Why phishing is about to get much harder to stop
Cofense
- Published
- Technology

Worrying new research from Cofense shows artificial intelligence is enabling phishing campaigns to evolve faster than many traditional security tools can respond. Here, the cybersecurity specialist examines how automated, constantly changing attacks are forcing organisations to rethink the way they detect and disrupt email threats
For years, phishing campaigns followed a familiar pattern: attackers built an email, delivered it at scale, and relied on volume to achieve success. Security teams responded in much the same way, identifying malicious indicators, blocking them, and removing matching emails from user inboxes. That model no longer reflects reality.
Artificial intelligence has fundamentally changed the economics of phishing. Rather than simply making phishing emails more convincing, AI has enabled threat actors to build campaigns that are faster to create, easier to adapt, and significantly harder to disrupt. The result is an operational shift that challenges many of the assumptions traditional email security has relied upon.
Cofense’s latest mid-year threat assessment highlights just how quickly that shift is accelerating. Business email compromise (BEC) activity increased by 56 per cent during the first half of 2026, while QR code phishing rose by 153 per cent. At the same time, phishing campaigns continue to become increasingly polymorphic, generating unique URLs and file hashes at a scale that makes traditional indicator-based detection progressively less effective.
The numbers matter, but they tell a much bigger story.
Attackers are no longer investing their time in creating a single convincing email. Instead, they are building campaigns capable of producing thousands of variations in minutes. AI allows them to personalise language, rotate infrastructure, vary delivery mechanisms, and continuously generate disposable indicators without changing the underlying objective.
This creates an uncomfortable reality for defenders. Security teams may successfully identify one malicious URL or file hash, only to discover that every other email in the campaign contains different indicators. The infrastructure, social engineering technique and attacker intent remain consistent, but the observable artefacts change constantly.
Cofense research reflects this transition. In 2025, 76 per cent of initial infection URLs were unique. By May 2026, that figure had risen to 88 per cent. The percentage of unique malicious file hashes increased from 82 per cent to 95 per cent over the same period. These campaigns are no longer exceptions; they are becoming the default operating model for modern phishing.
The implications extend well beyond email detection. Threat actors are also demonstrating greater operational maturity in how they deliver and maintain access. Legitimate remote access tools, trusted cloud services and common business platforms are increasingly being incorporated into phishing campaigns because they blend naturally into enterprise environments. Instead of introducing custom malware that immediately attracts attention, attackers are taking advantage of software and services that security teams expect to see every day.
Business email compromise is evolving in much the same way. The stereotypical email requesting an urgent gift card purchase has not disappeared entirely, but it is no longer representative of the most effective attacks. Today’s campaigns increasingly rely on lengthy email chains, realistic executive conversations and context-rich social engineering that mirrors genuine business workflows. AI allows attackers to produce these interactions at a speed and quality that would have required considerably more effort only a few years ago.
For security operations teams, this means detection cannot rely solely on identifying known malicious artifacts. Understanding campaign behaviour, communication patterns, and operational context is becoming equally important.
This is where phishing defence must continue to evolve. Effective security programmes should combine intelligent automation with contextual threat intelligence and human expertise. AI can identify relationships between messages, uncover campaign patterns and process emails at a level that would overwhelm human analysts. However, analysts provide the judgement needed to distinguish genuine attacks from legitimate business activity and understand the intent behind increasingly sophisticated campaigns.
Neither approach is sufficient in isolation. As attackers continue to automate more of the phishing lifecycle, defenders need visibility that extends beyond individual emails. The ability to connect related messages, identify campaigns despite changing indicators and rapidly remediate every malicious variant has become an operational requirement rather than an optimisation.
The defining challenge of AI-driven phishing is not that attackers can now write better emails. It is that they can execute campaigns at a speed, scale and level of variation that traditional security models were never designed to manage.
Security teams that adapt their operations around campaign-level visibility, contextual intelligence and rapid remediation will be far better positioned than those still fighting today’s phishing attacks one email at a time. The threat has changed. Defending against it requires a corresponding shift in how organisations detect, analyse and respond to phishing campaigns.
Further Information
Produced with support from Cofense. To find out more about its phishing defence, threat intelligence and incident response solutions, visit www.cofense.com. To learn more about how AI is reshaping the phishing threat landscape and what security teams can do to stay ahead, watch Cofense’s latest webinar here.
READ MORE: The end of IOC fatigue: why CISOs need to think in campaigns, not emails. Modern phishing campaigns evolve faster than traditional detection models can respond. To close the gap, CISOs must shift from analysing individual emails to understanding coordinated attack campaigns. Here, Cofense explains why campaign-based detection is becoming essential to phishing defence.
Do you have news to share or expertise to contribute? The European welcomes insights from business leaders and sector specialists. Get in touch with our editorial team to find out more.
Main image: Supplied
TOP STORIES
-
Germany’s former coal heartland makes pitch as Europe’s next AI hub -
Costa Rica’s MedTech firms now run services, not just factories -
The end of IOC fatigue: why CISOs need to think in campaigns, not emails -
AI ‘could leave us busier than ever’, Oxford professor warns -
The five pillars shaping technology-led entertainment platforms -
Ulugbek Mirzamukhamedov on how AI could power the 21st-century economy -
Burnham told to tackle Britain’s cyber weak spots on day one -
Doctors using AI before health systems set the rules -
Humanoid robots could become the next K-pop stars -
Burnham warned digital exclusion is now a national security risk -
GigaCloud and Cubbit launch sovereign cloud storage for Ukraine and Poland -
Scientists crack dinosaur egg mystery by building life-size nest -
WPSL golfers to receive global eSIM access in Yesim partnership -
Former Kyndryl Germany boss joins Infinigate in growth role -
Trump threatens 'immediate 100pc tariffs' on European countries over tech taxes -
Home routers named ‘Europe’s forgotten internet security risk’ -
AI lab says brain-like engine could slash chatbot bills by 98 per cent -
The board challenge: why security is no longer an IT problem -
The fist-bumping, selfie-taking humanoid guide that could usher sightseeing tours into the AI age -
EU says ‘time for change’ on child social media safety after survey links platforms to youth distress -
UK’s under-16s social media ban risks giving parents false comfort, experts warn -
Redefining optical gas detection: how Optronics Group is building the future of industrial safety -
Claude maker Anthropic valued at nearly $1tn after record AI funding round -
NASA to send rabbit-like drones to scout site for first Moon base -
Apollo, Artemis, Ali and Live Aid satellite station set for new Moon role in £37m deal
TOP STORIES
-
Germany’s former coal heartland makes pitch as Europe’s next AI hub -
Costa Rica’s MedTech firms now run services, not just factories -
The end of IOC fatigue: why CISOs need to think in campaigns, not emails -
AI ‘could leave us busier than ever’, Oxford professor warns -
The five pillars shaping technology-led entertainment platforms -
Ulugbek Mirzamukhamedov on how AI could power the 21st-century economy -
Burnham told to tackle Britain’s cyber weak spots on day one -
Doctors using AI before health systems set the rules -
Humanoid robots could become the next K-pop stars -
Burnham warned digital exclusion is now a national security risk -
GigaCloud and Cubbit launch sovereign cloud storage for Ukraine and Poland -
Scientists crack dinosaur egg mystery by building life-size nest -
WPSL golfers to receive global eSIM access in Yesim partnership -
Former Kyndryl Germany boss joins Infinigate in growth role -
Trump threatens 'immediate 100pc tariffs' on European countries over tech taxes -
Home routers named ‘Europe’s forgotten internet security risk’ -
AI lab says brain-like engine could slash chatbot bills by 98 per cent -
The board challenge: why security is no longer an IT problem -
The fist-bumping, selfie-taking humanoid guide that could usher sightseeing tours into the AI age -
EU says ‘time for change’ on child social media safety after survey links platforms to youth distress -
UK’s under-16s social media ban risks giving parents false comfort, experts warn -
Redefining optical gas detection: how Optronics Group is building the future of industrial safety -
Claude maker Anthropic valued at nearly $1tn after record AI funding round -
NASA to send rabbit-like drones to scout site for first Moon base -
Apollo, Artemis, Ali and Live Aid satellite station set for new Moon role in £37m deal



























