AI phishingdeepfakes in businesssocial engineering

    June 30, 2026 · 6 min read · By Fensivo Team

    AI phishing and deepfakes: what changed in 2026

    Leer en español

    The defense against AI phishing and deepfakes is not spotting the perfect fake, it is validating that the person resists the pretext that arrives with it. Deception technology improved so much that asking an employee to tell a generative email or a synthetic voice apart from the real thing is a battle lost before it starts. What can be measured and improved is something else: how a person responds when they receive an order that is urgent, credible and well written. That is the surface a security team still controls in 2026.

    What changed in 2026: generative emails, synthetic voice and fake video

    What changed is not that deception exists, it is that it stopped having a cost. A convincing phishing email used to take time and some command of the target's language, and that alone filtered out a good share of attackers. The Microsoft Digital Defense Report 2025, Microsoft's annual report on the threat landscape, documents that generative AI brought the drafting of a convincing phishing email down from up to 16 hours to 5 minutes, and that AI-generated emails reach a 54 percent click rate, more than four times the rate of hand-written ones. The barrier to entry collapsed.

    Voice adds to that. Mandiant's M-Trends 2026 report places vishing, voice-call fraud, as the second most used initial infection vector. Synthetic voice can clone an executive's tone from a few seconds of public audio, and fake video carries the same trick into a video call. The pretext no longer arrives only by email: it arrives through the channel the victim associates with trust.

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment

    Why technical filters are not enough against deceiving the person

    Technical filters stop what they can inspect, and modern deception is designed to leave nothing to inspect. A generative email with no malicious link, written in natural language, that only asks the recipient to reply or call a number, does not trip the rules an email filter uses to block. A call with a cloned voice happens entirely outside the email perimeter. Business email compromise (BEC), where the attacker poses as an executive or a vendor to authorize a payment, lives precisely in that gap: it convinces a person to do something that looks legitimate, with no malware a system can flag.

    The underlying figure comes from CISA: more than 90 percent of successful cyberattacks begin with a phishing email. When the first step of an attack is to persuade someone, the last line of defense is not the filter, it is the person's judgment under pressure. And pressure is now the deciding factor: the Verizon Data Breach Investigations Report 2025, Verizon's annual study of data breaches, measured a median of 21 seconds between someone receiving a phishing message and clicking. Twenty-one seconds leave no room for the careful analysis a traditional training course assumes.

    The human factor is still the target, not the weak link

    The person is not the weak link in the chain, they are the target the attacker chose because it is the most profitable. Cisco's 90-5-5 framework, which estimates that around 90 percent of breaches involve a human factor, does not describe careless people: it describes where the adversary aims when it wants in with the least effort. Treating the employee as the system's fault leads to the wrong response, which is to blame and re-train. Treating them as the surface the attacker prioritizes leads to the right one, which is to prepare them and measure their real resistance.

    This distinction matters because it defines what gets measured. If the problem is a person's "error", the metric is how many fail and the fix is a course. If the target is a risk surface the adversary exploits with ever better tools, the metric is how that surface's behavior changes over time, attack after attack. The second question is the one that still has a useful answer in a world of deepfakes.

    How to prepare teams: realistic simulation and later validation

    Preparing a team against modern deception has two parts that are often confused: exposing it to a realistic attack and validating afterward that it learned. The first part is adaptive phishing simulation: instead of sending the same generic email to the whole company, each person receives the pretext most likely to fool them based on their role, their context and the deceptions they already fell for. That reveals each person's real risk, not an average that hides the most exposed. It is the same shift seen across social engineering: from volume to precision, in both the attack and the defense.

    The second part is the one almost no one does and the one that truly proves change: testing again. Completing a training course does not prove behavior changed; the only thing that proves it is facing the person with an attack of the same kind, weeks later and with a different template, and observing whether they resist this time. Validating change by [testing the behavior again](/en/blog/why-training-not-working) is what separates "remembered last week's email" from "learned to recognize the pattern". Without that second test, an organization knows who failed once, but not who is still vulnerable.

    Practical signs for employees facing a suspicious pretext

    The most reliable sign is not in the fake, it is in what the message asks for. A deepfake can be perfect, but the pretext almost always shares a pattern: urgency that cuts the time to verify, an authority that pressures, and an irreversible action like paying, transferring or handing over a credential. When a message combines those three things, the channel it arrives through does not matter: email, call or video, the response is the same. Stop and verify through a path different from the one the request came in on.

    In practice, that means teaching reflexes, not facts. If a supposed executive calls asking for an urgent payment, hang up and call back on the known number. If an email from the "vendor" changes the bank details, confirm by phone with an already verified contact. If something rushes you, that urgency is itself the warning. Like the discipline behind catching [QR-code phishing](/en/blog/quishing-qr-code-phishing), these reflexes do not depend on detecting the technology, they depend on a habit that holds no matter how good the deception, and that is why they are the only thing that scales against tools that improve every month.

    Closing the gap between the realistic attack and the proof that the team learned is exactly the use case Fensivo works on: simulations personalized per person and a later validation that tests the behavior again, instead of measuring course attendance. It is how you know not just who fell once, but who is still exposed. You can see how we approach it in Fensivo's use cases.

    How many people in your organization would pass a second test today, three weeks after falling for the first one?

    Sources and references

    • CISA, "4 Things You Can Do To Keep Yourself Cyber Safe". cisa.gov
    • Cisco, "The 90-5-5 Concept: Your Key to Solving Human Risk in Cybersecurity", May 27, 2025. blogs.cisco.com
    • Verizon, "Data Breach Investigations Report (DBIR)". verizon.com
    • Mandiant (Google Cloud), "M-Trends 2026 Report". cloud.google.com
    • Microsoft, "Microsoft Digital Defense Report 2025". microsoft.com

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment