You receive a message from your CEO. The tone is right. The project it mentions exists. The signature is perfect. It only asks you to review a Microsoft 365 document before 17:00.
The message may be legitimate. It may also have been prepared using public information, written by AI, and sent from a domain almost identical to yours. Good English is no longer enough to tell the difference. You need to examine the request, the channel, and the destination.
Useful figures
What the sources actually allow us to say
60%
Of observed initial access routes involve phishing
Scope: 4,875 incidents studied in the European Union, ENISA Threat Landscape 2025
16%
Of requests for professional assistance concern phishing
The second most common reason for assistance among businesses and non-profits in France in 2025, Cybermalveillance.gouv.fr
+29%
Increase in phishing diagnoses among professionals
Change in 2025 compared with 2024 on the Cybermalveillance.gouv.fr platform
These figures do not measure the same thing: ENISA observes intrusion vectors across Europe; Cybermalveillance.gouv.fr counts assistance journeys in France. They therefore mean neither that “60% of SMEs are hacked” nor that “80% of emails are written by AI”.
ENISA also reports that in early 2025, AI-assisted phishing campaigns may have accounted for more than 80% of social engineering activity observed worldwide. The word “assisted” matters: AI may only have been used to translate, rephrase, or personalise. This figure, which ENISA cites from third-party sources, cannot reliably attribute every message to a model.
Read the ENISA 2025 analysis and the Cybermalveillance.gouv.fr 2025 review.
Understand
What AI changes — and what it does not
Before generative AI
A campaign required more work
- Manually research people and company practices
- Write or translate a credible message in the target's language
- Adapt the same pretext for several roles
- Produce a convincing voice or video using specialist resources
With generative AI
The same steps become faster
- Summarise public profiles and prepare a targeted pretext
- Reproduce a professional tone without obvious mistakes
- Adapt the message for executives, accounting, or HR
- Generate or clone text, audio, and images more easily
ANSSI describes generative AI as a tool for performance and scaling, not as an autonomous attacker. In February 2026, the agency said it had identified no system capable of carrying out every stage of a cyberattack on its own. People still control the scenario, infrastructure, choice of targets, and exploitation.
Read the ANSSI overview of the generative AI threat.
Pattern 1
The chain of an AI-assisted phishing attack
Step 1 — Observe
Collect public information
Websites, LinkedIn, press releases, job listings, and exposed documents reveal names, roles, suppliers, tools, and busy periods.
Step 2 — Prepare
Build a credible pretext
AI summarises the information and adapts the vocabulary to the target: accounting, HR, management, or IT support.
Step 3 — Approach
Send an email, SMS, QR code, or call
The channel is chosen according to the desired action. A lookalike domain, compromised account, or cloned voice increases trust.
Step 4 — Prompt action
Obtain a login, file, or payment
The victim is directed to a login page, attachment, change of bank details, or urgent transaction.
Step 5 — Exploit
Reuse the access or money
The attacker steals a session, reads email, follows up with contacts, deploys malware, or transfers the funds.
Examine the request
Seven signals more reliable than spelling mistakes
- An unusual action: signing in again, installing a tool, sharing a document, buying gift cards, changing bank details, or making a transfer.
- Urgency or secrecy: “before 17:00”, “I'm in a meeting”, “don't tell anyone”. Pressure prevents verification.
- An inconsistent address: the display name is correct, but the full domain differs by one letter, hyphen, or extension.
- A change of channel: a conversation that began by email moves to WhatsApp, SMS, a QR code, or an unusual video call.
- A login initiated by a link: the page looks like Microsoft 365, Google, or DocuSign, but its domain does not belong to the service.
- An MFA factor requested or pushed without any action from you: a six-digit code, approval notification, or device pairing.
- A bypassed procedure: the message specifically asks you to avoid a callback, dual approval, or the usual purchasing process.
Guided exercise
Break down a credible email in 60 seconds
Subject: Atlas contract — access the file before 16:00 Hi Leah, the firm has just uploaded the latest version. I'm leaving for a meeting; can you check the figures and confirm on my mobile? The link expires today:
sharepoint-revue-docs.com/atlas. Please keep the file confidential until the announcement.
The English is correct and the project may be real. Yet four points require verification:
- The domain is neither
sharepoint.comnor the company's Microsoft 365 domain. - The short deadline pushes you to click before thinking.
- The reply channel changes to a mobile phone.
- The confidentiality request discourages independent verification.
The right response is not to reply to the email. Open SharePoint from your usual bookmark or call the person on their saved number. If the document exists, you will find it without the link.
Pattern 2
Click, verify, or report: the decision tree
Yes
Move to the next question. Context reduces risk without proving authenticity.
No
Do not open the link or attachment. Verify the sender through a known channel.
Yes
Continue examining the request: urgency, secrecy, payment, credentials, or a change in procedure.
No
Report the message as phishing. Do not test the link or forward the email to colleagues.
Yes
Access the service from a bookmark or the app, never from the link you received.
No
Pause the action and ask a second person to confirm it through an independent channel.
Toolkit
Eight useful cybersecurity tools — and when to use them
These services provide indicators, not an absolute verdict. A link absent from blocklists can be malicious if it was just created. Conversely, an SPF or DKIM failure does not always prove fraud: forwarding or a mailing list can also alter the message.
