Join Doppel at Black Hat USA 2026 to win The Bigger Carry-On suitcase from Away
General

What Is AI Phishing? How Attackers Scale Social Engineering

AI phishing uses generative AI to write flawless, personalized lures across email, voice, and video. Learn how these attacks work and what stops them.

Doppel TeamSecurity Experts
August 2, 2026
5 min read

Generative AI can write a fluent phishing message in any language, personalize it from a target's public data, and clone a colleague's voice from a short recording, at a scale no manual operation could reach. One convincing message or call can hand over the credentials multi-factor authentication (MFA) protects, or approve a fraudulent payment, before anyone verifies it.

The exposure already shows in the data: the FBI's IC3 logged $16.6 billion in reported cybercrime losses in 2024, a record high, with phishing and spoofing the most-reported crime type. This article covers what AI phishing is, how an attack unfolds, why common defenses miss it, and what stops it.

Key takeaways

  • AI phishing uses generative AI to produce personalized, fluent lures across email, SMS, voice, and video.
  • It raises phishing's success rate by erasing the old language tells and carrying one pretext across trusted channels at scale.
  • Durable defense pairs out-of-band verification with campaign-level detection, infrastructure takedown, and live multi-channel rehearsal.

AI phishing is a social engineering attack built and scaled by generative AI

AI phishing is social engineering in which attackers use generative AI to create, personalize, and automate deceptive messages across email, text, voice, and video. The targets are unchanged: credentials that open the front door, and payments routed to accounts attackers control.

Once inside, they expand access. The psychology is the same; generative AI rebuilds the machinery behind it, cutting the cost and raising the hit rate of credential theft and payment fraud.

What generative AI changed about phishing

Generative AI removed four constraints that used to help defenders: it erased the language mistakes that exposed a lure, it personalizes messages from public data at scale, it extends the attack into cloned voice and video, and it lets autonomous agents run campaigns with little human effort.

AI erases the spelling and grammar tells that once exposed phishing

Employees long spotted phishing emails by poor spelling and awkward phrasing. AI now generates flawless, contextually natural content, and criminal tools automate it directly. LLM-written phishing outperforms real-world phishing on linguistic naturalness and draws lower suspicion, and AI-automated lures have reached a 54% click-through rate against 12% for standard phishing.

AI personalizes lures using data scraped from public sources

Attackers compress research that once took hours by scraping LinkedIn, press releases, earnings calls, and social posts. A small amount of public activity per target gives a model enough to mirror the target's own communication style.

A message that names a real manager and a real project reads less like a mass-blast scam, and AI-generated spear phishing now competes with expert human red teams.

Voice and video cloning push phishing past text and email

Synthetic media moves phishing onto channels email filtering cannot reach. Attackers turn an earnings call, podcast, or recorded meeting into training data for a usable voice clone, and deepfake video puts a trusted face on a live conference call.

An employee who gets a fraudulent email, a follow-up call, and a video interaction carrying one story is far more likely to accept it as real.

Autonomous AI agents launch campaigns at machine speed and scale

Agentic AI moves phishing from human-assisted to human-optional. Systems with full autonomy can plan a campaign, generate adaptive content, deliver it across channels, and refine it through feedback loops without an operator.

Scam operations using autonomous planning run multi-turn calls that adapt to a victim, evade guardrails, and complete end-to-end fraud, retrying at scale without fatigue.

The main types of AI phishing attacks

AI phishing shows up in five main forms: email phishing, spear phishing, smishing, vishing, and deepfake video phishing. Each carries the lure onto a different channel the target is used to trusting.

1. AI-generated email phishing sends flawless lures to the inbox at scale

Email remains the highest-volume vector, and AI has made it cleaner and more numerous, generating large volumes of unique, AI-generated variants of one campaign tuned by department.

Business email compromise sits at the costly end because many messages impersonate executives and vendor or finance contacts to trigger payments. Many carry no attachment or link, so signature-based tools have no artifact to match.

2. AI spear phishing tailors the attack to a specific person

Spear phishing targets one named individual, and AI has industrialized the reconnaissance behind it. A lure reading "per John's note on the Q3 vendor review, can you process the attached invoice today" sidesteps the red flags training teaches employees to watch for, precisely because the details are true.

3. AI smishing moves the lure into text messages

AI smishing carries the lure into SMS, a channel most email security never inspects. Some campaigns pair a text with a simultaneous call, keeping the target engaged on one channel while pushing a malicious link through another.

4. AI vishing uses cloned voices over the phone

AI vishing weaponizes real-time voice cloning against the phone, the channel people trust most. Attackers impersonate a known executive or help desk and layer urgency onto a familiar voice.

Targeted vishing guidance describes attackers posing as IT help desk staff, spoofing caller IDs, and steering staff to malicious links that harvest login credentials and MFA codes.

5. Deepfake video phishing puts a trusted face on the fraud

Deepfake video phishing puts a synthetic but convincing face on the fraud during a live meeting. In one attempt on a global advertising group, attackers cloned the CEO's voice, paired it with YouTube footage of him, and staged a Microsoft Teams meeting to push an executive to set up a new venture and move money.

The lure reached a live video call, entirely outside the reach of email-layer defense.

How an AI phishing attack unfolds

An AI phishing attack moves through the five stages of the social engineering attack chain: reconnaissance, weaponization, delivery, persuasion, and execution. AI compresses and sharpens each one.

Stage 1: Reconnaissance

AI removes the first bottleneck, scraping and analyzing public data faster than any manual team. Attackers map reporting lines and vendor relationships; conference recordings become voice-clone training data, and an org chart becomes raw material for a pretext.

Stage 2: Weaponization

The profile feeds tailored lure text, cloned voices built from harvested audio, and lookalike domains and phishing pages that look legitimate to users and defenses alike. Phishing-as-a-service platforms supply AI-generated email kits, and deepfake-as-a-service tools clone named executives.

Stage 3: Delivery

One campaign may start in email or text and continue through a spoofed phone call or video meeting, with attackers coordinating channels to reinforce a single story. Most tooling sees only this stage, so the campaign built earlier stays invisible until it reaches the inbox.

Stage 4: Persuasion

Attackers pair a trusted identity with manufactured urgency to shut down scrutiny, leaning on the authority and scarcity social engineers have always used, now delivered by a voice or face the target recognizes. AI extends this into multi-round conversations that adapt to the target's responses.

Stage 5: Execution

The target enters credentials on a convincing login page, or approves the payment or access the attacker asked for. Because phishing-initiated breaches can take months to identify and contain, attackers often operate inside a network long before the door closes.

Why AI phishing defeats traditional defenses

Most enterprise defenses miss AI phishing for four connected reasons:

1. Email Filters Hunt for Known-Bad Signatures AI Phishing Doesn't Carry

Signature-based filters break against polymorphic generation. AI produces a unique variant per recipient, weakening the pattern-matching filters depend on, and many attacks mutate as they probe defenses.

Attackers route lures through trusted-looking domains, and payload-free BEC messages carry no artifact to match.

2. The lures span channels email security never inspects

Email-layer defenses cover only the email slice of a broader attack surface. SMS, voice, WhatsApp, Slack, Microsoft Teams, and deepfaked video create interactions gateway filters never see. A deepfaked CFO on a video call, or a cloned voice on the phone, bypasses controls that only read email.

3. Awareness training runs on tells that no longer apply

AI has erased the spelling errors and generic phrasing employees were trained to catch, and personalization removes the sense that a message is a mass blast. When attackers launch large volumes of unique, targeted lures at once, some reach even well-trained staff.

Training has to evolve with current lures and channels.

4. Manual detection and takedown lag AI campaigns

Manual response runs on analyst queues, abuse reports, registrar coordination, and legal escalation while attackers regenerate domains, pages, messaging accounts, and phone numbers at machine speed.

Takedowns stretch across days, and attackers redeploy the same infrastructure elsewhere soon after removal.

What it takes to defend against AI phishing

Defending against AI phishing takes four moves working as one system: detect and dismantle phishing infrastructure across every channel, correlate scattered signals into campaign-level takedowns, verify high-stakes requests through a separate channel, and rehearse the workforce against live AI-generated lures.

Detect and dismantle phishing infrastructure across every channel

Defenders need coverage across the domains, spoofed pages, social profiles, messaging accounts, ads, and telco assets where attackers stage campaigns. Content-level signatures increasingly fail against fluent lures, but campaign-level signals like infrastructure reuse, timing, and delivery anomalies stay detectable at scale.

The job is to find the lookalike domains, spoofed pages, cloned voices, and malicious profiles, then dismantle them before a lure lands.

Correlate scattered signals to disrupt full campaigns

A single impersonation domain usually connects to linked phone numbers, messaging accounts, social profiles, and ad campaigns on the same infrastructure. Correlating those fragments into one campaign view lets a defender dismantle the whole operation in one action, so defenders stop chasing individual assets while the actor stands up more.

Verify high-stakes requests through a separate, trusted channel

Out-of-band verification works even when the content looks indistinguishable from the real thing. If a call requests a wire transfer, confirm by email; if an email requests credentials, confirm by phone on a known number. This defeats many deepfake attacks because an attacker usually controls only one channel.

For fund transfers, add step-up verification on a second trusted channel.

Rehearse the workforce against live AI-generated lures

Employees build resistance by rehearsing against the attacks actually in circulation. Simulations that still look like old templates train people for threats that have already moved on.

Multi-channel simulations that include AI-generated email and voice, deepfake exercises among them, give teams the recognition they need before they meet the real thing.

How Doppel defends enterprises against AI phishing

Doppel is the AI-native Social Engineering Defense (SED) platform built for these requirements. It unifies Digital Risk Protection and Human Risk Management on one intelligence layer, detecting AI-driven phishing infrastructure across email, web, social, and messaging before a lure lands. That coverage spans lookalike domains, spoofed pages, malicious profiles, and voice-cloning signals.

The Doppel Threat Graph turns scattered signals into campaign-level takedowns. When the platform surfaces an impersonation domain, the Threat Graph maps the connected telco numbers, messaging accounts, social profiles, and ad campaigns on the same registrar, then takes them all down in one action, freeing analysts for the escalations that need human judgment.

Legacy workflows often miss telcos, leaving a campaign's SMS leg live; direct telco relationships bring it down with the rest.

The platform then converts the attacks it finds into training. Any threat Doppel detects becomes an employee simulation in one click, so today's live lure is what the workforce rehearses against tomorrow, on the same channels attackers use.

Doppel's voice agents run adaptive calls using deepfake voice clones, including ones built from a customer's own executives from a short audio sample, and pivot mid-call to SMS or email when a target pushes back. Microsoft Teams and Zoom scenarios extend testing to the surfaces where deepfake video now lands.

Treat every channel and identity as untrusted

Security leaders need to verify a message, a call, or a face through controls that do not depend on how real it looks or sounds. AI has erased the surface tells that once made trust safe, and employees now face attacks technical filters may not catch.

The teams that pull ahead will run detection, infrastructure disruption, and workforce response as one system, and dismantle phishing infrastructure until the economics turn against the attacker. Attackers already treat your brand, your executives, and your employees as one connected attack surface.

Request a demo to see the platform defend it as one.

Last updated: August 2, 2026

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.