Why AI Phishing Keeps Fooling Experienced Users (And How to Fix It)
You have approved this request a hundred times. A vendor you pay every month emails from what looks like their usual address, references last week's invoice by number, and asks you to update their bank details before Friday's run. The grammar is clean, the tone matches, and the signature block is right. That fluency is why AI phishing fools experienced users: generative tools strip out the typos and odd phrasing you were trained to catch, so the only reliable defense left is process. To protect against AI phishing, you verify every high-impact request through a channel the sender did not give you, move your accounts to phishing-resistant MFA, and set up controls that limit the damage when someone slips.
The short version
AI phishing works on skilled people because it copies their routine instead of breaking it. Stop judging messages by how they look. Treat payment changes, password resets, MFA prompts, secrecy requests, and "skip the usual process" instructions as automatic triggers for independent verification. Then back that habit with passkeys or hardware keys, least-privilege access, and a reporting workflow that gets suspicious messages to someone fast.
Time required: about 90 minutes for an individual, two to six weeks for an organization rolling out controls. Difficulty: moderate. The MFA step needs admin access if you run a team.
Before you start
- A list of every account that can move money or grant access (email, banking, exchange, payroll, cloud admin)
- A phone or laptop that supports passkeys, or a FIDO2 security key
- Contact details for key vendors, your bank, and your exchange, saved from a source you trust (a contract, a past invoice, the official app)
- For teams: admin rights to your identity provider and email security settings
Step 1: Retire the typo test and name your high-risk requests
Write down the five request types that will get independent verification no matter who sends them: payment or bank-detail changes, password resets, MFA approvals, requests to keep something confidential, and instructions to bypass normal procedure. Everything else can run on judgment. These five run on rules.
The reason for rules is scale. Attackers now use AI across the whole phishing workflow, from researching targets and personalizing lures to translating, writing follow-ups, and spinning up infrastructure. Microsoft's Digital Defense Report 2025 measured AI-automated phishing emails drawing a 54% click-through rate against 12% for conventional attempts, roughly four and a half times higher. People on r/cybersecurityindia describe what that looks like on the ground: well-written, personalized, time-boxed messages that impersonate executives or the finance team.
I call the underlying problem the familiarity discount. The more often you have handled a workflow, the less scrutiny you give it, and attackers aim at exactly those workflows because your guard is lowest there. Expertise makes you faster, and speed is what the attacker wants.
Tip: Put the five triggers on a sticky note or a pinned message in your team chat. A rule you can see beats a rule you remember when a message says "urgent."
Step 2: Verify every high-risk request out of band
Confirm each trigger request through a separate channel using contact details you already had before the message arrived. Never use the phone number, link, or reply address inside the suspicious message, because the attacker controls all three.
| Request | Verify by | Red flag that ends the conversation |
|---|---|---|
| Vendor bank-detail change | Call the number on your signed contract | Sender says "use my mobile, the office line is down" |
| Password reset you did not start | Log in directly through the official app or bookmarked URL | Link goes to a lookalike domain or a legitimate page asking for a code |
| MFA push or code prompt | Ignore it, then check account activity yourself | Prompt appears when you were not signing in |
| Executive asking for a transfer or gift cards | Message them on a separate known channel, or walk over | "Keep this between us" |
| Exchange or wallet "security review" | Open the exchange app directly, never the email | Request for seed phrase or wallet connection |
The FBI's 2025 figures show why finance teams need this table. Businesses reported more than $30 million in losses from business-email-compromise scams that involved AI, according to the IC3 2025 annual report. That counts only reported cases.
Pitfall: voice and video no longer prove identity. A callback that reaches a convincing voice is only verification if you dialed the number from your own records.
Step 3: Switch to phishing-resistant MFA
Replace SMS codes and push approvals with passkeys or FIDO2 hardware keys on every account from your Step 1 list. Passkeys are bound to the real website's domain, so a lookalike page cannot collect a usable credential, and there is no code for you to read out to a caller.
This matters more after the rise of device-code phishing. In this attack, the criminal starts a sign-in on their own device, receives a short code, and sends it to you with a plausible reason. You go to Microsoft's genuine authentication page, enter the code, and approve. The page is real. The session belongs to the attacker. Huntress research, as reported by Axios, tracked a 1,380% jump in these attacks over the first four months of 2026 compared with the second half of 2025.
That jump explains a worry raised on r/AskReddit about whether AI agents can defeat 2FA. The weak point is usually the human approving a flow they did not start, and the fix is taking that approval away from them.
Warning: Never enter a code on a login page unless you started the sign-in yourself on the device in front of you. Admins running Microsoft Entra can use conditional access policies to block device-code flow for users who have no need for it.

Step 4: Trim what attackers can learn about you
Audit your public profiles and remove the details that make impersonation easy: reporting lines, travel dates, vendor names, and long voice or video clips. Job titles on LinkedIn tell an attacker who approves payments. An out-of-office reply naming your deputy tells them who to impersonate next.
You will not erase your footprint, and you should not try. The goal is to remove the specific facts that let a lure reference "the Mumbai offsite" or "our Tuesday call with the auditor." For crypto holders, that includes posts that reveal which exchange or hardware wallet you use, a pattern covered in our breakdown of AI crypto scams.
Tip: set out-of-office replies to external senders to a generic message with no names or dates.
Step 5: Add controls that contain a mistake
Assume someone will eventually click, and configure identity, browser, and access controls so one click cannot drain an account. Separate the two failure types: human judgment failures (approving the fake invoice) and control failures (that approval being enough to move money). You fix the second with engineering.
