{
  "slug": "phishing-detection-and-prevention",
  "name": "Phishing detection & prevention",
  "tier": "good-practice",
  "trend": "steady",
  "blockerType": null,
  "tools": [
    {
      "name": "Cofense PhishMe",
      "url": "https://cofense.com/product-services/phishme/"
    },
    {
      "name": "Proofpoint Email Protection",
      "url": "https://www.proofpoint.com/us/products/email-security-and-protection"
    },
    {
      "name": "Barracuda Sentinel",
      "url": "https://www.barracuda.com/products/email-protection/sentinel"
    },
    {
      "name": "Abnormal AI",
      "url": "https://abnormal.com/"
    },
    {
      "name": "Red Canary",
      "url": "https://redcanary.com/"
    }
  ],
  "evidence": [
    {
      "title": "MSPs needed to shore up school security",
      "url": "https://www.channeldive.com/news/msps-needed-to-shore-up-school-security/830378/",
      "date": "2026-09-15",
      "type": "adoption-metric",
      "added": "2026-09-18",
      "superseded_by": null,
      "window": null,
      "explanation": "Barracuda research on education sector: 58.8M phishing emails targeting 536 institutions over 3 months (~1,200 per day); highest demand among all industries (40%) for AI-assisted detection tools, revealing adoption gap."
    },
    {
      "title": "Midnight Blizzard-Linked Actor GTG-20006 Automated Device Code Phishing With AI",
      "url": "https://www.aegisai.ai/blog/anthropic-midnight-blizzard-ai-device-code-phishing",
      "date": "2026-09-11",
      "type": "research-paper",
      "added": "2026-09-18",
      "superseded_by": null,
      "window": null,
      "explanation": "Anthropic threat intelligence: GTG-20006 (Midnight Blizzard-linked) deployed AI-driven device code phishing against 20+ government/defense organizations, with AI automating domain registration, infrastructure building, and malware evasion."
    },
    {
      "title": "Anthropic Threat Report 2026: Every Case Explained",
      "url": "https://www.cyberkendra.com/2026/09/anthropic-threat-report-says-ai-now.html",
      "date": "2026-09-11",
      "type": "industry-report",
      "added": "2026-09-18",
      "superseded_by": null,
      "window": null,
      "explanation": "Anthropic documented real threat actors using AI agents to continuously modify and redeploy flagged phishing implants faster than vendors can ship signature patches; static signature-based detection insufficient against ML-assisted attackers."
    },
    {
      "title": "Detect and disrupt AI-themed attacks with Microsoft Defender",
      "url": "https://www.microsoft.com/en-us/security/blog/2026/09/10/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender/",
      "date": "2026-09-10",
      "type": "industry-report",
      "added": "2026-09-18",
      "superseded_by": null,
      "window": null,
      "explanation": "Microsoft Threat Intelligence documents phishing campaigns impersonating ChatGPT, Claude, and DeepSeek brands; 100K-email campaigns per day harvesting credit cards and credentials via multi-stage redirection chains."
    },
    {
      "title": "Half of New Zealand agencies still have an email security gap",
      "url": "https://www.insurancebusinessmag.com/nz/news/cyber/half-of-new-zealand-agencies-still-have-an-email-security-gap-589337.aspx",
      "date": "2026-09-10",
      "type": "adoption-metric",
      "added": "2026-09-18",
      "superseded_by": null,
      "window": null,
      "explanation": "Proofpoint research on 200+ NZ government entities: 50% enforce DMARC at strict Reject level (up from 26% in 2025); email authentication adoption shows foundation of phishing prevention infrastructure maturing."
    },
    {
      "title": "Browser-based phishing hides pages inside victims' browsers",
      "url": "https://blog.barracuda.com/2026/09/09/browser-based-phishing-blob-urls-microsoft-redirects",
      "date": "2026-09-09",
      "type": "case-study",
      "added": "2026-09-18",
      "superseded_by": null,
      "window": null,
      "explanation": "Barracuda discovered novel evasion: phishing pages rendered entirely in victim's browser using blob URLs via OAuth/Teams redirect chains; evades URL reputation blocklists and traditional email-gateway detection."
    },
    {
      "title": "Each level of LLM personalization raises phishing click intent odds by 28%",
      "url": "https://mindpattern.ai/s/2026-09-08-each-level-of-llm-personalization-raises-phishing-click-intent-odds-by-28",
      "date": "2026-09-08",
      "type": "research-paper",
      "added": "2026-09-18",
      "superseded_by": null,
      "window": null,
      "explanation": "Peer-reviewed study of 1,436 phishing evaluations: each level of AI personalization (name/title/responsibilities/projects) increased click-intent odds by 28%; also reduced user reporting signals that security teams rely on."
    },
    {
      "title": "Companies Using Proofpoint in 2026",
      "url": "https://technologychecker.io/technology/proofpoint",
      "date": "2026-09-07",
      "type": "adoption-metric",
      "added": "2026-09-18",
      "superseded_by": null,
      "window": null,
      "explanation": "Live DNS census: 53,149 active domains routing mail through Proofpoint; 42,005 identified organizations including Fortune 500 (Accenture, IBM, PwC, Bank of America, Wells Fargo), confirming enterprise-scale platform adoption."
    },
    {
      "title": "ASCII smuggling isn't just an AI security risk",
      "url": "https://www.theregister.com/security/2026/09/04/ascii-smuggling-isnt-just-an-ai-security-risk/5294595",
      "date": "2026-09-04",
      "type": "case-study",
      "added": "2026-09-18",
      "superseded_by": null,
      "window": null,
      "explanation": "Microsoft Security Research: large-scale phishing campaign (2.37M peak daily messages, Feb 2026) using invisible Unicode tag characters to bypass AI/NLP email filters; Defender's multi-layer defense blocked 99%+ despite evasion technique."
    },
    {
      "title": "Cybersecurity Pros Name Social Engineering as Top Human Risk",
      "url": "https://www.corporatecomplianceinsights.com/news-roundup-september-4-2026/",
      "date": "2026-09-04",
      "type": "adoption-metric",
      "added": "2026-09-18",
      "superseded_by": null,
      "window": null,
      "explanation": "SANS Institute survey of 1,700+ practitioners: 77% cite social engineering as top human risk; phishing remains primary attack method; AI-enabled social engineering jumped to 2nd place concern from 4th place two years prior."
    },
    {
      "title": "AI Cybersecurity Trends 2026: What 304 Real Incidents Show About How Attacks Actually Start",
      "url": "https://www.cynet.com/blog/ai-cybersecurity-trends-2026-what-304-real-incidents-show-about-how-attacks-actually-start/",
      "date": "2026-09-04",
      "type": "adoption-metric",
      "added": "2026-09-18",
      "superseded_by": null,
      "window": null,
      "explanation": "Cynet MDR analysis of 304 closed incidents in H1 2026: 80% breaches started with stolen credentials from phishing/social engineering; establishes phishing prevalence as dominant initial-access vector across real enterprise deployments."
    },
    {
      "title": "Impersonating IT support: How threat actors turn a remote session into enterprise-wide access",
      "url": "https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/",
      "date": "2026-09-02",
      "type": "case-study",
      "added": "2026-09-04",
      "superseded_by": null,
      "window": null,
      "explanation": "Real-world attack: threat actors impersonate IT via Teams social engineering, extract remote access credentials, deploy malware, execute lateral movement across domain infrastructure; demonstrates sophisticated phishing vector beyond email."
    },
    {
      "title": "Serta Simmons Bedding Fortifies Email Defense and Security Awareness with Abnormal AI",
      "url": "https://abnormal.ai/customers/stories/serta-simmons-bedding",
      "date": "2026-08-30",
      "type": "case-study",
      "added": "2026-09-04",
      "superseded_by": null,
      "window": null,
      "explanation": "Global bedding manufacturer deployed Abnormal AI on Microsoft 365; stopped thousands of advanced attacks monthly, automated graymail remediation, increased training participation from 10% to 40%, reducing analyst triage overhead."
    },
    {
      "title": "Best Email Security Software Solutions 2026: Platform Capability Analysis",
      "url": "https://checkthat.ai/answers/what-are-the-best-email-security-software-solutions",
      "date": "2026-08-28",
      "type": "industry-report",
      "added": "2026-09-04",
      "superseded_by": null,
      "window": null,
      "explanation": "Independent third-party evaluation of 7 leading platforms; Abnormal detects 1,200+ attacks per 1,000 mailboxes monthly bypassing upstream gateways; Proofpoint achieves 27.1% additional threat lift; Attune 1.0 model powers 85% of detections."
    },
    {
      "title": "Abnormal AI Expands Email Security Platform: Control Center, DLP, and Upgraded Phishing Coach GA",
      "url": "https://www.helpnetsecurity.com/2026/08/27/abnormal-ai-email-security-platform-expansion/",
      "date": "2026-08-27",
      "type": "product-ga",
      "added": "2026-09-04",
      "superseded_by": null,
      "window": null,
      "explanation": "Abnormal AI announces general availability (2026-08-31) of Control Center for custom detection models, Email DLP Rules, and upgraded AI Phishing Coach; extends behavioral AI across inbound, outbound, and human-layer defense surfaces."
    },
    {
      "title": "Userbase adopts Abnormal AI behavioral security platform protecting 2,000 Google Workspace mailboxes",
      "url": "http://www.atpress.ne.jp/news/625082",
      "date": "2026-08-26",
      "type": "case-study",
      "added": "2026-09-04",
      "superseded_by": null,
      "window": null,
      "explanation": "Japanese economic platform company deployed Abnormal AI on Google Workspace protecting 2,000 mailboxes; blocked ~3,000 additional attacks monthly, reduced helpdesk email inquiries significantly; demonstrates effectiveness outside English-speaking markets and on Google infrastructure."
    },
    {
      "title": "Cisco Talos Q2 2026 Incident Response: Phishing >50% of Initial Access, MFA Bypass Surge",
      "url": "https://blog.knowbe4.com/report-phishing-remains-the-primary-initial-access-vector",
      "date": "2026-08-25",
      "type": "adoption-metric",
      "added": "2026-09-04",
      "superseded_by": null,
      "window": null,
      "explanation": "Incident response data: phishing primary access vector in >50% of Q2 2026 engagements (up from ~33% Q1); MFA bypass in 65% (up from 35%); QR code phishing campaigns documented; shows sustained threat escalation in real breaches."
    },
    {
      "title": "MFA Bypass and AiTM Statistics 2026: Device Code Phishing and Session Token Theft",
      "url": "https://www.stingrai.io/blog/mfa-bypass-statistics-2026",
      "date": "2026-08-21",
      "type": "adoption-metric",
      "added": "2026-09-04",
      "superseded_by": null,
      "window": null,
      "explanation": "Aggregated primary-source threat intelligence: 59% of compromised accounts had MFA enabled; device code phishing surge 1,380% (H2 2025–Q1 2026); 8.6 billion stolen session cookies in 2025; reveals phishing tactics bypassing traditional MFA defenses."
    },
    {
      "title": "Device Code Phishing: The MFA Bypass Nobody Trains For",
      "url": "https://brandefense.io/blog/device-code-phishing-mfa-bypass/",
      "date": "2026-08-20",
      "type": "research-paper",
      "added": "2026-08-21",
      "superseded_by": null,
      "window": null,
      "explanation": "Brandefense research documenting device code phishing explosive growth (1,380% from H2 2025 to Q1 2026) with 25+ commodity kits. Technical analysis shows OAuth 2.0 device flow abuse bypasses all MFA forms including passkeys, with refresh tokens valid 90 days post-compromise."
    },
    {
      "title": "Phishing 3.0: The Fight Moves to Agent Versus Agent",
      "url": "https://thehackernews.com/2026/08/phishing-30-fight-moves-to-agent-versus-agent.html",
      "date": "2026-08-19",
      "type": "industry-report",
      "added": "2026-08-21",
      "superseded_by": null,
      "window": null,
      "explanation": "Industry analysis framing phishing evolution (Phishing 1.0 → 3.0) with agentic AI as defining vector. Quantifies detection gaps: Microsoft 365 misses 293 phishing per 100 mailboxes/30d, Google Workspace 350. Osterman Research (128 CISOs/1000-5K orgs): 88% experienced incidents undermining trust in digital comms, 60% lack confidence in deepfake defense."
    },
    {
      "title": "'Mirage2FA' (LinXcoded) Phishing-as-a-Service Platform at Scale",
      "url": "https://www.brinztech.com/breach-alerts/brinztech-alert-mirage2fa-linxcoded-phishing-as-a-service-platform-executes-large-scale-adversary-in-the-middle-attacks-on-microsoft-365-users/",
      "date": "2026-08-18",
      "type": "case-study",
      "added": "2026-08-21",
      "superseded_by": null,
      "window": null,
      "explanation": "Active disclosure of Mirage2FA PaaS executing AiTM attacks at scale via HTML smuggling, CAPTCHA gates, WebSocket relays. Platform leverages compromised Microsoft 365 tenants for distribution, captures tokens valid post-password-reset. Evidence of industrialized MFA-bypass attack infrastructure in production."
    },
    {
      "title": "AI Accuracy for Small Business Owners and MSPs: Critical Assessment of Phishing Detector Performance",
      "url": "https://www.linkedin.com/posts/robert-griffin-qualsis_msps-activity-7494105222697349120-QTAr",
      "date": "2026-08-14",
      "type": "opinion",
      "added": "2026-08-21",
      "superseded_by": null,
      "window": null,
      "explanation": "Negative signal: Independent testing shows AI phishing models scoring 99.78% in-distribution but dropping to 77.8% on unfamiliar email corpus, with 0.59 precision (4 false alarms per 10 flags). Highlights gap between vendor claims and production performance on novel attacks, informing realistic defenses."
    },
    {
      "title": "Payroll Pirates Campaign: Abnormal AI Pre-Disclosure Detection (49 Days Ahead)",
      "url": "https://www.linkedin.com/posts/jesus-garcia-aa8517188_arcticwolf-cybersecurity-abnormalai-activity-7493305398087815168-cI98",
      "date": "2026-08-12",
      "type": "case-study",
      "added": "2026-08-21",
      "superseded_by": null,
      "window": null,
      "explanation": "Independent validation: Abnormal customer detected and auto-remediated Payroll Pirates campaign on June 18 (49 days before Arctic Wolf public disclosure). Demonstrates behavioral AI detecting sophisticated AiTM attacks pre-disclosure, validating production deployment effectiveness against real-world threat campaigns."
    },
    {
      "title": "Push Security Threat Briefing: August 2026",
      "url": "https://www.linkedin.com/pulse/push-security-threat-briefing-august-2026-push-security-lwgse",
      "date": "2026-08-11",
      "type": "adoption-metric",
      "added": "2026-08-21",
      "superseded_by": null,
      "window": null,
      "explanation": "Threat briefing synthesizing Mandiant M-Trends (vishing 23% of cloud breaches), Verizon DBIR (41% breaches non-email, voice phishing 40% higher success), plus July 2026 high-impact breaches: Silent Ransom $48M from Am Law 100 firms via callback phishing. Documents multi-channel attack shift beyond email-centric defenses."
    },
    {
      "title": "Storm-2755: Multi-Sector AiTM Campaign with Hundreds of Organizations Targeted",
      "url": "https://www.techtimes.com/articles/323514/20260807/standard-mfa-wont-stop-hackers-who-route-microsoft-365-phishing-through-google.htm",
      "date": "2026-08-07",
      "type": "case-study",
      "added": "2026-08-21",
      "superseded_by": null,
      "window": null,
      "explanation": "Arctic Wolf Labs disclosure of Storm-2755 (Payroll Pirates) targeting hundreds of organizations across healthcare, education, manufacturing, government, and professional services in US, Canada, and Europe. Attack chain: Google Meet/S3 redirects, AiTM proxying, session token hijacking, persistence via proxy refresh. All victims deployed MFA."
    },
    {
      "title": "How AI-powered phishing killed blocklists for good",
      "url": "https://www.bleepingcomputer.com/news/security/how-ai-powered-phishing-killed-blocklists-for-good/",
      "date": "2026-08-04",
      "type": "adoption-metric",
      "added": "2026-08-07",
      "superseded_by": null,
      "window": null,
      "explanation": "Critical negative signal: 89% of phishing domains active <2 days; 25+ device code phishing kits in wild; 95% use bot protection evasion. Demonstrates indicator-based defenses structurally inadequate against AI-accelerated infrastructure rotation and automated page generation."
    },
    {
      "title": "Research spotlights phishing as a primary entry point in Q2",
      "url": "https://securityjournaluk.com/research-phishing-primary-entry-point-q2/",
      "date": "2026-07-31",
      "type": "adoption-metric",
      "added": "2026-08-07",
      "superseded_by": null,
      "window": null,
      "explanation": "Cisco Talos independent incident response data: phishing primary attack vector in >50% Q2 2026 engagements (up from 33% Q1); 65% involved authentication abuse; ARToken phishing-as-a-service exposed 80+ API endpoints. Documents attacker adoption of evasion and credential-theft platforms."
    },
    {
      "title": "AI-Powered Adversaries and the Enterprise Risk Challenge: Preparing for the New Reality",
      "url": "https://www.ibm.com/think/x-force/2026-cost-of-a-data-breach-ai-adversaries-enterprise-risk",
      "date": "2026-07-29",
      "type": "industry-report",
      "added": "2026-08-07",
      "superseded_by": null,
      "window": null,
      "explanation": "IBM/Ponemon Cost of Data Breach study (602 orgs): AI-driven attacks increased 56% YoY, adding USD 1M per breach; attackers can 'generate persuasive phishing content, adapt malware and test exploits at machine speed.' Quantifies deployment impact and attacker AI adoption."
    },
    {
      "title": "Email threat landscape: Q2 2026 trends and insights",
      "url": "https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/",
      "date": "2026-07-23",
      "type": "adoption-metric",
      "added": "2026-08-07",
      "superseded_by": null,
      "window": null,
      "explanation": "Microsoft Threat Intelligence Q2 2026: 7.6B phishing threats detected; Tycoon2FA disruption achieved 92% volume decline; QR code phishing peaked 18.7M (March), declined 38% (May). Documents both detection scale and threat evolution adaptation to evasion techniques."
    },
    {
      "title": "7 Real email attacks Barracuda blocked before the inbox",
      "url": "https://blog.barracuda.com/2026/07/23/real-email-attacks-stopped-by-barracuda",
      "date": "2026-07-23",
      "type": "case-study",
      "added": "2026-08-07",
      "superseded_by": null,
      "window": null,
      "explanation": "Production detection examples with monthly scale metrics: 4.9M brand impersonations, 46K QR phishing, 242K CEO impersonations, 960K Bayesian-poisoning detected monthly. Demonstrates multi-layer AI detection of evasion techniques in real-world deployment."
    },
    {
      "title": "A systematic literature review of large language models in phishing attack generation and detection",
      "url": "https://repository.essex.ac.uk/42995/",
      "date": "2026-07-19",
      "type": "research-paper",
      "added": "2026-08-07",
      "superseded_by": null,
      "window": null,
      "explanation": "PRISMA systematic review of 36 studies (2023-2025) across IEEE/ScienceDirect/ACM/Scopus showing LLMs accelerate and automate phishing processes while advancing defensive capabilities; LLM-based detection approaches outperform traditional ML and approach human-level performance."
    },
    {
      "title": "Text salting: How hidden text evades AI email security",
      "url": "https://blog.barracuda.com/2026/07/16/text-salting-ai-email-security",
      "date": "2026-07-16",
      "type": "research-paper",
      "added": "2026-08-07",
      "superseded_by": null,
      "window": null,
      "explanation": "Barracuda threat research on evasion technique: 1M+ retail-themed campaigns since April 2026 using CSS/HTML to hide benign text, diluting malicious keyword concentration. Demonstrates attacker adaptation targeting AI filters and LLM detection limitations; LLMs lack user-perspective rendering."
    },
    {
      "title": "Rate Fintech: Behavioral AI Phishing Detection Outperforms Legacy SEG",
      "url": "https://www.linkedin.com/posts/abnormal-ai_rate-a-leading-fintech-firm-in-the-us-activity-7483256318925885440-6-cC",
      "date": "2026-07-15",
      "type": "case-study",
      "added": "2026-08-07",
      "superseded_by": null,
      "window": null,
      "explanation": "Named fintech deployment: behavioral AI detects phishing attacks missed by legacy secure email gateway; fast incident response with transparent remediation. Demonstrates real-world deployment advantage of behavioral detection over rule-based systems."
    },
    {
      "title": "Evaluating Large Language Models' Ability to Automate Spear Phishing",
      "url": "https://www.schneier.com/academic/archives/2026/06/evaluating-large-language-models-ability-to-automate-spear-phishing.html",
      "date": "2026-07-05",
      "type": "research-paper",
      "added": "2026-07-10",
      "superseded_by": null,
      "window": null,
      "explanation": "Peer-reviewed research (Expert Systems with Applications) showing AI-automated phishing matches human expert performance (54% CTR) while Claude 3.5 Sonnet achieves 97.25% detection accuracy with zero false positives; economic analysis shows 50× profitability increase for attackers."
    },
    {
      "title": "Abnormal Email Security",
      "url": "https://www.securitystack.app/products/abnormal-email-security",
      "date": "2026-07-02",
      "type": "product-ga",
      "added": "2026-07-10",
      "superseded_by": null,
      "window": null,
      "explanation": "Product maturity signal: Abnormal named Gartner Magic Quadrant leader 2025, 99% Would Recommend, 3,200+ organizations protected; SOC 2 Type II, ISO 27001/27701 certified, behavioral baseline architecture independent of email gateway."
    },
    {
      "title": "AitM Phishing: MFA Bypass Detection (2026)",
      "url": "https://www.stingrai.io/blog/adversary-in-the-middle-aitm-phishing-detection-2026",
      "date": "2026-07-01",
      "type": "research-paper",
      "added": "2026-07-10",
      "superseded_by": null,
      "window": null,
      "explanation": "Multi-source research documenting Tycoon2FA and OAuth consent phishing at scale: 35,000 users across 13,000 organizations in 26 countries; MFA failed 84% of incident responses; AitM attacks rose 146% YoY with 40,000 incidents daily."
    },
    {
      "title": "Technical Details: Multi-Stage AiTM Attack Uses Code Of Conduct Phishing Emails",
      "url": "https://radar.offseq.com/threat/multi-stage-aitm-attack-uses-code-of-conduct-phish-7341fc66",
      "date": "2026-07-01",
      "type": "case-study",
      "added": "2026-07-10",
      "superseded_by": null,
      "window": null,
      "explanation": "Real campaign April 2026 targeting 35,000 users across 13,000 organizations in healthcare and financial services; demonstrates CAPTCHA evasion and MFA-bypass infrastructure at scale with legitimate delivery services and attacker-controlled domains."
    },
    {
      "title": "Train, triage, repeat: The AI agent changing how we fight phishing",
      "url": "https://redcanary.com/blog/threat-detection/phishing-ai-agent/",
      "date": "2026-06-30",
      "type": "case-study",
      "added": "2026-07-10",
      "superseded_by": null,
      "window": null,
      "explanation": "Red Canary production deployment of orchestrated AI subagent architecture for phishing triage achieving 94% accuracy with transparent reasoning; modular design enables analyst feedback and environment-specific tuning without model retraining."
    },
    {
      "title": "AI-Driven Email Security and Phishing Detection Market Size, Share ...",
      "url": "https://www.mordorintelligence.com/industry-reports/ai-driven-email-security-and-phishing-detection-market",
      "date": "2026-06-29",
      "type": "industry-report",
      "added": "2026-07-10",
      "superseded_by": null,
      "window": null,
      "explanation": "Market maturity indicator: USD 7.25B in 2026, 16.68% CAGR to 12.31B by 2031; primary drivers include $3.05B FBI-documented BEC losses (2025), cloud email adoption shift (3.2% driver), AI-enabled detection (2.1% driver)."
    },
    {
      "title": "Cloud email and BEC risk are outpacing legacy security models",
      "url": "https://nhimg.org/articles/cloud-email-and-bec-risk-are-outpacing-legacy-security-models/",
      "date": "2026-06-27",
      "type": "case-study",
      "added": "2026-07-10",
      "superseded_by": null,
      "window": null,
      "explanation": "Forrester TEI study of cloud-native phishing detection: 4 global organizations prevented $4M in combined losses; SOC analyst hours spent on email security reduced 95%; demonstrates API-based behavioral detection advantage over legacy gateway architecture."
    },
    {
      "title": "AI-driven email threats are outpacing legacy detection models",
      "url": "https://nhimg.org/articles/ai-driven-email-threats-are-outpacing-legacy-detection-models/",
      "date": "2026-06-27",
      "type": "opinion",
      "added": "2026-07-10",
      "superseded_by": null,
      "window": null,
      "explanation": "Critical assessment: signature/pattern-based controls fail against AI-generated phishing variants; Microsoft data shows 54% CTR for AI-automated lures vs 12% baseline; identifies shift to behavioral detection and identity-context integration as structural requirement."
    },
    {
      "title": "Protecting the Data Behind Australia's Top Game | Proofpoint US",
      "url": "https://www.proofpoint.com/us/customer-stories/australian-football-league",
      "date": "2026-06-26",
      "type": "case-study",
      "added": "2026-07-10",
      "superseded_by": null,
      "window": null,
      "explanation": "Australian Football League deployment across 700k+ participants: 99.99% threat blocking, 8M+ commodityThreats blocked monthly, 40k+ advanced threats blocked; security awareness training achieved 80% reduction in phishing simulation click rates."
    },
    {
      "title": "AI-Enhanced Email Security: A Novel Pipeline for Phishing Campaign Detection and Profiling",
      "url": "https://vaniea.com/publication/saka2026-toit/",
      "date": "2026-06-26",
      "type": "research-paper",
      "added": "2026-07-10",
      "superseded_by": null,
      "window": null,
      "explanation": "Peer-reviewed ACM Transactions on Internet Technology research proposing hybrid AI pipeline (feature extraction, campaign clustering, profiling) to enhance SOC efficiency; validates AI as complement to human expertise in threat response."
    },
    {
      "title": "Three Security Wrappers, One Redirect to a Google Docs Phishing Page",
      "url": "https://ironscales.com/threat-intelligence/edgepilot-barracuda-wrapper-redirect-google-docs-credential-harvest",
      "date": "2026-06-20",
      "type": "case-study",
      "added": "2026-06-26",
      "superseded_by": null,
      "window": null,
      "explanation": "Real-world credential-harvesting campaign detected by IRONSCALES Themis AI despite multi-layer legitimate-service abuse (EdgePilot, Barracuda LinkProtect wrappers) and gateway authentication failures, demonstrating behavioral AI effectiveness in production."
    },
    {
      "title": "What AI Can't Hide When It Writes a Phishing Email",
      "url": "https://blog.knowbe4.com/what-ai-cant-hide-when-it-writes-a-phishing-email",
      "date": "2026-06-18",
      "type": "adoption-metric",
      "added": "2026-06-26",
      "superseded_by": null,
      "window": null,
      "explanation": "KnowBe4 Threat Lab analysis documenting 86% AI-assisted phishing prevalence, 54% vs 12% CTR effectiveness advantage, detectable LLM fingerprints, and Unicode homoglyph evasion techniques used in production attacks."
    },
    {
      "title": "AI-powered email attacks: Red Team Report on phishing, ClickFix & MFA bypass",
      "url": "https://blog.barracuda.com/2026/06/17/red-team-report-ai-powered-email-attacks",
      "date": "2026-06-17",
      "type": "research-paper",
      "added": "2026-06-26",
      "superseded_by": null,
      "window": null,
      "explanation": "Barracuda red team demonstrates AI-generated phishing escalating to full endpoint compromise in 5 minutes via ClickFix payload, Evilginx MFA interception, and token hijacking—negative signal showing attack sophistication and detection evasion."
    },
    {
      "title": "Independent Testing Confirms Secure Email Threat Defense's Email Security Strength",
      "url": "https://blogs.cisco.com/security/independent-testing-confirms-secure-email-threat-defenses-email-security-strength",
      "date": "2026-06-16",
      "type": "case-study",
      "added": "2026-06-26",
      "superseded_by": null,
      "window": null,
      "explanation": "SE Labs AAA-rated independent evaluation of Cisco Secure Email Threat Defense: 98% phishing detection including 100% QR code/quishing protection, 97% nation-state malware (APT29, FIN7), zero false positives on legitimate email."
    },
    {
      "title": "Browser phishing gap exposes enterprise defences",
      "url": "https://www.1arabia.com/2026/06/browser-phishing-gap-exposes-enterprise.html",
      "date": "2026-06-16",
      "type": "adoption-metric",
      "added": "2026-06-26",
      "superseded_by": null,
      "window": null,
      "explanation": "Menlo Security 2026 report: 1 in 5 phishing attacks bypass enterprise detection at browser layer; 95.2% delivered over TLS encryption, 115K evasive campaigns detected; demonstrates detection limitations and multi-channel attack evolution beyond email-only controls."
    },
    {
      "title": "Microsoft Defender email security benchmarking: Key insights from one year of data",
      "url": "https://www.microsoft.com/en-us/security/blog/2026/06/15/microsoft-defender-email-security-benchmarking-key-insights-from-one-year-of-data/",
      "date": "2026-06-15",
      "type": "product-ga",
      "added": "2026-06-26",
      "superseded_by": null,
      "window": null,
      "explanation": "Microsoft publishes 4 quarters of production benchmarking (Jul 2025–Apr 2026) across 696+ customers: Defender post-delivery malicious catch improved to 96%, misses 59% fewer threats than competing SEG vendors, validates mature multi-vendor detection architecture."
    },
    {
      "title": "AI-Weaponized Phishing: Nation-State Quality at Commodity Scale",
      "url": "https://labs.cloudsecurityalliance.org/research/csa-research-note-ai-weaponized-phishing-systemic-risk-20260/",
      "date": "2026-06-14",
      "type": "research-paper",
      "added": "2026-06-26",
      "superseded_by": null,
      "window": null,
      "explanation": "Peer-reviewed CSA research documenting March 2025 inflection point when AI-generated spear phishing surpassed expert human attacks (23% higher failure rate for AI-crafted lures), with 54% CTR vs 12% baseline and government actors weaponizing LLMs."
    },
    {
      "title": "PhishLumos: From a Single URL to Campaign-Level Phishing Mitigation",
      "url": "https://www.eurekalert.org/news-releases/1131558",
      "date": "2026-06-13",
      "type": "research-paper",
      "added": "2026-06-26",
      "superseded_by": null,
      "window": null,
      "explanation": "IEEE Access peer-reviewed research from Tokyo Metropolitan University demonstrating infrastructure-based phishing campaign detection achieving 8-day faster discovery than experts, identifying 192K URLs with 92% malicious accuracy from 600 seed URLs."
    },
    {
      "title": "Zscaler ThreatLabz 2026 Phishing and Initial Access Report",
      "url": "https://www.zscaler.com/blogs/security-research/one-click-compromise-threatlabz-2026-phishing-and-initial-access-report",
      "date": "2026-06-10",
      "type": "adoption-metric",
      "added": "2026-06-12",
      "superseded_by": null,
      "window": null,
      "explanation": "Large-scale telemetry showing phishing volume declined 20% YoY as defenses matured, but effectiveness increased via personalization; services industry saw 65.5% surge; 413K AI-generated phishing domains identified."
    },
    {
      "title": "Security Software Fails to Detect Fifth of Browser Phishing Attacks",
      "url": "https://www.infosecurity-magazine.com/news/cybersecurity-fails-to-detect/",
      "date": "2026-06-10",
      "type": "adoption-metric",
      "added": "2026-06-12",
      "superseded_by": null,
      "window": null,
      "explanation": "Menlo Security telemetry across millions of browser sessions revealed 20% miss rate in enterprise phishing detection; traditional tools lack visibility into browser-layer social engineering (ClickFix, CAPTCHA overlays)."
    },
    {
      "title": "AI brands as bait: How threat actors are using the AI hype in social engineering",
      "url": "https://www.microsoft.com/en-us/security/blog/2026/06/08/ai-brands-as-bait-how-threat-actors-are-using-the-ai-hype-in-social-engineering/",
      "date": "2026-06-08",
      "type": "adoption-metric",
      "added": "2026-06-12",
      "superseded_by": null,
      "window": null,
      "explanation": "Microsoft threat intelligence documenting real-world campaigns impersonating ChatGPT/Claude/Copilot with multi-stage redirection chains (Bitrix24, awstrack, Rebrandly) and custom CAPTCHA obfuscation."
