Skip to content

Phishing Attacks Become More Sophisticated: Technical Filters Alone Are No Longer Sufficient

The Bottom Line: Phishing becomes more credible through generative AI and identity data from leaks, while technical filters increasingly fail—a strategic combination of FIDO2 authentication, frequent training, and high reporting rates is now necessary.

Generative AI and identity data from leaks make phishing attacks significantly more convincing while simultaneously weakening them against technical defenses. The BSI continues to classify phishing as the primary attack vector for ransomware and data exfiltration.

The central problem has intensified qualitatively: phishing emails are formulated grammatically flawlessly by large language models, linguistically adapted to the alleged sender role, and enriched with authentic contextual details. A CFO no longer receives a generic invoice, but a message about an actual project, real business partners, and a plausible timeframe—combined from data sourced from LinkedIn, business registries, and public procurement notices. Voice phishing with cloned voices left its experimental stage in 2024 and requires only a few seconds of audio material from company websites, podcasts, or video conferences.

Technical protection layers—email gateways with reputation databases, sandbox analysis, and machine learning—are increasingly losing their effectiveness. The reason lies in circumvention through legitimate services: phishing via Microsoft 365, Google Docs, Notion, or DocuSign bypasses reputation checks because these domains are inherently trustworthy. QR code phishing evades URL scans because the link only opens on the user’s device after scanning. Even multi-factor authentication no longer provides reliable protection: tools like Evilginx enable attackers to capture session cookies in real-time while the second authentication factor is forwarded in the background. Phishing-resistant procedures based on the FIDO2 standard address this shortcoming, but are not yet widely deployed in many organizations.

The Verizon Data Breach Investigations Report 2025 shows that roughly two-thirds of security incidents involve a human factor—not because employees are an uncontrollable risk, but because they represent a manageable line of defense when appropriately trained. One-time annual training is insufficient for this purpose. Effective security training must be short, frequent, and realistic, and must evaluate click and reporting rates. A clear, established reporting process for suspicious messages is essential. Many security concepts now use the reporting rate—the proportion of reported phishing attempts—as a central control metric. A high reporting rate enables the Security Operations Center to be informed early about new campaigns and to activate blocking rules in gateways and endpoint solutions.

A robust protection concept must combine technical, organizational, and cultural factors. Technically, this includes DMARC, DKIM, and SPF with strict reject policies, phishing-resistant authentication, monitoring, and rapid network segmentation in case of attack. Organizationally, it requires regular, high-frequency training and an established reporting culture. Culturally, a corporate culture is required that does not penalize suspicious activities but treats them as valuable early indicators for security teams.


Source: www.it-daily.net · Published 31 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: