By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Knowbe4Published April 16, 2026

TL;DR: AI-enabled phishing is rising sharply, including a 41% increase in teams-based attacks, a 449% surge in vishing, and a 92% jump in polymorphic attacks, according to KnowBe4 research. Human risk management, not awareness alone, is now the control gap that matters most.


At a glance

What this is: This is KnowBe4’s curated research hub on email security, phishing, social engineering, and human risk, with the key finding that AI is accelerating attack volume and adaptability.

Why it matters: It matters because IAM, SOC, and security awareness teams now need to treat user behaviour, email trust, and identity-driven attack paths as linked control problems rather than separate programmes.

By the numbers:

👉 Read KnowBe4's whitepaper on why email security is failing in the age of AI-powered phishing


Context

Email security failures increasingly begin with trust, not malware. Attackers are using AI to scale phishing, vishing, and collaboration-platform abuse faster than traditional controls can classify and block them. The primary problem is not a lack of filtering alone, but the speed at which identity-driven manipulation crosses channels and exploits human response.

For IAM and security teams, the important shift is that email, identity verification, and human behaviour now form a single attack surface. That creates a governance problem for access, reporting, coaching, and incident response, especially where user actions can trigger credential theft, delegated access abuse, or fraudulent payment workflows.


Key questions

Q: How should security teams reduce phishing risk when AI makes scam messages more convincing?

A: Teams should stop relying on obvious spelling mistakes and train people to verify the sender, destination, and request through a separate channel. The better control is a combination of realistic simulations, password managers, and simple confirmation habits for urgent or payment-related messages. That reduces both click risk and downstream credential theft.

Q: Why do human-risk programmes matter if email security tools already block threats?

A: Email security tools reduce volume, but they do not eliminate deception, platform abuse, or user decision failures. Human-risk programmes matter because many attacks succeed when a legitimate-looking message causes a person to approve, share, or ignore something unsafe. That makes behaviour measurement and intervention a necessary control layer.

Q: Why do collaboration platforms complicate phishing defence?

A: Collaboration platforms blend internal staff, vendors, and guests into one trusted-looking interface, which makes malicious requests look routine. That weakens user scrutiny and increases click likelihood. Defenders should treat shared threads as a governed trust boundary and restrict how external identities can place content there.

Q: Who is accountable when stolen credentials from a phishing email are used for fraud?

A: Accountability sits with the organisation that controls the affected identity, the approval workflow, and the downstream business process. Security, IAM, and finance teams all share responsibility because the damage often occurs after authentication succeeds. Frameworks that govern access, verification, and workflow approval all become relevant once the stolen identity is used.


Technical breakdown

Why AI-powered phishing bypasses static email controls

AI-powered phishing succeeds because message generation, language variation, and delivery timing can be automated at scale. Static detection rules struggle when each message is slightly different and legitimate platforms are used as delivery or impersonation channels. The security issue is not only malicious content, but the ability to mimic context, tone, and workflow cues closely enough to pass through user and system trust checks. This weakens the value of one-time awareness campaigns and pushes defenders toward layered behavioural detection, identity validation, and response workflows that work in real time.

Practical implication: tune controls for behaviour and context, not just signatures and blocklists.

How human risk management changes the control model

Human risk management treats employees as measurable security decision points rather than a generic awareness audience. Instead of assuming training alone will remove risk, it combines telemetry, coaching, simulation, and workflow interventions to reduce risky behaviour where it occurs. That matters because phishing, BEC, and social engineering increasingly succeed through small decision failures, such as approving a payment, sharing a code, or trusting a login prompt. In practice, this turns human behaviour into a governable control surface that can be measured and improved over time.

Practical implication: link human-risk telemetry to identity and email controls so intervention happens before misuse spreads.

Why collaboration platforms now matter in phishing defence

Teams-based attacks and similar collaboration-channel abuse exploit the assumption that internal messaging tools are trustworthy by default. When attackers hijack legitimate platforms, they inherit context and reduce user suspicion, which makes detection and user reporting harder. The technical challenge is that security teams often monitor mailboxes more closely than chat, shared workspaces, and embedded files or links. A modern defence model needs policy, logging, and response coverage across the collaboration stack, not just the email gateway.

Practical implication: extend monitoring and user reporting workflows across collaboration tools, not only email.


Threat narrative

Attacker objective: The attacker wants to convert trust in normal business communication into credential theft, fraudulent payment, or account takeover.

  1. Entry occurs through AI-generated phishing, vishing, or collaboration-platform abuse that mimics trusted business workflows and lowers user suspicion.
  2. Escalation follows when a user shares credentials, approves a malicious request, or opens a path into delegated access and internal communications.
  3. Impact comes through credential theft, payment fraud, or broader account compromise that bypasses perimeter email security and human review.

NHI Mgmt Group analysis

AI-powered phishing has become an identity governance problem, not only an email security problem. Once attackers can reliably imitate language, urgency, and business context, the control question shifts from message blocking to trust verification. That means IAM, verification, and email workflows have to be aligned so user actions are treated as access decisions with consequences. Practitioners should expect phishing defence to sit closer to identity governance than to perimeter filtering.

