Contents Phishing at scale

Synthetic methods

Phishing at scale

AI changes phishing mainly by reducing the work needed to create and adapt messages. The FBI assesses that it can increase speed, scale, automation, personalization and linguistic fluency within existing schemes.1 The UK National Cyber Security Centre similarly assesses that generative AI can produce convincing lure documents without familiar translation, spelling or grammar errors.2 These are capability assessments, not measurements of how many phishing messages were generated or how often they succeeded.

Observed malicious use also points toward acceleration rather than a new fraud structure. Investigations published in 2025 found operators using AI to scale established playbooks3 and produce multilingual material more efficiently.5 These findings point to more efficient execution of established playbooks, not new scam structures.

Complaint evidence cannot identify the scale of that change. In its United States complaint data for 2025, the FBI used an AI Related descriptor when complaint information referenced AI. That descriptor did not establish that investigators had verified AI use.4 The complaint system therefore does not record whether AI actually authored each message. Its categories and reported losses cannot be used to calculate AI's share of phishing.

In practice, polished language is weak identity evidence. A message that correctly names a colleague, supplier or recent activity can still be treated as a claim. When it asks for a password, account code or changed payment destination, polished language and specific details are still weak evidence of who sent it.

Boundary. This judgement does not mean every fluent message is fraudulent or every awkward message is genuine. AI may increase the speed and reach of an operation without changing every message. It also does not show that AI-written phishing produces greater consumer losses than conventional phishing. The practical distinction concerns verification, not writing style.

References

Quizzes
  1. A polished supplier email announces new payment details. Which check best addresses the risk?

    • Reply to the message and ask the supplier for reassurance
    • Use a previously held contact route
    • Inspect the logo, formatting, and writing style

    Fluency can be manufactured. An established contact route tests the requested change without relying on the message's presentation.

  2. Evidence from observed malicious operations indicates that AI is being used mainly to ____.

    • scale established playbooks
    • create entirely new scam structures
    • make every phishing attempt more successful

    Observed operations used language models to increase efficiency and fluency while retaining familiar scam structures.

  3. A fluent, personalized message is sufficient evidence that the sender controls the account they claim to represent.

    • True
    • False

    Style and personal details belong to the message. Identity requires confirmation through a trusted channel or account process.

Comments

No comments yet. Start the conversation.