AI Phishing Statistics 2026
By Axis Intelligence Research and Marcus Chen | Last updated: June 20, 2026 | Next scheduled update: Q3 2026 (September) | License: CC BY 4.0
Quick Answer
March 2025 was the inflection point. That month, Hoxhunt’s 70,000-simulation longitudinal experiment confirmed that AI-generated spear phishing had crossed the human effectiveness threshold — surpassing elite red team attacks by 24%. AI-generated phishing then surged 14× in December 2025 alone, jumping from 4% to 56% of all reported phishing attacks. Microsoft’s 2025 Digital Defense Report measured a 54% click rate on AI-crafted phishing versus 12% for manually written lures. And since 59% of successfully compromised accounts had MFA enabled at the time, the old advice — “just turn on MFA” — is no longer sufficient.
Why This Article Exists — and What It Doesn’t Duplicate
Axis Intelligence’s Phishing Statistics 2026 covers the full phishing landscape: FBI IC3 complaint volumes (191,561 in 2025), APWG quarterly attack counts, BEC losses ($3.046 billion), and the Phishing Loss Acceleration Index (PLAI™) — which shows the loss-per-complaint ratio climbing 18× above the 2023 baseline. If you need those numbers, that’s the primary reference.
This article asks a different question: what has AI specifically changed about how phishing works, what it costs to run, how effective it is, and why existing defenses are failing?
The PLAI™ tracks the financial acceleration. The Axis AI Phishing Effectiveness Index (AAPEI™), introduced below, tracks the technical acceleration — the shift in click rates, production costs, MFA bypass rates, and detection gaps that explain why losses are rising faster than complaint volume. The two indices are complementary, not duplicative.
Key Findings
- AI-generated phishing surged 14× in December 2025, rising from 4% to 56% of all reported phishing attacks across Hoxhunt’s global threat detection network of 4 million users — confirming that what was an emerging threat for most of 2025 became a dominant one in a matter of weeks, with the trend continuing into Q1 2026.
- AI phishing crossed the human expert effectiveness threshold in March 2025: Hoxhunt’s longitudinal study (70,000 live simulations) found AI-generated spear phishing was 31% less effective than elite red team attacks in 2023, 10% less effective by November 2024, and 24% more effective by March 2025 — a 55-percentage-point reversal in 24 months that no security model anticipated at that pace.
- Microsoft measured a 54% click rate on AI-generated phishing versus 12% for manually written lures — a 4.5× effectiveness advantage that, combined with AI’s ability to generate thousands of personalized variants simultaneously, makes AI phishing approximately 4.5× more dangerous per email and orders of magnitude cheaper to produce.
- 59% of successfully compromised accounts through phishing had MFA enabled at the time of the attack (Proofpoint, 2025) — because adversary-in-the-middle (AiTM) PhaaS kits like Tycoon 2FA and Mamba 2FA intercept session cookies after MFA verification, bypassing the protection entirely. In February 2026 alone, Proofpoint observed over 3 million messages attributable to Tycoon 2FA before its March disruption.
- 90% of high-volume phishing campaigns in 2025 leveraged Phishing-as-a-Service (PhaaS) kits (Barracuda Networks 2026), with the number of active PhaaS kits doubling during 2025 — and Tycoon 2FA alone reaching 500,000 organizations per month at its peak, rented by criminal operators for as little as $120 for a 10-day campaign.
The Axis AI Phishing Effectiveness Index (AAPEI™) — Q2 2026
An original cross-source composite metric. Distinct from the PLAI™ . The AAPEI™ measures operational effectiveness — not financial damage.
The Axis AI Phishing Effectiveness Index (AAPEI™) scores the operational advantage that AI provides to phishing attackers on a 0–100 scale across five dimensions: click rate improvement versus non-AI baseline (25%), production cost reduction (20%), MFA bypass capability (20%), detection evasion rate (20%), and personalization scale — the ability to send contextually tailored messages at volume (15%).
