Key insights
- More than ever, cybercriminals are using AI to make phishing attacks faster, smarter, and more convincing.
- Classic warning signs like spelling mistakes or poor translations are increasingly disappearing from phishing messages
- AI is creating new forms of attack, from deepfake videos and voice cloning to phishing via chats, QR codes and AI assistants.
- Technology remains important, but well-trained employees still form the most effective line of defence.
AI is rapidly changing the phishing landscape
Artificial intelligence significantly lowers the barrier for cybercriminals. Where attackers previously needed time to set up credible phishing campaigns, generative AI tools can now automate almost everything, such as:
- writing phishing emails;
- gathering business information;
- analysing targets;
- Adapting communication to specific target audiences.
This leads us to see two clear evolutions. On the one hand, the number of phishing attacks is rising sharply. It is becoming easier to send out campaigns on a large scale, often with different variants per target group or function.
On the other hand, the quality is also improving. Modern phishing emails rarely contain the typical mistakes that employees used to be taught to look out for. Many messages are professionally drafted, use the correct corporate context and fit in perfectly with day-to-day communication. This makes phishing much more dangerous today than it was a few years ago.
New attack vectors in the age of AI
AI has not replaced phishing, but it has significantly strengthened existing techniques. Cybercriminals are combining classic social engineering with new AI tools to make communications more convincing, personal, and harder to recognise.
Some types of attack have been around for some time, but AI is taking them to a whole new level. Other techniques have only recently emerged on a large scale. We’ll take a look at some of the most striking developments that businesses need to be aware of today.
Deepfakes: when video is no longer automatically trustworthy
For many people, video still feels trustworthy. That is precisely why deepfakes are so powerful. Using deepfake technology, cybercriminals can realistically mimic faces and facial expressions. What used to be complex technology is now becoming increasingly accessible thanks to AI tools.
Imagine a manager asking, during a video call, for a document to be shared urgently or for a payment to be authorised. Many employees are less likely to be suspicious when they see a familiar face. And that is precisely where the danger lies: people often instinctively trust visual communication. Cybercriminals cleverly exploit this.
Voice cloning and vishing are becoming more convincing

Telephone phishing is also evolving rapidly. With vishing, attackers try to convince victims over the phone to share sensitive information or perform certain actions. AI is making this technique much more believable today thanks to voice cloning.
With only a few short audio snippets, AI-generated voices can be replicated with surprising accuracy. For example, an employee might receive a phone call from someone who sounds like a colleague or manager. They are asked to quickly provide an MFA code, make a payment, or grant access to a system.
Because the voice sounds familiar, a degree of natural suspicion disappears. This can be particularly dangerous, especially in stressful situations or on busy workdays.
Hyper-personalised phishing exploits context
Phishing is becoming increasingly personal. AI tools can gather public information via:
- business websites
- social media
- Press releases
- public data sources
Based on this, they generate messages that feel surprisingly relevant. Instead of a generic phishing email, an employee suddenly receives a message referring to a real customer, a recent project or an internal meeting. Nowadays, cybercriminals no longer need to be technical experts to carry out credible social engineering. AI helps them to mimic trust.
QR-phishing or quishing: scanning without thinking
QR codes have now become fully established. We use them for payments, meetings, parking apps, Wi-Fi access and logistics processes. Cybercriminals are taking advantage of this. With quishing, a QR code leads users to a fraudulent website or fake login page. This often happens via smartphones, where users are less likely to check which URL they are being sent to.
At first glance, a QR code on an invoice, poster or email appears harmless. Yet, one scan can be enough to steal login details or install malware. Because QR codes exude visual trust, many people are less critical of them than they would be of a regular link in an email.
Conversation hijacking: phishing in the middle of a genuine conversation
In conversation hijacking, an attacker gains access to a mailbox and AI analyses existing email conversations. The attacker then sends a reply within an ongoing email thread. This could be about invoices, contracts, deliveries, or project follow-up.
Because the context is right and the message forms part of an existing conversation, staff are often less suspicious. After all, the email appears to build on previous correspondence. This makes this form of phishing particularly difficult to spot.
Phishing is shifting to Teams and chat platforms
Also collaboration tools such as Microsoft Teams Slack is increasingly being used for phishing attacks. People generally treat chat messages more quickly and informally than emails. A short message saying “Can you check this?” often feels harmless.
AI helps cybercriminals generate exactly that kind of believable, informal communication. As a result, a fake file, a fraudulent login link, or a false approval request can feel much more trustworthy. And precisely because employees are constantly processing notifications and messages, there's a greater chance someone will react impulsively.
Indirect prompt injection: AI assistants as a new target
As AI assistants such as Microsoft Copilot As they increasingly become part of daily workflows, new attack techniques are also emerging. One example is indirect prompt injection. In this scenario, attackers do not try to mislead an employee directly, but rather the AI assistant that supports them.
Suppose an employee receives a document and asks their AI assistant to summarise its content or formulate the key action points. If an attacker has embedded hidden instructions in that document, there is a risk that the AI will interpret these as well.
The employee does not see those instructions, but the AI possibly might. In certain cases, that could lead to the AI giving incorrect recommendations, considering a suspicious link as trustworthy, or ignoring important warnings.
Technology alone will not solve the problem
Many organisations are rightly investing in security technology such as:
- Mail filtering
- firewalls
- Multi-factor authentication (MFA)
- Endpoint security
- monitoring and detection
This remains absolutely necessary. However, technology alone is no longer sufficient. Modern phishing, in fact, doesn't exclusively target systems, but primarily people.
However, people remain an important target because cybercriminals know that trust, time pressure, and routine are often stronger than technical controls. This is why security awareness training is becoming increasingly important.
To make employees a strong layer of defence again
At VanRoey, we see that organisations achieve the most results when security awareness It becomes an ongoing process rather than a one-off exercise. Using platforms such as KnowBe4 and Phished, we help organisations with, amongst other things:
- relevant security awareness training;
- realistic phishing simulations;
- continue raising awareness;
- clear reporting and follow-up.
This makes it visible where the biggest risks lie and which teams or users require additional support. KnowBe4 offers extensive training opportunities and is an established global name within security awareness, while Phished distinguishes itself with a user-friendly, Belgian approach and smart automation.
The aim is not to catch employees out, but to gradually empower them to recognise modern threats. Because ultimately, one reflex remains crucial: stopping for a moment before you click, scan, share, or approve.
Do you want to know how resilient your organisation is against modern phishing techniques today? Our cybersecurity experts would be happy to discuss with you which approach best suits your organisation. Feel free to request a no-obligation meeting or a demo of the platform. This will give you immediate insight into the possibilities and how to practically strengthen your employees against phishing and social engineering.
VAT no.
Author
Article written by
share this post: