Resources / Articles / The Next Phishing Attack may Not Feel like Phishing at all
AI phishing attacks

The next phishing attack may not feel like phishing at all

Businesses need staff to trust normal communication without second-guessing every email, message or phone call. The challenge is that AI can make social engineering more polished, more personalised and potentially capable of adapting as the conversation develops.

Talk About Cyber Resilience
Business reality

Phishing advice used to be easier to explain

For years, staff awareness training has focused on familiar clues: spelling mistakes, strange wording, suspicious links, unexpected attachments and senders that do not quite look right.

Those checks are still worthwhile. But businesses can no longer assume that a well-written message is a trustworthy message.

Generative AI can help create polished language, process publicly available information quickly and tailor communication to the context of a particular person or organisation.

The important shift is from recognising a badly written fake message to recognising when a believable request should still be independently verified.

What is AI-powered phishing?

AI-powered phishing is social engineering where artificial intelligence assists with activities such as researching a target, producing convincing messages, personalising an approach or supporting later stages of an interaction.

The Australian Signals Directorate describes social engineering as an attempt to persuade people into actions such as revealing credentials, transferring funds, opening files or disclosing sensitive information.

Source: Australian Signals Directorate — Social engineering

Australian cyber snapshot

The underlying business risk is already significant

AI is not creating the need for cyber resilience from scratch. Email compromise, identity fraud and manipulated payment requests are already affecting Australian businesses. AI matters because it may help some attackers operate faster, personalise their approach and make their communication more convincing.

Phishing is also only one part of the wider exposure businesses need to think about. Accounts, email, cloud services, devices, suppliers and business processes can all create opportunities for attackers. We explore that wider picture in The 30 most common attack surfaces facing small businesses .

84,700+
cybercrime reports were received by ASD's ACSC in FY2024–25 — around one report every six minutes.
15%
of the top cybercrimes reported by businesses involved business email compromise fraud resulting in financial loss.
$56.6k
was the average self-reported cybercrime cost per report for small businesses.

Source: ASD Annual Cyber Threat Report 2024–25

What AI changes

A phishing attempt can potentially become a process, not a single message

Recent research is exploring how generative and agentic AI could support more adaptive forms of phishing. Public information about a person, company, supplier or role can potentially help attackers make an approach feel more relevant.

That does not mean every phishing campaign is suddenly autonomous or conversational. It does mean businesses should prepare for attacks where convincing language and relevant context are easier for attackers to produce.

A possible AI-assisted social engineering journey
This is a risk model, not a description of every phishing attack. Its value is showing why the entire interaction may matter more than the opening message.
01 Research Gather public information about people, suppliers, roles or current activity.
02 Approach Start with a message that fits the person's role or business context.
03 Respond Answer questions naturally rather than relying on one fixed script.
04 Adapt Change the explanation or tactic when the recipient hesitates.
05 Build trust Continue the interaction until the request begins to feel familiar.
06 Influence Seek money, credentials, information, access or another useful action.

Research example: Context-Aware Spear Phishing

The mindset shift

Move from “spot the bad email” to “verify the unusual request”

Staff should still pay attention to suspicious senders, links, attachments and language. The difference is that those clues should no longer be the only line of defence.

Old mental model

Does the email look fake?

Look for spelling mistakes.
Look for awkward wording.
Check whether the sender looks unusual.
Avoid obviously suspicious attachments.
Stronger mental model

Does the request make sense — and have we verified it?

Question unexpected changes to normal process.
Verify identity through a separate trusted channel.
Slow down requests involving money, credentials or access.
Report suspicious conversations, not only suspicious emails.
Practical defence

The strongest control may be a simple break in the conversation

When a request becomes unusual, businesses need a clear point where staff stop following the conversation and independently verify what they are being asked to do.

MFA, account security, clear approval processes and staff reporting pathways all still matter. They are also among the common cybersecurity gaps we see in small businesses , which is why phishing resilience is rarely just a training problem.

Pause. Verify. Then continue.
If a supplier suddenly changes bank details, a manager requests an unusual payment, an IT contact asks for a security code or a colleague wants sensitive information sent somewhere new, move outside the original conversation before acting.
1
Verify independently Call a known number, use an existing contact or confirm face-to-face rather than relying on details supplied in the message.
2
Protect accounts Use multi-factor authentication, strong account security and appropriate access controls to reduce the impact of stolen credentials.
3
Define high-risk processes Have clear verification steps for payment changes, password resets, sensitive data requests and access approvals.
4
Make reporting easy Staff should know who to contact when something feels unusual, even if they cannot prove it is malicious.
The Beach Geek™ approach

Good cyber resilience combines people, process and technology

The Beach Geek™ helps businesses look beyond individual security products and understand where cyber risk intersects with everyday business processes.

That means looking at where important requests arrive, who has authority to approve them, how identity is verified, how accounts are protected and whether staff know what to do when something feels wrong.

Technology controls matter. So do people and process. That broader view is part of building genuine cyber resilience rather than relying on one security product or one staff awareness rule.

Is AI creating completely new cyber threats?

In many cases, AI is better understood as an accelerator of existing risks rather than an entirely new category of attack.

That is useful context for small businesses because it means the fundamentals remain important: strong account protection, sensible verification processes, staff education, monitoring and a clear response pathway.

Continue reading

Build the wider cyber picture

AI-assisted phishing is one part of a broader cyber resilience challenge. These related guides explore some of the other practical areas worth reviewing.

Cyber Security Common cybersecurity gaps in small businesses Read the article → Cyber Resilience Cyber resilience is bigger than cyber security alone Read the article → Attack Surface The 30 most common attack surfaces facing small businesses Read the article →
The Beach Geek™

Build cyber habits that still work when the message looks convincing

AI may change how quickly and convincingly attackers communicate. Your response does not need to become complicated. Start with stronger verification habits, secure accounts, practical staff education and clear processes for unusual requests.

Start a Conversation Practical cyber resilience for Australian businesses.
People — practical staff awareness
Process — verify unusual requests
Protection — secure accounts & systems

This article provides general cyber security guidance. Phishing and social engineering techniques continue to evolve, and each organisation should assess controls in the context of its own people, systems, data and business processes.