What phishing is, and why it still works
At its core, phishing is a form of social engineering in which attackers deceive people into disclosing sensitive information, credentials, or performing an unsafe action. It remains effective because it exploits human psychology — trust, urgency, authority, and convenience — rather than a technical vulnerability.
By early 2026, an estimated 82.6% of phishing emails showed signs of AI assistance.
According to Hoxhunt's 2026 Phishing Trends Report, AI-generated phishing surged roughly fourteenfold in a single month at the end of 2025 — and that share has held into 2026. AI removes the classic warning signs: clumsy grammar and obvious errors are gone, replaced by fluent, personalised messages produced faster than any human team could write them.
The evolution of phishing: from generic emails to multi-channel attacks
Phishing has evolved far beyond the poorly crafted mass emails of the past. Today's attacks are targeted, AI-enhanced, and delivered across multiple channels at once.
Classic email phishing
Mass emails with obvious errors and generic subjects. As awareness of basic cues improved, attackers adapted by making lures contextual and targeted.
Spear phishing & BEC
Highly targeted attacks using social media and corporate data to build legitimacy. Business Email Compromise is now one of the most financially damaging attack classes.
AI-enhanced & multi-channel
Generative AI produces convincing messages at speed. Modern phishing spans email, SMS, voice, collaboration tools, and deepfake media — often in the same campaign.
Modern phishing now routinely extends to:
Phishing trends in 2025 and 2026
Organisations worldwide continue to face significant phishing volumes. In Australia, ASD's ACSC received more than 84,700 cybercrime reports in FY2024–25 — roughly one every six minutes — with phishing, compromised accounts, and identity-information gathering among the top three techniques observed across both government and non-government incidents.
surge in AI-generated phishing volume in a single month at the end of 2025.
Hoxhunt Phishing Trends Report, 2026average cost of a data breach that started with a phishing email.
IBM Cost of a Data Breach Report, 2025cybercrime reports received by ASD's ACSC in FY2024–25 — one every six minutes.
ASD's ACSC Annual Cyber Threat Report 2024–25Internal-themed lures — messages posing as HR or IT — dominated simulation failures through 2025, reflecting a deliberate emphasis on familiarity and trust. Campaigns increasingly use QR codes and redirect chains to obscure malicious URLs and slip past MFA controls.
The human factor and risk exposure
Phishing remains widely successful because the people being targeted still find it hard to distinguish malicious from legitimate communication — even experienced, digital-native users, particularly when attackers use AI-generated text and contextually accurate detail.
Verizon's 2025 Data Breach Investigations Report found phishing implicated in 36% of all breaches analysed — a reminder that awareness alone, without reinforcement, isn't closing the gap.
The real-world impact of phishing attacks
Phishing is not a theoretical risk — it directly contributes to data breaches, credential theft, ransomware, and BEC losses. Credential theft, frequently initiated via phishing, remains one of the fastest-growing categories of breach in 2025 and 2026 data.
In some recent large-scale incidents, phishing was the entry point to data compromise affecting millions of customer records.
Economically, an attack that starts with phishing can result in loss of sensitive data and intellectual property, direct financial fraud, disrupted operations, and regulatory or reputational damage — often all at once.
Phishing simulations and organisational resilience
A growing body of evidence shows that well-executed phishing simulation programs meaningfully improve organisational resilience — not as a compliance exercise, but as a measurable behaviour-change tool.
reduction in malicious clicks among organisations using behaviour-based training.
Hoxhunt, within 6 monthsimprovement in real-world threat reporting over the same period.
Hoxhunt, within 6 monthsdrop in phish-prone rate after 12 months of sustained training.
KnowBe4, 2025The programs that produce these outcomes share four traits: realistic scenarios that mirror current threat patterns, immediate feedback explaining why a lure was malicious, targeted follow-up training based on results, and continuous measurement and refinement. Organisations that treat this as iterative — rather than a once-a-year event — see measurable gains in both detection and reporting, shifting the culture from compliance-driven to behaviour-driven.
Outlook and strategic imperatives for 2026
As phishing tactics keep evolving, organisations need layered, dynamic strategies rather than a single annual training event:
AI-augmented phishing and multi-vector campaigns are very likely to keep accelerating through the rest of the decade — which makes human awareness and adaptive training more critical to organisational defence, not less.
What this means for your organisation
Phishing targets human decision-making
No amount of technical investment removes the need to train your people — phishing exploits psychology, not just technology.
AI has made attacks more convincing
Over 82% of phishing emails now show signs of AI assistance. Generic awareness training is no longer enough on its own.
Simulations must be realistic and current
Scenarios built from live threat intelligence produce measurably better outcomes than recycled templates.
Behaviour change requires reinforcement
One-off training produces one-off results. Sustained, iterative programs cut malicious clicks by up to 87% within six months.
See how Mono addresses the phishing challenge directly.
Click or Flick Corporate is built on intelligence-driven simulations, human-led support for high-risk employees, and behaviour change that lasts beyond the training session. If this resonated, the program page is the natural next step.