Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligenceai-enabled-threat-activityvoice-social-engineeringinitial-access-method

AI-Driven Phishing and Social Engineering Threats in 2025-2026

Updated 3mo agoFirst seen Dec 4, 20253 sources

Security researchers and industry experts are warning of a dramatic escalation in phishing and social engineering attacks, driven by the adoption of AI by both attackers and defenders. Reports highlight that threat actors are leveraging AI to craft highly targeted, convincing phishing emails, automate attack campaigns, and reduce the time from initial compromise to full breach to under an hour. Human Resources-themed phishing, especially termination and compensation adjustment lures, have surged in Q3 and Q4, exploiting employee trust and urgency. Security teams are urged to maintain a human-in-the-loop approach, as over-reliance on AI for detection can create blind spots, and context-driven analysis is now essential to counter increasingly sophisticated tactics.

Technical research and incident analysis reveal that attackers are using a variety of new techniques, including voicemail lures, open redirects, and legitimate hosting platforms to bypass traditional email security controls. The rise of mobile device attacks, supply chain threats via malicious apps, and the use of AI prompt injection in CI/CD pipelines further expand the attack surface. Experts recommend organizations strengthen mobile security, enrich detection with threat intelligence, and ensure skilled analysts remain involved in incident response to keep pace with the evolving threat landscape.

Share:
AI-Driven Phishing and Social Engineering Threats in 2025-2026
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Dec 4, 20257mo ago

Huntress documents five phishing techniques seen in 2025

Huntress published a roundup of five phishing techniques it observed during 2025, including malicious SVG voicemail lures, callback phishing, Microsoft brand impersonation with open redirects, shipping scams using ASCII QR codes, and Living off Trusted Sites attacks. The report emphasized attackers' use of trusted brands, legitimate platforms, and obfuscation to bypass defenses and deceive users.

Cofense outlines 2026 phishing threat predictions

Cofense published its 2026 phishing threat predictions, warning that AI-driven email threats are becoming more sophisticated and that time from phishing email to compromise may shrink to under an hour. The report also highlighted evasion through open redirects, link shorteners, legitimate platforms, and growing abuse of legitimate remote access tools such as ConnectWise and AnyDesk.

Dec 3, 20257mo ago

Cofense reports Q4 surge in HR-themed phishing

Cofense published analysis describing a seasonal increase in HR-themed phishing during Q4 and outlined seven recurring lure themes used in these campaigns. The report frames the trend as a recurring end-of-year phishing pattern targeting employees through HR-related pretexts.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

19 LINKEDOpen in app
Malware
2 linked
Organizations
17 linked
CofenseFigmaUpsFedexVisaCloudflareDropboxUnited Parcel ServiceDocuSignBank of AmericaCanvaConnectwiseMicrosoft CorporationAnyDesk Software GmbHHuntressNY PostShareFile
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.