Phishing in 2025: Cybercriminals Are Smarter Than You Know

Phishing in 2025: Cybercriminals Are Smarter Than You Know

May 22

Olivia Debroy
Olivia DebroyOlivia Debroy loves to craft impactful narratives at the intersection of journalism, data, and digital media, leveraging her expertise to tell stories that inform, engage, and inspire. She has reported for leading Indian publications such as The Hindu and Deccan Herald and is currently pursuing her Master’s in Journalism and Mass Communication with a minor in AI & Data Journalism at St. Joseph’s University, Bangalore, where she continues to sharpen her storytelling craft with a focus on data, innovation, and media strategy.
View Profile

In this world of advanced technology, cybercriminals aren’t shying away from employing artificial intelligence, social engineering, and platform loopholes with a kind of precision that would make James Bond villains jealous.

According to GreatHorn, 3.4 billion phishing emails are sent EVERY single day, making up 1.2% of global email traffic. And it’s not just the quantity - they’re getting eerily convincing too. Worse yet, the cost to businesses incurred by phishing attacks continues to rise. The IBM 2024 report highlights that the average cost of a phishing breach has now risen to $4.88 million from $4.45 million in 2023, a 10% rise, marking the highest post-pandemic jump yet.

So what’s changed this year? Read along to learn more about the latest phishing trends for 2025 and how you can stay one step ahead!

A Quick Recap of Phishing…

Gone are the days of broken English emails from ‘Nigerian princes’. Today’s phishing attacks are sophisticated and leverage AI to mimic corporate tone, internal threads, and even real voices.

Since the launch of generative AI tools like ChatGPT, DeepSeek and more, cyber analysts report that phishing volumes have surged by a whopping 4,151%. Attackers aren’t just after your inbox anymore, they’re in your DMs (direct messages), your LinkedIn messages, and even your job applications. 80 to95% of data breaches now involve phishing, according to the Comcast Business Cybersecurity Threat Report.

In fact, AI-generated phishing emails have a 54% click through rate, nearly indistinguishable from those written by humans. Scary? Definitely. But it’s also preventable, provided you know exactly what to look for.

1. Business Email Compromise

This is not your average ‘I need a wire transfer’ scam. Using AI, attackers thoroughly imitate the writing tone and structure of a CEO or any high ranking official, deceiving even the most seasoned employee into clicking those malicious links or approving large payments.

You’ll be shocked to know that BEC attacks now account for over 53% of phishing incidents (2024 CISA report); from 2013-2023 BEC scams caused a global loss of approximately $55 billion (FBI report).

 2. Credential Capture Phishing

Roughly 80% of phishing attacks now aim to steal your login credentials, a pattern especially common for cloud tools like Microsoft 365 and Google Workspace. Once inside, attackers move laterally through different organizations, installing malware or escalating privileges.

Oh, did you know that in organizations with 1,001-1,500 employees, about 1 in every 823 emails is malicious, that slips past filters? For smaller teams of 1–250 employees, it’s even worse, 1 in 323 emails could be an attack waiting to happen.

3. AI-Driven Phishing and Deepfakes

You guessed correctly! AI is everywhere, helping everyone get their job done - even cybercriminals. Attackers are now creating real time voice deepfakes of executives or family members and looting their targets. Not only do they increase the volume of phishing attacks cyber criminals can deploy, AI phishing tools also excel at copying the tone, grammar, and sentence length of real senders.

Even more concerning? Cybercriminals can now hijack ongoing email threads using AI generated replies that blend perfectly into existing conversations.

4. The Smishing and Vishing Boom

SMS based phishing (smishing) uses manipulative texts to steal personal passwords, credentials and work information. These attacks have surged by 328% globally with average losses of $800 per incident. Deadly!

In parallel, voice phishing (vishing) uses telephone calls to persuade their targets to reveal their sensitive information increased by 28% in 2024. Attackers impersonate HR reps, banks, or delivery services to trick users into giving up sensitive data instantly.

5. Malicious Attachments and Quishing

You ought to know this: according to the 2024 Verizon DBIR report, 94% of malware is delivered through email attachments, often disguised as PDFs or Word documents. QR phishing, or quishing, has become particularly dangerous, with a 20x spike in late 2023. Hackers plant these QR codes in fake invoices, posters, or even restaurant menus and you're just one scan away from losing your personal data.

