People are falling for AI phishing attempts 4.5x more often than human ones but the solutions are the same as ever

Hacker
(Image credit: Caroline Purser/Getty)

There's a peculiar tint to the modern digital landscape: everything is somehow both the same as it's always been, and yet entirely different. We still use Google, but we get a handy AI summary up top. We still get phished, but it's being done to us by AI. On this latter point, Microsoft's 2025 Digital Defense Report (PDF warning) points out that AI is now actually 4.5x more successful at getting users to click malicious links than standard attempts (via The Register).

More specifically, "AI-automated phishing emails achieved 54% click-through rates compared to 12% for standard attempts" because "AI enables more targeted phishing and better phishing lures." The bulk of the data from the report is collected from Microsoft's fiscal year 2025, from July 1, 2024 to June 30, 2025.

In addition, "AI automation has the potential to increase phishing profitability by up to 50 times by scaling highly targeted attacks to thousands of targets at minimal cost. This massive return on investment will incentivise cyber threat actors who aren’t yet using AI to add it to their toolbox in the future."

Hacker, IT and person with code on computer, programming and phishing scam with malware or virus.

(Image credit: seksan Mongkhonkhamsao @ Getty Images)

These phishing stats just point towards a more general—and, of course, expected—trend towards AI being used for nefarious purposes, not just for phishing:

"We’re witnessing adversaries deploy generative AI for a variety of activities, including scaling social engineering, automating lateral movement, engaging in vulnerability discovery, and even real-time evasion of security controls. Autonomous malware and AI-powered agents are now capable of adapting their tactics on the fly, challenging defenders to move beyond static detection and embrace behavior-based, anticipatory defense."

It can be easy to jump on the anti-AI bandwagon upon hearing things like this—and I'm no stranger to such sentiment—but I'm conscious that I'm hearing about this on the same day I'm hearing that AI has discovered a promising new cancer treatment method. Pros and cons, as always.

Plus, there's the fact that AI is used to help defend from cyber attacks these days. I suppose that's just what happens in an arms race, though; the neorealist in me sees such tit-for-tat escalations as inevitable to maintain equilibrium between different states and powers.

The good news is that it doesn't seem there's much different, in principle, that we should be doing—just ramping up more of the same. For instance, Microsoft says that "no matter how much the cyber threat landscape changes, multifactor authentication (MFA) still blocks over 99% of unauthorized access attempts, making it the single most important security measure an organization can implement."

Of course, MFA might do little to prevent you from falling for a phishing attack. On that front, though, Microsoft's recommendations are again more and better implementations of the same defences we're used to: Inbox filters, restrictions on external communications, limiting remote access tools, educating users, and keeping an eye out for common patterns of attack behaviours.

Razer Blade 16 gaming laptop
Best gaming rigs 2025

1. Best gaming laptop: Razer Blade 16

2. Best gaming PC: HP Omen 35L

3. Best handheld gaming PC: Lenovo Legion Go S SteamOS ed.

4. Best mini PC: Minisforum AtomMan G7 PT

5. Best VR headset: Meta Quest 3


👉Check out our list of guides👈

TOPICS
Jacob Fox
Hardware Writer

Jacob got his hands on a gaming PC for the first time when he was about 12 years old. He swiftly realised the local PC repair store had ripped him off with his build and vowed never to let another soul build his rig again. With this vow, Jacob the hardware junkie was born. Since then, Jacob's led a double-life as part-hardware geek, part-philosophy nerd, first working as a Hardware Writer for PCGamesN in 2020, then working towards a PhD in Philosophy for a few years while freelancing on the side for sites such as TechRadar, Pocket-lint, and yours truly, PC Gamer. Eventually, he gave up the ruthless mercenary life to join the world's #1 PC Gaming site full-time. It's definitely not an ego thing, he assures us.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.