Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI-driven phishing evasion is rising fast. What should teams change?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Cybercriminals are using AI to scale polymorphic attacks, evade Microsoft native security and secure email gateways by 47%, and drive ransomware resurgence through phishing, according to Knowbe4’s 2025 Phishing Threat Trends Report. The control gap is no longer email filtering alone, but behavioural detection, identity hardening, and rapid response to credential theft.

NHIMG editorial — based on content published by Knowbe4: 2025 Phishing Threat Trends Report, Vol. 5

By the numbers:

Questions worth separating out

Q: How should security teams handle AI-powered phishing that changes faster than human review?

A: They should prioritise controls that evaluate behaviour in near real time, not just known malicious indicators after the fact.

Q: Why do phishing attacks still lead to major breaches when email filters are in place?

A: Email filters reduce exposure, but they do not stop a convincing lure that reaches a human and captures credentials or MFA approvals.

Q: What do organisations get wrong about ransomware recovery?

A: Many organisations treat recovery as a storage or backup problem and underweight identity control.

Practitioner guidance

  • Deploy phishing-resistant authentication Prioritise passkeys or FIDO2 for high-risk users and administrators so a captured password or OTP cannot be reused to authenticate into critical systems.
  • Correlate mail events with identity telemetry Join inbox security alerts with sign-in logs, device posture, and privilege changes so a click, consent grant, or impossible travel event can trigger investigation before the attacker establishes durable access.
  • Reduce standing privilege in user workflows Remove persistent elevated access from accounts that are reachable by phishing, and require just-in-time elevation for admin tasks so a compromised identity cannot immediately act with broad permissions.

What's in the full report

Knowbe4's full report covers the operational detail this post intentionally leaves for the source:

  • Breakdown of the phishing themes and lures driving ransomware delivery in 2025.
  • The report's fuller analysis of why Microsoft native security and SEGs are being evaded more often.
  • Job-application lure patterns and the roles attackers most frequently target.
  • Additional statistics and report methodology for teams that need source data for internal briefing.

👉 Read Knowbe4's 2025 Phishing Threat Trends Report, Vol. 5 →

AI-driven phishing evasion is rising fast. What should teams change?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

AI has made phishing a scaling problem, not a novelty problem. The report’s core signal is that adversaries are using AI to increase variation, not invent entirely new tradecraft. That means email defenders are now fighting a volume and entropy problem where one lure can become thousands of distinct messages. For practitioners, the operational conclusion is that static rules will keep degrading unless detection becomes adaptive.

A question worth separating out:

Q: How can teams tell whether phishing controls are actually working?

A: Look for fewer successful credential submissions on lookalike domains, lower password reuse, and faster reporting of suspicious messages. If users still reach fake login pages and can submit credentials without friction, the control environment is only reducing risk on paper. The goal is to stop secrets from leaving the user’s device.

👉 Read our full editorial: Phishing threat trends show AI-driven evasion is scaling fast



   
ReplyQuote
Share: