PhishingAISMEsSocial engineering

AI phishing in 2026: how to detect a credible message

AI does not make every phishing attempt undetectable. It mainly removes mistakes, speeds up personalisation, and makes it easier to impersonate a voice or image. These signals remain reliable.

Hakim Djelili14 min read

You receive a message from your CEO. The tone is right. The project it mentions exists. The signature is perfect. It only asks you to review a Microsoft 365 document before 17:00.

The message may be legitimate. It may also have been prepared using public information, written by AI, and sent from a domain almost identical to yours. Good English is no longer enough to tell the difference. You need to examine the request, the channel, and the destination.

Useful figures

What the sources actually allow us to say

60%

Of observed initial access routes involve phishing

Scope: 4,875 incidents studied in the European Union, ENISA Threat Landscape 2025

16%

Of requests for professional assistance concern phishing

The second most common reason for assistance among businesses and non-profits in France in 2025, Cybermalveillance.gouv.fr

+29%

Increase in phishing diagnoses among professionals

Change in 2025 compared with 2024 on the Cybermalveillance.gouv.fr platform

These figures do not measure the same thing: ENISA observes intrusion vectors across Europe; Cybermalveillance.gouv.fr counts assistance journeys in France. They therefore mean neither that “60% of SMEs are hacked” nor that “80% of emails are written by AI”.

ENISA also reports that in early 2025, AI-assisted phishing campaigns may have accounted for more than 80% of social engineering activity observed worldwide. The word “assisted” matters: AI may only have been used to translate, rephrase, or personalise. This figure, which ENISA cites from third-party sources, cannot reliably attribute every message to a model.

Read the ENISA 2025 analysis and the Cybermalveillance.gouv.fr 2025 review.

Understand

What AI changes — and what it does not

Before generative AI

A campaign required more work

  • Manually research people and company practices
  • Write or translate a credible message in the target's language
  • Adapt the same pretext for several roles
  • Produce a convincing voice or video using specialist resources

With generative AI

The same steps become faster

  • Summarise public profiles and prepare a targeted pretext
  • Reproduce a professional tone without obvious mistakes
  • Adapt the message for executives, accounting, or HR
  • Generate or clone text, audio, and images more easily

ANSSI describes generative AI as a tool for performance and scaling, not as an autonomous attacker. In February 2026, the agency said it had identified no system capable of carrying out every stage of a cyberattack on its own. People still control the scenario, infrastructure, choice of targets, and exploitation.

Read the ANSSI overview of the generative AI threat.

Pattern 1

The chain of an AI-assisted phishing attack

  1. Step 1 — Observe

    Collect public information

    Websites, LinkedIn, press releases, job listings, and exposed documents reveal names, roles, suppliers, tools, and busy periods.

  2. Step 2 — Prepare

    Build a credible pretext

    AI summarises the information and adapts the vocabulary to the target: accounting, HR, management, or IT support.

  3. Step 3 — Approach

    Send an email, SMS, QR code, or call

    The channel is chosen according to the desired action. A lookalike domain, compromised account, or cloned voice increases trust.

  4. Step 4 — Prompt action

    Obtain a login, file, or payment

    The victim is directed to a login page, attachment, change of bank details, or urgent transaction.

  5. Step 5 — Exploit

    Reuse the access or money

    The attacker steals a session, reads email, follows up with contacts, deploys malware, or transfers the funds.

Examine the request

Seven signals more reliable than spelling mistakes

  • An unusual action: signing in again, installing a tool, sharing a document, buying gift cards, changing bank details, or making a transfer.
  • Urgency or secrecy: “before 17:00”, “I'm in a meeting”, “don't tell anyone”. Pressure prevents verification.
  • An inconsistent address: the display name is correct, but the full domain differs by one letter, hyphen, or extension.
  • A change of channel: a conversation that began by email moves to WhatsApp, SMS, a QR code, or an unusual video call.
  • A login initiated by a link: the page looks like Microsoft 365, Google, or DocuSign, but its domain does not belong to the service.
  • An MFA factor requested or pushed without any action from you: a six-digit code, approval notification, or device pairing.
  • A bypassed procedure: the message specifically asks you to avoid a callback, dual approval, or the usual purchasing process.

Guided exercise

Break down a credible email in 60 seconds

Subject: Atlas contract — access the file before 16:00 Hi Leah, the firm has just uploaded the latest version. I'm leaving for a meeting; can you check the figures and confirm on my mobile? The link expires today: sharepoint-revue-docs.com/atlas. Please keep the file confidential until the announcement.

The English is correct and the project may be real. Yet four points require verification:

  1. The domain is neither sharepoint.com nor the company's Microsoft 365 domain.
  2. The short deadline pushes you to click before thinking.
  3. The reply channel changes to a mobile phone.
  4. The confidentiality request discourages independent verification.

The right response is not to reply to the email. Open SharePoint from your usual bookmark or call the person on their saved number. If the document exists, you will find it without the link.

Pattern 2

Click, verify, or report: the decision tree

1Were you specifically expecting this message or document?

Yes

Move to the next question. Context reduces risk without proving authenticity.

No

Do not open the link or attachment. Verify the sender through a known channel.

2Are the full address and destination domain exact?

Yes

Continue examining the request: urgency, secrecy, payment, credentials, or a change in procedure.

No

Report the message as phishing. Do not test the link or forward the email to colleagues.

3Does the request follow the usual procedure?

Yes

Access the service from a bookmark or the app, never from the link you received.

No

Pause the action and ask a second person to confirm it through an independent channel.

Toolkit

Eight useful cybersecurity tools — and when to use them

These services provide indicators, not an absolute verdict. A link absent from blocklists can be malicious if it was just created. Conversely, an SPF or DKIM failure does not always prove fraud: forwarding or a mailing list can also alter the message.

Before clicking: check a link's reputation

  • Google Safe Browsing — Site Status: paste the link address without opening it to see whether Google has already classified it as dangerous. “No data available” does not mean the site is safe.
  • VirusTotal — URL or domain search: compares detections from several engines and reputation services. Search for the URL or its domain first. Never upload a contract, invoice, exported email, or internal file: standard submissions may be shared with the service's partners and customers.

Understand where an email came from

  • Google Admin Toolbox — Messageheader: turns an email's full headers into a readable route. It helps identify the servers involved and SPF, DKIM, or DMARC results. It cannot decide on its own whether a message is legitimate.
  • Microsoft Message Header Analyzer: an alternative suited to Microsoft 365 and Outlook environments. Before pasting a header into an external service, check your internal policy: it contains email addresses, server names, and routing information.

Measure the company's exposure

  • Have I Been Pwned: checks whether a work address appears in known data breaches. A positive result does not prove that the account is currently compromised, but it warrants checking the password, MFA, and sessions. The service also offers domain monitoring after ownership has been verified.
  • MxToolbox — DMARC, SPF, and DKIM: allows the domain owner to check email protection records. For DKIM, you need to know the selector used by Microsoft 365, Google Workspace, or your provider.

Report an incident or request help in France

  • Signal Spam: reports a phishing email or URL without visiting the page. The message's technical data helps organisations that can block the site or identify the sender.
  • 17Cyber: a free public diagnosis and assistance service, available 24 hours a day, 7 days a week to individuals, businesses, and local authorities. Depending on the situation, it provides recommendations and may offer a conversation with a police officer or gendarme.

Real cases

Two stories that show where the real defence lies

Arup: $25 million lost after a fake video conference

In January 2024, an employee of engineering company Arup in Hong Kong received a message attributed to the CFO. He was initially suspicious. A video conference reassured him: he believed he could see and hear the CFO and several colleagues. Every participant except him was synthetic. The employee made 15 transfers to five accounts, totalling approximately $25 million. The company confirmed the use of fake voices and images.

The lesson is not “learn to spot a deepfake by eye”. A credible video can deceive. The reliable defence would have been independent payment verification and dual authorisation.

Read CNN's account, with confirmation from Arup.

In France: a manager hangs up and blocks the fraud

In a case shared by the DGSI and reported in early 2026, the manager of a French industrial site was contacted by video call by someone who appeared to be the group's CEO. The face and voice were imitated. The caller requested a transfer of funds related to a confidential acquisition. The manager found the approach unusual, ended the call, and contacted management through the usual channels. The attempt failed.

The contrast with Arup is instructive: image quality did not determine the outcome; the verification procedure did.

Read the case and its analysis.

What protects you

Five measures to implement in an SME

  1. Priority 1

    Phishing-resistant authentication

    Enable passkeys or FIDO2/WebAuthn keys as a priority for email, administrator accounts, and finance roles. An SMS or six-digit code is still better than a password alone, but a fake site can relay it in real time.

  2. Priority 2

    Out-of-band verification for sensitive actions

    For new bank details, an exceptional transfer, sharing a secret, or installing software, call back on a number already known or request approval in the internal tool. Never use the number in the suspicious message.

  3. Priority 3

    SPF, DKIM, and DMARC on the domain

    DMARC in reject mode reduces exact impersonation of your own domain when properly aligned. It blocks neither a lookalike domain nor a compromised partner account: it is one layer, not a guarantee.

  4. Priority 4

    A report button and a blame-free response

    Staff must be able to report in one click and alert someone immediately if they clicked. A prompt alert allows you to revoke a session, block a domain, and warn other recipients.

  5. Priority 5

    Short, regular exercises

    Test several scenarios: a Microsoft 365 link, QR code, change of bank details, text from the CEO, and MFA notification. Focus on reporting time, not just click rate.

See CISA's MFA recommendations and the ANSSI authentication guide.

After a click

What to do immediately

  • Immediately alert your IT contact or provider, even if nothing unusual appears.
  • From a clean device, change the password if you entered it and revoke all active sessions.
  • Reject every unsolicited MFA notification and check that no new factor or device has been registered.
  • If a payment or bank details are involved, contact the bank immediately and then file a police report.
  • Keep the message, headers, URL, timestamps, and screenshots; do not continue browsing the fraudulent site.
  • Warn other recipients and look for forwarding or deletion rules added to the mailbox.

Sources

References and scope of the data

Would you like to assess your teams' responses without tricking or blaming them? Cyber Expert designs role-based simulations and measures reporting time. Arrange an initial discussion.

Need a second opinion?

Let's talk for 30 minutes — no commitment

A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.

Book a call