Human risk management is the named concept this market needs because awareness alone does not change decision quality. The article’s emphasis on continuous training and behavioural improvement reflects a larger truth: risk is created when predictable human responses meet adaptive attacker tactics. That makes measurement essential, because programmes that cannot observe behaviour cannot reduce it. Practitioners should treat human risk as an operational metric, not a culture slogan.

Identity verification must now extend into collaboration and communication workflows. Attackers increasingly exploit trusted channels where users infer legitimacy from the platform itself. That intersects with IAM because approvals, password resets, payment authorisations, and account recovery all depend on trust decisions made in workflow. Practitioners should assume that verification failure in one channel can cascade into access compromise elsewhere.

The rise of AI-enabled social engineering validates layered controls over single-point defences. Filtering, awareness, and reporting all matter, but each fails differently when attackers can iterate rapidly. The better model is defence in depth across detection, coaching, identity validation, and response orchestration. Practitioners should align controls so the failure of one layer does not create immediate account or payment risk.

Security teams should interpret phishing trends as an early warning for broader agentic abuse. The same techniques that manipulate people are being adapted to manipulate systems, workflows, and delegated trust. That makes human-risk data useful beyond awareness, because it indicates where identity assumptions are brittle. Practitioners should use phishing telemetry to strengthen identity governance, not just training completion rates.

What this signals

Phishing defence is no longer just a user-awareness problem. The operational signal is that teams need to connect identity verification, email security, and workflow approvals into one response model, because attackers increasingly move across those boundaries faster than manual review can keep up.

Human decision telemetry: the useful metric is not whether users attended training, but whether risky actions decline across the channels attackers actually use. When reporting latency, approval mistakes, and repeated susceptibility stay high, the programme is measuring activity rather than reducing exposure.

For identity teams, the next step is to treat trust decisions in collaboration platforms as part of access governance. That means tightening step-up checks, improving reporting paths, and aligning controls with the real channels where social engineering now lands.


For practitioners

  • Measure human-risk outcomes, not just training completion Track click-through, credential submission, reporting latency, and repeat susceptibility by team and workflow. Use those signals to identify where coaching or controls need to change before attacks translate into access loss.
  • Extend phishing detection into collaboration tools Monitor chat, shared workspaces, and file-sharing channels with the same seriousness as email. Correlate suspicious messages with identity events so a compromised conversation can trigger access review and containment.
  • Add verification steps for high-risk approvals Require step-up validation for payment changes, password resets, and delegated access requests. This reduces the chance that a convincing message alone can trigger a business-impacting action.
  • Connect awareness to incident response workflows Route user-reported phishing into SOAR playbooks, triage queues, and identity containment actions. Rapid response matters when attackers are iterating quickly across multiple communication channels.

Key takeaways

  • AI is making phishing, vishing, and collaboration abuse harder to distinguish from legitimate business communication.
  • The meaningful defence is behavioural measurement plus identity-aware verification, not awareness alone.
  • Organisations should extend controls across email, chat, approvals, and incident response so one convincing message does not become an access event.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Phishing defence depends on verifying identity before granting trust in messages and workflows.
NIST SP 800-53 Rev 5IA-2Identity assurance is central when attackers impersonate trusted business contacts.
NIST AI RMFMANAGEAI-enabled phishing is a risk management issue because attacker behaviour is adaptive and dynamic.
MITRE ATT&CKTA0001 , Initial Access; TA0006 , Credential AccessThe article focuses on phishing-driven initial access and credential theft.

Map phishing detections to TA0001 and TA0006 to prioritise containment and user verification.


Key terms

  • Human Risk Management: The practice of managing how people interact with security controls, especially under pressure, distraction, or deception. It combines training, policy, and friction management so identity systems are still usable enough that users do not bypass them in day-to-day work.
  • AI-Personalised Phishing: Phishing that uses context, tone, and timing tailored to the target rather than generic mass messaging. In practice, it reduces obvious red flags and forces defenders to rely on identity, behaviour, and channel correlation instead of message signatures alone.
  • Collaboration Channel Abuse: The misuse of trusted collaboration tools such as Teams, calendar systems, and internal messaging to deliver phishing or social engineering payloads. These channels amplify trust, reduce user suspicion, and can carry identity-related abuse into everyday workflows.

What's in the full report

KnowBe4's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • Benchmark data on human-risk programme maturity, including how organisations measure behaviour change across the workforce
  • Practical guidance for reducing phishing susceptibility through coaching, simulations, and response workflows
  • Implementation detail for integrating human risk metrics with email security and incident response
  • Specific tactics for improving reporting, triage, and verification across collaboration tools

👉 The full KnowBe4 whitepaper covers the architectural gaps, human-risk controls, and response practices in more detail.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, IAM, and secrets management. It helps security practitioners connect identity control, lifecycle discipline, and operational risk across modern programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org