    },
    {
      "title": "User-Centric Phishing Detection: A RAG and LLM-Based Approach",
      "url": "https://aisecurity-portal.org/literature-database/user-centric-phishing-detection-a-rag-and-llm-based-approach/",
      "date": "2026-06-07",
      "type": "research-paper",
      "added": "2026-06-12",
      "superseded_by": null,
      "window": null,
      "explanation": "Recent peer-reviewed research achieving F1=0.9703 detection accuracy using RAG+LLM with user-specific context, demonstrating 66.7% false-positive reduction while maintaining detection precision."
    },
    {
      "title": "Findings from the 2026 Verizon DBIR that should shape your defenses",
      "url": "https://www.mimecast.com/blog/2026-verizon-dbir-findings/",
      "date": "2026-06-04",
      "type": "industry-report",
      "added": "2026-06-12",
      "superseded_by": null,
      "window": null,
      "explanation": "22,000 breach incidents analyzed showing phishing in 62% of breaches with human element present; AI-assisted attacks doubled in volume; phishing accounts for 44% of AI-assisted initial access attempts."
    },
    {
      "title": "Exclusive: Phishing Costs Are Climbing Even As Defenses Get Faster, IRONSCALES Warns",
      "url": "https://expertinsights.com/industry-perspectives/ironscales-phishing-costs-are-climbing",
      "date": "2026-06-04",
      "type": "adoption-metric",
      "added": "2026-06-12",
      "superseded_by": null,
      "window": null,
      "explanation": "Analysis of defense economics: IT professionals spend 36.5% of hours on phishing ($51,948/year burden); 9 of 10 organizations deployed AI email security by Aug 2023 yet costs escalated faster than per-incident efficiency improved."
    },
    {
      "title": "Why Legacy Enterprise Email Security Fails",
      "url": "https://www.uctoday.com/security-compliance-risk/legacy-enterprise-email-security-fails/",
      "date": "2026-06-02",
      "type": "industry-report",
      "added": "2026-06-12",
      "superseded_by": null,
      "window": null,
      "explanation": "Darktrace analysis revealing critical detection gaps: 70% of malicious emails bypass DMARC authentication; 1.6M newly created phishing domains evade blocklists; QR code phishing surged 336% with image-based evasion."
    },
    {
      "title": "Anatomy of a Modern Phishing Attack: Caught by AI Security Mailbox",
      "url": "https://abnormal.ai/blog/modern-phishing-attack-ai-security-mailbox",
      "date": "2026-06-01",
      "type": "case-study",
      "added": "2026-06-12",
      "superseded_by": null,
      "window": null,
      "explanation": "Abnormal AI case study at Lewisville Independent School District: deployment stopped 14.3K advanced attacks monthly, reduced email triage time by 95%, eliminated 92% of false positive investigation burden."
    },
    {
      "title": "ChatGPhish: When the AI Assistant Becomes the Phishing Vector",
      "url": "https://labs.cloudsecurityalliance.org/research/csa-research-note-chatgphish-ai-prompt-injection-phishing-20/",
      "date": "2026-05-31",
      "type": "research-paper",
      "added": "2026-06-12",
      "superseded_by": null,
      "window": null,
      "explanation": "CSA research documenting prompt injection attacks targeting AI assistants as phishing delivery mechanism; NIST study shows 81% task-hijacking success rate via indirect injection; six named attack techniques disclosed."
    },
    {
      "title": "CERT-In warns AI-assisted adversaries amplifying lateral movement, exploitation, data exfiltration across critical systems",
      "url": "https://industrialcyber.co/ai/cert-in-warns-ai-assisted-adversaries-amplifying-lateral-movement-exploitation-data-exfiltration-across-critical-systems/",
      "date": "2026-05-26",
      "type": "industry-report",
      "added": "2026-05-29",
      "superseded_by": null,
      "window": null,
      "explanation": "Government cybersecurity agency (CERT-In) formally documents AI-powered phishing bypassing traditional awareness-based detection via realism and contextual accuracy; urges shift to adaptive defense."
    },
    {
      "title": "Attacks Tailored to Federal Workflows: Agency Insights from Abnormal's 2026 Attack Landscape Report",
      "url": "https://abnormal.ai/blog/federal-email-threats-2026-attack-landscape-report",
      "date": "2026-05-26",
      "type": "adoption-metric",
      "added": "2026-05-29",
      "superseded_by": null,
      "window": null,
      "explanation": "Real-world attack analysis across 4,600+ organizations shows phishing tactics adapt to organizational structure: file-sharing 25.1% in finance/accounting, redirect chains 21.6% in SMEs, 12% brand impersonation."
    },
    {
      "title": "AI-Powered Phishing in 2026: Why Your Filters Aren't Enough",
      "url": "https://www.stmicro.net/blog/ai-powered-phishing-attacks-2026/",
      "date": "2026-05-21",
      "type": "opinion",
      "added": "2026-05-29",
      "superseded_by": null,
      "window": null,
      "explanation": "Strategic analysis documenting 82.6% AI-generated phishing prevalence, 54% vs 12% click-through rates, and $25.6M loss case (Arup deepfake BEC), exposing pattern-based filter obsolescence."
    },
    {
      "title": "When the Bait Writes Itself: How AI-Powered Phishing Is Rewriting the Rules of Social Engineering",
      "url": "https://reconshield.in/blog/ai-powered-phishing-attacks-2026-threat-analysis",
      "date": "2026-05-21",
      "type": "industry-report",
      "added": "2026-05-29",
      "superseded_by": null,
      "window": null,
      "explanation": "ReconShield comprehensive threat analysis from 23 authoritative sources: phishing accounts for 42% of 2026 breaches, IBM shows 192× speed improvement, Okta documents 30-second AI phishing site generation."
    },
    {
      "title": "Gartner Peer Insights Customers' Choice for Email Security for Microsoft 365 and Gmail",
      "url": "https://www.contentree.com/vendor-sheets/gartner-peer-insights-customers-choice-for-email-security-for-microsoft-365-and-gmail_484566",
      "date": "2026-05-19",
      "type": "product-ga",
      "added": "2026-05-29",
      "superseded_by": null,
      "window": null,
      "explanation": "Harmony Email & Collaboration receives Gartner Peer Insights recognition for AI-powered email security with phishing/ransomware/account takeover blocking across Microsoft 365 and Gmail."
    },
    {
      "title": "Abnormal Named a Leader in The Forrester Wave™: Email, Messaging, And Collaboration Security Solutions, Q2 2025",
      "url": "https://madison.techreports.com/en/Resource/Detail/292684",
      "date": "2026-05-18",
      "type": "industry-report",
      "added": "2026-05-29",
      "superseded_by": null,
      "window": null,
      "explanation": "Forrester Wave evaluation names Abnormal AI a Leader with highest scores in Strategy, Vision, Innovation, and Roadmap; recognizes API-based behavioral AI as new era of email defense."
    },
    {
      "title": "Cofense Adds AI-Driven Campaign Detection to Phishing Defense Platform",
      "url": "https://siliconangle.com/2026/05/13/cofense-adds-ai-driven-campaign-detection-phishing-defense-platform/",
      "date": "2026-05-13",
      "type": "product-ga",
      "added": "2026-05-15",
      "superseded_by": null,
      "window": null,
      "explanation": "Cofense Vision 3.2 uses clustering to identify polymorphic campaigns, Triage 3.0 routes automated responses; campaign creation compressed from hours to minutes with AI integration."
    },
    {
      "title": "AI Cybersecurity Statistics 2026: Comprehensive Threat Landscape Compilation",
      "url": "https://www.stingrai.io/blog/ai-cyber-attack-statistics-2026",
      "date": "2026-05-13",
      "type": "adoption-metric",
      "added": "2026-05-15",
      "superseded_by": null,
      "window": null,
      "explanation": "Aggregated 89 verified statistics from 26 publishers (IBM, CrowdStrike, Microsoft, ENISA, KnowBe4, Mandiant): AI phishing 54% CTR vs 12% human (4.5x gap); 82.6% of phishing emails contain AI; initial-access time collapsed 8+ hours to 22 seconds."
    },
    {
      "title": "Barracuda 2026 Email Threats Report: 3.1B Email Analysis",
      "url": "https://www.barracuda.com/reports/2026-email-threats-report",
      "date": "2026-05-11",
      "type": "adoption-metric",
      "added": "2026-05-15",
      "superseded_by": null,
      "window": null,
      "explanation": "3.1B email telemetry: 1 in 3 emails malicious/spam; 48% of malicious activity is phishing; 34% of companies experience monthly account takeover; 90% of high-volume campaigns use phishing-as-a-service kits."
    },
    {
      "title": "3.4 Billion AI Phishing Emails Daily: Attack Effectiveness and Bypass Metrics",
      "url": "https://weproms.com/blog/ai-phishing-email-deliverability-pakistan/",
      "date": "2026-05-09",
      "type": "adoption-metric",
      "added": "2026-05-15",
      "superseded_by": null,
      "window": null,
      "explanation": "3.4B daily AI phishing emails at 82.6% prevalence; 54% click-through rate vs 12% human; 47.3% bypass rate of Proofpoint/Mimecast/Google filters; 192x acceleration in attack generation time with GenAI."
    },
    {
      "title": "IRONSCALES Unveils Three Purpose-Built AI Agents for Phishing Defense at RSAC 2026",
      "url": "https://thenextweb.com/news/ironscales-ai-email-agents-rsac-2026",
      "date": "2026-05-08",
      "type": "product-ga",
      "added": "2026-05-15",
      "superseded_by": null,
      "window": null,
      "explanation": "AI-powered agents for Red Teaming (attack simulation), Phishing SOC (forensics in minutes), and Phishing Simulation (hyper-personalized training); addresses operational gaps in defense at machine speed."
    },
    {
      "title": "Shinhan Financial Group: Real-Time Voice Phishing Detection System Prevents 800M Won Damage",
      "url": "https://www.mk.co.kr/en/society/12037677",
      "date": "2026-05-06",
      "type": "case-study",
      "added": "2026-05-15",
      "superseded_by": null,
      "window": null,
      "explanation": "Named Korean financial conglomerate deployed real-time phishing detection across group companies; in 2 weeks prevented 800M won customer asset damage, analyzing 1,111 suspected transactions with 41 confirmed phishing attempts."
    },
    {
      "title": "M-Trends 2026: Vulnerability Exploitation Now Outpaces Phishing as Initial Access Vector",
      "url": "https://www.secure.com/blog/soc/m-trends-2026-key-findings",
      "date": "2026-05-06",
      "type": "industry-report",
      "added": "2026-05-15",
      "superseded_by": null,
      "window": null,
      "explanation": "Mandiant 15-year incident dataset shows structural shift: vulnerability exploitation (38%) now exceeds phishing (17%) as primary initial access; signals maturation of phishing defenses forcing attacker pivot."
    },
    {
      "title": "KnowBe4 Phishing Threat Trends Report Vol. 7: AI-Driven Phishing at Scale",
      "url": "https://www.indiablooms.com/life/86-of-phishing-attacks-now-ai-driven-experts-warn-of-a-dangerous-new-era/details",
      "date": "2026-05-02",
      "type": "adoption-metric",
      "added": "2026-05-15",
      "superseded_by": null,
      "window": null,
      "explanation": "KnowBe4 six-month analysis: 86% of phishing AI-driven; calendar phishing +49%, Teams attacks +41%, reverse proxies +139%; multi-channel orchestration replacing email-only tactics."
    },
    {
      "title": "1st May 2026 Cyber Update: UK Survey Shows Phishing Still Owns the Breach Economy",
      "url": "https://www.cybernewscentre.com/1st-may-2026-cyber-update-uk-survey-phishing-breach-economy/",
      "date": "2026-05-01",
      "type": "adoption-metric",
      "added": "2026-05-15",
      "superseded_by": null,
      "window": null,
      "explanation": "UK government survey of 612,000+ businesses finds 38% reported phishing attacks; 85% of breached organizations involved phishing in incident chain, validating phishing as persistent dominant breach vector."
    },
    {
      "title": "Microsoft Q1 2026 Phishing: 8.3 Billion Blocked, QR Surge 146%",
      "url": "https://www.gblock.app/articles/microsoft-q1-2026-phishing-83-billion-qr",
      "date": "2026-05-01",
      "type": "adoption-metric",
      "added": "2026-05-15",
      "superseded_by": null,
      "window": null,
      "explanation": "Microsoft Defender for Office 365 Q1 2026 telemetry: 8.3B phishing blocked; QR attacks +146%, CAPTCHA +125%, HTML attachments +175%; reveals detection gap widening as evasion techniques move inside email."
    },
    {
      "title": "Anatomy of a Low-Detection Credential Phishing Campaign",
      "url": "https://dev.to/toxy4ny/anatomy-of-a-low-detection-credential-phishing-campaign-2bho",
      "date": "2026-05-01",
      "type": "case-study",
      "added": "2026-05-15",
      "superseded_by": null,
      "window": null,
      "explanation": "Technical reverse-engineering of live phishing attack with 3% AV detection rate; hybrid human-AI code generation (LLM artifacts + operator fingerprints) demonstrates attack democratization through AI assistance."
    },
    {
      "title": "AI-Driven Phishing Surges in 2026 as Attackers Exploit Collaboration Tools, Bypass MFA, and Scale Personalized Campaigns",
      "url": "https://www.enterprisesecuritytech.com/post/ai-driven-phishing-surges-in-2026-as-attackers-exploit-collaboration-tools-bypass-mfa-and-scale-pe",
      "date": "2026-04-30",
      "type": "adoption-metric",
      "added": "2026-05-01",
      "superseded_by": null,
      "window": null,
      "explanation": null
    },
    {
      "title": "2026 Attack Landscape Report: Phishing Tactics Calibrate to Your Environment",
      "url": "https://abnormal.ai/blog/2026-attack-landscape-report-phishing",
      "date": "2026-04-29",
      "type": "adoption-metric",
      "added": "2026-05-15",
      "superseded_by": null,
      "window": null,
      "explanation": "800K+ attacks across 4,600+ organizations showing attackers use workflow-adaptive tactics; redirect links 21.6% (26.6% in SMEs), file-sharing 12.4%, brand impersonation 12%; demonstrates evasion sophistication."
    },
    {
      "title": "Threat Spotlight: Boutique phishing kit Saiga 2FA hides behind 'lorem ipsum' metadata",
      "url": "https://blog.barracuda.com/2026/04/28/threat-spotlight--boutique-phishing-kit-saiga-2fa",
      "date": "2026-04-28",
      "type": "research-paper",
      "added": "2026-05-01",
      "superseded_by": null,
      "window": null,
      "explanation": "Barracuda threat research documenting AiTM phishing kit with novel evasion (lorem ipsum metadata, CAPTCHA gating, dev tool detection) showing attackers actively circumventing NLP-based detection."
    },
    {
      "title": "Phishing Statistics 2026: BEC, AiTM, AI Attacks - Stingrai",
      "url": "https://www.stingrai.io/blog/phishing-statistics-2026",
      "date": "2026-04-26",
      "type": "adoption-metric",
      "added": "2026-05-01",
      "superseded_by": null,
      "window": null,
      "explanation": "Comprehensive verified statistics compilation from 23 named sources (APWG, Verizon, IBM, Proofpoint, Cofense, KnowBe4, Microsoft) showing phishing adoption metrics, AI prevalence, and training effectiveness benchmarks."
    },
    {
      "title": "Abnormal AI 2026 Attack Landscape Report: Threat Actors Move Beyond Technical Exploits",
      "url": "https://abnormal.ai/about/news/2026-attack-landscape-report",
      "date": "2026-04-22",
      "type": "adoption-metric",
      "added": "2026-05-01",
      "superseded_by": null,
      "window": null,
      "explanation": "Analysis of 800K+ real-world phishing attacks across 4,600+ orgs showing 58% phishing prevalence, 21.6% redirect-chain evasion, 61% BEC is vendor-related, with attackers targeting behavioral weaknesses rather than technical exploits."
    },
    {
      "title": "Phishing reclaims the top initial access spot, attackers experiment with AI tools",
      "url": "https://www.helpnetsecurity.com/2026/04/22/cisco-phishing-initial-access-2026/",
      "date": "2026-04-22",
      "type": "adoption-metric",
      "added": "2026-05-01",
      "superseded_by": null,
      "window": null,
      "explanation": "Cisco Talos Q1 2026 incident response data shows phishing as #1 initial access vector (>1/3 of engagements), with attackers using AI web dev platforms (Softr) for credential harvesting."
    },
    {
      "title": "FBI IC3 2025 report: Email fraud is now a $4 billion problem - Red Sift",
      "url": "https://redsift.com/blog/fbi-ic3-2025-report-email-fraud",
      "date": "2026-04-21",
      "type": "adoption-metric",
      "added": "2026-05-01",
      "superseded_by": null,
      "window": null,
      "explanation": "Official FBI IC3 2025 data documenting $4B+ email-origin fraud, 208% YoY phishing loss growth, $893M AI-related complaints, but only 35-44% large US orgs have full DMARC enforcement."
    },
    {
      "title": "How AI Phishing Targets US Banks, Fintechs and Insurers in 2026",
      "url": "https://cybelangel.com/blog/blog-ai-phishing-us-financial-services-2026/",
      "date": "2026-04-18",
      "type": "industry-report",
      "added": "2026-05-01",
      "superseded_by": null,
      "window": null,
      "explanation": "Sector analysis showing 82.6% of phishing emails use AI (Sept 2024–Feb 2025), AI emails achieve 60% higher click rates, and only 17% of orgs use AI to defend—documenting AI arms race in financial services."
    },
    {
      "title": "Memory-Augmented Multi-Modal LLM Agent for Phishing URL Detection at Scale",
      "url": "https://openreview.net/forum?id=itvQXLVWf4",
      "date": "2026-04-18",
      "type": "research-paper",
      "added": "2026-05-01",
      "superseded_by": null,
      "window": null,
      "explanation": "Peer-reviewed ACL 2026 Industry Track paper demonstrating production deployment: agentic LLM processing 60K URLs/week with 91.44% recall, protecting millions of customers at scale."
    },
    {
      "title": "CISA Emergency Directive: AI-Powered Phishing Campaign Analysis",
      "url": "https://radar.offseq.com/threat/cisa-emergency-directive-ai-powered-phishing-campa-d846f0fb",
      "date": "2026-04-16",
      "type": "adoption-metric",
      "added": "2026-04-17",
      "superseded_by": null,
      "window": null,
      "explanation": "Government threat intelligence reporting AI-powered phishing surge with specific metrics: 300% YoY increase, 200+ orgs compromised in 30 days, NIST prediction that 90% of breaches will be AI-driven. Demonstrates threat maturation and detection challenges."
    },
    {
      "title": "AI Risk Report 2026 - Press Release - Hornetsecurity",
      "url": "https://www.hornetsecurity.com/en/blog/ai-risk-report-press-release/",
      "date": "2026-04-14",
      "type": "adoption-metric",
      "added": "2026-04-17",
      "superseded_by": null,
      "window": null,
      "explanation": "Hornetsecurity survey of 500 UK leaders: 57% cite AI phishing as primary worry, 50% uncertain they can defend against AI-powered attacks, 54% experienced increased cyberattacks versus 45% two years ago."
    },
    {
      "title": "AI-Driven Campaign Compromises Accounts More Effectively than Traditional Phishing Attacks",
      "url": "https://thejournal.com/articles/2026/04/13/ai-driven-campaign-compromises-accounts-more-effectively-than-traditional-phishing-attacks.aspx",
      "date": "2026-04-13",
      "type": "research-paper",
      "added": "2026-04-17",
      "superseded_by": null,
      "window": null,
      "explanation": "Microsoft Defender Security Research Team's discovery of large-scale attack using device code flow abuse and EvilToken PhaaS toolkit—shows attack evolution beyond password theft to auth token abuse."
    },
    {
      "title": "Email Security at an Inflection Point: The 2026 Strategy Report - ITPro",
      "url": "https://www.itpro.com/security/email-security-at-an-inflection-point-the-2026-strategy-report",
      "date": "2026-04-09",
      "type": "adoption-metric",
      "added": "2026-04-17",
      "superseded_by": null,
      "window": null,
      "explanation": "Kaseya 2026 Email Security Report metric showing 83% of phishing emails now contain AI-generated content, representing major shift in attack sophistication and prevalence."
    },
    {
      "title": "Proofpoint vs Mimecast vs Abnormal Security - TechnologyMatch",
      "url": "https://technologymatch.com/blog/proofpoint-vs-mimecast-vs-abnormal-security-email-security-comparison",
      "date": "2026-04-08",
      "type": "opinion",
      "added": "2026-04-17",
      "superseded_by": null,
      "window": null,
      "explanation": "Vendor-neutral comparative analysis of three email security architectures explaining different approaches to phishing detection (SEG vs API-based). Documents adoption trend and architectural trade-offs relevant to practice maturity."
    },
    {
      "title": "How to Detect & Disrupt Phishing Websites - Netcraft",
      "url": "https://www.netcraft.com/guide/phishing-website-detection-disruption",
      "date": "2026-04-07",
      "type": "adoption-metric",
      "added": "2026-04-17",
      "superseded_by": null,
      "window": null,
      "explanation": "Netcraft publishes disruption metrics and adoption trends in phishing website attacks, showing 37% increase in attacks and 1.3M websites disrupted in 12 months."
    },
    {
      "title": "Inside an AI‑enabled device code phishing campaign | Microsoft Security Blog",
      "url": "https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/",
      "date": "2026-04-06",
      "type": "research-paper",
      "added": "2026-04-17",
      "superseded_by": null,
      "window": null,
      "explanation": "Microsoft Defender Security Research documents widespread AI-enabled device code phishing campaign with advanced backend automation, dynamic code generation, and AI-personalized lures; represents escalation in threat sophistication."
    },
    {
      "title": "Phishing Simulation Software: How It Works & Best Tools In 2026",
      "url": "https://www.articsledge.com/post/phishing-simulation-software",
      "date": "2026-04-05",
      "type": "tutorial",
      "added": "2026-04-17",
      "superseded_by": null,
      "window": null,
      "explanation": "Comprehensive practitioner guide with adoption metrics: phishing simulation market $98.87B (2024)→$224.3B (2034); AI phishing 54% click rate vs 12% human; 73.8% of phishing uses AI."
    },
    {
      "title": "The Complete Guide to Email Security in 2026 - Montreal Times",
      "url": "https://mtltimes.ca/montreal/the-complete-guide-to-email-security-in-2026/",
      "date": "2026-04-03",
      "type": "adoption-metric",
      "added": "2026-04-17",
      "superseded_by": null,
      "window": null,
      "explanation": "Quantifies AI phishing prevalence, DMARC adoption benchmarks, and regulatory mandates driving email security investment."
    },
    {
      "title": "Age of the AI adversary, evasive browser attacks and phishing trends",
      "url": "https://www.optery.com/evasive-browser-attacks-phishing-trends/",
      "date": "2026-03-31",
      "type": "opinion",
      "added": "2026-04-03",
      "superseded_by": null,
      "window": null,
      "explanation": "Multi-source threat intelligence (CrowdStrike, Push Security, Hoxhunt) documenting AI acceleration: fake CAPTCHA +563% in 2025, 29-minute eCrime breakout, 95% attacks use bot-protection, Tycoon2FA accounts for 59% of AiTM."
    },
    {
      "title": "Proofpoint strengthens agentic workspace protection for enterprises",
      "url": "https://entelechyasia.com/2026/03/25/proofpoint-strengthens-agentic-workspace-protection-for-enterprises/",
      "date": "2026-03-25",
      "type": "product-ga",
      "added": "2026-04-03",
      "superseded_by": null,
      "window": null,
      "explanation": "Proofpoint unified SEG and API email protection with AI-driven detection across external/internal threats, threat intelligence correlation, and data governance Q2 2026, signaling platform consolidation trend."
    },
    {
      "title": "12 Questions and Answers About Proofpoint Core Email Protection",
      "url": "https://www.securityscientist.net/blog/proofpoint-core-email-protection/",
      "date": "2026-03-23",
      "type": "opinion",
      "added": "2026-04-03",
      "superseded_by": null,
      "window": null,
      "explanation": "Independent technical analysis validating Proofpoint's multi-layer phishing detection: Nexus AI ensemble (LLM, ML classifiers, relationship graphs, computer vision) analyzed 3.4B emails; deployed at 85 Fortune 100 companies."
    },
    {
      "title": "AI Phishing Detection: How It Works and What Security Teams Actually Need",
      "url": "https://daylight.ai/blog/ai-phishing-detection",
      "date": "2026-03-17",
      "type": "opinion",
      "added": "2026-04-03",
      "superseded_by": null,
      "window": null,
      "explanation": "MDR firm analysis of detection state: 193K FBI phishing complaints 2024, $2.77B BEC losses; identifies structural gap—post-alert investigation fragmentation across email/identity/endpoint/cloud allows attackers exploitation."
    },
    {
      "title": "The Emerging Obfuscation Technique Designed to Evade Email Security NLP Detection Capabilities",
      "url": "https://blog.knowbe4.com/nlp-obfuscation-techniques-email-security-evasion",
      "date": "2026-03-16",
      "type": "adoption-metric",
      "added": "2026-04-03",
      "superseded_by": null,
      "window": null,
      "explanation": "KnowBe4 analysis of 40 live attacks: malicious actors append benign content (157 line breaks, 4.68 legitimate links) to evade NLP detection; in-the-wild evidence of attackers actively targeting AI defenses."
    },
    {
      "title": "Why Most Phishing Training Programs Fail - And the Best Phishing Simulation Tools to Turn Them Around",
      "url": "https://outthink.io/community/thought-leadership/blog/best-phishing-simulation-tools/",
      "date": "2026-03-11",
      "type": "industry-report",
      "added": "2026-04-03",
      "superseded_by": null,
      "window": null,
      "explanation": "Peer-reviewed research (UC San Diego Health, 19.5K employees) found annual training shows 1-2% improvement vs 10-30% real click rates; 75% complete training in <1 minute; demonstrates critical gap in human-factor defense."
    },
    {
      "title": "Phishing statistics 2025 - 2026: The numbers you need to know",
      "url": "https://zensec.co.uk/blog/2025-phishing-statistics-the-alarming-rise-in-attacks/",
      "date": "2026-03-11",
      "type": "adoption-metric",
      "added": "2026-04-03",
      "superseded_by": null,
      "window": null,
      "explanation": "Comprehensive 2026 statistics from FBI IC3, CISA: 82.6% of phishing AI-powered (53% YoY rise), 60% higher AI phishing click rates, 400% rise in successful AI scams 2025, BEC losses $2.77B, phishing costs $4.88M per breach."
    },
    {
      "title": "Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale",
      "url": "https://www.microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/",
      "date": "2026-03-04",
      "type": "research-paper",
      "added": "2026-04-03",
      "superseded_by": null,
      "window": null,
      "explanation": "Microsoft threat intelligence documented Tycoon2FA phishing-as-a-service targeting 500K+ organizations monthly with MFA bypass, token capture, evasion tactics (anti-bot, fingerprinting, polymorphic payloads), and facilitated global takedown with Europol."
    },
    {
      "title": "Evaluating Large Language Models' Ability to Automate Spear Phishing",
      "url": "https://www.schneier.com/academic/archives/2026/02/evaluating-large-language-models-ability-to-automate-spear-phishing.html",
      "date": "2026-02-27",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2026-02",
      "explanation": "Peer-reviewed study finds LLM-automated spear phishing achieved 54% CTR matching human experts, and AI detection achieved 97.25% accuracy with zero false positives, showing dual-use nature of LLM automation."
    },
    {
      "title": "Proofpoint joins AWS Security Hub Extended for email AI",
      "url": "https://securitybrief.asia/story/proofpoint-joins-aws-security-hub-extended-for-email-ai",
      "date": "2026-02-27",
      "type": "product-ga",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2026-02",
      "explanation": "Proofpoint integrates with AWS Security Hub Extended, combining Nexus AI detection (threat intelligence, ML, LLM, computer vision) into major cloud platform, signaling ecosystem maturity and expanded deployment surface."
    },
    {
      "title": "NTT DATA Group Corporation Relies on Proofpoint to Protect 6.5 Million Emails a Day",
      "url": "https://www.contentree.com/caseStudy/ntt-data-group-corporation-relies-on-proofpoint-to-protect-65-million-emails-a-day_477996",
      "date": "2026-02-26",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2026-02",
      "explanation": "NTT DATA deployed Proofpoint for comprehensive threat protection across global operations protecting 6.5 million emails daily, demonstrating sustained enterprise adoption in multinational environments."
    },
    {
      "title": "AI-Powered Phishing Attacks Surge Across Schools and Businesses",
      "url": "https://evrimagaci.org/gpt/aipowered-phishing-attacks-surge-across-schools-and-businesses-530192",
      "date": "2026-02-19",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2026-02",
      "explanation": "Acronis and Dataminr analysis: phishing accounts for 83% of email threats with 80% AI-powered, attacks rising 16% per organization YoY, 52% of MSP incidents, and collaboration platform attacks surged from 12% to 31% in one year."
    },
    {
      "title": "Cofense Report Reveals AI-Powered Phishing Accelerated to One Attack Every 19 Seconds",
      "url": "https://www.dataproof.co.za/index.php/2026/02/04/cofense-report-reveals-ai-powered-phishing-accelerated-to-one-attack-every-19-seconds/",
      "date": "2026-02-04",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2026-02",
      "explanation": "Cofense threat intelligence reveals AI-powered phishing doubled pace to one attack every 19 seconds in 2025, with 76% polymorphic URLs, 82% unique hashes, and 18% conversational attacks, showing threat sophistication acceleration."
    },
    {
      "title": "AI-Powered Phishing: Why \"Look for Typos\" Is No Longer Enough to Save Your Business in 2026",
      "url": "https://www.clearpath360.org/ai-powered-phishing-why-look-for-typos-is-no-longer-enough-to-save-your-business-in-2026/",
      "date": "2026-02-01",
      "type": "opinion",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2026-02",
      "explanation": "Critical analysis of AI-powered phishing limitations in 2026 shows traditional defenses obsolete: 82.6% AI-generated content, attacks every 19 seconds, 76% unique URLs, and pattern-matching evasion, confirming production deployment fragility."
    },
    {
      "title": "2025 Year in Review and Predictions for 2026 in the Cyber, AI, and Privacy Domains",
      "url": "https://www.jdsupra.com/legalnews/2025-year-in-review-and-predictions-for-8712298/",
      "date": "2026-01-28",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2026-01",
      "explanation": "Legal/cybersecurity review reports 400% increase in successful phishing scams in 2025 due to AI tools and threat actors weaponizing AI for hard-to-detect campaigns, signaling accelerating threat sophistication."
    },
    {
      "title": "Proofpoint Experiencing a Service Interruption for Mail Flow to Microsoft 365",
      "url": "https://excelmicro.kayako.com/en-us/article/1036-stable-proofpoint-essentials-proofpoint-experiencing-a-service-interruption-for-mail-flow-going-to-microsoft-365-january-22-2026",
      "date": "2026-01-22",
      "type": "news-coverage",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2026-01",
      "explanation": "Proofpoint Essentials service interruption on January 22, 2026 caused DSN=4 deferrals and email delays to Microsoft 365, exposing integration reliability and operational resilience challenges in major platform."
    },
    {
      "title": "Barracuda Report Finds Phishing Kits Doubled in 2025 as Attacks Grew More Evasive",
      "url": "https://siliconangle.com/2026/01/07/barracuda-report-finds-phishing-kits-doubled-2025-attacks-grew-evasive/",
      "date": "2026-01-07",
      "type": "industry-report",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2026-01",
      "explanation": "Barracuda threat report documents threat acceleration: phishing kits doubled in 2025, 90% of high-volume campaigns use phishing-as-a-service with AI-generated content and MFA bypass/URL obfuscation in 48% of campaigns."
    },
    {
      "title": "Phishing Trends in 2026: The Rise of AI, MFA Exploits and Polymorphic Attacks",
      "url": "https://managedservicesjournal.com/articles/phishing-trends-in-2026-the-rise-of-ai-mfa-exploits-and-polymorphic-attacks/",
      "date": "2026-01-06",
      "type": "opinion",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2026-01",
      "explanation": "Barracuda director predicts 90%+ of credential attacks will use sophisticated phishing kits by end of 2026, with MFA no longer fail-safe due to fatigue/relay attacks; advocates AI-driven detection and phishing-resistant MFA."
    },
    {
      "title": "Benchmark Electronics Enhances Email Security with Proofpoint Solutions",
      "url": "https://asiagrowthpartners.com/zh/case-study/benchmark-electronics-enhances-email-security-with-proofpoint-solutions/c24437",
      "date": "2026-01-01",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2026-01",
      "explanation": "Fortune 1000 aerospace company deployed Proofpoint Email Protection and TAP, preventing 90% of phishing/spoofing incidents and reducing monthly attacks from 20 to 1-2."
    },
    {
      "title": "Scalar Reduces Risk and Transforms Incident Response with Proofpoint Email Security Solutions",
      "url": "https://asiagrowthpartners.com/zh/case-study/scalar-reduces-risk-and-transforms-incident-response-with-proofpoint-email-security-solutions/c24440",
      "date": "2026-01-01",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2026-01",
      "explanation": "Canadian IT solutions provider deployed Proofpoint Email Protection and TAP enterprise-wide, reducing email delays from 10-45 minutes to on-time with drastic reduction in malware and phishing reaching users."
    },
    {
      "title": "Phishing Attacks Trends Report: Analysis & Prevention Strategies 2025",
      "url": "https://acsmi.org/blogs/phishing-attacks-trends-report-analysis-amp-prevention-strategies-2025-original-data",
      "date": "2025-11-19",
      "type": "industry-report",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q4",
      "explanation": "ACSMI 2025 trends analysis covering AI-driven phishing evolution, sector-specific threats (healthcare, finance, government), and cost impact: U.S. hospital ransomware incidents in 2025 exceeded $10M recovery costs per incident."
    },
    {
      "title": "Security Awareness – Exploitation of Proofpoint's Email Protection Enables Widespread Brand Impersonation",
      "url": "https://www.waterisac.org/security-awareness-exploitation-proofpoints-email-protection-enables-widespread",
      "date": "2025-10-28",
      "type": "news-coverage",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q4",
      "explanation": "WaterISAC security alert documenting active exploit campaign (since Jan 2024) of Proofpoint misconfiguration flaw enabling attacker relaying; 3-14M spoofed emails daily average, demonstrating critical deployment vulnerability."
    },
    {
      "title": "AI Phishing Attacks: Why Traditional Training Fails",
      "url": "https://www.brside.com/blog/ai-phishing-attacks-why-traditional-training-fails",
      "date": "2025-10-25",
      "type": "opinion",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q4",
      "explanation": "Critical assessment of training ROI: controlled study showed 54% CTR for AI phishing matching human experts; 82.6% of phishing using AI; training effectiveness contested between vendor claims (86% reduction) and academic evidence of minimal impact."
    },
    {
      "title": "4 Results",
      "url": "https://www.frontiersin.org/articles/10.3389/frai.2025.1496580/full",
      "date": "2025-10-23",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q4",
      "explanation": "Peer-reviewed bibliometric analysis of 1,096 scientific documents in Frontiers in AI examining AI/ML/DL/NLP in phishing detection, confirming consistent field growth and research focus shift from ML to deep learning."
    },
    {
      "title": "Chicago Blackhawks selects Proofpoint Email Security and Protection for Secure Email Gateways",
      "url": "https://www.appsruntheworld.com/customers-database/purchases/view/chicago-blackhawks-united-states-selects-proofpoint-email-security-and-protection-for-secure-email-gateways-segs",
      "date": "2025-10-13",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q4",
      "explanation": "Mid-sized enterprise (600 employees, $300M revenue) in Leisure & Hospitality sector selected Proofpoint Email Security, indicating ongoing vendor platform adoption in vertical market segments."
    },
    {
      "title": "Improving Phishing Resilience with AI-Generated Training: Evidence on Prompting, Personalization, and Duration",
      "url": "https://arxiv.org/html/2512.01893v1",
      "date": "2025-09-16",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q3",
      "explanation": "Controlled study (N=480) validates LLMs for generating phishing resilience training with significant pre-post learning gains; shows simple prompting sufficient without complex personalization."
    },
    {
      "title": "What needs improvement with Proofpoint Email Protection? - PeerSpot",
      "url": "https://www.peerspot.com/questions/what-needs-improvement-with-proofpoint-email-protection",
      "date": "2025-09-11",
      "type": "opinion",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q3",
      "explanation": "Practitioner feedback highlights deployment barriers in market-leading solution: high cost due to local circumstances, complex multi-portal interfaces, localization gaps limiting organizational adoption."
    },
    {
      "title": "A Systematic Review of Artificial Intelligence Techniques for Phishing Detection",
      "url": "https://www.oajaiml.com/archive/a-systematic-review-of-artificial-intelligence-techniques-for-phishing-detection",
      "date": "2025-08-07",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q3",
      "explanation": "Peer-reviewed systematic review finds DL and Gen AI models achieve >99% accuracy in phishing detection; CNN, LSTM, TCN demonstrated consistent performance on complex scenarios."
    },
    {
      "title": "Phishing Simulator Market 2025-2032: Industry Outlook, Trends Analysis, New Opportunities",
      "url": "https://www.openpr.com/news/4124680/phishing-simulator-market-2025-2032-industry-outlook-trends",
      "date": "2025-07-29",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q3",
      "explanation": "Global phishing simulator market size USD 113.01B in 2025, growing 7.2% CAGR; cloud-based simulators 62% of revenue; 15% BFSI adoption increase Q1 2025 signals broad ecosystem maturation."
    },
    {
      "title": "Analysis Reveals the ROI of Proofpoint Prime",
      "url": "https://www.proofpoint.com/us/blog/email-and-cloud-threats/analysis-reveals-roi-proofpoint-prime",
      "date": "2025-07-15",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q3",
      "explanation": "Independent ESG analysis reports 237% ROI for Proofpoint Prime deployments over three years, demonstrating significant financial value from enterprise-scale phishing detection adoption."
    },
    {
      "title": "Barracuda Unveils Next-Generation Threat Detection Powered by Multimodal AI",
      "url": "https://www.barracuda.com/company/news/2025/barracuda-next-generation-threat-detection-multimodal-ai",
      "date": "2025-07-02",
      "type": "product-ga",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q3",
      "explanation": "Barracuda announces multimodal AI analyzing text and visual data (URLs, documents, images, QR codes) for context-aware phishing protection, advancing vendor detection capabilities."
    },
    {
      "title": "Half the spam in your inbox is generated by AI - Barracuda and academic research",
      "url": "https://blog.barracuda.com/2025/06/18/half-spam-inbox-ai-generated",
      "date": "2025-06-18",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q2",
      "explanation": "Barracuda-Columbia-Chicago research: 51% of spam and 14% of BEC emails were AI-generated by April 2025, with AI-generated phishing showing higher formality and fewer grammatical errors enabling bypass of defenses."
    },
    {
      "title": "Using AI to outsmart AI-driven phishing scams - Help Net Security",
      "url": "https://www.helpnetsecurity.com/2025/05/30/ai-phishing-defense/",
      "date": "2025-05-30",
      "type": "opinion",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q2",
      "explanation": "Analyst perspective on AI-powered phishing defenses: discusses ML/NLP/deep learning techniques and critical limitations including false positives, privacy concerns, skill gaps, emphasizing human-AI collaboration necessity."
    },
    {
      "title": "Cofense Reveals Rapid Rise in AI-Powered Phishing: New Threat Every 42 Seconds",
      "url": "https://cofense.com/blog/cofense-reveals-rapid-rise-in-ai-powered-phishing-new-threat-every-42-seconds",
      "date": "2025-05-14",
      "type": "industry-report",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q2",
      "explanation": "Cofense Phishing Defense Center tracked one malicious email every 42 seconds in 2024; BEC attacks surged 70% YoY, with polymorphic campaigns evading traditional filters and AI enabling automated malware development at scale."
    },
    {
      "title": "New next-generation threat detection capabilities in Barracuda Email Security",
      "url": "https://blog.barracuda.com/2025/05/07/new-next-generation-threat-detection-capabilities-in-barracuda-a",
      "date": "2025-05-07",
      "type": "product-ga",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q2",
      "explanation": "Barracuda GA of multimodal AI sandbox engine delivering 3x threat detection power and 8x speed increase for phishing detection; detects QR codes and embedded malicious links in PDFs with 68% prevalence analysis."
    },
    {
      "title": "IBM X-Force 2025 Threat Intelligence Index",
      "url": "https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/2025-threat-intelligence-index",
      "date": "2025-04-16",
      "type": "industry-report",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q2",
      "explanation": "IBM X-Force 2025 report documents threat actors actively integrating AI into phishing and deepfake campaigns; infostealers delivered via phishing surge 84% YoY, indicating rapid attacker adoption of AI-powered tactics."
    },
    {
      "title": "Global Manufacturer Adds Abnormal to Block What Proofpoint Couldn't",
      "url": "https://abnormalsecurity.com/blog/proofpoint-limits-global-industrial-manufacturer",
      "date": "2025-04-09",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q2",
      "explanation": "Aerospace manufacturer deployed Abnormal alongside Proofpoint and detected 3,232 malicious messages missed over three months; saved 335 SOC hours monthly and revealed $5.8M annual exposure gap in market-leading vendor."
    },
    {
      "title": "KnowBe4 Phishing Threat Trend Report Q1 2025: 82% of Phishing Emails Use AI",
      "url": "https://www.iotinsider.com/industries/security/82-of-all-phishing-emails-had-some-use-of-ai-latest-knowbe4-report-shows/",
      "date": "2025-03-26",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q1",
      "explanation": "KnowBe4 analysis of early 2025 phishing trends shows 82.6% of emails use AI; 17.3% email volume increase; 76.4% exhibit polymorphic tactics; signals rapid attacker AI adoption."
    },
    {
      "title": "Proofpoint Core Email Protection",
      "url": "https://www.proofpoint.com/us/resources/solution-briefs/core-email-protection",
      "date": "2025-03-12",
      "type": "product-ga",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q1",
      "explanation": "Proofpoint GA of Core Email Protection with claimed 99.99% threat block rate, powered by NexusAI and global threat intelligence for BEC, ransomware, and phishing at scale."
    },
    {
      "title": "The dark reality of AI-driven phishing: Hoxhunt analysis of actual AI phishing prevalence",
      "url": "https://hoxhunt.com/blog/ai-phishing-attacks",
      "date": "2025-02-19",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q1",
      "explanation": "Hoxhunt data from 2.5M users in 131+ countries: only 0.7-4.7% of phishing emails are AI-crafted despite hype; traditional human phishing still dominates, providing critical counterbalance to AI threat narrative."
    },
    {
      "title": "Beyond Phishing: Exploring the Rise of AI-enabled Cybercrime",
      "url": "https://cltc.berkeley.edu/2025/01/16/beyond-phishing-exploring-the-rise-of-ai-enabled-cybercrime/",
      "date": "2025-01-16",
      "type": "industry-report",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q1",
      "explanation": "UC Berkeley CLTC tabletop exercise findings: AI-enabled phishing becoming hyper-targeted and personalized; defensive imperative to leverage same AI for threat detection and behavior analysis."
    },
    {
      "title": "Improving phishing email detection performance through deep learning with adaptive optimization",
      "url": "https://squ.elsevierpure.com/en/publications/improving-phishing-email-detection-performance-through-deep-learn/",
      "date": "2025-01-12",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q1",
      "explanation": "Peer-reviewed Nature Portfolio paper demonstrating hybrid deep learning model (BERT+CNN+GRU) with 96.8% accuracy and 2.5% false positive reduction, advancing transformer-based email analysis."
    },
    {
      "title": "ProofPoint Email Security Integration with ConnectWise Asio",
      "url": "https://www.connectwise.com/case-studies/proofpoint",
      "date": "2025-01-01",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2025-Q1",
      "explanation": "ConnectWise platform integration enabling MSPs to deploy Proofpoint's AI-driven email security at scale with centralized visibility and faster threat response across SMB customer base."
    },
    {
      "title": "Researchers achieve 96% accuracy in detecting phishing emails with open-source AI",
      "url": "https://the-decoder.com/researchers-achieve-96-accuracy-in-detecting-phishing-emails-with-open-source-ai/",
      "date": "2024-12-05",
      "type": "news-coverage",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q4",
      "explanation": "Kaiserslautern University research: open-source LLMs (Llama 3.1 70B and Gemma2 9B) achieve 95-96% detection accuracy using few-shot learning and RAG, democratizing high-performance phishing detection capability."
    },
    {
      "title": "Proofpoint Fell Short: Why a F500 Insurer Chose Abnormal",
      "url": "https://abnormalsecurity.com/blog/proofpoint-limits-fortune-500-insurance-provider",
      "date": "2024-12-02",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q4",
      "explanation": "Fortune 500 insurer replaced Proofpoint after Abnormal detected 6,454 missed attacks in three months (4,791 phishing, 42 BEC), revealing critical detection gaps in deployed market-leading solution."
    },
    {
      "title": "Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects",
      "url": "https://arxiv.org/abs/2412.00586v1",
      "date": "2024-11-30",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q4",
      "explanation": "Peer-reviewed study with 101 human participants: AI-automated spear phishing achieved 54% click-through rate (matching human experts); Claude 3.5 Sonnet detection exceeded 90% accuracy with low false positives."
    },
    {
      "title": "PEEK: Phishing Evolution Framework for Phishing Generation and Evolving Pattern Analysis using Large Language Models",
      "url": "https://arxiv.org/abs/2411.11389v2",
      "date": "2024-11-18",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q4",
      "explanation": "Peer-reviewed arXiv paper demonstrating LLM-based framework that improves phishing detection robustness: raises usable phishing samples from 21.4% to 84.8% and boosts detector accuracy to over 88%."
    },
    {
      "title": "Adapting to Cyber Threats: A Phishing Evolution Network (PEN) Framework for Phishing Generation and Analyzing Evolution Patterns using Large Language Models",
      "url": "https://www.promptlayer.com/research-papers/ai-powered-phishing-a-new-era-of-cyber-threats",
      "date": "2024-11-18",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q4",
      "explanation": "Research framework using LLMs to generate realistic phishing emails (75% indistinguishable from human-crafted) and train detection models: adversarial training reduces attack success rate by up to 70%."
    },
    {
      "title": "Threat Spotlight: The evolving use of QR codes in phishing attacks",
      "url": "https://blog.barracuda.com/2024/10/22/threat-spotlight-evolving-qr-codes-phishing-attacks",
      "date": "2024-10-22",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q4",
      "explanation": "Barracuda detection data: 500K+ phishing emails with QR codes embedded in PDFs over three months (51% Microsoft impersonation), demonstrating rapid attacker adoption of quishing tactics in production deployments."
    },
    {
      "title": "75% of Organizations Say Phishing Poses the Greatest AI Risk",
      "url": "https://www.securitymagazine.com/articles/101068-75-of-organizations-say-phishing-poses-the-greatest-ai-risk",
      "date": "2024-09-25",
      "type": "industry-report",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q3",
      "explanation": "Team8 CISO survey: 75% report phishing as greatest AI-powered threat; 70% had budget increases; 58% cite lack of expertise; signals organizational focus and investment prioritizing phishing defense."
    },
    {
      "title": "Barracuda's AI Innovations Boost Email Security Against Emerging Threats",
      "url": "https://www.grcviewpoint.com/barracudas-ai-innovations-boost-email-security-against-emerging-threats/",
      "date": "2024-09-19",
      "type": "news-coverage",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q3",
      "explanation": "Barracuda research shows Microsoft 365 native security has 47% miss rate for phishing, increasing to 70% for BEC; Barracuda blocks 99.2% of targeted attacks, revealing detection gaps in mainstream cloud platforms."
    },
    {
      "title": "Fortune 1000 Manufacturer Replaces Proofpoint with Abnormal AI",
      "url": "https://abnormal.ai/blog/proofpoint-replacement-fortune-1000-manufacturer",
      "date": "2024-09-11",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q3",
      "explanation": "Real deployment: Fortune 1000 manufacturer with 20K+ mailboxes switched from Proofpoint, with Abnormal detecting 10x more attacks (1,278 missed in 25 days) and $876k annual savings from redundant licensing."
    },
    {
      "title": "The New Face of Fraud: 40% of Business Email Compromise (BEC) Attacks Are AI-Generated",
      "url": "https://vipre.com/resources/press-releases/40-percent-bec-ai-generated/",
      "date": "2024-08-22",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q3",
      "explanation": "VIPRE Q2 2024 Email Threat Trends Report: 40% of BEC emails are AI-generated (1.8B emails analyzed); BEC up 20% YoY; shows rapid attacker adoption of generative AI for phishing and business email compromise."
    },
    {
      "title": "Unveiling suspicious phishing attacks: enhancing detection ...",
      "url": "https://www.frontiersin.org/journals/computer-science/articles/10.3389/fcomp.2024.1428013/full",
      "date": "2024-07-02",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q3",
      "explanation": "Peer-reviewed ML study on 274K URLs with random forest achieving 97.52% accuracy, demonstrating continued technical progress in AI-driven phishing URL detection and feature vectorization optimization."
    },
    {
      "title": "Utilizing Large Language Models with Human Feedback Integration for Generating Dedicated Warning for Phishing Emails",
      "url": "https://research.monash.edu/en/publications/utilizing-large-language-models-with-human-feedback-integration-f",
      "date": "2024-07-02",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q3",
      "explanation": "ACM SecTL 2024 conference paper: LLM-human feedback framework achieves over 80% effectiveness in phishing semantics identification with zero false positives/negatives, advancing human-centric AI detection."
    },
    {
      "title": "Survey Results: Making Sense of Deepfakes and GenAI Created Phishing Attacks",
      "url": "https://www.bitdefender.com/en-us/blog/businessinsights/survey-results-making-sense-of-deepfakes-and-gen-ai-created-phishing-attacks/",
      "date": "2024-06-25",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q2",
      "explanation": "Bitdefender survey finds 96% of security professionals see GenAI as significant threat, yet 73% are overconfident in spotting deepfakes, revealing gap between perceived and actual defensive capability against AI-generated attacks."
    },
    {
      "title": "Business Email Compromise Accounts for 1 in 10 Email Attacks",
      "url": "https://blog.barracuda.com/2024/06/18/new-report-business-email-compromise-email-attacks",
      "date": "2024-06-18",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q2",
      "explanation": "Barracuda analysis of 69 million email attacks shows BEC at 10.6% of social engineering attacks; conversation hijacking up 70%, phishing at 35.5%, with attackers leveraging AI to scale and tailor attacks."
    },
    {
      "title": "Proofpoint Sets New Industry Standard in Email Security with Adaptive Threat Protection",
      "url": "https://www.silicon.co.uk/press-release/proofpoint-sets-new-industry-standard-in-email-security-with-adaptive-threat-protection-capabilities-across-the-entire-email-delivery-chain",
      "date": "2024-05-06",
      "type": "product-ga",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q2",
      "explanation": "Proofpoint GA of LLM-based pre-delivery detection and Adaptive Email Security at RSA 2024; blocks 66M+ BEC attacks monthly and detects 4.5M unique malicious URLs daily, indicating continued vendor platform maturation."
    },
    {
      "title": "Zscaler Research Finds 60% Increase in AI-Driven Phishing Attacks",
      "url": "https://www.zscaler.com/press/zscaler-research-finds-60-increase-ai-driven-phishing-attacks",
      "date": "2024-04-23",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q2",
      "explanation": "Zscaler analysis of 2 billion blocked transactions reveals 60% YoY increase in AI-driven phishing; finance/insurance targeted 27.8% of attacks (393% YoY increase), showing rapid adoption of AI tools by attackers."
    },
    {
      "title": "Evaluating the Effectiveness and Robustness of Visual Similarity-Based Phishing Detection",
      "url": "https://arxiv.org/html/2405.19598v2",
      "date": "2024-04-22",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q2",
      "explanation": "Large-scale evaluation of visual similarity phishing detection on 451k real-world sites reveals low performance (PhishZoo 93.2% false positive rate) and vulnerabilities to adversarial manipulation, highlighting robustness gaps."
    },
    {
      "title": "Phishing Email Detection with Generative AI",
      "url": "https://jp.security.ntt/insights_resources/tech_blog/cpd-phishing-email-detection-with-generative-ai/",
      "date": "2024-04-03",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q2",
      "explanation": "NTT Security's ChatSpamDetector LLM-based system achieves 99.70% accuracy on 2,010 emails across 19 languages, with GPT-4 outperforming other models, demonstrating advanced AI capability for phishing detection."
    },
    {
      "title": "Barracuda Sentinel Integration - Netsurion",
      "url": "https://www.netsurion.com/data-source-integrations/barracuda-sentinel",
      "date": "2024-03-29",
      "type": "product-ga",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q1",
      "explanation": "Barracuda Sentinel (AI-powered spear phishing and BEC defense) integrated with Netsurion's Open XDR platform; demonstrates continued product maturity and ecosystem interoperability in production deployments."
    },
    {
      "title": "Unveiling the AI Threat: Trustwave SpiderLabs Exposes the Rise of AI in BEC and Phishing Attacks",
      "url": "https://www.trustwave.com/en-us/resources/blogs/trustwave-blog/unveiling-the-ai-threat-trustwave-spiderlabs-exposes-the-rise-of-ai-in-bec-and-phishing-attacks-2024-technology-threat-landscape-report/",
      "date": "2024-03-20",
      "type": "industry-report",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q1",
      "explanation": "Trustwave SpiderLabs 2024 report documents AI-generated BEC emails, WormGPT and FraudGPT tool adoption, deepfakes (e.g., $25M video-call scam); shows rapid offensive AI advancement and detection evasion."
    },
    {
      "title": "Devising and Detecting Phishing Emails Using Large Language Models - Schneier on Security",
      "url": "https://www.schneier.com/academic/archives/2024/03/devising-and-detecting-phishing-emails-using-large-language-models.html",
      "date": "2024-03-14",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q1",
      "explanation": "IEEE Access research comparing phishing effectiveness of GPT-4 (30-44% CTR), V-Triad (69-79% CTR), and combined approaches (43-81%), plus LLM detection capabilities; demonstrates AI arms race in both offense and defense."
    },
    {
      "title": "Annual State of Email Security by the Numbers | Cofense",
      "url": "https://cofense.com/blog/annual-state-of-email-security-by-the-numbers",
      "date": "2024-03-07",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q1",
      "explanation": "Cofense 2024 analysis of 35M+ trained employees shows malicious emails bypassing all secure email gateways increased 100%+; SEGs miss 30-50% of threats; one malicious email bypassing SEGs detected every minute."
    },
    {
      "title": "AI Alone is Not Bulletproof: Weaknesses in AI/ML Email Security",
      "url": "https://cofense.com/blog/ai-alone-is-not-bulletproof-weaknesses-in-ai-ml-email-security",
      "date": "2024-02-04",
      "type": "opinion",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q1",
      "explanation": "Cofense critical assessment highlighting SEG bypass techniques, offensive AI advantages, and fundamental limitations of detection-only approaches; notes deepfake attacks and AI-enhanced phishing effectiveness."
    },
    {
      "title": "Proofpoint Attachment Defense failure at University of Washington",
      "url": "https://mailman22.u.washington.edu/pipermail/eoutage/2024-January/000152.html",
      "date": "2024-01-17",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2024-Q1",
      "explanation": "Proofpoint email security outage (Jan 17 2024) disabled Attachment Defense for 4.5 hours, allowing unscanned emails; real-world example of critical detection gaps in production phishing defense systems."
    },
    {
      "title": "Cofense launches fully managed vishing service",
      "url": "https://cofense.com/blog/cofense-adds-fully-managed-vishing-service/",
      "date": "2023-12-13",
      "type": "product-ga",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2023-H2",
      "explanation": "Cofense GA of fully managed vishing (voice phishing) service addressing $1.2B annual losses; product expansion indicates vendor response to voice-based phishing threat evolution."
    },
    {
      "title": "State of Phishing Report 2023: AI Fueling Dramatic Rise in Cybercrime",
      "url": "https://stage.njbia.org/state-of-phishing-report-shows-ai-fueling-dramatic-rise-in-cybercrime/",
      "date": "2023-10-30",
      "type": "industry-report",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2023-H2",
      "explanation": "SlashNext analysis documented 1,265% increase in malicious phishing emails in 12 months since ChatGPT launch, with 31,000 phishing attacks launched daily, signaling AI-driven threat acceleration."
    },
    {
      "title": "AI vs. human deceit: Unravelling new age phishing tactics",
      "url": "https://www.ibm.com/think/x-force/ai-vs-human-deceit-unravelling-new-age-phishing-tactics",
      "date": "2023-10-24",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2023-H2",
      "explanation": "IBM X-Force Red controlled study at healthcare organization: ChatGPT-generated phishing emails created in 5 minutes matched human-crafted emails (16 hours) in click rates during simulation of 800+ employees."
    },
    {
      "title": "LLMs lower the barrier for entry into cybercrime - Egress 2023 threat intelligence",
      "url": "https://www.helpnetsecurity.com/2023/10/05/traditional-perimeter-detection/",
      "date": "2023-10-05",
      "type": "industry-report",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2023-H2",
      "explanation": "Egress analysis showed year-over-year detection degradation: Microsoft Defender missed 25% more phishing emails in 2023 vs 2022; secure email gateways missed 29% more, indicating threat evolution outpacing defenses."
    },
    {
      "title": "Proofpoint Security - AWS Marketplace",
      "url": "https://aws.amazon.com/marketplace/pp/prodview-dcj7rctb55qie",
      "date": "2023-09-01",
      "type": "product-ga",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2023-H2",
      "explanation": "Proofpoint's email security suite available on AWS Marketplace with 87 of Fortune 100 as customers, indicating cloud-native platform integration and enterprise adoption at scale."
    },
    {
      "title": "Barracuda XDR Insights: AI-based pattern analysis for phishing and identity threats",
      "url": "https://de.blog.barracuda.com/2023/08/23/barracuda-xdr-insights-ai-patterns-protect",
      "date": "2023-08-23",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2023-H2",
      "explanation": "Barracuda production deployment analyzed 950B IT events and detected 6,000 high-risk incidents in H1 2023, using AI-based pattern analysis to block phishing and identity abuse attacks across thousands of customers."
    },
    {
      "title": "Leader in The Forrester Wave for Email Security, Q2 2023",
      "url": "https://www.proofpoint.com/us/blog/email-and-cloud-threats/proofpoint-recognized-forrester-wave-email-security-q2-2023",
      "date": "2023-06-21",
      "type": "industry-report",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2023-H1",
      "explanation": "Forrester Wave recognizes Proofpoint as Leader in Enterprise Email Security with highest current offering score among competitors, validating market maturity and vendor differentiation."
    },
    {
      "title": "An Explainable Transformer-based Model for Phishing Email Detection: A Large Language Model Approach",
      "url": "https://arxiv.org/html/2402.13871v2",
      "date": "2023-05-12",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2023-H1",
      "explanation": "Academic paper presents fine-tuned RoBERTa model for phishing detection with high accuracy and explainability; addresses LLM-powered attack evasion (ChatGPT-like models generating phishing content)."
    },
    {
      "title": "Quantum Titan's AI Deep Learning Engines Detect and Block Zero-Day Phishing Attacks in Real-Time",
      "url": "https://blog.checkpoint.com/2023/04/03/quantum-titans-ai-deep-learning-engines-detect-and-block-zero-day-phishing-attacks-in-real-time/",
      "date": "2023-04-03",
      "type": "product-ga",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2023-H1",
      "explanation": "Check Point's Zero Phishing AI engine in Quantum Titan achieves 4x more zero-day detection than traditional solutions and 40% more than other AI vendors; deployed in production via Harmony Browse and Mobile."
    },
    {
      "title": "Barracuda Networks uses ML on Databricks Lakehouse to prevent email phishing",
      "url": "https://www.databricks.com/blog/2023/03/21/barracuda-networks-uses-ml-databricks-lakehouse-prevent-email-phishing.html",
      "date": "2023-03-21",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2023-H1",
      "explanation": "Barracuda production ML pipeline blocks tens of thousands of phishing emails daily for thousands of customers using Databricks Data Intelligence Platform with improved deployment speed."
    },
    {
      "title": "Barracuda reveals three novel tactics being used by attackers in phishing",
      "url": "https://www.technologyforyou.org/barracuda-reveals-three-novel-tactics-being-used-by-attackers-in-phishing/",
      "date": "2023-03-17",
      "type": "news-coverage",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2023-H1",
      "explanation": "Barracuda research identifies emerging phishing tactics (Google Translate abuse, image-only emails, special characters) affecting 11-15% of organizations; shows threat innovation outpacing detection advancement."
    },
    {
      "title": "Web Phishing Net (WPN): A scalable machine learning approach for real-time phishing campaign detection",
      "url": "https://ar5iv.labs.arxiv.org/html/2502.13171",
      "date": "2023-01-01",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2023-H1",
      "explanation": "BT Group research proposing unsupervised ML for phishing campaign detection addressing privacy concerns and AI-generated threats; notes 71% of AI-crafted email attacks go undetected."
    },
    {
      "title": "Cofense PhishMe? You reeled me in! | TrustRadius",
      "url": "https://www.trustradius.com/reviews/cofense-phishme-2022-12-06-09-16-37",
      "date": "2022-12-06",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2022-H2",
      "explanation": "Independent user review at large software company (5K-10K employees) reports Cofense PhishMe significantly increased threat detection and freed cybersecurity team time for other projects."
    },
    {
      "title": "Proofpoint Expands Threat Protection Platform with New Deployment, Detection, and Behavioral Analytics Innovations",
      "url": "https://www.globenewswire.com/news-release/2022/10/12/2533328/35374/en/Proofpoint-Expands-Threat-Protection-Platform-with-New-Deployment-Detection-and-Behavioral-Analytics-Innovations.html",
      "date": "2022-10-12",
      "type": "product-ga",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2022-H2",
      "explanation": "Proofpoint's Supernova Behavioral Analysis Engine deployed to select customers since May 2022 blocked 19M BEC and phishing attacks monthly, including one $194M attempted theft."
    },
    {
      "title": "Analysis and Prevention of AI-Based Phishing Email Attacks",
      "url": "https://ouci.dntb.gov.ua/en/works/456bKQOl/",
      "date": "2022-10-01",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2022-H2",
      "explanation": "Journal article in Electronics (2024, DOI: 10.3390/electronics13101839) analyzing AI-generated phishing emails found machine learning achieves high accuracy identifying AI-generated vs human-crafted phishing."
    },
    {
      "title": "Spam filter/virus scan blocks mails globally (September 29, 2022)",
      "url": "https://borncity.com/win/2022/09/29/barracuda-networks-spam-filter-virenprfung-blockt-mails-29-september-2022/",
      "date": "2022-09-29",
      "type": "news-coverage",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2022-H2",
      "explanation": "Global outage of Barracuda Email Security Gateway and Email Protection caused widespread email delays and queue backlogs, exposing reliability issues in production phishing detection deployments."
    },
    {
      "title": "Improving Phishing Detection Via Psychological Trait Scoring",
      "url": "http://arxiv.org/abs/2208.06792",
      "date": "2022-08-14",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2022-H2",
      "explanation": "arXiv research on psychological traits in phishing emails (urgency, fear, enticement) shows BERT/SBERT/CNN models with trait scoring outperform state-of-the-art F1 score by 4.54%."
    },
    {
      "title": "KnowBe4's Annual Benchmarking Report Finds One in Three Untrained Employees Will Click on a Phishing Link",
      "url": "https://www.knowbe4.com/press/knowbe4s-annual-benchmarking-report-finds-one-in-three-untrained-employees-will-click-on-a-phishing-link",
      "date": "2022-07-12",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2022-H2",
      "explanation": "KnowBe4 2022 analysis of 9.5M users across 30K+ orgs found 32.4% baseline phishing click rate, dropping to 17.6% after 90 days training and 5% after 12 months, measuring training effectiveness at scale."
