Home  /  Blog  /  Phishing in 2025

Phishing

Phishing in 2025: What Changed,
and What's Coming in 2026


Forget the stereotype. The classic phishing email — garbled English, a suspicious link, an implausible story about a Nigerian inheritance — is largely dead. What replaced it in 2025 is significantly harder to spot, significantly more targeted, and arriving through channels that most businesses never thought to worry about.

For Irish small businesses in particular, phishing remains the single most common way attackers get in. Understanding what changed last year — and what's coming — is the difference between staying ahead of it and becoming another statistic.

What 2025 Actually Looked Like

The headline number: phishing attacks globally reached over one million incidents in a single quarter for the first time, with the Anti-Phishing Working Group recording more than 1,003,924 attacks in Q1 2025 alone.[1] Total financial losses from phishing hit $17.4 billion globally in 2024 — a 45% jump year-on-year. Business Email Compromise (BEC), the targeted variant where attackers impersonate executives or suppliers to redirect payments, accounted for $2.77 billion in reported US losses in 2024 according to the FBI's Internet Crime Complaint Center.[2]

Those are global figures. But Ireland was not insulated. Ireland ranked in the top seven countries targeted by phishing campaigns in 2024, receiving 3% of all global phishing attempts[3] — a small percentage of a very large number. For context, the United States received 46%, Great Britain 16%. For a country of Ireland's size, 3% is disproportionately high.

The Grammar Problem Is Gone

For years, the standard advice was simple: look for poor grammar, odd phrasing, suspicious urgency. That advice has not aged well. In 2025, the majority of phishing emails were AI-assisted in their construction. One major analysis found that up to 73.8% of phishing emails showed signs of AI-generated content — rising above 90% for highly polymorphic attacks[4] — cleaner prose, better brand impersonation, localised language, contextually aware openers.

IBM X-Force security researchers ran an experiment pitting AI against their own social engineering team. The AI needed five prompts and just five minutes to build an attack nearly as effective as one that took their human experts sixteen hours to construct.[5] That is the new economics of phishing. Attackers can now generate thousands of unique, convincing, personalised messages with minimal effort. The scattergun approach has been replaced with something much more surgical.

What this means for you: You can no longer train staff to spot bad grammar. The emails landing in your inbox in 2026 will read like they were written by a colleague. The signals you are looking for have shifted — more on that at the end of this post.

QR Codes: The Attack Vector Nobody Saw Coming

One of the most significant developments of 2025 was the explosion of "quishing" — phishing attacks delivered via QR code. Over the six-month period spanning Q4 2024 and Q1 2025 alone, Mimecast detected more than 1.7 million unique malicious QR codes embedded in phishing emails — with a further 716,306 unique malicious QR codes recorded in Q3 2025.[6]

The reason quishing is effective is almost embarrassingly simple: QR codes are images. Most email security filters are built to scan text-based links. They cannot read what is encoded inside a QR code image. So an email containing a malicious QR code sails straight through filters that would have caught the same URL pasted as a link.

The attacks typically look like legitimate business communications — a shared document notification, an invoice, a Microsoft 365 account alert, an MFA verification request. The recipient scans the code with their phone, which takes them to a convincing fake login page on a personal device that has none of the endpoint protection of their work computer. Credentials entered. Account compromised.

This is particularly relevant for Irish SMEs because QR codes have become embedded in everyday business life — menus, parking meters, delivery confirmations, supplier invoices. The familiarity is exactly what attackers are exploiting.

Vishing and Voice Deepfakes: When You Cannot Trust a Phone Call

Voice phishing — vishing — surged 442% from the first to the second half of 2024, according to CrowdStrike's 2025 Global Threat Report, with incidents rising from just two recorded cases in January 2024 to 93 in December.[7] AI voice cloning tools have become cheap, fast, and frighteningly accurate. A credible clone of someone's voice can now be generated from as little as a few seconds of publicly available audio — a LinkedIn video, a podcast appearance, a YouTube interview.

The most high-profile case of 2024 involved a finance worker at the global engineering firm Arup, who transferred $25.6 million after attending what appeared to be a legitimate video conference with the company's CFO and senior colleagues. Every face on the screen, every voice, was an AI-generated deepfake — confirmed by Arup's own Chief Information Officer.[8] The attack succeeded not because the employee was careless, but because the fakes were genuinely indistinguishable from the real thing.

