For years, employees have been trained to spot traditional phishing emails by looking for suspicious links, spelling mistakes, unknown senders, or strange attachments. While this advice was once effective, cyberattacks are rapidly evolving with the AI’s introduction and many of the old warning signs no longer apply.
Today’s phishing attacks are becoming more advanced, more convincing, and increasingly powered by artificial intelligence (AI). The attacks that are succeeding today do not look like the phishing of five years ago. In many cases, attackers are no longer relying on obviously fake emails or malicious software. Instead, they are using legitimate websites, trusted cloud platforms, and real authentication systems to trick users into unknowingly giving them access.
Why must traditional phishing training account for AI-driven risks?
Traditional phishing relied on deception that was visible, if you looked carefully enough. Fake domains. Poor grammar. Unexpected attachments. The training worked because the warning signs were there to be found. Modern attacks have removed those warning signs entirely.
One of the most concerning developments is the rise of identity-based attacks. Rather than stealing passwords directly, attackers now target user sessions and authentication processes. In a few recent campaigns affecting hundreds of organisations worldwide, users interacted with what appeared to be completely normal Microsoft login pages and legitimate authentication requests. There were no suspicious attachments, no fake websites, and often no obvious signs of compromise.
The reason is a structural shift in how attacks work. Attackers are no longer primarily trying to steal passwords. They are targeting user sessions and authentication processes themselves. Once a valid session is hijacked, the attacker operates as a legitimate user. Multi-factor authentication (MFA), long considered one of the strongest available defences, does not protect against this, because the login itself was genuine.
This is what makes these attacks particularly dangerous. Employees may actually be following company security guidance and still become victims because the attack flow appears legitimate from start to finish.
How is AI changing the scale and sophistication of phishing?
According to the IBM X-Force Threat Intelligence Index 2026, the exploitation of public-facing applications and systems rose 44% year-over-year, with 56% of disclosed vulnerabilities able to be exploited without any authentication at all.
AI is changing the scale and sophistication of these threats. Cybercriminals can now use AI tools to:
- Create highly convincing phishing emails,
- Mimic writing styles and business communication,
- Analyse stolen emails and documents automatically,
- Identify high-value targets within organisations,
- And launch large-scale campaigns in minutes rather than days.
Cybercrime itself is becoming professionalised in parallel. Some phishing platforms now operate as commercial software businesses, complete with customer support, subscription pricing, and continuously updated features designed to evade the latest detection methods.
This creates a structural challenge that awareness training alone cannot solve. When attackers use trusted infrastructure and legitimate authentication systems, the historical signals employees were trained to notice simply are not present.
How should organisations strengthen their defences?
This creates a major challenge for organisations. Traditional awareness training alone is no longer enough when attackers are using trusted infrastructure and legitimate authentication systems. Even multi-factor authentication (MFA), long considered one of the strongest protections, is not always sufficient against newer techniques that abuse valid login sessions.
At the moment, there is no single solution that fully eliminates this risk. Security teams across the industry are still adapting as these attack methods evolve quickly. Organisations that are ahead of this threat share a common approach. They have moved from awareness-based defences toward architecture-based ones. However, organisations can begin strengthening their defenses by:
Move toward phishing-resistant authentication over traditional MFA
Passkeys and hardware security keys are resistant to session hijacking attacks in ways that traditional MFA is not. This is the direction the industry is moving, and organisations should be evaluating their current authentication infrastructure now.
Implement behaviour-based monitoring
When attacks bypass technical indicators, behavioural signals become the primary detection mechanism. It is a more effective method to implement rather than relying on suspicious links or domains. Unusual access patterns, unexpected login locations, and anomalous activity after a legitimate login are the signals that matter.
Apply conditional access and device-based security controls
Even where authentication is compromised, conditional access policies that restrict what can be done from unmanaged or unexpected devices add a meaningful layer of friction for attackers.
Treat intelligence as a security function
Understanding which threat actors are targeting your sector, what attack patterns they are using, and which of your employees or executives have a visible digital footprint is no longer optional for organisations in high-risk sectors. Open source intelligence (OSINT) and digital footprint analysis are increasingly relevant components of a robust security posture.
Review your third-party partnerships and vendor exposure
Supply chain attacks and credential theft through third-party platforms present serious risks that often go unnoticed in traditional training. Phishing frequently serves as the entry point for these attacks. Organisations must conduct thorough due diligence before onboarding third-party vendors and verify their credentials. Ongoing monitoring is equally vital post-onboarding to track what access vendors hold and what monitoring is in place.
Above all, fostering collaboration and increasing intelligence-sharing among the cybersecurity community are the most effective strategies to remain informed and promote awareness.
TenIntelligence Thoughts
The reality is that the cybersecurity landscape is changing faster than ever. AI is not only transforming businesses and productivity, it is also transforming cyber threats. Organisations, employees, and technology providers will need to continuously adapt as attackers become more automated, scalable, and difficult to detect.
The goal of training should shift from “spot the fake email” toward “understand the nature of the threat.” If your organisation needs to understand its exposure through digital footprint analysis, OSINT-based threat assessment, or a structured review of third-party risk, reach out to TenIntelligence experts.

Written by
Salma Abouahmed | Analyst
