By NHI Mgmt Group Editorial TeamBased on 1Password: “Survey: Holiday scammers are getting bolder with AI, and Americans are taking the bait” (November 5, 2025)

TL;DR: AI is making phishing more convincing and more common during holiday shopping, while 82% of respondents still report being phished or nearly phished, according to 1Password’s survey of 2,000 U.S. adults. The real gap is not awareness alone but the outdated signals, impulse buying pressure, and password reuse that scammers continue to exploit.


At a glance

What this is: This article is a holiday phishing analysis showing that AI-generated scams are weakening traditional red-flag detection, especially around shopping, shipping, and social media bait.

Why it matters: It matters because human identity controls still rely heavily on pattern recognition, while scammers are shifting to channels and messages that fit normal holiday behaviour.

By the numbers:

  • 82% of respondents have still been phished or come dangerously close to it.
  • 66% of Americans say they’ve noticed more scammy messages, phone calls, and ads since AI became more prevalent.
  • 59% of respondents said they encounter suspected phishing scams in texts.
  • 76% of Americans who’ve fallen victim to a shopping scam still reuse passwords across multiple accounts.

Context

AI-driven phishing is a human identity problem first: attackers are improving the realism, timing, and delivery of scams faster than people can adapt their instincts. The result is not just more phishing attempts, but phishing that better fits everyday shopping, shipping, and social behaviour.

Holiday periods compress attention and increase click-through risk because buyers are looking for deals, package updates, and time-sensitive offers. That makes social channels, SMS, and email especially vulnerable when the scam blends into a normal consumer workflow.


Key questions

Q: What breaks when phishing lures look polished and grammatically correct?

A: The old habit of using spelling mistakes and awkward wording as the main warning sign breaks down. When AI generates fluent, brand-like messages, users need to rely more on source validation, urgency checks, and destination verification instead of surface quality alone.

Q: Why do holiday scams succeed even when people know the warning signs?

A: They succeed because they attach malicious requests to moments people already expect, such as shipping updates, gift cards, and limited-time deals. That creates pressure, narrows attention, and makes impulsive clicks more likely, especially when the message appears to fit the season.

Q: What are the signs that password reuse is making phishing worse?

A: A warning sign is when a single phishing event can plausibly affect multiple services, such as email, shopping, travel, or banking. If users reuse passwords, one captured credential can become a broad account takeover path instead of a contained incident.

Q: How should security teams reduce phishing risk without relying only on awareness training?

A: They should combine user training with behavioural detection, vendor verification, and tighter controls on high-risk identity actions. Awareness helps users spot obvious lures, but it does not stop impersonation that looks routine. The stronger model is to detect trust abuse across mail, identity, and workflow layers before approval or credential use occurs.


Technical breakdown

Why AI-generated phishing is harder to spot

Traditional phishing detection depends on visible defects such as spelling mistakes, awkward phrasing, and obvious URL errors. AI reduces those tells by generating fluent copy, plausible sender language, and context-specific lures that mimic real merchants, shipping updates, and promotions. That shifts the detection burden away from surface quality and toward behavioural cues such as urgency, source verification, and unexpected requests. For identity teams, the core change is that user judgement is now the primary control being attacked, while the scam itself looks increasingly routine.

Practical implication: strengthen user verification habits around urgency and destination checking, not just language quality.

How holiday pressure amplifies phishing success

Holiday phishing works because scams align with pre-existing intent. People expect package notices, gift cards, shipping alerts, discounts, and job-related opportunities, so an attacker does not need to create interest from scratch. They only need to attach a malicious link or credential prompt to an already plausible moment. This is why pressure tactics remain effective even when users know the classic warning signs. The security issue is not ignorance alone, but decision-making under time pressure and bargain-seeking behaviour.

Practical implication: treat urgency and limited-time offers as risk signals in consumer and employee awareness programmes.

Why password reuse turns a single phish into account takeover

Phishing becomes far more damaging when a stolen password can be reused across several services. In that model, a fake shipping site or impersonated retailer is not just a one-off fraud attempt. It becomes a credential collection point that can unlock email, shopping, travel, banking, and loyalty accounts if the same password was reused elsewhere. That is a classic human identity failure mode because the compromise does not stay contained to the first site where the victim typed credentials.

Practical implication: prioritise unique passwords and password manager adoption so one phishing event cannot cascade across accounts.


Threat narrative

Attacker objective: The attacker wants victims to reveal credentials or payment information and then reuse those details to take over additional accounts.

  1. Entry occurs through holiday-themed lures delivered by text, email, phone, or social media, often disguised as shipping alerts, gifts, discounts, or job-related offers.
  2. Credential capture or data theft follows when the victim clicks a convincing look-alike site or submits login details to a fake brand or retailer.
  3. Impact expands when reused passwords let the attacker access multiple accounts beyond the original scam target, turning one phish into broader account compromise.
  • Mailchimp breach 2022: Attackers socially engineered Mailchimp staff, used a support tool to export 102 customer lists and exposed customer API keys for phishing.
  • CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Holiday phishing is now a human identity governance problem, not just an awareness problem. AI has reduced the usefulness of the classic red flags people were trained to look for, so the control surface has shifted from spotting bad grammar to recognising suspicious intent and context. That weakens a model built on user vigilance alone and makes the case for stronger identity hygiene and safer authentication patterns.

