Fighting Back Against AI-Powered Phishing
Over 80% of security breaches in organisations stem from human error. Traditional awareness training and phishing simulations were meant to fix this, but in reality, they’ve kept security breaches stuck at an unacceptable status quo. With phishing attacks evolving faster than most training programmes, organisations need smarter, targeted approaches to human risk management.
The Rise of Phishing
Phishing first emerged in 1995 when hackers impersonated AOL staff on AOL Instant Messenger to steal passwords. Since then, it has spread across email, social media, gaming, and now corporate messaging apps such as Microsoft Teams.
From Spray-and-Pray to Precision Attacks
For years, phishing attacks followed two main paths:
-
Mass attacks – so-called “spray and pray” campaigns, where millions of emails are sent in the hope that a few users will click.
-
Spear-phishing – highly targeted emails crafted using reconnaissance and psychological triggers to lure specific individuals.
These attacks exploit the four Ps of persuasion:
-
Product: trusted brands are impersonated.
-
Price: offers of freebies or cash incentives.
-
Place: messages land in inboxes rather than junk folders.
-
Promotion: urgency or authority pressures users to act quickly.
New AI-Powered Phishing
Large Language Models (LLMs) such as WormGPT are now transforming phishing campaigns. Unlike the error-ridden attempts of the past, AI-generated phishing emails are polished, persuasive, and even able to carry on convincing conversations with users.
At the same time, Phishing-as-a-Service (PaaS) has taken off. Platforms like Greatness provide cybercriminals with advanced tools that clone Microsoft 365 login portals, steal session cookies, and mimic corporate branding automatically. As a result, traditional anti-phishing filters are struggling to keep pace.
Rethinking Anti-Phishing Measures
The goal of anti-phishing solutions isn’t just to stop attacks—it’s to reshape behaviour. Organisations need to ensure that:
-
Employees adopt stronger security habits.
-
Progress is tracked and training adapted to individual needs.
-
High-risk individuals receive tailored interventions.
-
Ultimately, fewer users click on malicious links.
UK-based cybersecurity company OutThink calls this approach Human Lateral Movement. It maps connections between people, identifies where risk clusters, and targets training where it will have the biggest impact.
Human Risk Management in Action
This is why FUEL has partnered with OutThink. Together, we help organisations implement intelligent, human-focused security awareness training that:
-
Reduces risk at an individual level.
-
Improves resilience against AI-powered phishing.
-
Provides measurable progress over time.