Before clicking: check a link's reputation
- Google Safe Browsing — Site Status: paste the link address without opening it to see whether Google has already classified it as dangerous. “No data available” does not mean the site is safe.
- VirusTotal — URL or domain search: compares detections from several engines and reputation services. Search for the URL or its domain first. Never upload a contract, invoice, exported email, or internal file: standard submissions may be shared with the service's partners and customers.
Understand where an email came from
- Google Admin Toolbox — Messageheader: turns an email's full headers into a readable route. It helps identify the servers involved and SPF, DKIM, or DMARC results. It cannot decide on its own whether a message is legitimate.
- Microsoft Message Header Analyzer: an alternative suited to Microsoft 365 and Outlook environments. Before pasting a header into an external service, check your internal policy: it contains email addresses, server names, and routing information.
Measure the company's exposure
- Have I Been Pwned: checks whether a work address appears in known data breaches. A positive result does not prove that the account is currently compromised, but it warrants checking the password, MFA, and sessions. The service also offers domain monitoring after ownership has been verified.
- MxToolbox — DMARC, SPF, and DKIM: allows the domain owner to check email protection records. For DKIM, you need to know the selector used by Microsoft 365, Google Workspace, or your provider.
Report an incident or request help in France
- Signal Spam: reports a phishing email or URL without visiting the page. The message's technical data helps organisations that can block the site or identify the sender.
- 17Cyber: a free public diagnosis and assistance service, available 24 hours a day, 7 days a week to individuals, businesses, and local authorities. Depending on the situation, it provides recommendations and may offer a conversation with a police officer or gendarme.
Real cases
Two stories that show where the real defence lies
Arup: $25 million lost after a fake video conference
In January 2024, an employee of engineering company Arup in Hong Kong received a message attributed to the CFO. He was initially suspicious. A video conference reassured him: he believed he could see and hear the CFO and several colleagues. Every participant except him was synthetic. The employee made 15 transfers to five accounts, totalling approximately $25 million. The company confirmed the use of fake voices and images.
The lesson is not “learn to spot a deepfake by eye”. A credible video can deceive. The reliable defence would have been independent payment verification and dual authorisation.
Read CNN's account, with confirmation from Arup.
In France: a manager hangs up and blocks the fraud
In a case shared by the DGSI and reported in early 2026, the manager of a French industrial site was contacted by video call by someone who appeared to be the group's CEO. The face and voice were imitated. The caller requested a transfer of funds related to a confidential acquisition. The manager found the approach unusual, ended the call, and contacted management through the usual channels. The attempt failed.
The contrast with Arup is instructive: image quality did not determine the outcome; the verification procedure did.
Read the case and its analysis.
What protects you
Five measures to implement in an SME
Priority 1
Phishing-resistant authentication
Enable passkeys or FIDO2/WebAuthn keys as a priority for email, administrator accounts, and finance roles. An SMS or six-digit code is still better than a password alone, but a fake site can relay it in real time.
Priority 2
Out-of-band verification for sensitive actions
For new bank details, an exceptional transfer, sharing a secret, or installing software, call back on a number already known or request approval in the internal tool. Never use the number in the suspicious message.
Priority 3
SPF, DKIM, and DMARC on the domain
DMARC in reject mode reduces exact impersonation of your own domain when properly aligned. It blocks neither a lookalike domain nor a compromised partner account: it is one layer, not a guarantee.
Priority 4
A report button and a blame-free response
Staff must be able to report in one click and alert someone immediately if they clicked. A prompt alert allows you to revoke a session, block a domain, and warn other recipients.
Priority 5
Short, regular exercises
Test several scenarios: a Microsoft 365 link, QR code, change of bank details, text from the CEO, and MFA notification. Focus on reporting time, not just click rate.
See CISA's MFA recommendations and the ANSSI authentication guide.
After a click
What to do immediately
- Immediately alert your IT contact or provider, even if nothing unusual appears.
- From a clean device, change the password if you entered it and revoke all active sessions.
- Reject every unsolicited MFA notification and check that no new factor or device has been registered.
- If a payment or bank details are involved, contact the bank immediately and then file a police report.
- Keep the message, headers, URL, timestamps, and screenshots; do not continue browsing the fraudulent site.
- Warn other recipients and look for forwarding or deletion rules added to the mailbox.
Sources
References and scope of the data
- ANSSI — Synthèse de la menace sur l'IA générative face aux attaques informatiques, February 2026: observed offensive uses, limitations, and absence of a fully autonomous attack.
- ENISA — Threat Landscape 2025: analysis of 4,875 incidents in the European Union between July 2024 and June 2025.
- Cybermalveillance.gouv.fr — Menaces visant les professionnels en 2025: statistics from assistance journeys, not from all French companies.
- CISA — More than a Password: hierarchy of MFA methods and recommendation of FIDO/WebAuthn.
- CNN — Arup, victime d'une fraude au deepfake de 25 millions de dollars: facts confirmed by the company and Hong Kong police.
- La Banque Postale — IA et fraude, 2026: French case drawn from a DGSI briefing and analysis of useful controls.
Would you like to assess your teams' responses without tricking or blaming them? Cyber Expert designs role-based simulations and measures reporting time. Arrange an initial discussion.
Let's talk for 30 minutes — no commitment
A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.
Book a call