Which Industries Are The Most Targeted?

You might be currently working in one of the industries that are most highly targeted by phishing. Cybercriminals don't play favorites, but they do have their top targets.

  • Finance & Banking (high value transactions, sensitive customer data)
  • Healthcare (personal health records fetch big money on the dark web)
  • Education (universities are vulnerable due to limited IT staff and constant student turnover)
  • Energy (nfrastructure-related phishing campaigns are on the rise)
  • IT & Tech (Remote workforce, cloud tools, and fast-paced environments make tech companies a common bullseye)

Surprisingly, new hires are 44% more likely to fall for phishing attacks in their first 90 days, making onboarding periods a key vulnerability window.

Want to Boost Cyber Secure Behavior?

The main question that you should be asking yourself is : How do I stay safe?

Well, the simple answer is, it all starts with awareness.

Most of the phishing attacks succeed not because of technology fails, but because people are caught off guard or lack basic cybersecurity knowledge. You might be surprised to know that 68% of breaches originate with human elements according to the Verizon DBIR 2024 report.

That’s where OutThink steps in. Unlike generic security awareness training, OutThink maps real-time human risk across your teams and turns that data into targeted, personalized interventions. It’s not just training, it’s culture change powered by insights.

If you’re serious about reducing risk where it starts (with people), explore OutThink's Cybersecurity Human Risk Management platform. You’ll see how smart nudges and adaptive security awareness training can shift habits before the next attack hits.

Building Phishing Resilience in the Age of AI

Phishing isn’t just an IT problem , it’s a human trust problem. With AI generated content, deepfakes, and evolving tactics, cybercriminals are infiltrating our digital conversations seamlessly.

But forewarned is forearmed. To take, invest in prevention and foster a culture of cyber awareness in your organization to reduce human risk.

Next time you get a job offer, a file request, or a QR code in a cafeteria, pause there. Consider whether a cyber attack might already be in your pocket.

Share

Build Phishing Resilience With OutThink

Related Articles
Phishing in 2025: Cybercriminals Are Smarter Than You Know
Olivia Debroy
22/05/2025

Phishing in 2025: Cybercriminals Are Smarter Than You Know

Read More about AI-Native Cybersecurity Human Risk Management
How to Run a Cybersecurity Awareness Training Program in Academia
Ravi Miranda
15/05/2025

How to Run a Cybersecurity Awareness Training Program in Academia

Read More about AI-Native Cybersecurity Human Risk Management
Why Cybersecurity Human Risk Management Benefits CISOs
Gry Evita Sivertsen
29/04/2025

Why Cybersecurity Human Risk Management Benefits CISOs

Read More about AI-Native Cybersecurity Human Risk Management
Cybersecurity's Comfort Zone Problem
Jane Frankland
15/04/2025

Cybersecurity's Comfort Zone Problem

Read More about AI-Native Cybersecurity Human Risk Management
Turning Employees into Payment Security Champions: Your Guide to Free PCI Awareness Training
Roberto Ishmael Pennino
11/04/2025

Turning Employees into Payment Security Champions: Your Guide to Free PCI Awareness Training

Read More about AI-Native Cybersecurity Human Risk Management
AI Phishing: The Rising Threat of Intelligent Cyber Deception
Roberto Ishmael Pennino
02/04/2025

AI Phishing: The Rising Threat of Intelligent Cyber Deception

Read More about AI-Native Cybersecurity Human Risk Management
What Maslow’s Hierarchy of Needs Reveals About Cybersecurity Flaws
Jane Frankland
01/04/2025

What Maslow’s Hierarchy of Needs Reveals About Cybersecurity Flaws

Read More about AI-Native Cybersecurity Human Risk Management
Smishing: The Phishing Attack That Lives in Your Pocket
Roberto Ishmael Pennino
24/03/2025

Smishing: The Phishing Attack That Lives in Your Pocket

Read More about AI-Native Cybersecurity Human Risk Management
How Adaptive Security Awareness Training Drives Better Cybersecurity Outcomes: The Science
Rory Attwood
11/03/2025

How Adaptive Security Awareness Training Drives Better Cybersecurity Outcomes: The Science

Read More about AI-Native Cybersecurity Human Risk Management
Quishing: When QR Codes Become Cyber Traps - Your Essential Guide to Protection
Roberto Ishmael Pennino
10/03/2025

Quishing: When QR Codes Become Cyber Traps - Your Essential Guide to Protection

Read More about AI-Native Cybersecurity Human Risk Management
Domain Spoofing: The Cyber Trick You Can’t Afford to Ignore
Roberto Ishmael Pennino
10/03/2025

Domain Spoofing: The Cyber Trick You Can’t Afford to Ignore

Read More about AI-Native Cybersecurity Human Risk Management
PIPEDA Compliance: Why PIPEDA Training is Important
Roberto Ishmael Pennino
21/02/2025

PIPEDA Compliance: Why PIPEDA Training is Important

Read More about AI-Native Cybersecurity Human Risk Management
CCPA Training: Building a Culture of Privacy and Compliance
Roberto Ishmael Pennino
10/02/2025

CCPA Training: Building a Culture of Privacy and Compliance

Read More about AI-Native Cybersecurity Human Risk Management
Data Privacy Week: How Convention 108 Paved the Way for Modern Privacy Laws
Roberto Ishmael Pennino
31/01/2025

Data Privacy Week: How Convention 108 Paved the Way for Modern Privacy Laws

Read More about AI-Native Cybersecurity Human Risk Management
TISAX Training: Strengthening Automotive Information Security and Compliance
Roberto Ishmael Pennino
27/01/2025

TISAX Training: Strengthening Automotive Information Security and Compliance

Read More about AI-Native Cybersecurity Human Risk Management
GDPR Training: Building a Culture of Compliance
Roberto Ishmael Pennino
20/01/2025

GDPR Training: Building a Culture of Compliance

Read More about AI-Native Cybersecurity Human Risk Management
What Is DORA? DORA Training for Compliance
Dr. Charlotte Jupp
20/01/2025

What Is DORA? DORA Training for Compliance

Read More about AI-Native Cybersecurity Human Risk Management
Risk Quantification for Cybersecurity Human Risk Management
Lev Lesokhin
13/12/2024

Risk Quantification for Cybersecurity Human Risk Management

Read More about AI-Native Cybersecurity Human Risk Management
NIST Recommends New Guidelines for Password Security
Roberto Ishmael Pennino
11/11/2024

NIST Recommends New Guidelines for Password Security

Read More about AI-Native Cybersecurity Human Risk Management
Empowering Organizations with Adaptive Security Awareness Training
Roberto Ishmael Pennino
07/11/2024

Empowering Organizations with Adaptive Security Awareness Training

Read More about AI-Native Cybersecurity Human Risk Management
Why Humans Should Be the New Frontline in Cyber Defense
Roberto Ishmael Pennino
06/11/2024

Why Humans Should Be the New Frontline in Cyber Defense

Read More about AI-Native Cybersecurity Human Risk Management
Behavioral Analytics Are Changing Cybersecurity
Roberto Ishmael Pennino
04/11/2024

Behavioral Analytics Are Changing Cybersecurity

Read More about AI-Native Cybersecurity Human Risk Management
Cybersecurity Awareness Training for Remote Workforces
Roberto Ishmael Pennino
25/10/2024

Cybersecurity Awareness Training for Remote Workforces

Read More about AI-Native Cybersecurity Human Risk Management
Would You Skip an Update if You Knew What It Could Cost You?
Roberto Ishmael Pennino
24/10/2024

Would You Skip an Update if You Knew What It Could Cost You?

Read More about AI-Native Cybersecurity Human Risk Management
Why Every Cyber Strategy Fails Without This Element
Roberto Ishmael Pennino
22/10/2024

Why Every Cyber Strategy Fails Without This Element

Read More about AI-Native Cybersecurity Human Risk Management
Your Password Isn't Enough: Why Your Digital Life Needs Multifactor Authentication Today
Roberto Ishmael Pennino
21/10/2024

Your Password Isn't Enough: Why Your Digital Life Needs Multifactor Authentication Today

Read More about AI-Native Cybersecurity Human Risk Management
Is Your Cybersecurity Working From Home Too?
Roberto Ishmael Pennino
18/10/2024

Is Your Cybersecurity Working From Home Too?

Read More about AI-Native Cybersecurity Human Risk Management
Human Risk Management Gets Adaptive
Lev Lesokhin
08/10/2024

Human Risk Management Gets Adaptive

Read More about AI-Native Cybersecurity Human Risk Management
Your Cybersecurity Is Only as Strong as Your People
Roberto Ishmael Pennino
08/10/2024

Your Cybersecurity Is Only as Strong as Your People

Read More about AI-Native Cybersecurity Human Risk Management
How Ready Is Your Workforce for a Real Phishing Attack?
Roberto Ishmael Pennino
01/10/2024

How Ready Is Your Workforce for a Real Phishing Attack?

Read More about AI-Native Cybersecurity Human Risk Management
What is Cybersecurity Human Risk Management? What You Need to Know
Lev Lesokhin
23/09/2024

What is Cybersecurity Human Risk Management? What You Need to Know

Read More about AI-Native Cybersecurity Human Risk Management
Engagement Strategies for Cybersecurity Human Risk Management
Lev Lesokhin
16/08/2024

Engagement Strategies for Cybersecurity Human Risk Management

Read More about AI-Native Cybersecurity Human Risk Management
Enhance Your Phishing Training With Outthink
Lavinia Manocha
02/08/2024

Enhance Your Phishing Training With Outthink

Read More about AI-Native Cybersecurity Human Risk Management
Adaptive Security Awareness Training for Frontline Workers
Lavinia Manocha
26/07/2024

Adaptive Security Awareness Training for Frontline Workers

Read More about AI-Native Cybersecurity Human Risk Management
The Role of Security Awareness Training After IT Outages
Lev Lesokhin
26/07/2024

The Role of Security Awareness Training After IT Outages

Read More about AI-Native Cybersecurity Human Risk Management
Human Risk Management's Eight Dimensions of Secure Behavior Segmentation
Lev Lesokhin
25/07/2024

Human Risk Management's Eight Dimensions of Secure Behavior Segmentation

Read More about AI-Native Cybersecurity Human Risk Management
State-Sponsored Phishing Attacks Target 40,000 Corporate Users: What This Means for Protecting Your Business
Lev Lesokhin
18/07/2024

State-Sponsored Phishing Attacks Target 40,000 Corporate Users: What This Means for Protecting Your Business

Read More about AI-Native Cybersecurity Human Risk Management
Adaptive Security Awareness Training: Unlearning and Relearning Routines
Lev Lesokhin
10/07/2024

Adaptive Security Awareness Training: Unlearning and Relearning Routines

Read More about AI-Native Cybersecurity Human Risk Management
Did You Think Your Password Was Secure? Let’s Talk Password Security
Lev Lesokhin
24/05/2024

Did You Think Your Password Was Secure? Let’s Talk Password Security

Read More about AI-Native Cybersecurity Human Risk Management
Rethinking Security Awareness: Towards a Cybersecurity Human Risk Management Framework
Lev Lesokhin
23/05/2024

Rethinking Security Awareness: Towards a Cybersecurity Human Risk Management Framework

Read More about AI-Native Cybersecurity Human Risk Management
Password Security: Why the UK is Banning Generic Passwords
Lev Lesokhin
17/05/2024

Password Security: Why the UK is Banning Generic Passwords

Read More about AI-Native Cybersecurity Human Risk Management
Instagram Security Awareness Training: A Step-by-Step Guide
Lev Lesokhin
10/05/2024

Instagram Security Awareness Training: A Step-by-Step Guide

Read More about AI-Native Cybersecurity Human Risk Management
Cybersecurity Human Risk Management Forum Kicks Off in London
Lev Lesokhin
18/04/2024

Cybersecurity Human Risk Management Forum Kicks Off in London

Read More about AI-Native Cybersecurity Human Risk Management
Gamification Can Enhance Security Awareness Training – Badges and Leaderboards Are Just the First Step
Rory Attwood
31/01/2024

Gamification Can Enhance Security Awareness Training – Badges and Leaderboards Are Just the First Step

Read More about AI-Native Cybersecurity Human Risk Management