Threats & attacks

What is AI-Powered Phishing

A plain guide to AI-powered phishing, the attacks it powers and the one habit that stops them.

Key takeaways
  • AI-powered phishing uses generative AI to write convincing messages and to clone voices and faces, so the old spelling and grammar tells no longer work.
  • The UK National Cyber Security Centre assessed in 2024 that AI will make phishing more effective and harder to detect.
  • Phishing remains the most reported cybercrime complaint in the United States, per the FBI’s IC3.
  • Business email compromise drove about 2.9 billion US dollars in reported US losses in 2023, per the FBI.
  • In 2024 a finance employee at Arup paid about 25 million US dollars after a deepfake video call, per Hong Kong police.
  • Attacks on Ferrari and WPP in 2024 failed because someone verified the request through another channel.
  • You cannot reliably spot the fake by eye or ear, so watch the behaviour around the request instead.
  • Out-of-band verification, a callback on a number you already hold, stops most attacks in one step.
  • Security awareness training and phishing simulations are required under NIS2, in force in Sweden as Cybersäkerhetslagen since 15 January 2026.
  • Under GDPR Article 33 a phishing breach that exposes personal data must be reported to IMY within 72 hours.

AI-Powered Phishing Defined in Plain Terms

AI-powered phishing is a phishing attack that uses artificial intelligence to make the deception more convincing. Generative AI writes fluent tailored messages, clones a voice from a short sample or fakes a face on a live video call. The goal is the same as any phishing, to trick a person into paying, clicking or handing over access.

What changed is the barrier to entry. Convincing phishing once took time, language skill and research. AI now does that work in seconds and at scale, so an attacker can target hundreds of staff with messages that read as if a real colleague wrote them. The old advice to watch for bad spelling no longer protects you.

How AI Powers a Phishing Attack

An attacker starts the way phishing always has, by choosing a target and a pretext. AI then does the heavy lifting. A large language model drafts the email or chat message, matching the tone of a real supplier or manager and pulling in details scraped from public sources like LinkedIn. The result reads naturally in fluent business English or Swedish.

Voice and video raise the stakes. Modern tools can clone a recognisable voice from a short clip of someone speaking, then generate a phone call or voicemail in that voice. Others place a synthetic face onto a live video call. The person on the other end sounds and looks like someone the victim trusts.

None of this needs a specialist any more. The generative AI tools that help people write and edit are open to criminals too and underground services now bundle these features into ready-made phishing kits. The UK National Cyber Security Centre assessed in 2024 that AI will make phishing more effective and harder to detect over the following two years.

Types of AI-Powered Phishing Attacks

Types of AI-Powered Phishing Attacks

AI turns up in several forms of phishing. The channel changes but the aim stays the same.

  • AI-written Email Phishing: Fluent tailored emails that imitate a real sender and drop the old spelling and grammar tells.
  • Spear Phishing at Scale: AI researches many targets at once so highly personalised messages can be sent in bulk rather than one at a time.
  • Voice Phishing or Vishing: A cloned voice makes a phone call or leaves a voicemail impersonating a manager or supplier.
  • Deepfake Video Calls: A synthetic face joins a live call so a request appears to come from a trusted executive.
  • AI Chatbots and Fake Sites: Automated chat agents hold a convincing conversation and cloned login pages harvest credentials in real time.

The Business Impact of AI-Powered Phishing

Phishing is where most breaches begin and AI makes each attempt more likely to succeed. The direct cost is stolen money. Business email compromise, the fraud that AI-powered phishing feeds, drove about 2.9 billion US dollars in reported losses in the United States in 2023, according to the FBI’s Internet Crime Complaint Center.

The damage rarely stops at the payment. A successful phish can hand over an email account which the attacker then uses to reach colleagues, suppliers and customers from a trusted address. That can trigger a personal data breach, regulatory reporting and a loss of trust that outlasts the financial hit.

The scale is large and rising. In 2024 reported cybercrime losses in the United States reached a record 16.6 billion US dollars, per the FBI. Phishing stayed the most reported complaint type. Not every case involves AI but AI lowers the effort behind each attempt.

Real-World Cases

The clearest examples so far pair a phishing approach with a deepfake.

The Arup Video-Call Fraud

In early 2024 a finance employee at the engineering firm Arup was invited to a video call about a confidential transaction. Everyone on the call appeared to be senior colleagues including the chief financial officer. All of them were deepfakes, generated from public footage.

The employee made several transfers worth about 200 million Hong Kong dollars, roughly 25 million US dollars before the fraud came to light. Hong Kong police confirmed the case in February 2024. The approach had begun with a message that raised suspicion but the realistic call overrode it.

A callback to the executives on a number held in advance would have exposed the fake. No video call, however convincing, should authorise a payment on its own.

The Ferrari Voice-Clone Attempt

In July 2024 an executive at Ferrari received WhatsApp messages and a phone call that used an AI clone of the chief executive’s voice, pushing an urgent and secret deal.

The executive asked a question only the real chief executive could answer, about a book he had recently recommended. The caller could not answer and the attempt ended there.

The WPP Executive Impersonation

In 2024 the advertising group WPP warned staff about a scam that used a fake WhatsApp account, a cloned voice and video footage of its chief executive in an online meeting. The aim was to set up a new business and extract money.

The attempt did not succeed. Staff recognised the warning signs and did not act. The approach came off-platform and skirted the normal sign-off process. WPP’s chief executive described the attempt publicly in May 2024 to warn others.

AI-Powered Phishing and Compliance

In Sweden the law now requires organisations to manage phishing risk with penalties for those that fail. NIS2 is transposed as Cybersäkerhetslagen (SFS 2025:1506), in force since 15 January 2026. Article 21 requires security awareness training and incident handling and Article 20 makes the board personally accountable for security measures.

If phishing leads to a significant incident, the reporting clock starts. An affected organisation must send an early warning to MCF (formerly MSB) within 24 hours, a full notification within 72 hours and a final report within one month.

Two other regimes often apply at the same time. Under GDPR Article 33, a phishing breach that exposes personal data must be reported to IMY within 72 hours. For financial entities, DORA Article 17 sets ICT incident management rules supervised by Finansinspektionen.

The EU AI Act (Regulation (EU) 2024/1689) adds a transparency rule that deepfakes and other AI-generated media be labelled as artificial with those obligations applying from August 2026. Criminals will ignore it so the value is for honest platforms and detection rather than for stopping the attacker at your door.

How to Spot AI-Powered Phishing

How to Spot AI-Powered Phishing

The hard truth is that you cannot rely on spotting the fake itself. AI-written messages read cleanly and cloned voices sound right so the old tells are fading. The UK National Cyber Security Centre assessed in 2024 that generative AI will make it difficult for anyone to judge whether a message is genuine.

So watch the behaviour around the request, which is far harder to fake than a face or a voice.

  • Urgency and secrecy, a deal or transfer that supposedly cannot wait and must be kept quiet.
  • Pressure to skip the usual payment or approval steps.
  • First contact through an unusual channel such as a personal WhatsApp or a surprise video call.
  • A change to bank details or a new payee, sent by message.
  • Reluctance to move to a known phone number or an official channel.

If two or more of these appear together, treat the request as suspect until you have verified it another way.

How to Defend Against AI-Powered Phishing

Defence works best in layers across people, process and technology. No single tool catches AI-powered phishing, so the aim is to make the attack fail even when a message gets through.

The strongest single control is out-of-band verification. For any unusual or high-value request, confirm it through a second known channel before acting. Never use the channel the request arrived on. A quick call to a number you already hold defeats a cloned voice or a faked email in one step.

Put these controls in place.

  • Require two people to approve payments above a set threshold.
  • Agree a verification word or question for sensitive or urgent requests.
  • Confirm any change to supplier bank details on a number you already hold.
  • Turn on phishing-resistant multi-factor authentication for email and key systems.
  • Run regular security awareness training and phishing simulations so staff practise the response.

Technology still helps. Email authentication such as DMARC cuts spoofing of your domain. Link filtering and alerts on unusual sign-ins raise the cost of an attack further. Treat these as support for the verification habit, not a replacement for it. The tools buy time. The habit is what stops the payment.

Myths & Facts

Myth

AI-powered phishing is easy to spot because the writing is bad.

A phone call from my manager proves it is really them.

A live video call means the person is real.

This is an IT problem.

Our spam filter and antivirus will catch it.

Only large companies are targeted.

Fact

Generative AI writes fluent error-free messages. The bad-grammar tell is gone, so clean writing is no longer proof that a message is safe.

AI can clone a familiar voice from a short sample. A phone call proves nothing on its own, so confirm the request through a second known channel.

At Arup every executive on the call was a deepfake except the victim. A live call can be faked in real time, so it cannot authorise a payment by itself.

AI-powered phishing targets finance, HR and anyone who approves payments or access. The fix is a verification habit those teams own, backed by training.

Filters help but miss tailored AI messages and voice calls. Technology raises the cost of an attack. Verification is what actually stops the payment.

Any organisation that moves money or holds data is a target, and AI makes it cheap to attack many at once. Smaller teams are often less prepared.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. You join a video call about a confidential deal. Your CFO and two colleagues are on screen and ask you to wire a large sum today.

    What do you do?

    • Make the payment, since you can see and hear them
    • Call the CFO back on a number you already have before doing anything
    • Reply on the same call to confirm the bank details
  2. You get a WhatsApp voice message from your managing director, who sounds stressed and needs an urgent transfer kept secret.

    What is the safest response?

    • Ask a question only the real director would know, or call a known number
    • Act quickly because the director asked you to keep it quiet
    • Forward the voice message to finance to action
  3. A long-standing supplier emails to say their bank details have changed and the next invoice should go to a new account. The email is well written and looks normal.

    What do you do first?

    • Update the details, the email reads as genuine
    • Call the supplier on the number you already hold to confirm
    • Reply to the email to ask if the change is real
  4. An email from your CEO asks you to buy gift cards for a client surprise, keep it between you two and send the codes right away.

    Which signals should worry you?

    • Urgency, secrecy and an unusual request together
    • Nothing, the CEO often emails staff
    • Only the sender's email address

Knowledge Test

  1. What makes AI-powered phishing harder to detect than older phishing?

    • The messages are full of spelling errors
    • The messages are fluent and tailored, with no obvious tells
    • It only arrives by post

    AI removes the spelling and grammar mistakes that used to give phishing away.

  2. Which single control most reliably stops these attacks?

    • A stronger spam filter
    • Out-of-band verification on a known channel
    • Replying to confirm the request

    Confirming through a second known channel exposes a faked message or call.

  3. In the 2024 Arup case, how were the executives on the video call faked?

    • They were real but bribed
    • They were deepfakes generated from public footage
    • The call never happened

    Every executive on the call except the victim was an AI-generated deepfake.

  4. How much was reported lost in the Arup fraud?

    • About 25 thousand US dollars
    • About 2.5 million US dollars
    • About 25 million US dollars

    The finance employee transferred roughly 25 million US dollars before the fraud was found.

  5. Under Sweden's Cybersäkerhetslagen, who is accountable for security measures?

    • Only the IT team
    • The management body, or board
    • Nobody in particular

    Article 20 makes the board personally accountable for approving and overseeing security.

  6. A phishing breach exposes personal data. How quickly must it be reported to IMY under GDPR?

    • Within 72 hours
    • Within 30 days
    • There is no deadline

    GDPR Article 33 requires notification to IMY within 72 hours.

Why Training Matters

Most staff have never seen a live deepfake or a cloned voice, and the instinct to help a senior colleague is exactly what these attacks exploit. Training turns an unusual request into a moment to pause and verify.

Under Cybersäkerhetslagen, Sweden’s NIS2 law, security awareness training is now a legal duty, and the board is accountable for it. eBuilder Security runs Sweden-based security awareness and phishing-simulation training that builds the verification habit this guide describes.

Frequently Asked Questions

What is AI-powered phishing?

AI-powered phishing is a phishing attack that uses artificial intelligence to make the deception more convincing. Generative AI writes fluent tailored messages, clones voices and fakes faces on video calls. The aim is unchanged, to trick someone into paying, clicking or granting access, but the fake is now far harder to detect.

How is AI phishing different from normal phishing?

AI phishing differs from normal phishing mainly in quality and scale. The goal is the same. AI removes the spelling and grammar mistakes that once gave scams away, tailors each message from public data and can clone a voice or face. That lets attackers reach far more people with far more convincing lures.

Can you spot an AI-generated phishing email?

You often cannot spot an AI-generated phishing email from the text alone, because the writing is clean and well targeted. Focus on the behaviour instead. Be wary of urgency, secrecy, a request to skip normal steps or a new set of bank details, and verify anything unusual through a separate channel.

How do deepfakes fit into phishing?

Deepfakes extend phishing from text into voice and video. Attackers clone an executive's voice for a phone call or place a synthetic face on a live video meeting, then use it to push an urgent payment. The Arup fraud in 2024, which cost about 25 million US dollars, worked this way.

What is the best defence against AI-powered phishing?

The best defence against AI-powered phishing is out-of-band verification. For any unusual or high-value request, confirm it through a second known channel, such as a phone number you already hold, before you act. Add payment approvals by two people, multi-factor authentication and regular staff training around that habit.

Is AI-powered phishing covered by NIS2 in Sweden?

Yes, AI-powered phishing falls squarely under NIS2 in Sweden. Transposed as Cybersäkerhetslagen since 15 January 2026, it requires security awareness training and incident handling under Article 21, with the board accountable under Article 20. A resulting personal data breach also triggers a 72-hour report to IMY under GDPR Article 33.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.