Reusable credentials remain the easiest escalation path in consumer and workforce phishing. The article’s 76% password reuse figure shows that one successful phish can still become multi-account compromise when users recycle secrets across services. That is a governance failure in identity behaviour, not just a user mistake, and it is why password reuse keeps turning low-grade scams into broader exposure.

AI-driven phishing is widening the gap between scam volume and scam recognisability. The article notes that 66% of Americans are seeing more scammy messages, calls, and ads as AI becomes more prevalent, which indicates the threat is scaling faster than habitual detection. The practical conclusion is that identity programmes need controls that do not depend on perfect human spotting.

Behavioural trust debt: phishing now exploits normal holiday intent, not just technical deception. Users expect shipping updates, digital gifts, and last-minute deals, so attackers increasingly win by blending into expected behaviour rather than by breaking technical controls. Practitioners should treat contextual normalcy as part of the attack surface and design identity education around real decision moments.

Human help-seeking is an underused control against modern phishing. The article shows many people help others spot scams but are less likely to ask for help themselves, which means social validation can function as a practical control. Security teams should frame second-opinion behaviour as part of identity resilience, not embarrassment avoidance.

What this signals

Behavioural trust debt: holiday phishing increasingly succeeds by matching normal consumer intent, which means identity programmes have to address context, not just recognition.

Password reuse remains the easiest way for a single scam to become broader account compromise, so consumer and workforce identity hygiene still matters even when the lure looks obvious.


For practitioners

  • Update scam training around AI-generated lures Teach users that polished grammar, clean branding, and plausible formatting no longer prove legitimacy. Focus training on urgency, source verification, and destination checking for shopping and shipping messages.
  • Promote second-opinion verification habits Encourage employees and families to pause before acting on a message that demands urgency, then check it with a colleague or friend before clicking, paying, or logging in.
  • Push unique passwords across all accounts Eliminate password reuse for consumer and work-facing services so a stolen credential from one phishing site cannot unlock additional accounts elsewhere.
  • Route users to official sites directly In awareness guidance, tell users to open retailer and shipping sites through bookmarks or direct navigation rather than through links in posts, ads, DMs, or texts.
  • Treat social media as a phishing channel Add social ads, sponsored posts, and direct messages to phishing guidance because attackers increasingly exploit impulse buying and look-alike storefronts there.

Key takeaways

  • AI-generated phishing weakens the classic cues people were taught to watch for, which makes traditional awareness signals less reliable during holiday shopping.
  • The survey results show a large gap between confidence and exposure, with most respondents reporting they can spot red flags even though many have still been phished or nearly phished.
  • The most effective response is to combine better user habits with stronger password hygiene, so one phishing event does not spread across multiple accounts.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0, OWASP ASVS and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63B — AuthenticationPassword reuse and phishing directly affect authentication assurance for human users.
Recommendation — Strengthen authentication practices to reduce reuse-driven compromise across consumer and work accounts.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centers on accounts being abused after credentials are captured.
Recommendation — Review account authorization scope so stolen credentials do not expose unnecessary services.
OWASP ASVSV6 — AuthenticationThe article’s core issue is user credential capture through deceptive login flows.
Recommendation — Use authentication controls that reduce the impact of credential harvesting and reused passwords.
CIS Controls v8CIS-5 — Account ManagementAccount hygiene and password reuse are central to the scam impact described here.
Recommendation — Enforce account management practices that prevent one phish from compromising multiple accounts.
MITRE ATT&CKTA0006 — Credential AccessThe scam’s goal is credential theft through phishing and fake login pages.
Recommendation — Map phishing-driven credential theft to TA0006 and prioritize controls that reduce credential capture.

Key terms

  • Phishing: Phishing is a deceptive message or website designed to trick a person into revealing credentials or other sensitive information. In identity terms, it is an unauthorised collection method that turns human trust into downstream account access and potential privilege abuse.
  • Password reuse: Password reuse is the practice of using the same password across multiple accounts. It turns one successful compromise into a much larger account takeover problem because the attacker can try the stolen credential elsewhere, widening the blast radius beyond the original target.
  • Smishing: Smishing is phishing delivered by text message instead of email. It works because users often treat SMS as immediate and legitimate, especially for shipping alerts, deliveries, and offers, which makes it an effective channel for urgent or click-driven deception.
  • Look Alike Website: A look alike website is a fraudulent site designed to resemble a trusted brand or service closely enough to fool users at a glance. It is commonly used to mimic login pages, donation portals, or delivery tracking screens so attackers can capture credentials and other sensitive data.

Deepen your knowledge

NHI governance, human identity lifecycle, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org