AI-Powered Phishing Defined in Plain Terms
AI-powered phishing is a phishing attack that uses artificial intelligence to make the deception more convincing. Generative AI writes fluent tailored messages, clones a voice from a short sample or fakes a face on a live video call. The goal is the same as any phishing, to trick a person into paying, clicking or handing over access.
What changed is the barrier to entry. Convincing phishing once took time, language skill and research. AI now does that work in seconds and at scale, so an attacker can target hundreds of staff with messages that read as if a real colleague wrote them. The old advice to watch for bad spelling no longer protects you.
How AI Powers a Phishing Attack
An attacker starts the way phishing always has, by choosing a target and a pretext. AI then does the heavy lifting. A large language model drafts the email or chat message, matching the tone of a real supplier or manager and pulling in details scraped from public sources like LinkedIn. The result reads naturally in fluent business English or Swedish.
Voice and video raise the stakes. Modern tools can clone a recognisable voice from a short clip of someone speaking, then generate a phone call or voicemail in that voice. Others place a synthetic face onto a live video call. The person on the other end sounds and looks like someone the victim trusts.
None of this needs a specialist any more. The generative AI tools that help people write and edit are open to criminals too and underground services now bundle these features into ready-made phishing kits. The UK National Cyber Security Centre assessed in 2024 that AI will make phishing more effective and harder to detect over the following two years.
Types of AI-Powered Phishing Attacks

AI turns up in several forms of phishing. The channel changes but the aim stays the same.
- AI-written Email Phishing: Fluent tailored emails that imitate a real sender and drop the old spelling and grammar tells.
- Spear Phishing at Scale: AI researches many targets at once so highly personalised messages can be sent in bulk rather than one at a time.
- Voice Phishing or Vishing: A cloned voice makes a phone call or leaves a voicemail impersonating a manager or supplier.
- Deepfake Video Calls: A synthetic face joins a live call so a request appears to come from a trusted executive.
- AI Chatbots and Fake Sites: Automated chat agents hold a convincing conversation and cloned login pages harvest credentials in real time.
The Business Impact of AI-Powered Phishing
Phishing is where most breaches begin and AI makes each attempt more likely to succeed. The direct cost is stolen money. Business email compromise, the fraud that AI-powered phishing feeds, drove about 2.9 billion US dollars in reported losses in the United States in 2023, according to the FBI’s Internet Crime Complaint Center.
The damage rarely stops at the payment. A successful phish can hand over an email account which the attacker then uses to reach colleagues, suppliers and customers from a trusted address. That can trigger a personal data breach, regulatory reporting and a loss of trust that outlasts the financial hit.
The scale is large and rising. In 2024 reported cybercrime losses in the United States reached a record 16.6 billion US dollars, per the FBI. Phishing stayed the most reported complaint type. Not every case involves AI but AI lowers the effort behind each attempt.
Real-World Cases
The clearest examples so far pair a phishing approach with a deepfake.
The Arup Video-Call Fraud
In early 2024 a finance employee at the engineering firm Arup was invited to a video call about a confidential transaction. Everyone on the call appeared to be senior colleagues including the chief financial officer. All of them were deepfakes, generated from public footage.
The employee made several transfers worth about 200 million Hong Kong dollars, roughly 25 million US dollars before the fraud came to light. Hong Kong police confirmed the case in February 2024. The approach had begun with a message that raised suspicion but the realistic call overrode it.
A callback to the executives on a number held in advance would have exposed the fake. No video call, however convincing, should authorise a payment on its own.
The Ferrari Voice-Clone Attempt
In July 2024 an executive at Ferrari received WhatsApp messages and a phone call that used an AI clone of the chief executive’s voice, pushing an urgent and secret deal.
The executive asked a question only the real chief executive could answer, about a book he had recently recommended. The caller could not answer and the attempt ended there.
The WPP Executive Impersonation
In 2024 the advertising group WPP warned staff about a scam that used a fake WhatsApp account, a cloned voice and video footage of its chief executive in an online meeting. The aim was to set up a new business and extract money.
The attempt did not succeed. Staff recognised the warning signs and did not act. The approach came off-platform and skirted the normal sign-off process. WPP’s chief executive described the attempt publicly in May 2024 to warn others.
AI-Powered Phishing and Compliance
In Sweden the law now requires organisations to manage phishing risk with penalties for those that fail. NIS2 is transposed as Cybersäkerhetslagen (SFS 2025:1506), in force since 15 January 2026. Article 21 requires security awareness training and incident handling and Article 20 makes the board personally accountable for security measures.
If phishing leads to a significant incident, the reporting clock starts. An affected organisation must send an early warning to MCF (formerly MSB) within 24 hours, a full notification within 72 hours and a final report within one month.
Two other regimes often apply at the same time. Under GDPR Article 33, a phishing breach that exposes personal data must be reported to IMY within 72 hours. For financial entities, DORA Article 17 sets ICT incident management rules supervised by Finansinspektionen.
The EU AI Act (Regulation (EU) 2024/1689) adds a transparency rule that deepfakes and other AI-generated media be labelled as artificial with those obligations applying from August 2026. Criminals will ignore it so the value is for honest platforms and detection rather than for stopping the attacker at your door.
How to Spot AI-Powered Phishing

The hard truth is that you cannot rely on spotting the fake itself. AI-written messages read cleanly and cloned voices sound right so the old tells are fading. The UK National Cyber Security Centre assessed in 2024 that generative AI will make it difficult for anyone to judge whether a message is genuine.
So watch the behaviour around the request, which is far harder to fake than a face or a voice.
- Urgency and secrecy, a deal or transfer that supposedly cannot wait and must be kept quiet.
- Pressure to skip the usual payment or approval steps.
- First contact through an unusual channel such as a personal WhatsApp or a surprise video call.
- A change to bank details or a new payee, sent by message.
- Reluctance to move to a known phone number or an official channel.
If two or more of these appear together, treat the request as suspect until you have verified it another way.
How to Defend Against AI-Powered Phishing
Defence works best in layers across people, process and technology. No single tool catches AI-powered phishing, so the aim is to make the attack fail even when a message gets through.
The strongest single control is out-of-band verification. For any unusual or high-value request, confirm it through a second known channel before acting. Never use the channel the request arrived on. A quick call to a number you already hold defeats a cloned voice or a faked email in one step.
Put these controls in place.
- Require two people to approve payments above a set threshold.
- Agree a verification word or question for sensitive or urgent requests.
- Confirm any change to supplier bank details on a number you already hold.
- Turn on phishing-resistant multi-factor authentication for email and key systems.
- Run regular security awareness training and phishing simulations so staff practise the response.
Technology still helps. Email authentication such as DMARC cuts spoofing of your domain. Link filtering and alerts on unusual sign-ins raise the cost of an attack further. Treat these as support for the verification habit, not a replacement for it. The tools buy time. The habit is what stops the payment.


