AI Phishing and Deepfake Fraud: The 2026 Threat Briefing Every CISO Needs to Read


September 3, 2026

Introduction

In December 2025, something changed in the threat landscape almost overnight. AI generated phishing emails, which had hovered below 5% of all reported phishing attacks for eleven straight months, suddenly jumped to 56% of everything landing in security teams' inboxes. In a single month, the proportion of AI crafted attacks increased fourteenfold.


That is not a gradual trend. That is a step change, and it is the clearest signal yet that the threat model your organisation built its defences around is already out of date.


If you are a CISO, security director, or IT leader responsible for protecting your organisation, this briefing is for you. We have pulled together the most current data on AI powered phishing and deepfake fraud, explained exactly how these attacks work, and set out what a credible response looks like in 2026. No hype, no scaremongering, just the numbers and what they mean for your risk posture.

The AI Phishing Explosion: Why the Numbers Should Worry You

Let's start with the headline figures, because they tell a story that most security awareness programmes have not caught up with yet.


AI generated phishing attacks jumped from roughly 4% of reported phishing in November 2025 to 56% in December, before settling at around 40% in January 2026, according to threat intelligence from Hoxhunt's global detection network, which monitors more than four million users. That is not a niche technique anymore. AI is now involved in a significant share of the phishing emails hitting real inboxes, and the proportion is only trending upward.


What makes these emails dangerous is not just volume, it is quality. Large language models can now produce phishing content with polished grammar, professional formatting, and contextually accurate details pulled from public sources such as LinkedIn, company websites, and press releases. The clumsy, typo ridden phishing email that security awareness training has spent a decade teaching staff to spot is becoming the exception rather than the rule.


Attackers are also diversifying their delivery methods faster than defences can adapt. Callback phishing, where victims are lured into phoning a fraudulent number, rose by around 500% in the final quarter of 2025. Malicious calendar invites are producing failure rates four to six times higher than standard phishing baselines, because staff instinctively trust anything that lands in their calendar. SVG file attachments, an image format that most email filters were never built to inspect properly, saw a fiftyfold increase in malicious use compared with the previous year.


The financial impact is significant and rising. IBM's most recent breach cost analysis puts the average cost of a phishing related breach at £3.9 million (roughly $4.88 million), an increase of almost 10% year on year. Credential theft and broader social engineering incidents carry similarly steep price tags.

When MFA Stops Being Enough

For years, multi-factor authentication has been the gold standard recommendation for preventing account takeover. It still matters, but CISOs need to understand a hard truth that the data now makes plain: MFA alone is no longer sufficient to stop a determined, AI assisted attacker.


Proofpoint's 2025 research found that 59% of successfully compromised accounts had MFA enabled at the time of the breach. That figure should stop any security leader in their tracks. The mechanism behind it is called adversary in the middle phishing, or AiTM. Rather than trying to guess or brute force a password, these attack platforms sit as a reverse proxy between the victim and the genuine login page. The victim enters their real credentials and completes their real MFA challenge, and the attacker's platform silently captures the resulting session cookie the moment authentication succeeds. From that point on, the attacker has a fully authenticated session and does not need the password or the MFA code again.


Microsoft's 2025 Digital Defense Report attributes around 80% of MFA bypass breaches to this exact session token theft technique. One phishing as a service platform, Tycoon 2FA, was reportedly being used to target as many as 500,000 organisations a month before it was disrupted by law enforcement in March 2026.



The practical implication is straightforward: if your organisation's security strategy still treats "we have MFA" as a box ticked and a risk closed, that box needs reopening. Phishing resistant authentication methods, such as FIDO2 security keys and passkeys that are cryptographically bound to a specific domain, are now the meaningful upgrade path, because they cannot be relayed through an AiTM proxy the way a one time passcode or push notification can.

Deepfakes Have Moved From Novelty to Weapon

If AI phishing is the volume threat, deepfakes are the precision threat, and the case studies emerging over the past two years show exactly how effective they can be against even sophisticated organisations.


The most widely reported example remains the Hong Kong case from early 2024, in which a finance employee at a multinational engineering firm joined what appeared to be a routine video conference call with the company's CFO and several other senior colleagues. Every person on that call, bar the victim, was an AI generated deepfake, rendered convincingly enough in real time video and audio that the employee proceeded to authorise a series of transfers totalling HK$200 million, roughly £19 million. The fraud was only discovered once the employee later checked with head office directly.


This is no longer an isolated curiosity. Voice cloning based fraud, sometimes described as the new business email compromise, has grown rapidly as the underlying technology has become cheaper and more accessible. Convincing voice clones can now be generated from just a few seconds of publicly available audio, such as a conference keynote, a podcast appearance, or a company earnings call. That is a low bar for attackers targeting finance teams, particularly around wire transfer approvals and vendor payment changes, which remain among the highest value targets for this style of fraud.