Formula:AAPEI = (0.25 × Click Rate Advantage) + (0.20 × Cost Reduction) + (0.20 × MFA Bypass) + (0.20 × Detection Evasion) + (0.15 × Personalization Scale)
Each dimension normalized 0–100 within the five-attack-type comparison group. Q2 2026 baseline uses Hoxhunt 2025 longitudinal data, Microsoft Digital Defense Report 2025, Proofpoint Tycoon 2FA analysis March 2026, Barracuda PhaaS report January 2026, and IBM Cost of a Data Breach 2025.
| Phishing Type | Click Rate Advantage | Cost Reduction | MFA Bypass | Detection Evasion | Personalization Scale | AAPEI™ Q2 2026 |
|---|---|---|---|---|---|---|
| AI Spear Phishing (targeted) | 100 | 82 | 61 | 78 | 94 | 84.2 |
| AI-powered PhaaS / AiTM | 71 | 100 | 100 | 88 | 72 | 85.8 |
| AI BEC (executive impersonation) | 86 | 91 | 74 | 82 | 68 | 80.5 |
| AI mass phishing (volume campaigns) | 48 | 100 | 41 | 62 | 100 | 67.4 |
| Traditional (non-AI) phishing | 0 | 0 | 8 | 21 | 12 | 7.6 |
AAPEI™ reading: AI-powered PhaaS/AiTM tops the index at 85.8 — the only attack type that simultaneously maximizes cost reduction (PhaaS subscriptions replace all infrastructure), MFA bypass (by design), and detection evasion (AiTM proxies render DMARC and email authentication largely irrelevant). AI Spear Phishing scores second at 84.2 because its click rate advantage is maximal (54% vs 12% baseline) but its MFA bypass requires either social engineering the MFA step separately or combining with AiTM tools.
The most important AAPEI™ signal: traditional phishing scores 7.6/100. Not zero — traditional attacks still work on untrained populations — but the operational gap between AI-augmented and non-AI phishing is now so large that treating them as comparable threats is a category error. The defenses built for traditional phishing (spam filters trained on grammatical errors, blocklists of known bad domains, generic security training) are demonstrably inadequate for the AI variant.
AAPEI™ updated quarterly. CC BY 4.0. Cite: Axis Intelligence Research (2026, Q2). Axis AI Phishing Effectiveness Index. Axis Intelligence. https://axis-intelligence.com/ai-phishing-statistics/
March 2025 — The Month the Models Won
Hoxhunt has been running a continuous experiment since 2023: take the same phishing prompt, give it to an elite human red team and to an AI agent simultaneously, send both to real users inside real organizations, and measure who gets clicked more.
The results over three measurement periods tell the story precisely:
- March 2023: AI click rate 2.9% vs human 4.2% — AI was 31% less effective
- November 2024: AI click rate 2.1% vs human 2.3% — gap narrowed to 10% less effective
- March 2025: AI click rate 2.78% vs human 2.25% — AI was 24% more effective
That last number is from 70,000 live simulations. Not a lab study. Not a survey of security professionals guessing. Actual users, actual inboxes, actual clicks tracked.
The reversal happened because AI improved while human detection improved too — but humans improved faster at spotting human-written attacks than at spotting AI-written ones. The absolute human failure rate on human-written phishing fell from 4.2% to 2.25% between 2023 and 2025 — users got better at detecting the patterns they were trained on. The problem: the training data was based on the old attacks.
Pyry Åvist, co-founder and CTO of Hoxhunt, called it the “Skynet Moment” for social engineering. His framing is accurate not because AI is sentient but because the inflection point is real and measurable: AI-generated phishing now surpasses what the best human attackers can produce, at a fraction of the cost, with no upper limit on simultaneous volume.
