LIVE
Study finds gender bias in GPT models is not reduced but reshaped across generations17/09/26 · OpenAI|Architectural tweaks may break conventional scaling law exponents16/09/26|OpenAI publishes a framework for reporting model misalignment16/09/26 · OpenAI|NVIDIA's Vera Rubin NVL72 Debuts in MLPerf Inference v6.116/09/26 · NVIDIA|OpenAI expands ChatGPT advertising with Sponsored Agents16/09/26 · OpenAI|OpenAI moves into advertising with 'Sponsored Agents'16/09/26 · OpenAI|Google DeepMind Introduces Gemini 3.8 Live and Its Extended Thinking Variant15/09/26 · Google DeepMind|What's at stake in AI's trillion-dollar infrastructure bet15/09/26|A Flaw in Chain-of-Thought Safety Monitoring14/09/26|Stellar Colosseum: A Multi-Agent System for Long-Horizon Mathematical Research14/09/26|Apple Code Hints Siri Could Be Swapped for ChatGPT or Claude14/09/26 · Apple|Anthropic says Houthi-linked actors used Claude Code for missile guidance software13/09/26 · Anthropic|Study finds gender bias in GPT models is not reduced but reshaped across generations17/09/26 · OpenAI|Architectural tweaks may break conventional scaling law exponents16/09/26|OpenAI publishes a framework for reporting model misalignment16/09/26 · OpenAI|NVIDIA's Vera Rubin NVL72 Debuts in MLPerf Inference v6.116/09/26 · NVIDIA|OpenAI expands ChatGPT advertising with Sponsored Agents16/09/26 · OpenAI|OpenAI moves into advertising with 'Sponsored Agents'16/09/26 · OpenAI|Google DeepMind Introduces Gemini 3.8 Live and Its Extended Thinking Variant15/09/26 · Google DeepMind|What's at stake in AI's trillion-dollar infrastructure bet15/09/26|A Flaw in Chain-of-Thought Safety Monitoring14/09/26|Stellar Colosseum: A Multi-Agent System for Long-Horizon Mathematical Research14/09/26|Apple Code Hints Siri Could Be Swapped for ChatGPT or Claude14/09/26 · Apple|Anthropic says Houthi-linked actors used Claude Code for missile guidance software13/09/26 · Anthropic|
Beginner🎣

AI phishing: the new wave (vishing, smishing) in 2026

95% of security pros say AI makes detection harder. Cloned voice vishing, perfect emails, hyper-personalized SMS: we explain everything with pro diagrams and 6-layer defense plan.

14 min readPublished May 5, 2026· Updated September 17, 2026

In one sentence

AI-powered phishing is no longer the badly written email in broken Russian. It's your boss calling you on the phone with his real voice, it's a perfectly personalised email that knows you better than you know yourself, it's an SMS from your banker sending you to a fake site indistinguishable from the real one. In 2026, 95% of security pros say that LLMs significantly complicate detection.

🎣
The analogy that works
Classic phishing was like net fishing: you cast wide, you catch whoever passes by. AI phishing is spear fishing: the attacker knows you (LinkedIn, Facebook), adapts their message, targets your exact position in the company. You're no longer one target among 10,000, you are THE target. And the weapon is invisible.

🛡️ Want to learn how to secure your company globally?

Complete framework for CISOs/managers: Google SAIF, OWASP LLM Top 10, action plan.

Read the enterprise guide

The AI phishing boom in numbers

The official 2026 figures are staggering:

Phishing: before AI vs with AI (2026)

202621 000 000/day
202412 000 000/day
2022 (pre-ChatGPT)6 500 000/day
AI targeted phishing (spear phishing)28%
AI phishing 202611%
Classic phishing 20224%
Phishing attacks detected (per day)0
Success rate (% victim clicks)0

Reading: we've gone from 6.5M attacks/day to 21M/day. And the click rate has almost tripled on targeted attacks.

How AI transforms phishing

AI phishing kill chain in 2026
1. RECONNAISSANCE 🔍 LinkedIn, X Corp. site 2-5 min 2. AI PROFILING 🧠 Position, hobbies Network, style 30 sec 3. GENERATION ✍️ Email/SMS Cloned voice 5-15 sec 4. MASS SENDING 📤 10K-1M targets Personalised 15 min 5. EXFILTRATION 🗝️ Credentials Data 1-60 min 6. MONETISATION 💰 Data resale Ransomware hours ⚡ TOTAL TIME 25 min vs 8h in 2022 🤖 AUTOMATION 95% of the chain An AI phishing attack = 25 min end-to-end, 95% automated
The 6 stages of a modern AI phishing attack, automated end-to-end

The 3 new forms of AI phishing

1. 📧 Phishing email: narrative perfection

AI generates perfectly written, personalised, contextual emails. No more errors, no more odd accents, no more "Dear Customer".

Real example (anonymised)
Email received by a salesperson at X (April 2026): > Hi Julien, > > Hope you're well since the Bordeaux seminar. I saw on LinkedIn that you recently got promoted to Account Executive, congratulations! > > I wanted to share an opportunity regarding the AXA client we talked about. I've prepared a detailed brief that I'd like you to validate before Thursday's meeting with [his real manager]. > > The doc is here: [MALICIOUS LINK] > > Can you quickly confirm if you can read it before 5pm? I need your input before pushing further. > > Have a good day, > Thomas Why it's tricky: - ✅ Mentions a real seminar (public LinkedIn info) - ✅ Real recent promotion (LinkedIn info) - ✅ Real client (LinkedIn / corporate news info) - ✅ Real manager (LinkedIn info) - ✅ Reasonable urgency (before 5pm, not "right now") - ✅ Natural style, informal, colleague tone → Click probability: 70-80% on naive target. AI did everything in 30 seconds.

2. 📞 Vishing: the boss's cloned voice

AIs clone a voice from 10-30 seconds of audio capture (LinkedIn video, podcast, conference). Then call in real-time.

AI vishing: voice attack architecture
📋 PREPARATION (48h before) Target voice retrieval YouTube, podcast, LinkedIn video Voice cloning (ElevenLabs) 10-30s sufficient → model ready Target research Manager, ongoing projects, context Script generation GPT creates attack scenario VoIP with spoofing Displayed number = boss's number 📞 EXECUTION (real-time - 5 min) ▶ ATTACKER (cloned voice) "Hi Marie, it's Pierre." "I'm in a meeting, urgent..." ◀ VICTIM "Oh hi Pierre, you OK?" "Is there a problem?" ▶ ATTACKER "Need to approve a transfer" "£50K, I'll send you the account" ⚠ COGNITIVE BIASES USED • Authority (boss) • Urgency • Familiarity (voice) • Trust 💸 IMPACT (immediate) $25M Hong Kong case (2024) +1,300% Vishing 2022→2026 35% Targeted success rate (vs 5% in 2022)
AI vishing combines cloned voice + real phone call + generated script

3. 📱 Smishing: hyper-personalised SMS

SMS are more effective than emails because:

  • 98% are read within 3 minutes
  • SMS anti-spam filters are less mature
  • Links seem more legitimate (without dodgy HTML)
Recent example (May 2026)
SMS received: > [BANK_NAME] Urgent verification: £489 transaction to AMAZON detected at 3:42pm. If not you, block here: [Short URL bit.ly/...] Why it works: - ✅ Plausible amount (not £50,000) - ✅ Common merchant (Amazon) - ✅ Recent time = panic - ✅ The sending number appears to be your real bank (spoofing) - ✅ Short URL = obscures what's behind → 35% of people have already clicked on smishing in 2026.

Tools used by attackers

AI phishing toolkit in 2026

 🛠️Tool🦹Attacker use
WormGPT, FraudGPT (blackhat LLM)Jailbroken variants of GPT/LlamaPhishing email generation without limits
ElevenLabs / Resemble.aiLegitimate AI voice toolsBoss voice cloning (vishing)
OSINT tools (Maltego, theHarvester)Public info retrievalBuild target profile in 30 sec
Phishing kits (Evilginx, GoPhish)Attack frameworksClone bank sites in 2 min
VoIP with caller ID spoofingVoIP service ($10/month)Display real boss's number
Pre-equipped Telegram bots'Phishing-as-a-service' platformsComplete kit at $50-200/month

Black market: a complete AI phishing kit costs between $50 and $500/month on the dark web. Accessible to any script-kiddie.

The 7 signals of AI phishing in 2026

Anti-AI phishing checklist
1. ⚡ Sudden urgency "Before 5pm", "right now", "don't do anything until..." → red flag. 2. 🔄 Request to change usual channel "Don't reply by email, call this number" → suspicious. 3. 💰 Unusual financial action Transfer to new account, gift card purchase → verify twice rather than once. 4. 🔗 Shortened or suspicious link Weird domain ("paypa1.com" instead of "paypal.com"), unexpected bit.ly, strange subdomain. 5. 🎯 TOO precise personalisation If someone knows too many personal details they shouldn't → OSINT sources. 6. ❓ Refusal of verification questions "No time", "call me after the meeting instead" → avoiding verification. 7. 📱 Emotional pressure "If you don't do it immediately, serious problem..." → classic manipulation.

How to defend yourself: the protection stack

6-layer anti-AI phishing defence stack
LAYER 1 : HUMAN AWARENESS Monthly simulated phishing training • Office posters • Internal security newsletter • Vishing exercises 👥 LAYER 2 : INTELLIGENT EMAIL/SMS FILTERS Microsoft Defender, Proofpoint, Mimecast • AI detection • SPF/DKIM/DMARC • Auto-quarantine 📧 LAYER 3 : MANDATORY 2FA / MFA Authenticator app (not SMS!) • FIDO2/WebAuthn keys • Conditional access based on location 🔐 LAYER 4, 2ND CHANNEL VERIFICATION Internal code word • Direct callback to known number • Slack confirmation • Manager validation 🔄 LAYER 5 : BEHAVIOURAL DETECTION (UEBA) Abnormal transfer monitoring • Unusual country login • Outgoing email volume alerts 📊 LAYER 6 : INCIDENT RESPONSE (24/7) Internal hotline • Isolation procedure • Bank callback • Data protection authority notification if data leak 🚨 ⚠️ No single layer is sufficient. Defence is in depth.
Each layer blocks one type of attack; none is sufficient alone

Express action plan for your company

📚30-day implementation

Week 1 : Audit and urgency

  • 2FA everywhere: deploy Microsoft Authenticator or YubiKey keys on all critical accounts (admin, finance, HR)
  • Identify VIPs: who can be targeted as priority? (CEO, CFO, CISO, accountants)
  • Audit recent incidents: have we suffered phishing? Which ones worked?

Week 2 : Technical prevention

  • Professional email filters: if you don't have Microsoft Defender Premium / Proofpoint, it's time
  • SPF, DKIM, DMARC: check that it's properly configured (otherwise: your emails go to spam, and imitations get through)
  • Block cloning tools: impossible at 100%, but blacklist known domains

Week 3 : Awareness

  • Flash training: 1h for all employees (short videos + real examples)
  • Simulated phishing: send 3-5 phishing emails deliberately to measure baseline click rate
  • Internal code word: decide on a code (e.g., "PROJECT TITAN") known to all, to request in case of doubt

Week 4 : Procedures

  • Transfer process: all transfers >£5K validated by 2 people via different channels
  • Security hotline: set up a number/Slack channel to report phishing in 30 sec
  • Incident plan: who calls who, how to isolate, when to alert banks/clients/data protection authority

The metaphor that sums it all up

🏰
Defending a medieval castle
Before AI, phishing was like a clumsy knight knocking on the castle gate with a fake letter from the king written by hand. The guard immediately sees it's fake: badly done signature, weird seal. With AI, it's like a professional spy who presents himself with: - The real voice of the king (cloned) - A perfect letter (generated) - The real seal (retrieved) - Knows the names of the courtiers The guard can no longer distinguish real from fake with the naked eye. → Solution: defence in depth. Multiple guards (awareness), multiple doors (2FA), multiple checks (code word), a commander watching (UEBA). No single layer is sufficient alone.

Absolute takeaways

  • AI phishing has multiplied attacks by 3 and success rate by 2-3
  • 3 vectors: perfect email, cloned voice vishing, personalised SMS smishing
  • Attacker tools available at $50-500/month on the dark web
  • Defence in depth: 6 layers (human → email → 2FA → 2nd channel → UEBA → response)
  • 2FA everywhere is measure #1 (but on app, NOT SMS)
  • Internal code word = simple and formidable weapon against vishing

You can't eliminate the risk, but you can reduce your exposure by 95% with these measures.

🧠 Quiz
Question 1 of 3

How much voice time does an attacker need to clone an executive's voice in 2026?

Going further

Tags
PhishingCybersécuritéVishingSmishingSécurité

Read next