The regulatory and industry response confirms the scale of the concern. In the UK specifically, total payment fraud losses reached £1.28 billion in 2025, with authorised push payment fraud, the category that covers most deepfake enabled scams where a victim is manipulated into authorising a transfer themselves, rising by 19% to £576.4 million. UK Finance's managing director of economic crime, Ruth Ray, noted that organised criminal groups are rapidly adopting AI to automate attacks and increase their credibility, allowing scams to be carried out at far greater scale than manual fraud ever permitted. Encouragingly, banks also blocked a record £1.68 billion of unauthorised fraud over the same period, showing that better detection is possible, but the attackers are still winning ground on the authorised fraud side, precisely where deepfakes and social engineering do their damage.


For a CISO, the lesson is that deepfake fraud is not a future risk to plan for eventually. It is an active, well documented threat vector, targeting a very specific and very human point of failure: the trust your staff place in a familiar voice or face on a call.

Why Traditional Security Awareness Training Is Falling Behind

Most organisations still run security awareness training on a quarterly or annual cycle, often built around spotting the tell tale signs of a badly written phishing email. That model was reasonably effective against yesterday's threats. It is increasingly inadequate against today's.


Baseline phishing reporting rates in organisations relying on traditional, infrequent training sit at around 10%, meaning nine out of ten suspicious emails go unreported. Organisations that have shifted to continuous, behaviour based training programmes, with realistic simulated attacks run regularly rather than annually, report improvement well beyond that baseline, with reporting rates exceeding 20% and, in the best performing organisations, over 60%. After twelve months of sustained, adaptive training, click through rates on phishing simulations drop by approximately 87% compared with the starting point.



The takeaway is not that training does not work. It is that training built around outdated attack patterns, delivered infrequently, does not work well enough against an adversary that is iterating on its methods on a monthly basis. Training programmes need to reflect current attack techniques, including AI generated content, callback phishing, and deepfake based verification requests, and they need to run continuously rather than as an annual compliance exercise.

The Cost of Getting This Wrong

It is worth being explicit about what is actually at stake here, because the figures above are easy to skim past as abstract industry statistics rather than genuine board level risk.


A single successful deepfake incident, as the Hong Kong case demonstrates, can result in a loss measured in the tens of millions within one afternoon, executed by a small team exploiting nothing more sophisticated than a video call and some publicly available footage of your executives. A single successful AiTM phishing attack can hand an attacker a fully authenticated session inside your environment, bypassing the MFA control your board was told made account takeover unlikely. And the average phishing related breach now carries a direct cost approaching £4 million before factoring in regulatory exposure, customer notification obligations, reputational damage, and the cost of the incident response itself.


None of this requires a nation state adversary or a bespoke, custom built attack. The tooling behind AI generated phishing and voice cloning is now cheap, widely available, and improving month on month. The organisations getting hit are not unusually careless. They are simply the ones whose controls, training, and monitoring have not yet caught up with how quickly the attacker side of this equation has moved.

What a Credible 2026 Defence Strategy Actually Looks Like

Given everything above, what should a security leader actually be prioritising right now? A few principles stand out from the data.


First, move toward phishing resistant authentication wherever it is feasible, particularly for finance, IT administration, and executive accounts. FIDO2 keys and platform passkeys close the specific AiTM session hijacking gap that standard MFA leaves open.


Second, put formal out of band verification procedures in place for any payment change, wire transfer, or credential reset request that arrives by video call, phone call, or email, regardless of how senior or familiar the requester appears to be. A short callback to a known, previously verified number remains one of the most effective, low cost controls against deepfake fraud, precisely because it breaks the single channel that the attacker controls.


Third, treat email filtering and endpoint detection as necessary but not sufficient. AI generated phishing content is specifically designed to defeat the pattern matching that traditional filters rely on, and file types like SVGs and calendar invites are being used precisely because they sit outside many organisations' existing inspection rules.


Fourth, and perhaps most importantly given the speed at which these attacks now move, build in continuous monitoring rather than relying on periodic reviews. Fortinet's 2026 threat research found that the time between an initial AI assisted breach and lateral movement inside a network can now occur in under an hour. A security team that reviews alerts once a day, or only during office hours, is operating on a timeline that no longer matches the threat.



This last point is worth sitting with. Attackers do not work nine to five, and increasingly they do not need to, because AI tooling lets a small team run automated attacks around the clock at a scale that would previously have required a much larger operation. Ninety five percent of organisations report a cybersecurity skills gap, according to industry research, which means most security teams simply do not have the headcount to match that around the clock pressure through people alone.

Why 24/7 Monitoring Is No Longer a Nice to Have

This is precisely the gap that continuous, always on security monitoring is designed to close, and it is why we built CyberGen Security around genuinely round the clock protection rather than office hours coverage with an on call rota bolted on.


An AI driven credential harvesting campaign does not pause overnight, and a deepfake enabled fraud attempt against your finance team is just as likely to land at 7pm on a Friday as it is at 10am on a Tuesday. The organisations best placed to withstand this new wave of AI powered attacks are the ones whose detection and response capability operates on the same timeline as the threat itself, not the working day.