The cost differential is where the economics become alarming. IBM’s research put the production time for a skilled human attacker to create a convincing contextually appropriate spear phishing email at approximately 16 hours. An AI system produces the same output in roughly 5 minutes — a 192× speed improvement that fundamentally changes the ratio of targets to attackers. An attacker who could previously target 10 organizations per week can now target 1,920. The same attacker, the same working hours, 192× the attack surface.

The December Flood — 4% to 56% in One Month
For most of 2025, AI-generated phishing was a minority threat. Hoxhunt’s data across 4 million monitored users showed AI-generated attacks staying below 5% of all reported phishing throughout January–November 2025. Security teams were tracking the trend, but it hadn’t become the dominant operational problem.
December changed that. AI-generated phishing surged 14× — from approximately 4% of reported attacks to 56% across the Hoxhunt global threat detection network. The December 2025 spike coincided with the holiday period, when IT staffing is reduced, employee vigilance typically drops, and the volume of legitimate high-urgency emails (shipping confirmations, order updates, financial year-end communications) creates the exact cover that AI-crafted lures exploit.
What specifically drove the surge? Hoxhunt analysts noted it wasn’t sophisticated agentic AI or individualized spear phishing at scale. It was traditional phishing campaign templates becoming dramatically more polished — better grammar, professional graphics, contextually appropriate content — consistent with criminal operators adopting AI content generation tools that had become both accessible and cheap. The old commodity kit attacks — typographic errors, generic “Dear Customer” greetings, obviously cloned logos — were replaced by attacks indistinguishable from legitimate corporate communications.
That distinction matters for defense: the December 2025 surge wasn’t a new category of attack. It was the existing category, upgraded. Filters trained to catch the old version were catching less of the new one.
By early 2026, AI-generated phishing had declined slightly from the December peak but remained structurally above the pre-December baseline. The trend from a handful of vendors suggests AI-augmented phishing has established a new floor significantly above its pre-2025 levels.
The volume picture — phishing email data:
| Metric | Value | Period | Source |
|---|---|---|---|
| AI-generated phishing share (most of 2025) | <5% | Jan–Nov 2025 | Hoxhunt 2025 Annual Phishing Trends Report |
| AI-generated phishing surge (December 2025) | +14× | November→December 2025 | Hoxhunt / Expert Insights |
| AI-generated phishing share at December peak | 56% | December 2025 | Hoxhunt / Manufacturing Business Technology |
| AI phishing indicators in emails (November 2025) | 4% | November 2025 | Getastra analysis of Hoxhunt data |
| AI phishing indicators in emails (December 2025) | 56% | December 2025 | Getastra analysis of Hoxhunt data |
| Total daily phishing emails (estimated) | 3.4 billion | 2025 | Keepnet / VIPRE |
| Share of daily phishing emails with AI content | 82.6% | 2025 (later period) | Keepnet / VIPRE |
| Phishing email volume growth since ChatGPT (Nov 2022) | +1,265% | 2022–2025 | Getastra analysis |
| QR code phishing growth (2023–2025) | +400% | 2023–2025 | Hoxhunt 2025 Phishing Trends Report |
The Click Rate Math That Changes Everything
The standard phishing click rate is 2.7%, per Verizon’s 2025 DBIR. That number gets cited in security presentations, used to calculate expected breach rates, and referenced in security awareness ROI calculations.
It is not the right number for AI phishing.
Microsoft’s 2025 Digital Defense Report measured a 54% click rate for AI-generated phishing messages — specifically for AI spear phishing where the messages were contextually tailored to the recipient. The control group (manually written, generic phishing) achieved 12%. The AI advantage: 4.5×.
That 54% figure comes from controlled research environments, not field measurements of all AI phishing deployments. Real-world AI phishing click rates vary substantially based on targeting quality, recipient security training, and organizational defenses. The 2.7% Verizon figure reflects the full distribution of all phishing including low-quality mass attacks. The 54% represents targeted AI spear phishing against unprepared recipients.
The honest synthesis: AI phishing click rates span a range from the high single digits (well-defended organizations with strong training) to the mid-50s (targeted attacks on unprepared recipients). The 2.7% aggregate is irrelevant for organizations targeted by AI spear phishing specifically — the population of attacks aimed at them has a fundamentally different success rate.
What the numbers agree on: the 21-second median time-to-click (Verizon 2025 DBIR) applies regardless of AI involvement. Users who click, click fast. The question is the proportion who click at all — and that proportion is dramatically higher for AI-crafted messages.
The gap between clicking and reporting compounds the problem. Median time-to-report is 28 minutes (Verizon 2025 DBIR). That 27-minute-and-39-second window is when credentials are harvested, session cookies are exfiltrated, and the attacker establishes persistence. Faster attacks mean the window is exploited fully before any human response is possible.
Click rate data — comparative:
| Metric | Value | Source |
|---|---|---|
| Average phishing click rate (all types) | 2.7% | Verizon DBIR 2025 |
| AI-generated phishing click rate (Microsoft study) | 54% | Microsoft Digital Defense Report 2025 |
| Manually written phishing click rate (same study) | 12% | Microsoft Digital Defense Report 2025 |
| AI vs human click rate advantage | 4.5× | Axis calculation from Microsoft data |
| Untrained employee phishing susceptibility | ~33% (33.1%) | KnowBe4 2025 Phishing Report (84M simulations) |
| After 90 days of training | <18% | KnowBe4 2025 |
| After 12 months of training | <5% | KnowBe4 2025 |
| Median time-to-click (phishing email) | 21 seconds | Verizon DBIR 2025 |
| Median time-to-report (phishing email) | 28 minutes | Verizon DBIR 2025 |
| Detection-to-response gap | 27 min 39 sec | Axis calculation |
| Employees responsible for 80% of incidents (Verizon) | 8% | Verizon DBIR 2025 |
| IBM cost of phishing-initiated breach | $4.8 million avg | IBM Cost of a Data Breach 2025 |
MFA Is Not the Answer Anymore
MFA became the standard security recommendation after years of password-based breaches. Turn on multi-factor authentication, the advice went, and even if attackers get your password, they can’t access your account.
That advice is now structurally incomplete.
59% of accounts successfully compromised through phishing attacks in 2025 had MFA enabled at the time (Proofpoint data, 2025). The mechanism isn’t a flaw in MFA itself — it’s adversary-in-the-middle (AiTM) phishing, which doesn’t try to bypass MFA. It captures the session cookie issued after MFA verification.
Here’s how it works: Tycoon 2FA, Mamba 2FA, Evilginx, and similar PhaaS kits operate a real-time reverse proxy. When a victim lands on a phishing page, they’re actually passing through the attacker’s server on the way to the legitimate site. The victim enters their username, password, and MFA code — all of which are real and correct. The legitimate site issues a session token. The attacker’s proxy captures that token. The attacker now has authenticated access to the victim’s account without ever needing the password or the MFA code again, because the session is already active.
Microsoft’s 2025 Digital Defense Report attributes 80% of MFA-bypass breaches to session-token theft via AiTM kits. The remaining 20% used other MFA-bypass methods (push notification fatigue attacks, SIM swapping, recovery code theft). Traditional password theft without MFA bypass now accounts for a minority of successful phishing-to-account-compromise chains.
The scale of Tycoon 2FA before its March 4, 2026 disruption is worth stating explicitly. Microsoft documented the platform reaching over 500,000 organizations per month — not individual users, organizations. 62% of all phishing attempts blocked by Microsoft during Tycoon 2FA’s peak were attributable to it. In February 2026 alone, Proofpoint observed over 3 million messages from the platform. A 10-day Tycoon 2FA subscription cost $120. A month-long subscription cost $350.