Three settings do most of the work. Least privilege means the person reading vendor email should not also hold the rights to release payments alone. Dual approval on transfers above a threshold turns one fooled employee into two people who must both be fooled. Browser and network isolation, from tools such as Cloudflare Zero Trust, can block known malicious sites and isolate risky ones. Cloudflare's layer does not replace identity controls, verification procedures, or phishing-resistant MFA. It catches traffic, and an attacker who convinces you to approve a genuine Microsoft flow never touches a malicious URL.
For teams deploying AI assistants that can read inboxes or act on accounts, apply the same limits to the bots. Our guide to AI agent security covers scoping their permissions.
Step 6: Train with simulations and measure reporting speed
Run phishing simulations that include voice and callback scenarios, and track two numbers: how fast suspicious messages get reported, and how often staff verify a trigger request before acting. Click rate alone rewards people for ignoring email, which is the wrong lesson.
KnowBe4 is one of the larger platforms here, built around AI-selected simulations, simulated vishing, a report-phish button, and real-time coaching. The company says its customers' average Phish-Prone Percentage fell from 33.1% to about 4% within a year. Treat that as vendor-reported product data, measured on KnowBe4's own customers, and not as an independent benchmark. Pricing for its U.S. SAT Foundation tier starts at $2.40 per user per month for 25 to 50 seats on a three-year term, as listed in May 2026.
A fair objection comes from r/AskNetsec: employees may learn to spot the simulation platform's habits rather than real attacks. Counter it by rotating scenarios, mixing in internal red-team tests, and weighting verification behavior above click rates.
Individuals need a version of this too. Attack techniques change month to month, and a short daily read such as Verityadaily's The Daily Brief newsletter is one way to hear about a new lure before it reaches your inbox.
Troubleshooting
What if I already entered a device code or approved a prompt?
Sign out of all sessions from the account's security page, change the password, and revoke unknown devices and app consents. For work accounts, report it immediately so an admin can revoke tokens. Speed matters more than embarrassment.
What if the vendor's "verified" number turns out to be fake?
Your source was contaminated. Pull contact details only from documents created before the relationship could be compromised, such as the original contract or onboarding form, and flag that vendor record for review.
What if the security team is buried in reports?
Users on r/EmailSecurity argue that human review of every AI-generated phish does not scale, and they are right. Automate triage so reports matching known campaigns close on their own, and route only novel or high-risk ones to analysts.
What if leadership says the numbers do not justify the effort?
Show them the trend. The FBI logged 1,008,597 internet-crime complaints in 2025, up from 859,532 a year earlier, with phishing and spoofing among the most-reported categories. Microsoft's report adds that AI automation could make phishing up to 50 times more profitable by cutting the cost of each targeted lure.
Next steps
Do Steps 1 and 3 this week: they cost almost nothing and close the most common paths. The FBI counted more than 22,000 AI-related complaints in 2025 with adjusted losses above $893 million, so the problem is already in the reported numbers. For more on spotting the lures themselves, read our guide to AI phishing attacks in 2026.
Frequently asked questions
How do I protect against AI phishing if I can't spot it anymore?
Stop relying on spotting it. Verify any payment change, password reset, MFA prompt, or secrecy request through a channel you already trusted, such as a number from your contract or the official app. Then switch your important accounts to passkeys or hardware keys so that even a convincing fake page cannot collect a usable login. Process and controls work when your eyes cannot tell real from fake.
Why do experienced employees fall for AI phishing more than beginners?
Experience speeds up routine approvals. Someone who processes vendor updates every week gives each one less scrutiny, and AI-written lures copy those routines closely, with correct grammar, real invoice references, and a familiar tone. The cues experienced staff learned to catch, such as typos and awkward phrasing, are gone. A fixed verification rule for high-risk requests removes the reliance on instinct.
Can a real Microsoft login page be part of a phishing attack?
Yes. In device-code phishing, an attacker starts a sign-in, then tricks you into entering their code on Microsoft's genuine authentication page. You approve a session the attacker controls. The page is legitimate, so URL checks do not help. Only enter codes for sign-ins you started yourself, and ask admins to block device-code flow where it is not needed.
Does security awareness training work against AI phishing?
It helps, but it works better as one layer than as the whole defense. Vendor figures such as KnowBe4's reported drop in phish-prone rates come from their own customers, not independent trials. Training delivers the most when it measures reporting speed and verification habits, rotates scenarios so staff cannot memorize the platform, and sits on top of phishing-resistant MFA and least-privilege access.
Is SMS two-factor authentication enough to stop AI-driven account takeover?
No. SMS codes and push approvals can be relayed or approved by a user who has been talked into it. Passkeys and FIDO2 security keys are tied to the real website's domain, so a fake site cannot use them and there is no code to read out to a caller. Move email, banking, and exchange accounts to passkeys first.
Related Reading
- 11 AI Phishing Mistakes to Avoid in 2026
- AI Cyberattacks: 11 Warning Signs of Automated Threats
- Cryptocurrency Security: The Complete Protection Resource
- How to Keep Up With AI News Without Missing Major Breakthroughs
- How AI Is Changing Financial Services: Benefits, Risks, and Examples
- Can You Trust AI Crypto News? And Other Verification Questions
- 9 Best Practices for Keeping Up With AI Changes
- How to Verify a Crypto Airdrop Without Losing Funds
- Veritya Daily โ AI, Crypto, Finance & Tech News
- 8th Pay Commission Verdict Tracker: What Is Confirmed vs Pending โ September 2026
The Daily Brief A daily email newsletter delivering the day's trending technology, cryptocurrency, and finance news every morning.