Cybersecurity · Threat Landscape

Why phishing still presents a significant risk

Written by the Mono training team · · 15 min read Share
Executive summary Despite decades of cybersecurity investment, phishing remains one of the most effective and persistent vectors of cyberattack. As attackers evolve their tactics — increasingly leveraging AI, personalised social engineering, multi-channel delivery, and deepfake techniques — organisations continue to face meaningful risk across every industry. This article looks at why phishing endures, how it has developed over time, what the current data shows, and the role well-designed simulation programs play in building real resilience.
Data sources
Hoxhunt Phishing Trends Report (2026)·Verizon Data Breach Investigations Report (2025)·IBM Cost of a Data Breach Report (2025)·ASD's ACSC Annual Cyber Threat Report 2024–25
Figures reflect publicly reported research as of mid-2026. Findings evolve — verify current studies before citing externally.
01The oldest trick still works

What phishing is, and why it still works

At its core, phishing is a form of social engineering in which attackers deceive people into disclosing sensitive information, credentials, or performing an unsafe action. It remains effective because it exploits human psychology — trust, urgency, authority, and convenience — rather than a technical vulnerability.

By early 2026, an estimated 82.6% of phishing emails showed signs of AI assistance.

According to Hoxhunt's 2026 Phishing Trends Report, AI-generated phishing surged roughly fourteenfold in a single month at the end of 2025 — and that share has held into 2026. AI removes the classic warning signs: clumsy grammar and obvious errors are gone, replaced by fluent, personalised messages produced faster than any human team could write them.

02From spam to spear

The evolution of phishing: from generic emails to multi-channel attacks

Phishing has evolved far beyond the poorly crafted mass emails of the past. Today's attacks are targeted, AI-enhanced, and delivered across multiple channels at once.

Era one

Classic email phishing

Mass emails with obvious errors and generic subjects. As awareness of basic cues improved, attackers adapted by making lures contextual and targeted.

Era two

Spear phishing & BEC

Highly targeted attacks using social media and corporate data to build legitimacy. Business Email Compromise is now one of the most financially damaging attack classes.

Era three

AI-enhanced & multi-channel

Generative AI produces convincing messages at speed. Modern phishing spans email, SMS, voice, collaboration tools, and deepfake media — often in the same campaign.

Modern phishing now routinely extends to:

SMS (smishing) Voice calls (vishing) Collaboration tools Fake web pages Deepfake media Multi-channel campaigns
03Where the numbers sit right now

Phishing trends in 2025 and 2026

Organisations worldwide continue to face significant phishing volumes. In Australia, ASD's ACSC received more than 84,700 cybercrime reports in FY2024–25 — roughly one every six minutes — with phishing, compromised accounts, and identity-information gathering among the top three techniques observed across both government and non-government incidents.

14×

surge in AI-generated phishing volume in a single month at the end of 2025.

Hoxhunt Phishing Trends Report, 2026
$4.88M

average cost of a data breach that started with a phishing email.

IBM Cost of a Data Breach Report, 2025
84,700

cybercrime reports received by ASD's ACSC in FY2024–25 — one every six minutes.

ASD's ACSC Annual Cyber Threat Report 2024–25

Internal-themed lures — messages posing as HR or IT — dominated simulation failures through 2025, reflecting a deliberate emphasis on familiarity and trust. Campaigns increasingly use QR codes and redirect chains to obscure malicious URLs and slip past MFA controls.

04Why the click still happens

The human factor and risk exposure

Phishing remains widely successful because the people being targeted still find it hard to distinguish malicious from legitimate communication — even experienced, digital-native users, particularly when attackers use AI-generated text and contextually accurate detail.

Convenience over caution
Trust in familiar brands
Lack of reinforcement
Low threat visibility

Verizon's 2025 Data Breach Investigations Report found phishing implicated in 36% of all breaches analysed — a reminder that awareness alone, without reinforcement, isn't closing the gap.

05Beyond the inbox

The real-world impact of phishing attacks

Phishing is not a theoretical risk — it directly contributes to data breaches, credential theft, ransomware, and BEC losses. Credential theft, frequently initiated via phishing, remains one of the fastest-growing categories of breach in 2025 and 2026 data.

In some recent large-scale incidents, phishing was the entry point to data compromise affecting millions of customer records.

Economically, an attack that starts with phishing can result in loss of sensitive data and intellectual property, direct financial fraud, disrupted operations, and regulatory or reputational damage — often all at once.

06What actually reduces risk

Phishing simulations and organisational resilience

A growing body of evidence shows that well-executed phishing simulation programs meaningfully improve organisational resilience — not as a compliance exercise, but as a measurable behaviour-change tool.

87%

reduction in malicious clicks among organisations using behaviour-based training.

Hoxhunt, within 6 months

improvement in real-world threat reporting over the same period.

Hoxhunt, within 6 months
33.1%→4.1%

drop in phish-prone rate after 12 months of sustained training.

KnowBe4, 2025

The programs that produce these outcomes share four traits: realistic scenarios that mirror current threat patterns, immediate feedback explaining why a lure was malicious, targeted follow-up training based on results, and continuous measurement and refinement. Organisations that treat this as iterative — rather than a once-a-year event — see measurable gains in both detection and reporting, shifting the culture from compliance-driven to behaviour-driven.

07Where this is heading

Outlook and strategic imperatives for 2026

As phishing tactics keep evolving, organisations need layered, dynamic strategies rather than a single annual training event:

Train beyond email — voice, SMS, collaboration tools Use behavioural analytics to spot anomalies Keep simulations current with live threat intelligence Coach, don't punish

AI-augmented phishing and multi-vector campaigns are very likely to keep accelerating through the rest of the decade — which makes human awareness and adaptive training more critical to organisational defence, not less.

Key takeaways

What this means for your organisation

01

Phishing targets human decision-making

No amount of technical investment removes the need to train your people — phishing exploits psychology, not just technology.

02

AI has made attacks more convincing

Over 82% of phishing emails now show signs of AI assistance. Generic awareness training is no longer enough on its own.

03

Simulations must be realistic and current

Scenarios built from live threat intelligence produce measurably better outcomes than recycled templates.

04

Behaviour change requires reinforcement

One-off training produces one-off results. Sustained, iterative programs cut malicious clicks by up to 87% within six months.

Enjoyed this article?

See how Mono addresses the phishing challenge directly.

Click or Flick Corporate is built on intelligence-driven simulations, human-led support for high-risk employees, and behaviour change that lasts beyond the training session. If this resonated, the program page is the natural next step.