That incident involved a large multinational. But the same technology is now being used against small businesses. A call from your "bank", your "supplier", or your "IT provider" asking you to urgently authorise a payment or verify your credentials may not be who it appears to be.

MFA Is No Longer the Silver Bullet

Multi-factor authentication is still worth enabling — it stops the vast majority of basic credential theft attacks. But 2025 saw a significant rise in attacks specifically designed to defeat it. Adversary-in-the-Middle (AiTM) attacks — where attackers sit between you and a legitimate website, capturing your session token after you complete MFA — surged 146% in 2024.[9]

The practical upshot: MFA alone is not enough. Attackers have adapted. Enabling MFA is still the right thing to do — it raises the bar significantly — but it should be treated as one layer of defence, not a complete solution.

What 2026 Looks Like From Here

Every credible forecast points in the same direction. Global losses from deepfake and AI-enabled fraud are projected to reach $40 billion by 2027, according to Deloitte, representing a compound annual growth rate of over 32% from a 2023 base.[10]

For 2026 specifically, the trends to watch are:

What to Actually Do About It

The threat has evolved. The defences need to evolve with it. Here is what matters in 2026:

  1. Verify payment changes by phone, always. Any request to change supplier bank details, authorise an urgent transfer, or redirect a payment should be verified by calling a number you already have on file — never a number provided in the email or message making the request. This single control defeats the majority of BEC attacks.
  2. Treat QR codes in emails with the same scepticism as links. Before scanning any QR code in an email, ask: did I expect this? Does it make sense that a QR code would be needed here? If in doubt, go to the service directly through your browser rather than scanning.
  3. Enable MFA everywhere — but know its limits. MFA significantly raises the cost of attacking your accounts. Enable it on email, cloud services, banking, and any remote access tools. Just understand that it is not infallible.
  4. Establish a verbal codeword for urgent financial requests. For very small teams where everyone knows each other, a simple agreed codeword for urgent out-of-process requests can stop a voice deepfake attack cold. If your "MD" calls and cannot provide the codeword, something is wrong.
  5. Run your Windows security baseline. Many phishing attacks succeed not because the email was convincing, but because the attacker exploited a vulnerable, unpatched system after credentials were entered. Keeping your Windows machines properly configured removes much of the damage potential even if a phishing attack initially succeeds.

The honest summary: Phishing in 2026 will be more convincing, more targeted, and delivered across more channels than ever before. The old advice — "just look for spelling mistakes" — no longer holds. What holds is process: verify before you act, slow down when you are being pressured to speed up, and never let urgency override your verification steps.


References

  1. Anti-Phishing Working Group (APWG). Phishing Activity Trends Report, Q1 2025. Published July 2025. apwg.org
  2. FBI Internet Crime Complaint Center (IC3). 2024 Internet Crime Report. Reported via APWG Q1 2025 Trends Report. ic3.gov
  3. APWG / VIPRE. Phishing Activity Trends Report, Q2 2024 — country targeting breakdown. Reported in Brightdefense phishing statistics compilation. brightdefense.com
  4. Secureframe. 60+ Phishing Attack Statistics: Insights for 2026 — citing analysis of 2024 phishing email corpus. secureframe.com
  5. Carruthers, S. (IBM X-Force Red). AI vs. Human Deceit: Unravelling the New Age of Phishing Tactics. IBM Security Intelligence, 2023. ibm.com
  6. Mimecast, reported in: APWG. Phishing Activity Trends Report, Q1 2025 and Q3 2025. apwg.org
  7. CrowdStrike. 2025 Global Threat Report. Published February 2025. crowdstrike.com — also reported in Security Magazine, March 2025. securitymagazine.com
  8. Greig, R. (Arup CIO). Lessons Learned from a $25m Deepfake Crime. World Economic Forum, February 2025. weforum.org
  9. Brightdefense. 200+ Phishing Statistics for 2026 — citing Microsoft Threat Intelligence data on AiTM surge. brightdefense.com
  10. Deloitte Center for Financial Services. AI-enabled fraud projection to $40B by 2027. Reported in: DeepStrike. Deepfake Statistics 2025: AI Fraud Data & Trends. deepstrike.io
← Back to Blog