled attackers while also letting sophisticated ones scale their operations far beyond what manual effort would allow.
The Response From Security Teams
Detection tools and employee training programs have had to adapt in parallel, since the traditional advice to “look for spelling and grammar errors” has become considerably less reliable as a detection heuristic against AI-generated attempts.
Bottom Line
The evidence supports a real, documented increase in phishing volume driven by AI, but the more consequential change is the personalization AI enables at scale — a shift that has pushed both detection tools and employee training to evolve past older, now less-reliable warning signs like obvious spelling and grammar mistakes.
Go deeper
Frequently asked questions
Is volume or sophistication the bigger concern?
Both matter, but many security researchers consider the personalization AI enables — tailoring an attempt to a specific target using scraped information — a bigger shift than raw volume alone.
Related questions
- What makes AI generated phishing harder to spot than traditional phishing?
- How realistic have AI-generated phishing emails become?
- Can AI detect AI-generated phishing attempts?
- Can AI clone someone's voice well enough to fool a phone call verification?
- Why are AI chatbots themselves becoming targets for social engineering scams?
- How are deepfakes being used in business email compromise scams?
Sources
- [1]Cybersecurity guidance — Cybersecurity and Infrastructure Security Agency
- [2]AI security research — National Institute of Standards and Technology
Written by Editorial Team
Last updated July 30, 2026
Get one well-sourced answer a week
No spam. Unsubscribe anytime.