Practically, that means a security operations capability that is actively monitoring authentication events, flagging anomalous session activity that could indicate AiTM session theft, and able to respond to a suspected incident in minutes rather than the next business morning. It also means having a partner who understands these specific attack techniques well enough to help you build the verification protocols, phishing resistant authentication rollout, and staff training programme that actually reflect the threats described above, rather than a generic checklist from several years ago.

Frequently Asked Questions

What is AI phishing? AI phishing refers to phishing emails, messages, or calls generated or enhanced using artificial intelligence, typically large language models. These attacks use AI to produce grammatically polished, contextually convincing content at a scale and speed that would be impossible for a human attacker to replicate manually.


Can multi-factor authentication still be trusted? MFA remains an important control and should not be removed, but standard MFA methods such as one time passcodes and push notifications can be bypassed through adversary in the middle phishing, which steals the authenticated session after MFA succeeds. Phishing resistant methods such as FIDO2 security keys offer significantly stronger protection.


How common is deepfake fraud in 2026? Deepfake enabled fraud has grown sharply, with documented cases including a £19 million loss from a single deepfake video conference incident. UK authorised push payment fraud, much of which involves social engineering and impersonation, rose 19% in 2025 to reach £576.4 million.


What is the single most effective defence against deepfake fraud? Out of band verification. Any request to change payment details, approve a large transfer, or reset credentials should be confirmed through a separate, previously verified communication channel before it is actioned, regardless of how convincing the original request appears.

Summary

The threat landscape has shifted faster in the past twelve months than in the previous several years combined. AI generated phishing, session hijacking that sidesteps MFA, and deepfake fraud capable of costing an organisation millions in a single incident are not emerging risks anymore. They are active, well documented, and growing.


The organisations that will handle this well are not necessarily the ones with the biggest security budgets. They are the ones that update their assumptions in line with the evidence, close the specific gaps this new generation of attacks is designed to exploit, and make sure their protection operates continuously, because the threat certainly does.


If you would like to talk through how these attack techniques apply to your organisation specifically, or want a clear view of where your current defences stand against AI powered phishing and deepfake fraud, get in touch with the CyberGen Security team. Protecting your organisation 24/7 is not a slogan for us, it is the operating model this threat landscape now demands.


Sources:

Hoxhunt Phishing Trends Report 2026, Proofpoint 2025 Threat Research, Microsoft 2025 Digital Defense Report, IBM Cost of a Data Breach Report, UK Finance Annual Fraud Report 2025 (via IBTimes UK), Fortinet 2026 Cybersecurity Trends, Reuters (Hong Kong deepfake fraud case, February 2024).

Ready to strengthen your security posture? Contact us today for more information on protecting your business.


Let's get protecting your business

Disaster Recovery

Keep your data secure and protected at all times.


Cybergen News

Sign up to get industry insights, trends, and more in your inbox.

Contact Us

SHARE THIS

Latest Posts

Turquoise shield emblem with a white crowned castle on a dark blue background
September 2, 2026
What UK boards need to know about the Cyber Security and Resilience Bill, including its scope, 24-hour reporting rule, penalties and compliance steps.
Dark dashboard UI with purple glow, showing a 24/7 notification panel and task list
August 26, 2026
CISOs are closing the SME detection gap without building a SOC from scratch. See the real cost of 24/7 monitoring vs. accessing enterprise-grade protection through Cybergen.
Aerial view of a city freeway interchange with glowing blue traffic lines overlayed
August 15, 2026
Critical infrastructure organisations face increasing cyber threats. Discover how Thales security solutions help improve resilience and protect essential services.
August 11, 2026
Modern web applications are a primary attack target. Discover how CREST web application penetration testing identifies exploitable vulnerabilities before attackers do.
Glowing blue AI letters inside a neon circular digital interface
August 3, 2026
AI adoption is accelerating across organisations, increasing the need for stronger data protection, visibility, and access control strategies.
Blue digital tunnel of binary code spiraling toward a bright center
July 28, 2026
Discover why modern organisations are prioritising data security, encryption and access control to strengthen cyber resilience against evolving threats.
Glitched computer screen with pink warning triangle and static noise on a dark background
June 21, 2026
Learn how Cyber Threat Intelligence helps organisations reduce cyber risk, prioritise vulnerabilities, improve incident response and strengthen security in 2026.
Person interacting with futuristic holographic icons and touchscreen in a blue digital interface
June 11, 2026
Discover how Shadow AI, unmanaged AI usage and poor governance are creating compliance, security and data protection risks. Learn how to close the AI compliance gap and protect sensitive information.
Neon AI letters with a glowing purple orbit on a dark tech-style background
June 3, 2026
Discover how Shadow AI is creating hidden security, compliance and data risks. Learn how to regain visibility, govern AI usage and reduce exposure.
Two professionals in a tech office with a laptop showing code and a digital globe display
May 19, 2026
Traditional threat intelligence is no longer enough. Discover how intelligence-led cybersecurity helps organisations predict, prioritise, and prevent cyber threats before they escalate.