TL;DR: AI is making phishing more convincing and more common during holiday shopping, while 82% of respondents still report being phished or nearly phished, according to 1Password’s survey of 2,000 U.S. adults. The real gap is not awareness alone but the outdated signals, impulse buying pressure, and password reuse that scammers continue to exploit.
Editorial analysis by NHI Mgmt Group, based on content published by 1Password: “Survey: Holiday scammers are getting bolder with AI, and Americans are taking the bait”.
By the numbers:
- 82% of respondents have still been phished or come dangerously close to it.
- 66% of Americans say they’ve noticed more scammy messages, phone calls, and ads since AI became more prevalent.
- 59% of respondents said they encounter suspected phishing scams in texts.
Key questions
Q: What breaks when phishing lures look polished and grammatically correct?
A: The old habit of using spelling mistakes and awkward wording as the main warning sign breaks down.
Q: Why do holiday scams succeed even when people know the warning signs?
A: They succeed because they attach malicious requests to moments people already expect, such as shipping updates, gift cards, and limited-time deals.
Q: What are the signs that password reuse is making phishing worse?
A: A warning sign is when a single phishing event can plausibly affect multiple services, such as email, shopping, travel, or banking.
Practitioner guidance
- Update scam training around AI-generated lures Teach users that polished grammar, clean branding, and plausible formatting no longer prove legitimacy.
- Promote second-opinion verification habits Encourage employees and families to pause before acting on a message that demands urgency, then check it with a colleague or friend before clicking, paying, or logging in.
- Push unique passwords across all accounts Eliminate password reuse for consumer and work-facing services so a stolen credential from one phishing site cannot unlock additional accounts elsewhere.
Bottom line: AI-generated phishing weakens the classic cues people were taught to watch for, which makes traditional awareness signals less reliable during holiday shopping.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Holiday phishing is now a human identity governance problem, not just an awareness problem. AI has reduced the usefulness of the classic red flags people were trained to look for, so the control surface has shifted from spotting bad grammar to recognising suspicious intent and context. That weakens a model built on user vigilance alone and makes the case for stronger identity hygiene and safer authentication patterns.
A question worth separating out:
Q: How should security teams reduce phishing risk without relying only on awareness training?
A: They should combine user training with behavioural detection, vendor verification, and tighter controls on high-risk identity actions. Awareness helps users spot obvious lures, but it does not stop impersonation that looks routine. The stronger model is to detect trust abuse across mail, identity, and workflow layers before approval or credential use occurs.
👉 Read our full editorial: AI-driven phishing is weakening holiday scam defenses