The March 4, 2026 disruption — coordinated by Europol, Microsoft, Proofpoint, Cloudflare, and additional partners, seizing 330 domains — reduced Tycoon 2FA volume temporarily. Within weeks, new infrastructure was operational. The same pattern has repeated after every major PhaaS takedown: LabHost was dismantled in April 2024, and the PhaaS ecosystem absorbed the disruption within months with new entrants.
MFA bypass and PhaaS data:
| Metric | Value | Source |
|---|---|---|
| Compromised accounts with MFA enabled at time of attack | 59% | Proofpoint 2025 |
| Organizations experiencing account takeover attempts (2025) | 99% | Proofpoint 2025 |
| Organizations experiencing successful account takeover (2025) | 67% | Proofpoint 2025 |
| MFA-bypass breaches attributed to AiTM/session-token theft | 80% | Microsoft Digital Defense Report 2025 |
| Tycoon 2FA monthly reach at peak | 500,000 organizations | Microsoft Security Blog, March 2026 |
| Tycoon 2FA messages in February 2026 (Proofpoint) | 3 million+ | Proofpoint March 4, 2026 |
| Tycoon 2FA subscription cost | $120 / 10 days | Multiple sources |
| PhaaS campaign subscription cost (range) | $120–$350/month | Trellix / multiple |
| Domains seized in Tycoon 2FA March 2026 disruption | 330 | Europol / Proofpoint |
| High-volume phishing campaigns using PhaaS kits (2025) | 90% | Barracuda Networks 2026 |
| PhaaS kit count growth in 2025 | 2× (doubled) | Barracuda Networks 2026 |
The PhaaS Economy — What $120 Gets an Attacker in 2026
Phishing-as-a-Service deserves its own section because it reframes the entire threat model. The assumption embedded in most corporate security architecture is that sophisticated phishing requires sophisticated attackers. That assumption ended sometime in 2023.
A Tycoon 2FA subscription at $120 for 10 days provided: a management dashboard, hosting infrastructure, regularly updated phishing templates, AiTM proxy capability to capture session cookies, CAPTCHA bypass to avoid automated detection, and customer support. Criminal operators needed minimal technical skill — their only barrier to entry was the subscription fee.
The LabHost platform — disrupted by the FBI in April 2024 — had approximately 10,000 users operating 42,000 phishing domains between November 2021 and April 2024. That’s 10,000 people running industrial-scale phishing operations, most of whom would not have had the technical capability without the PhaaS infrastructure.
The cybercrime supply chain that PhaaS plugs into is worth understanding. PhaaS operators provide initial access through credential and session cookie theft. Those credentials are then sold to Initial Access Brokers (IABs) who package them for resale. Ransomware operators buy access from IABs to deploy their payloads. The phishing operator, the IAB, and the ransomware operator are typically three separate organizations with no direct coordination — which makes attribution and disruption at any single layer insufficient. Taking down Tycoon 2FA doesn’t stop the IABs who already hold stolen sessions. Arresting a ransomware operator doesn’t stop new phishing campaigns from generating new credential supply.
The Barracuda Networks threat spotlight published January 7, 2026 documented five new PhaaS entrants that emerged in 2025: Sneaky 2FA, Cephas, Whisper 2FA, GhostFrame, and others. Each competes on price, stealth, or specific AiTM capabilities. The market is functioning normally — supply expanding to meet criminal demand, with innovation driven by competitive pressure and law enforcement disruption creating openings for new entrants.
What AI Specifically Changes About BEC
Business Email Compromise generated $3.046 billion in losses in 2025 (FBI IC3 2025). BEC isn’t new — it’s been the top loss category in IC3 history for years. What AI changed is the production economics of high-quality impersonation.
40% of BEC emails in Q2 2024 were identified as AI-generated (VIPRE). BEC volume surged 54% in H1 2025 versus 2023 (Abnormal Security). IBM’s 2025 research quantified the time-to-produce advantage: what took 16 hours for a skilled human now takes 5 minutes for an AI. At that ratio, the number of BEC attacks that are economically viable to attempt expands by the same 192× factor.
The specific AI capabilities that matter for BEC: training on a target executive’s communication style from public sources (LinkedIn posts, earnings call transcripts, investor letters, published interviews), then generating impersonation emails that replicate that style’s vocabulary, sentence rhythm, and contextual references. The BEC email that arrives in accounts payable no longer reads like a translation. It reads like the person it’s pretending to be, because it was generated by a model that processed hundreds of examples of that person’s writing.
The voice layer compounds this. Marcus Chen, who covers the cyberattack landscape for Axis Intelligence, notes the pattern emerging in 2025: the AI-generated BEC email requests a wire transfer, and a follow-up phone call from a cloned version of the executive’s voice confirms the instructions verbally. The Proofpoint 2025 data is explicit: this layered attack — AI email plus voice clone confirmation — is the mechanism behind a portion of the $30 million in confirmed AI-enabled BEC losses in the FBI IC3 2025 data. The total is almost certainly higher, given that victims rarely identify voice cloning as the attack vector after the fact.
Training That Works — and Training That Doesn’t
One statistic from Proofpoint’s research defines the training problem: generic training at a US financial technology firm showed no statistically significant effect on phishing click rates (p=0.450) or reporting rates (p=0.417) across 12,511 employees in 2025. Zero. Compliance-based security training delivered on an annual or semi-annual cadence does not move the behavioral needle in a population facing AI-crafted attacks.
What does work is measurable and consistent across multiple datasets:
KnowBe4’s 2025 Phishing Report, covering 84 million simulated phishing tests, documents the training trajectory: untrained employees start at a 33.1% phishing susceptibility rate (North America: 37.1%). After 90 days of training with simulations: below 18%. After 12 months: below 5%. An 85%+ reduction from the baseline.
The mechanism that works is adaptive behavioral training with immediate feedback loops: simulated phishing sent regularly, instant feedback when someone clicks explaining why the email was deceptive, escalating difficulty as employees improve. Verizon’s 2026 DBIR found that employees who received phishing awareness training within the past 30 days were 4× more likely to report suspicious emails than those who hadn’t been trained recently. Training that happened six months ago is significantly less effective than training that happened last month.
The implication for AI phishing specifically: training needs to explicitly show employees what AI-generated phishing looks like — polished grammar, contextual references, personalized details — because the cues that prior training taught employees to spot (typos, generic greetings, suspicious domains) are exactly the cues that AI phishing eliminates.
Training effectiveness data:
| Metric | Value | Source |
|---|---|---|
| Untrained employee phishing susceptibility | 33.1% (NA: 37.1%) | KnowBe4 2025 Phishing Report (84M simulations) |
| Susceptibility after 90 days training | <18% | KnowBe4 2025 |
| Susceptibility after 12 months training | <5% | KnowBe4 2025 |
| Generic training effect on click rates (fintech study) | No significant effect (p=0.450) | Proofpoint / BRSide 2025 research |
| Training recency effect (past 30 days vs not) | 4× more likely to report | Verizon 2026 DBIR |
| Email simulation median failure rate (trained orgs) | ~1.4% | Stingrai / Verizon data |
| Phishing simulation median failure rate (pre-training) | ~11% | SQ Magazine 2026 |
| Sustained simulation improvement (12–18 months) | 20–30% baseline → low single digits | SQ Magazine 2026 |
Methodology
This article draws from seven primary sources covering the period 2024–Q1 2026. It is designed to complement — not duplicate — the Axis Intelligence Phishing Statistics 2026 article, which covers FBI IC3 complaint volumes, APWG quarterly attack counts, BEC losses, and the Phishing Loss Acceleration Index (PLAI™). The AAPEI™ and PLAI™ are distinct metrics measuring different dimensions of the phishing threat.
