PhishByte warns AI phishing has outpaced detection
Thu, 17th Sep 2026 (Today)
PhishByte has warned Australian businesses that AI-generated phishing has made traditional detection methods obsolete, reshaping the country's cyber threat landscape.
The warning centres on how generative AI has transformed phishing emails from broad, error-filled messages into tailored communications that appear credible and specific to each recipient. PhishByte, a provider of phishing simulation and security awareness training, said the spelling mistakes, generic greetings and implausible scenarios that once helped staff identify scams have largely disappeared.
Figures cited by PhishByte point to a sharp rise in the use of AI in phishing campaigns. AI-generated phishing accounted for 56% of all phishing attacks during the December 2025 holiday period, up from a baseline of about 4%, it said. AI-related cyber threats across Australia and New Zealand also doubled in 2025 from the previous year.
Losses linked to these attacks are also rising. Australian businesses lost AUD $166.8 million to payment redirection fraud in 2025, according to the cited figures, with AI-generated business email compromise messages increasingly tied to those losses. The average cost of a cybercrime incident for an Australian small business now stands at AUD $56,600, PhishByte said.
Changing tactics
The shift reflects a broader change in attacker methods. Instead of sending large volumes of generic emails in the hope of catching a few recipients, criminals can now use large language models and automated data collection to produce tailored messages at scale.
Attackers are using dark-web tools such as FraudGPT and WormGPT to produce polished corporate language within seconds, according to PhishByte. AI-based personalisation systems can also use scraped employee information to generate thousands of unique emails built around a recipient's role, employer and work context.
The threat extends beyond email. Voice-cloning systems can reproduce an executive's voice from only a few seconds of audio, while video deepfakes are being used in fraudulent calls that appear to involve real senior leaders, the company said.
One widely cited example involved a finance employee in Hong Kong who authorised a USD $25 million payment after joining a video conference in which every other participant, including the Chief Financial Officer, was an AI-generated deepfake.
Confidence gap
PhishByte also pointed to research from Commonwealth Bank and UNSW Sydney that tested more than 1,900 Australians by asking them to distinguish between real and AI-generated faces. According to the cited findings, 90% of participants believed they could identify a fake, but only 42% succeeded.
"90% of Australians are confident they can spot a deepfake. Only 42% actually can," PhishByte said.
"The gap between confidence and capability is exactly what attackers are exploiting. And with AI-generated phishing accelerating at a pace the threat landscape has never seen before, the training your team received last year is already out of date," the company said.
Security limits
The warning also highlights the limits of existing email defences. Content filters often rely on known malicious wording, suspicious phrasing or poor syntax, but AI-generated messages can be written in fluent, original prose that does not match older phishing patterns.
Authentication standards such as SPF, DKIM and DMARC still play a role in validating legitimate domains, but they do not stop attackers from using lookalike domains or compromised accounts. PhishByte said polymorphic AI attacks can also alter email structure in ways that cause security scanners to treat phishing messages as ordinary business correspondence.
The company argued that many awareness programs still focus too heavily on visible errors in fraudulent emails, even though those clues are becoming less reliable. In practice, that means staff may remain vulnerable when a malicious request appears professionally written and closely aligned with normal business language.
Response measures
Businesses should focus less on spotting poor grammar and more on identifying departures from established process, PhishByte said. Requests involving bank account changes, urgent payments or credential checks should be verified through an independent channel before any action is taken.
The company also identified mandatory out-of-band verification, hardware-based multi-factor authentication and continuous simulation-based training using current AI-generated phishing formats as the most effective controls for organisations facing the latest wave of attacks.
The warning comes as Australia places greater emphasis on the human element in cyber security. PhishByte pointed to the federal government's AUD $90 million Horizon 2 commitment as a sign that policymakers now recognise the risks created by staff exposure to increasingly persuasive digital deception.
For employers, the central problem is no longer whether a suspicious message contains obvious errors. It is whether internal controls can withstand messages, calls and video interactions that look and sound legitimate.