By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Knowbe4Published January 9, 2026

TL;DR: Cybercriminals are using AI to scale polymorphic attacks, evade Microsoft native security and secure email gateways by 47%, and drive ransomware resurgence through phishing, according to Knowbe4’s 2025 Phishing Threat Trends Report. The control gap is no longer email filtering alone, but behavioural detection, identity hardening, and rapid response to credential theft.


At a glance

What this is: Knowbe4’s 2025 phishing report argues that AI is making familiar phishing tactics more effective, especially through polymorphic variation and SEG evasion.

Why it matters: For IAM and security teams, this matters because phishing now targets identity systems as much as inboxes, turning credential capture, consent abuse, and session theft into enterprise access problems.

By the numbers:

👉 Read Knowbe4's 2025 Phishing Threat Trends Report, Vol. 5


Context

Phishing remains effective because it attacks the trust layer, not just the email layer. When adversaries combine AI-generated variation, ransomware delivery, and job-themed lures, traditional filtering becomes only part of the control surface, while identity verification, authentication strength, and user behaviour detection become equally important.

For IAM practitioners, the key issue is that phishing increasingly leads to identity compromise rather than isolated email compromise. That makes the downstream risk broader than mailbox abuse, because captured credentials, MFA fatigue, and session hijacking can open access across SaaS, cloud, and privileged workflows.


Key questions

Q: How should security teams handle AI-powered phishing that changes faster than human review?

A: They should prioritise controls that evaluate behaviour in near real time, not just known malicious indicators after the fact. If campaign mutation outpaces analyst review, detection must shift toward baselines, contextual scoring, and automated correlation so one changed message does not become a missed intrusion. Manual review still matters, but it can no longer be the primary gate.

Q: Why do phishing attacks still lead to major breaches when email filters are in place?

A: Email filters reduce exposure, but they do not stop a convincing lure that reaches a human and captures credentials or MFA approvals. The breach happens when the attacker turns that interaction into authenticated access. That is why email security must be paired with identity controls, session monitoring, and least privilege.

Q: What do organisations get wrong about ransomware recovery?

A: Many organisations treat recovery as a storage or backup problem and underweight identity control. In practice, an attacker who still has active access can relock systems, delete backups, or trigger more encryption before restoration finishes. Recovery is only reliable when identity pathways are narrowed first.

Q: How can teams tell whether phishing controls are actually working?

A: Look for fewer successful credential submissions on lookalike domains, lower password reuse, and faster reporting of suspicious messages. If users still reach fake login pages and can submit credentials without friction, the control environment is only reducing risk on paper. The goal is to stop secrets from leaving the user’s device.


Technical breakdown

How polymorphic phishing evades native email controls

Polymorphic phishing changes message content, formatting, links, and sender patterns at scale so static indicators age quickly. AI helps attackers generate many variations from one underlying lure, which reduces signature reuse and increases the chance that a message slips past secure email gateways and native platform filtering. The control problem is not that email security is absent, but that the adversary’s variation rate outpaces deterministic detection. Practical implication: shift from content-only filtering to behaviour-based detection, URL detonation, and post-delivery identity monitoring.

Practical implication: augment email controls with behaviour-based detection and identity monitoring.

Why phishing now behaves like an identity attack

Modern phishing is often designed to collect credentials, intercept MFA, or induce malicious consent so the attacker can operate as a legitimate user. Once that happens, the email itself is no longer the main threat object. The real issue is authenticated access into SaaS, cloud, and privileged systems, where the attacker can blend into normal activity and bypass many perimeter controls. Practical implication: treat phishing as an access-control failure path and correlate mail events with sign-in, device, and privilege telemetry.

Practical implication: correlate email, sign-in, device, and privilege telemetry.

Why ransomware delivery via phishing still matters

Phishing continues to deliver ransomware because human interaction remains a reliable initial access vector, even as payload delivery methods evolve. Attackers use lures that increase execution probability, then pivot from a single successful click to credential theft, lateral movement, and encryption or extortion. The report’s point is not that ransomware is new, but that email remains a durable entry path when defenders rely too heavily on legacy filtering. Practical implication: align phishing controls with incident response paths that assume account compromise, not just malware detonation.

Practical implication: prepare response paths for account compromise, not only malware detonation.


Threat narrative

Attacker objective: The attacker aims to turn a successful email lure into authenticated enterprise access that can be monetised through ransomware, theft, or broader compromise.

  1. Entry begins when a phishing email reaches the target with AI-generated variation that helps it evade Microsoft native security and secure email gateways.
  2. Escalation follows when the user clicks, submits credentials, approves an MFA prompt, or opens a payload that gives the attacker authenticated access or execution rights.
  3. Impact occurs when that access is used to deploy ransomware, steal data, or move into adjacent systems through legitimate identity pathways.

NHI Mgmt Group analysis

AI has made phishing a scaling problem, not a novelty problem. The report’s core signal is that adversaries are using AI to increase variation, not invent entirely new tradecraft. That means email defenders are now fighting a volume and entropy problem where one lure can become thousands of distinct messages. For practitioners, the operational conclusion is that static rules will keep degrading unless detection becomes adaptive.

Phishing should be managed as an identity boundary event. Once a credential, token, or MFA approval is captured, the mailbox is just the first compromise point. The real security failure is downstream access to SaaS, cloud consoles, and privileged workflows under a trusted identity. That makes phishing governance inseparable from IAM, PAM, and session monitoring, especially where standing privilege and weak conditional access still exist.

Ransomware resilience now depends on reducing the value of a single successful click. The report links phishing and ransomware resurgence because initial access still scales into extortion. That should push teams to limit blast radius through least privilege, phishing-resistant authentication, and fast containment of suspicious sign-ins. A mature programme assumes some phishing will land and focuses on making compromise non-catastrophic.

Job-themed lures show social engineering is becoming more context-aware. When attackers apply for jobs, they are exploiting hiring workflows, trust signals, and response expectations. That creates a bridge between fraud, identity verification, and enterprise security, because recruitment processes can become an entry point into systems, data, or account creation. Practitioners should review trust assumptions in every user-facing workflow, not just email intake.

Behavioral detection has become the differentiator for email security programmes. If 92% of polymorphic attacks are AI-assisted, then the control question is whether the organisation can detect abnormal sequence, sender, and post-click behaviour after the content has changed. This strengthens the case for layered telemetry across identity, endpoint, and mail, because phishing defence now needs correlation, not only filtering.

What this signals

Phishing programmes are increasingly identity programmes in disguise. Once the attack path shifts from inbox delivery to credential capture, consent abuse, or session theft, the governance question becomes whether IAM, PAM, and SOC telemetry are joined tightly enough to contain a compromise before it turns into enterprise access.

Trust-signal erosion: the rise of AI-assisted phishing means organisations must harden every trust signal that users rely on, from sender reputation to recruitment workflows. The practical shift is away from email-only defence and toward cross-domain controls that combine identity assurance, anomaly detection, and rapid privilege containment.

For teams managing NHI and workload access, phishing intelligence should feed into secrets governance as well. Compromised human accounts often become the bridge to tokens, API keys, and administrative consoles, so the boundary between human identity compromise and NHI exposure is operational, not theoretical.


For practitioners

  • Deploy phishing-resistant authentication Prioritise passkeys or FIDO2 for high-risk users and administrators so a captured password or OTP cannot be reused to authenticate into critical systems. Pair rollout with conditional access policies that block legacy and low-assurance sign-ins.
  • Correlate mail events with identity telemetry Join inbox security alerts with sign-in logs, device posture, and privilege changes so a click, consent grant, or impossible travel event can trigger investigation before the attacker establishes durable access.
  • Reduce standing privilege in user workflows Remove persistent elevated access from accounts that are reachable by phishing, and require just-in-time elevation for admin tasks so a compromised identity cannot immediately act with broad permissions.
  • Test detection against polymorphic lures Run simulations that vary wording, sender structure, and attachment patterns to measure whether your controls detect the behaviour of the campaign rather than one fixed message template.
  • Review recruitment and vendor onboarding trust paths Scrutinise job applications, invoice workflows, and third-party intake processes for identity checks that are too weak to resist context-aware social engineering.

Key takeaways

  • AI-assisted phishing is making old attack patterns more durable by increasing message variation and evasion at scale.
  • The real risk is identity compromise, because a single successful lure can produce authenticated access across SaaS, cloud, and privileged systems.
  • Teams need layered controls that combine phishing-resistant authentication, telemetry correlation, and fast containment of suspicious sign-ins.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0006 , Credential Access; TA0040 , ImpactPhishing here leads to credential theft and ransomware impact, both central ATT&CK tactics.
NIST CSF 2.0PR.AC-1The report is fundamentally about access compromise after phishing.
NIST SP 800-53 Rev 5IA-2Phishing-resistant authentication is the key mitigation against account takeover.
CIS Controls v8CIS-6 , Access Control ManagementPhishing risk is reduced when access is tightly governed after initial compromise.
NIST Zero Trust (SP 800-207)Zero trust thinking fits the need to verify identity continuously after phishing attempts.

Map suspicious email-to-access paths to credential access and impact tactics, then tune detections for post-click identity abuse.


Key terms

  • Polymorphic phishing: Phishing that changes content, structure, or delivery details so the same campaign appears different across messages. The goal is to defeat signature-based detection and increase the chance that at least one variant reaches a user and produces a credential, consent, or payload interaction.
  • Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
  • Identity compromise: Identity compromise is the abuse of valid credentials, tokens, or delegated access to perform actions as a trusted identity. It is dangerous because it often bypasses perimeter controls and looks like normal activity. In cloud and AI-heavy environments, it is one of the easiest ways to move laterally without obvious alarms.
  • Secure Email Gateway: A secure email gateway is a control layer that inspects email before it reaches users and can also inspect outbound mail. It filters malicious content, enforces policy, and reduces exposure to phishing, malware, and data leakage, but it does not replace identity governance or account monitoring.

What's in the full report

Knowbe4's full report covers the operational detail this post intentionally leaves for the source:

  • Breakdown of the phishing themes and lures driving ransomware delivery in 2025.
  • The report's fuller analysis of why Microsoft native security and SEGs are being evaded more often.
  • Job-application lure patterns and the roles attackers most frequently target.
  • Additional statistics and report methodology for teams that need source data for internal briefing.

👉 The full Knowbe4 report includes the supporting statistics, trend breakdowns, and lure examples behind the 2025 findings.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, and secrets management. It helps practitioners connect identity controls to the wider security programme that protects access paths and privileged workflows.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org