IBM Research says AI can make phishing, already used in ~90% of cyberattacks, more effective at scale, although the team has not yet detected widespread use
Phishing attacks are already devastatingly successful. What happens when artificial intelligence makes them even harder to spot?
Context & Ripple Effects
IBM Research identifies phishing as a dominant entry point in cyberattacks and flags generative AI as a way to increase the volume and quality of social-engineering attempts, while stressing that broad adoption had not yet been observed.
The warning fits later coverage of more personalized phishing aimed at corporate executives and a wider AI-driven contest between attackers and defenders. It matters because phishing is a distribution problem: small gains in credibility or targeting can be applied across many potential victims.
First-order effects
- Security teams face pressure to treat polished, tailored phishing as a growing risk scenario even before IBM sees widespread AI-enabled campaigns.
- Attackers that adopt AI can reduce the effort required to draft and vary lures, potentially making familiar email-based defenses less reliable against higher-volume targeting.
Second-order effects
- Email-security vendors and corporate defenders will need to emphasize behavioral signals, authentication controls, and user verification rather than relying chiefly on obvious writing flaws in suspicious messages.
- Higher-quality impersonation attempts can shift more security spending toward executive protection and identity-focused defenses, consistent with reports of personalized executive phishing.
Third-order effects
- If AI-assisted phishing becomes routine, social engineering may industrialize into an iterative attacker-defender cycle, with both sides applying AI to generate, detect, and adapt campaigns.
- The durable constraint may shift from producing convincing messages to controlling trusted identities and verification channels; the pace of that shift remains uncertain because IBM had not detected widespread use at the time.
The trend: This is one early signal of AI industrialization in cybersecurity, where automation lowers the cost of both offensive targeting and defensive response.