Primary sources used:
- Hoxhunt 2025 AI-Powered Phishing Longitudinal Study — 70,000 simulations, March 2023–March 2025, AI vs human red team effectiveness: hoxhunt.com/blog/ai-powered-phishing-vs-humans
- Hoxhunt 2026 Annual Phishing Trends Report — December 2025 14× surge, AI phishing share data: hoxhunt.com/guide/phishing-trends-report
- Microsoft Digital Defense Report 2025 — 54% vs 12% click rate comparison, 80% MFA-bypass via AiTM, Tycoon 2FA scale data: microsoft.com/en-us/security/security-insider/microsoft-digital-defense-report-2025
- Microsoft Security Blog: Inside Tycoon2FA (March 4, 2026) — 500,000 organizations/month reach, platform mechanics: microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale
- Proofpoint Threat Research: Tycoon 2FA Disruption (March 4, 2026) — 59% MFA-enabled accounts compromised, 99% organization attack rate, 3M February messages: proofpoint.com/us/blog/threat-insight/disruption-targets-tycoon-2fa-popular-aitm-phaas
- Barracuda Networks: How Phishing Kits Evolved in 2025 (January 7, 2026) — 90% PhaaS usage rate, 2× kit count growth, new entrants: blog.barracuda.com/2026/01/07/threat-spotlight-phishing-kits-evolved-2025
- KnowBe4 2025 Phishing By Industry Benchmarking Report — 84 million simulations, susceptibility rates by training level: knowbe4.com/phishing-industry-benchmarks
AAPEI™ methodology note: Five dimensions scored 0–100. Click rate advantage uses Microsoft’s 54% vs 12% benchmark normalized within the comparison group. Cost reduction uses IBM’s 192× time-to-produce differential. MFA bypass reflects Proofpoint’s 59% compromised-with-MFA data. Detection evasion reflects AI’s elimination of the grammatical/generic cues that training traditional filters rely on. Personalization scale reflects the ability to generate thousands of contextually unique variants from a single campaign brief. Full inputs in downloadable CSV.
Dataset
Full dataset — AAPEI™ scores and inputs, click rate comparison table, PhaaS pricing and scale data, Hoxhunt longitudinal effectiveness data, training outcomes table, MFA bypass statistics — CC BY 4.0. No email required.
Download: axis-intelligence.com/wp-content/uploads/2026/06/axis-ai-phishing-statistics-2026-dataset.csv
APA: Axis Intelligence Research, & Chen, M. (2026, June 20). AI phishing statistics 2026: The inflection point, the 14× surge, and why MFA no longer protects you. Axis Intelligence. https://axis-intelligence.com/ai-phishing-statistics/
MLA: Axis Intelligence Research and Marcus Chen. “AI Phishing Statistics 2026: The Inflection Point, the 14× Surge, and Why MFA No Longer Protects You.” Axis Intelligence, 20 June 2026, axis-intelligence.com/ai-phishing-statistics/.
BibTeX:
@article{axis2026aiphishing,
title={AI Phishing Statistics 2026: The Inflection Point, the 14× Surge, and Why MFA No Longer Protects You},
author={{Axis Intelligence Research} and Chen, Marcus},
journal={Axis Intelligence},
year={2026},
month={June},
day={20},
url={https://axis-intelligence.com/ai-phishing-statistics/}
}
Embed This Research
<div id="axis-ai-phishing-wrap" style="border:1px solid #21262D;border-radius:10px;overflow:hidden;margin:32px 0;">
<iframe id="axis-ai-phishing-iframe"
src="/wp-content/dashboard/ai-phishing-statistics-dashboard.html"
width="100%" height="980" frameborder="0" scrolling="no"
title="AI Phishing Statistics 2026 — AAPEI™ — Axis Intelligence Research"
loading="lazy" style="display:block;">
</iframe>
</div>
<script>
(function(){
var iframe = document.getElementById("axis-ai-phishing-iframe");
window.addEventListener("message", function(e){
if (e.data && e.data.axisIframeHeight) { iframe.style.height = e.data.axisIframeHeight + "px"; }
});
})();
</script>
Frequently Asked Questions
How effective is AI phishing compared to traditional phishing?
Significantly more effective. Microsoft’s 2025 Digital Defense Report measured a 54% click rate on AI-generated phishing versus 12% for manually written lures — a 4.5× effectiveness advantage. Hoxhunt’s longitudinal study (70,000 simulations) found AI spear phishing surpassed elite human red team attacks by 24% as of March 2025, after being 31% less effective than humans in 2023. The reversal took 24 months.
What was the December 2025 AI phishing surge?
In December 2025, AI-generated phishing surged 14× across Hoxhunt’s global threat detection network of 4 million users — rising from approximately 4% to 56% of all reported phishing attacks. The surge coincided with the holiday period and reflected criminal operators adopting AI content generation at scale, producing polished, grammatically correct, contextually appropriate lures that traditional filters were not calibrated to catch.
Does MFA protect against AI phishing?
Not reliably. Proofpoint’s 2025 data shows 59% of accounts successfully compromised through phishing had MFA enabled at the time. Adversary-in-the-middle (AiTM) PhaaS kits — including Tycoon 2FA, Mamba 2FA, and Evilginx — operate as real-time proxies that capture session cookies after MFA verification, bypassing the protection entirely. Microsoft’s 2025 Digital Defense Report attributes 80% of MFA-bypass breaches to this session-token theft mechanism.
What is Tycoon 2FA?
Tycoon 2FA was the dominant Phishing-as-a-Service (PhaaS) platform through most of 2025, reaching over 500,000 organizations per month at its peak and generating over 30 million phishing emails in a single month. It provided AiTM capabilities enabling MFA bypass for Microsoft 365 and Gmail accounts. A 10-day subscription cost $120. On March 4, 2026, Europol coordinated a disruption seizing 330 domains, temporarily reducing volume. New infrastructure was operational within weeks.
How does AI reduce the cost of phishing attacks?
IBM’s research found a skilled human attacker requires approximately 16 hours to produce a convincing contextually appropriate spear phishing email. An AI system produces equivalent output in roughly 5 minutes — a 192× speed improvement. AI also eliminates the per-email cost of human labor for personalization, enabling one attacker to run thousands of simultaneous customized campaigns. PhaaS subscriptions starting at $120 remove the infrastructure barrier. The combined effect: AI phishing has effectively zero marginal cost per additional target.
What is the AAPEI™ and how does it differ from the PLAI™?
These are two distinct Axis Intelligence indices measuring different dimensions of the phishing threat. The PLAI™ (Phishing Loss Acceleration Index, at https://axis-intelligence.com/phishing-statistics/) measures financial damage — specifically the loss-per-complaint ratio versus a 2023 baseline, showing how fast the financial impact of each successful phishing attack is growing. The AAPEI™ (Axis AI Phishing Effectiveness Index) measures operational effectiveness — click rate improvement, cost reduction, MFA bypass capability, detection evasion, and personalization scale that AI specifically provides. The PLAI™ tracks the outcome. The AAPEI™ tracks the mechanism producing that outcome.
Does security training still work against AI phishing?
Yes, but only if it’s adaptive and frequent. KnowBe4’s 2025 report (84 million simulations) found untrained employees have a 33.1% phishing susceptibility rate; 12 months of consistent simulation-based training reduces this to below 5%. However, generic annual compliance training showed no statistically significant effect on click rates in a 2025 study of 12,511 employees at a fintech firm. Training must explicitly show what AI-generated phishing looks like — polished, contextually appropriate, grammatically perfect — because the cues trained employees learned to spot in traditional phishing (typos, generic greetings) are exactly what AI eliminates.