    },
    {
      "title": "Cybersecurity Customer Success Stories | Proofpoint AU",
      "url": "https://www.proofpoint.com/au/customer-stories",
      "date": "2022-06-30",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2022-H1",
      "explanation": "ACCO Brands (6,000 users) deployed Proofpoint email security with measurable improvement in threat management and user confidence, confirming continued enterprise adoption."
    },
    {
      "title": "Designing a New Net for Phishing Detection with NVIDIA Morpheus",
      "url": "https://developer.nvidia.com/blog/designing-a-new-net-for-phishing-detection-with-nvidia-morpheus/",
      "date": "2022-06-02",
      "type": "product-ga",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2022-H1",
      "explanation": "NVIDIA announces Morpheus AI framework for cybersecurity with BERT-based phishing detection achieving 99.68% accuracy on combined datasets, expanding vendor ecosystem."
    },
    {
      "title": "Feature rich security awareness platform with deep email security integration | TrustRadius",
      "url": "https://www.trustradius.com/reviews/barracuda-security-awareness-training-formerly-barracuda-phishline-2022-04-21-06-06-27",
      "date": "2022-04-21",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2022-H1",
      "explanation": "Independent user review (Kappa Data) reports reduced security team workload, increased staff awareness, and prevention of malware via email through Barracuda PhishLine platform."
    },
    {
      "title": "Research Shows Over 400% Increase In Phishing Attacks",
      "url": "https://www.zscaler.com/press/new-zscaler-research-shows-over-400-increase-phishing-attacks-retail-and-wholesale-industries",
      "date": "2022-04-20",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2022-H1",
      "explanation": "Zscaler analysis of 200B daily transactions: phishing attacks grew 29% to 873.9M globally; retail/wholesale hit 400% YoY increase, signaling sustained threat evolution."
    },
    {
      "title": "Towards Web Phishing Detection Limitations and Mitigation - arXiv",
      "url": "https://arxiv.org/abs/2204.00985",
      "date": "2022-04-03",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2022-H1",
      "explanation": "Research identifies ML evasion techniques (benign service obfuscation, JS hiding, delayed content) and proposes Anti-SubtlePhish model achieving 98.8% accuracy and 100% on 0-day attacks."
    },
    {
      "title": "Evaluation of Contextual and Game-Based Training for Phishing ...",
      "url": "https://ideas.repec.org/a/gam/jftint/v14y2022i4p104-d779616.html",
      "date": "2022-02-02",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2022-H1",
      "explanation": "Study of 41 participants shows training supports secure behavior but 'training alone is insufficient' to prevent user susceptibility, indicating limitations in human-centric defense approaches."
    },
    {
      "title": "Barracuda Email Protection detects malicious attacks and unauthorized activity",
      "url": "https://www.helpnetsecurity.com/2021/12/10/barracuda-email-protection/",
      "date": "2021-12-10",
      "type": "product-ga",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2021",
      "explanation": "Barracuda launched three new Email Protection plans combining gateway and API-based AI; SE Labs testing named Barracuda 'Best Email Security Service' in November 2021."
    },
    {
      "title": "Protect against phishing with Attack Simulation Training in Microsoft Defender for Office 365",
      "url": "https://www.microsoft.com/en-us/security/blog/2021/11/16/protect-against-phishing-with-attack-simulation-training-in-microsoft-defender-for-officer-365/",
      "date": "2021-11-16",
      "type": "product-ga",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2021",
      "explanation": "Microsoft GA of Attack Simulation Training in Defender for Office 365 with behavior-based phishing risk mitigation, premade payloads modeled on real attacks, and training in 20+ languages."
    },
    {
      "title": "Proofpoint Email Protection URL Rewrite Bypass via Invalid URL",
      "url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2021-0011",
      "date": "2021-11-11",
      "type": "news-coverage",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2021",
      "explanation": "CVE-2021-31608: Proofpoint vulnerability where invalid URL schemes bypass rewrite feature, allowing phishing emails to reach users undetected despite deployed protections."
    },
    {
      "title": "Customer Has Success Using Proofpoint Essentials",
      "url": "https://www.gothamtg.com/blog/customer-has-success-using-proofpoint-essentials",
      "date": "2021-10-22",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2021",
      "explanation": "Manufacturing company deployed Proofpoint Essentials, achieving 30-50% decrease in unwanted emails over 11 months and 51% quarantine/block rate on 45K+ daily emails."
    },
    {
      "title": "Black Hat insights: Deploying 'human sensors' to reinforce phishing email detection and response",
      "url": "https://www.lastwatchdog.com/black-hat-insights-deploying-human-sensors-to-reinforce-phishing-email-detection-and-response/",
      "date": "2021-09-05",
      "type": "conference-talk",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2021",
      "explanation": "Black Hat USA 2021: Cofense demonstrated cross-customer threat sharing where oil/gas company phishing was detected and indicators propagated to two other customers within minutes."
    },
    {
      "title": "State of the Phish Report 2021: 4 Key Metrics",
      "url": "https://www.secureworld.io/industry-news/state-of-the-phish-report-2021",
      "date": "2021-02-15",
      "type": "industry-report",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2021",
      "explanation": "Proofpoint's 2021 report found 57% of organizations experienced successful phishing in 2020; 34% paid ransoms post-breach, indicating widespread attack success despite defenses."
    },
    {
      "title": "Barracuda Sentinelで検出できる攻撃の分析 (Anatomy of Sentinel-Caught Attacks)",
      "url": "https://www.barracuda.co.jp/anatomy-of-a-sentinel-catch/",
      "date": "2020-12-02",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2020",
      "explanation": "Barracuda Sentinel detected sophisticated spear-phishing attack with credential harvesting in Japanese enterprise while legacy gateways failed, demonstrating real-world efficacy in production Office 365 environment."
    },
    {
      "title": "Mobile Phishing Increases More Than 300% in Q3 2020",
      "url": "https://www.proofpoint.com/us/blog/threat-protection/mobile-phishing-increases-more-300-2020-chaos-continues",
      "date": "2020-11-02",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2020",
      "explanation": "Proofpoint telemetry of 80%+ North America mobile messages found 328% increase in mobile phishing Q3 2020 vs Q2, with 84% of organizations subject to mobile phishing attacks."
    },
    {
      "title": "Proofpoint Patches URL Sandbox Bypass Bug",
      "url": "https://www.brandenwilliams.com/blog/2020/11/02/proofpoint-patches-url-sandbox-bypass-bug/",
      "date": "2020-11-02",
      "type": "opinion",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2020",
      "explanation": "Independent security researcher disclosed vulnerability in Proofpoint URLDefense where URLs over 770 characters bypassed sandbox detection, revealing limitations in production phishing detection tools."
    },
    {
      "title": "The Phish Scale: NIST-Developed Method Helps IT Staff See Why Users Click",
      "url": "https://www.nist.gov/news-events/news/2020/09/phish-scale-nist-developed-method-helps-it-staff-see-why-users-click",
      "date": "2020-09-17",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2020",
      "explanation": "NIST researchers developed Phish Scale, a standardized 5-point methodology for evaluating phishing email difficulty in training programs based on operational data from 1000+ organizations."
    },
    {
      "title": "A comprehensive survey of AI-enabled phishing attacks and defenses",
      "url": "https://pubmed.ncbi.nlm.nih.gov/33110340/",
      "date": "2020-07-20",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2020",
      "explanation": "Peer-reviewed survey in Telecommunication Systems comprehensively reviewing Machine Learning, Deep Learning, and Hybrid Learning techniques for phishing detection, signaling research maturity."
    },
    {
      "title": "Email Spam Management using Proofpoint at Baruch College",
      "url": "https://bctc.baruch.cuny.edu/facultyandstaff/email-spam-proofpoint/",
      "date": "2020-03-15",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2020",
      "explanation": "Baruch College deployed Proofpoint as email security gateway, inspecting 200,000+ message attributes with high detection success rate for spam and phishing protection in production."
    },
    {
      "title": "NRI Secure Cofense PhishMe managed service launch",
      "url": "https://www.nri-secure.co.jp/news/2019/1008",
      "date": "2019-10-08",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2019",
      "explanation": "Japanese cybersecurity firm NRI Secure launched managed services for Cofense PhishMe deployment, supporting enterprise adoption and addressing training coordination challenges for phishing defense."
    },
    {
      "title": "Detecting and characterizing lateral phishing at scale",
      "url": "https://blog.acolyer.org/2019/10/04/lateral-phishing-at-scale/",
      "date": "2019-10-04",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2019",
      "explanation": "USENIX Security 2019 research with Barracuda analyzing 113M emails across 92 organizations found 180 lateral phishing incidents affecting 101K mailboxes, with 87.3% detection rate and 0.00036% false positive rate."
    },
    {
      "title": "Why legacy email gateways blind cloud security: Check Point critique of Proofpoint and Mimecast",
      "url": "https://emailsecurity.checkpoint.com/blog/why-proofpoint-and-mimecast-cant-secure-office-365-and-gmail",
      "date": "2019-09-02",
      "type": "opinion",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2019",
      "explanation": "Critical assessment showing potential limitations of traditional email gateways in cloud environments like Office 365 and Gmail, highlighting evolution required in phishing detection architecture."
    },
    {
      "title": "Proofpoint people-centric innovations: Adaptive security controls and customized training",
      "url": "https://www.helpnetsecurity.com/2019/07/23/proofpoint-people-centric-innovations/",
      "date": "2019-07-23",
      "type": "product-ga",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2019",
      "explanation": "Proofpoint GA of adaptive URL isolation based on user risk profile and integrated threat intelligence, plus customized security awareness training with Learning Science Evaluator."
    },
    {
      "title": "Characterizing the Networks Sending Enterprise Phishing Emails",
      "url": "https://arxiv.org/html/2412.12403v1",
      "date": "2019-02-23",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2019",
      "explanation": "Barracuda Networks research analyzing 800K+ phishing and 4B non-phishing emails found one-third of phishing originates from reputable networks like AWS and Azure; a deployed classifier improved detection by 3-5%."
    },
    {
      "title": "OFS-NN: An Effective Phishing Websites Detection Model Based on Optimal Feature Selection and Neural Network",
      "url": "https://discovery.researcher.life/article/ofs-nn-an-effective-phishing-websites-detection-model-based-on-optimal-feature-selection-and-neural-network/8ca5388a00c33b70a2c3657147a203f9",
      "date": "2019-01-01",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2019",
      "explanation": "IEEE Access peer-reviewed paper proposing neural network model with optimal feature selection for phishing website detection, demonstrating improved accuracy and stability in experiments."
    },
    {
      "title": "Learning from the ones that got away: Detecting new forms of phishing attacks",
      "url": "https://pure.psu.edu/en/publications/learning-from-the-ones-that-got-away-detecting-new-forms-of-phish",
      "date": "2018-11-01",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2018",
      "explanation": "Penn State's SAFe-PC system detects over 70% of phishing emails that evaded production Sophos deployment, demonstrating incremental ML retraining effectiveness in university IT environment."
    },
    {
      "title": "Stop Phishing with Avanan's Anti-Phishing Software",
      "url": "https://emailsecurity.checkpoint.com/blog/stop-phishing-with-avanan",
      "date": "2018-09-05",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2018",
      "explanation": "FS-ISAC (a major cybersecurity organization) phishing incident in March 2018: employee clicked malicious link and email spread internally until reported, showing successful attacks persist even at security-aware organizations."
    },
    {
      "title": "Modern email protection relies on innovation and multiple layers of defense",
      "url": "https://blog.barracuda.com/2018/07/26/modern-email-protection-relies-on-innovation-and-multiple-layers-of-defense",
      "date": "2018-07-26",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2018",
      "explanation": "Barracuda reports 232% YoY Essentials growth, 36% email security growth to $100M+ annual run rate, and 50,000+ customers, signaling rapid vendor scale in AI-powered phishing defense market."
    },
    {
      "title": "Barracuda Discover 18 Partner Event - Email Security",
      "url": "https://www.kascade.co.uk/define-tomorrow/blog/2018-7-3-barracuda-discover-18-partner-event-email-security/",
      "date": "2018-07-03",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2018",
      "explanation": "Fortune 500 side-by-side test: Barracuda Sentinel caught 621 attacks and 366 Microsoft impersonations missed by Office 365 ATP in one month, validating AI-powered spear-phishing detection at enterprise scale."
    },
    {
      "title": "Here's some phish-AI research: Machine-learning code crafts phishing URLs that dodge auto-detection",
      "url": "https://www.theregister.com/2018/06/19/ai_phishing_generator/",
      "date": "2018-06-19",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2018",
      "explanation": "Cyxtera's DeepPhish LSTM system increases phishing URL evasion rates from 0.69% to 20.90%, demonstrating that adversarial AI can evade detection systems, indicating offensive capabilities matching defensive evolution."
    },
    {
      "title": "PhishMe® Acquired by Private Equity Syndicate and Rebrands as Cofense™",
      "url": "https://www.prnewswire.com/news-releases/phishme-acquired-by-private-equity-syndicate-and-rebrands-as-cofense-300603749.html",
      "date": "2018-02-26",
      "type": "news-coverage",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2018",
      "explanation": "$400 million acquisition with 80% CAGR, 10M+ workstation deployments, and coverage of nearly half of Fortune 500, validating phishing awareness and training as investable market segment."
    },
    {
      "title": "2017 Enterprise Phishing Resiliency and Defense Report",
      "url": "https://siliconangle.com/2017/11/30/phishing-attacks-cost-1-6m-average-enterprises-successfully-fighting-back/",
      "date": "2017-11-30",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2017",
      "explanation": "PhishMe analysis of 52M simulations across 1,400 customers shows 65% increase in phishing attempts but susceptibility rates dropping to 5% among mature defense programs."
    },
    {
      "title": "Office 365 Adoption Survey: Security Concerns and Phishing Risk",
      "url": "https://blog.barracuda.com/2017/10/12/office-365-active-usage-soars-some-still-unclear-on-security",
      "date": "2017-10-12",
      "type": "adoption-metric",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2017",
      "explanation": "Survey of 1,100+ organizations shows 63% Office 365 adoption and 89% express concern about phishing, but only 36% deploy third-party phishing solutions despite rising cloud attack surface."
    },
    {
      "title": "Systematization of Knowledge: A Systematic Review of Software-Based Web Phishing Detection",
      "url": "https://researchwith.njit.edu/en/publications/systematization-of-knowledge-sok-a-systematic-review-of-software-/",
      "date": "2017-10-01",
      "type": "research-paper",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2017",
      "explanation": "Peer-reviewed IEEE survey identifying phishing as a mature research subfield, reporting 36% annual growth in unique phishing sites over six years and 97% growth in the preceding two years."
    },
    {
      "title": "Abusing Cloud Providers for Enhanced Phishing: Bypassing Proofpoint via Office 365",
      "url": "https://www.insomniacsecurity.com/2017/07/11/365phish.html",
      "date": "2017-07-11",
      "type": "opinion",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2017",
      "explanation": "Technical proof-of-concept demonstrating a method to bypass Proofpoint's phishing detection by exploiting misconfigured Office 365 SMTP relays, revealing detection evasion limitations."
    },
    {
      "title": "Introducing Barracuda Sentinel",
      "url": "https://blog.barracuda.com/2017/06/28/introducing-barracuda-sentinel",
      "date": "2017-06-28",
      "type": "product-ga",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2017",
      "explanation": "Barracuda announces AI-powered spear phishing defense product with three-layer approach: AI-based impersonation detection, DMARC domain fraud protection, and anti-fraud training."
    },
    {
      "title": "Cofense PhishMe for global consumer products company deployment",
      "url": "https://roi4cio.com/catalog/implementation/cofense-phishme-dlja-globalnoi-proizvodstvennoi-kampanii",
      "date": "2017-04-01",
      "type": "case-study",
      "added": "2026-03-18",
      "superseded_by": null,
      "window": "2017",
      "explanation": "Global CPG company with 40K employees deployed Cofense PhishMe and Triage, reducing click rates from 28% to under 10% and achieving 80% automated email resolution."
    }
  ],
  "tierHistory": [
    {
      "tier": "research",
      "from": "2017-01-01",
      "to": "2017-01-01"
    },
    {
      "tier": "bleeding-edge",
      "from": "2017-01-01",
      "to": "2018-01-01"
    },
    {
      "tier": "leading-edge",
      "from": "2018-01-01",
      "to": "2019-01-01"
    },
    {
      "tier": "good-practice",
      "from": "2019-01-01",
      "to": null
    }
  ],
  "trendHistory": [
    {
      "trend": "steady",
      "blockerType": null,
      "from": "2026-09-26",
      "to": null
    }
  ],
  "description": "AI that identifies phishing attempts across email, messaging, and web, including sophisticated spear-phishing campaigns. Includes NLP-based email analysis and URL reputation scoring; distinct from data loss prevention which protects outbound data rather than detecting inbound threats.",
  "overview": "AI-powered phishing detection is a proven, widely deployed practice — but it faces a critical bifurcation in 2026 between technical capability and operational effectiveness. Detection research and vendor platforms have reached theoretical maturity: models exceed 97% accuracy in controlled settings, production deployments block billions of emails monthly, and the ecosystem spans leading vendors (Proofpoint, Barracuda, Cofense) to specialized entrants (Abnormal, IRONSCALES). Yet real-world evidence reveals persistent gaps. UK government data shows 38% of businesses report phishing attacks and 85% of breached organisations involve phishing in the attack chain. Real-world deployments reveal detection failures: large organisations consistently find 3,000+ phishing emails missed quarterly by leading platforms, while attackers have systematised response with phishing-as-a-service (90% of high-volume campaigns) and AI-assisted code generation (hybrid human-AI attacks achieving 54% click-through vs 12% human baseline). The defining tension is not technical but operational: the organisations deploying pure-detection play defenses face attackers adapting faster than filters improve, with multi-channel tactics (email, Teams, calendar, reverse proxies) overwhelming email-only controls. Practitioner surveys confirm overconfidence masking underpreparedness: 86% of attacks now use AI while only 17% of organisations deploy AI-powered defences. The practice remains on a plateau—mature capability coexisting with expanding threat surface and human-factor limitations that no detection improvement overcomes.",
  "currentLandscape": "August 2026 telemetry confirms an inflection in attacker tactics toward post-authentication and multi-channel vectors while AI-powered phishing reaches human-level sophistication. Adversary-in-the-middle (AiTM) and OAuth consent phishing have emerged as the dominant credential-theft mechanism: Tycoon2FA and related campaigns reached 500,000+ organizations with 40,000 incidents detected daily, employing CAPTCHA evasion and MFA-bypass infrastructure at industrial scale. Device code phishing—exploiting OAuth 2.0's device authorization flow—has escalated rapidly (1,380% growth from H2 2025 to Q1 2026) across 25+ commodity phishing kits, bypassing all MFA forms including passkeys with 90-day valid refresh tokens post-compromise. Industrialized attack infrastructure: Mirage2FA and related PaaS platforms execute AiTM campaigns at scale via HTML smuggling, CAPTCHA gates, and WebSocket relays, leveraging compromised Microsoft 365 tenants for distribution. Real incident data shows AiTM attacks achieving 84% MFA failure rates, collapsing the assumption that multi-factor authentication alone protects against modern phishing. Multi-sector real-world evidence: Storm-2755 (Payroll Pirates) targeted hundreds of organizations across healthcare, education, manufacturing, government, and professional services, demonstrating operational maturity of redirect-chain attacks (Google Meet → S3 → AiTM). High-impact breaches: Silent Ransom extracted $48M from Am Law 100 law firms via callback phishing targeting payroll/finance data.\n\nPeer-reviewed research validates the escalation: AI-automated spear phishing now matches human expert performance at 54% click-through rates (vs. 12% for traditional campaigns), while AI-generated attacks have grown from 40% of volume (mid-2024) to 86%+ prevalence. Detection capability has simultaneously matured: Red Canary's orchestrated AI subagent deployment achieves 94% accuracy with transparent reasoning, Abnormal's behavioral baseline approach demonstrated 49-day pre-disclosure detection of the Payroll Pirates campaign (vs. public disclosure), and behavioral AI protects 3,200+ organizations including 25% of Fortune 500. Yet real-world effectiveness gaps persist and are widening. Detection accuracy gaps quantified: Mandiant M-Trends 2026 shows vishing now accounts for 23% of cloud breaches (exceeding email phishing at 15%), while Verizon DBIR documents 41% of social engineering breaches involving non-email vectors with voice phishing 40% higher success rate. Microsoft 365 detection misses 293 phishing emails per 100 mailboxes per 30 days; Google Workspace misses 350. Vendor accuracy claims diverge sharply from production performance: AI detection models scoring 99.78% in controlled settings drop to 77.8% accuracy on unfamiliar email corpuses, producing false-alarm rates requiring manual triage. Behavioral AI detection successfully blocks sophisticated attacks (Australian Football League prevented 8M+ threats monthly at 99.99% effectiveness), but 20% of phishing attacks still bypass enterprise detection at the browser layer where late-stage redirects and CAPTCHA overlays execute. Post-delivery analysis shows 30% of business email compromise emails land in inboxes despite passing technical filters—evidence that context-aware detection exceeds message-scoring capability. The multi-channel fragmentation documented in May continues through August: calendar phishing, Teams-based attacks, reverse proxy credential interception, and voice phishing remain elevated, forcing detection systems to correlate signals across identity, access, and email layers rather than treating inbox defense in isolation. Detection latency compounds the gap: AI-generated phishing variants reach production at machine speed, outpacing signature-based defenses' ability to fingerprint novel payloads. The foundational constraint remains organizational: 86% of attacks use AI while only a fraction of enterprise deployments employ behavioral AI detection, signaling that mature technical capability exists but organizational adoption and skill gaps limit operational impact.",
  "history": "- **2017:** Phishing detection established as mature research discipline with widespread organizational awareness but selective AI-based defense adoption. Major vendor launches (Sentinel, Triage expansion) and documented deployments reducing susceptibility from 28% to under 10%; however, 64% of organizations lacked third-party solutions despite high threat volume and sophistication in campaigns like FreeMilk.\n- **2018:** Vendor market consolidation and scale-up with Barracuda reaching 50,000+ customers (232% YoY Essentials growth) and Cofense's $400M acquisition by private equity, backing 10M+ workstation deployments. Enterprise validation through Fortune 500 testing showed Barracuda Sentinel outperforming Microsoft ATP by 621 missed attacks in side-by-side trial. Adversarial AI research (DeepPhish) demonstrated evasion capabilities accelerating in parallel with defense (0.69%→20.90% evasion rates), and real-world incidents at security-aware organizations (FS-ISAC phishing spread) revealed persistent human-factor vulnerabilities despite technical maturity.\n- **2019:** Market consolidation and analyst validation with Cofense and Barracuda earning Gartner and Forrester recognition. USENIX Security 2019 research documented lateral phishing incidents across 92 organizations with 87.3% detection rates; separate Barracuda research showed cloud infrastructure (AWS, Azure) as phishing origin sources with deployed classifiers improving detection 3-5%. Global deployment expansion visible with Cofense entering Japanese market via managed services. Check Point analysis flagged detection gaps in cloud email platforms (Office 365, Gmail), highlighting architectural tensions as enterprises migrated.\n- **2020:** Threat landscape intensity increased sharply with mobile phishing attacks rising 328% in Q3 while email gateways matured. Research methodologies advanced (NIST Phish Scale standardized training evaluation; comprehensive AI detection survey published). Vendor maturity demonstrated through international expansion and industry awards (Barracuda SC Awards for AI/ML in email security). However, critical vulnerabilities exposed limitations: Proofpoint URLDefense sandbox bypass (770+ character URLs) revealed gaps in production detection tools. Deployment infrastructure challenges persisted with tension between legacy email gateways and cloud-native solutions (Office 365, Gmail) as attack vectors diversified.\n- **2021:** Market solidification continued with major platform GAs: Microsoft Attack Simulation Training launched integrated into Defender for Office 365; Barracuda released three new Email Protection plans validated by SE Labs as best in class; new entrants like Phished and dPhish provided alternative approaches to simulation and detection. Real-world deployments confirmed practice maturity with manufacturing and enterprise cases showing 30-50% email reduction and strong adoption metrics. However, attack success remained high: Proofpoint data showed 57% of organizations experienced successful phishing in 2020 with 34% paying follow-up ransoms, and CVE-2021-31608 revealed a URL bypass vulnerability in Proofpoint itself. Cross-customer threat intelligence sharing (demonstrated at Black Hat via Cofense) emerged as an emerging mitigation pattern, but detection limitations persisted.\n- **2022-H1:** Vendor ecosystem expanded with new entrants (NVIDIA Morpheus with 99.68% accuracy) while established players consolidated. Threat volume accelerated: phishing attacks grew 29% globally to 873.9M annually with 400% surge in retail/wholesale. Real-world deployments (ACCO Brands with 6,000 users, Kappa Data) showed continued adoption and marginal improvements in awareness and team efficiency. Research advances: evasion-resistant detection models (Anti-SubtlePhish) achieved 98.8% accuracy but training effectiveness studies revealed fundamental limits—training alone insufficient to prevent user susceptibility, signaling maturity plateau where technical gains face persistent organizational barriers.\n- **2022-H2:** Proofpoint's Supernova behavioral engine demonstrated large-scale efficacy, blocking 19M BEC/phishing attacks monthly and preventing a $194M theft among select customers. Training improvements measurable: KnowBe4 benchmarking 9.5M users showed phishing click rates dropping from 32.4% baseline to 5% after 12 months training. Research on AI-generated phishing and psychological trait scoring advanced detection techniques. However, critical incident exposed vulnerability: September 2022 Barracuda email security gateway outage caused global email delays, revealing infrastructure reliability concerns despite vendor maturity. Practice showed technical progress alongside operational and human-factor bottlenecks.\n- **2023-H1:** Cloud-native ML pipelines accelerated deployment speed (Barracuda on Databricks blocking tens of thousands daily); Check Point's Zero Phishing GA claimed 4x zero-day detection. Research identified AI-generated phishing (71% undetected) and novel attacker tactics (11-15% of orgs hit). Analyst validation continued (Forrester Wave, Gartner Market Guide), but emerging threat sophistication—especially adversary-generated content—revealed structural limitations in purely technical defenses. Tension between detection capability advancement and threat evolution remained unresolved.\n- **2023-H2:** Vendors expanded capabilities (Cofense vishing service, Proofpoint AWS Marketplace integration, Barracuda 950B event analysis across customers) and analyst recognition held. However, AI-driven threat acceleration became undeniable: 1,265% increase in malicious phishing since ChatGPT, 31,000 daily attacks. Detection systems degraded year-over-year: Microsoft Defender missed 25% more phishing, secure email gateways missed 29% more in 2023 vs 2022. IBM study showed ChatGPT-generated emails matched human-crafted campaigns in click effectiveness. 71% of AI-generated attacks evaded production detection. Practice reached inflection point where threat evolution outpaced defense advancement.\n- **2024-Q1:** Vendor scale continued (Barracuda Sentinel ecosystem integration) and research advanced with IEEE Access study documenting GPT-4 phishing at 30-44% CTR and LLM detection trade-offs. However, production deployment fragility emerged: Proofpoint Attachment Defense outage at major university left emails unscanned; Cofense metrics showed SEGs missing 30-50% of threats with malicious bypasses increasing 100%+ YoY. Offensive AI tooling adoption accelerated (WormGPT, FraudGPT) with deepfakes enabling $25M attacks. Practice demonstrated sustained technical advancement masked by widening detection gaps in production systems—commodity AI tools now accessible to attackers, detection evasion techniques outpacing traditional ML defense models.\n- **2024-Q2:** Vendor innovation accelerated with Proofpoint GA of LLM-based pre-delivery detection (NexusAI) and Adaptive Email Security platform updates; Barracuda continued ML pipeline scaling blocking tens of thousands daily. Threat landscape intensified: Zscaler documented 60% YoY increase in AI-driven attacks across 2B blocked transactions; BEC attacks grew to 10.6% of social engineering vectors with 70% surge in conversation hijacking. Research showed detection capability maturity (NTT ChatSpamDetector 99.70% accuracy) alongside robustness limitations (451k site evaluation revealed >93% false positive rate in visual detection). Practitioner overconfidence emerged: 96% of security professionals perceive GenAI threat yet 73% overestimate their deepfake detection ability, exposing perception-reality gap in organizational defenses.\n- **2024-Q3:** ML research matured (274K-URL study: 97.52% accuracy; LLM-human framework: 80%+ effectiveness) while deployment dynamics shifted: Fortune 1000 manufacturer replaced Proofpoint with Abnormal AI citing 10x better detection and $876k savings, signaling vendor-neutral migration patterns. Threat acceleration continued: 40% of BEC attacks AI-generated; Microsoft 365 native security showed 47% phishing miss rate (70% for BEC), exposing platform dependency risks. Organizational investment surged: 75% of CISOs identified phishing as greatest AI-powered threat with 70% increasing budgets, yet 58% cited lack of expertise. Practice reached mature plateau where technical sophistication (detection accuracy near 97-99%) coexisted with widening real-world deployment gaps driven by mainstream platform limitations and accelerating attacker AI adoption.\n- **2024-Q4:** LLM-based phishing research matured with frameworks improving detection robustness (PEEK raising training samples from 21.4% to 84.8%, boosting accuracy to 88%+) and adversarial approaches (PEN reducing attack success by 70%); human-subject studies validated AI-automated spear phishing at 54% CTR matching human experts, with AI detection exceeding 90% accuracy. Real-world deployments revealed critical gaps: Fortune 500 insurer detected 6,454 Proofpoint-missed attacks in three months, signaling that vendor market leadership masks persistent detection failures. Attacker adoption accelerated with 500K+ quishing campaigns in three months and LLM-generated emails becoming production threat; open-source detection reached 95-96% accuracy, democratizing defenses. Practice remained at inflection point: technical capability plateaued near theoretical maximums while threat sophistication and deployment fragility continued diverging, with attacker AI and evasion tactics outpacing vendor mitigation in mainstream platforms.\n- **2025-Q1:** Vendor platform maturity deepened with Proofpoint Core Email Protection GA (99.99% threat block rate), Barracuda ML pipeline enhancements, and academic research advancing detection to 96.8% accuracy with reduced false positives. Channel expansion accelerated through Proofpoint-ConnectWise MSP integration enabling SMB deployment at scale. Threat landscape showed mixed signals: KnowBe4 reported 82.6% of phishing emails using AI with 76.4% polymorphic tactics and 17.3% volume increase; UC Berkeley warned of hyper-targeted AI-powered phishing becoming mainstream. Critical counter-signal emerged: Hoxhunt analysis from 2.5M users across 131+ countries found only 0.7-4.7% of phishing emails actually AI-generated, revealing hype-reality gap while human-crafted phishing remained dominant vector. Practice showed simultaneous technical advancement and threat acceleration with persistent deployment fragility in mainstream cloud platforms.\n- **2025-Q2:** Attacker AI adoption accelerated with 51% of spam and 14% of BEC emails AI-generated by mid-year; threat volume surged with 70% YoY BEC increase and one malicious email every 42 seconds tracked by Cofense. Vendor platform capabilities matured: Barracuda launched multimodal AI sandbox with 3x detection power and 8x speed; Proofpoint and Cofense reported strong threat block metrics. However, real-world detection gaps persisted: global aerospace manufacturer deploying Abnormal alongside Proofpoint detected 3,232 missed attacks over three months ($5.8M exposure). Analyst perspectives highlighted fundamental tensions—AI-powered defenses advancing in capability, but plagued by false positives, privacy concerns, and organizational skill gaps limiting effective deployment. Practice showed highest evidence of simultaneous vendor capability advancement and attacker AI adoption with persistent deployment fragility and cost impact on real organizations.\n- **2025-Q3:** Research consensus solidified with peer-reviewed systematic review confirming >99% accuracy for DL/Gen AI models (CNN, LSTM, TCN); controlled study (N=480) validated AI-generated training for user resilience without complex personalization. Market maturity accelerated: global phishing simulator market reached $113B with 7.2% CAGR; Proofpoint Prime deployments showed 237% ROI over three years. Vendor innovation continued with Barracuda multimodal AI analyzing text, images, URLs, and QR codes. However, deployment barriers persisted: practitioner feedback highlighted high costs, complex interfaces, and localization gaps in market-leading solutions, exposing organizational friction masking adoption metrics. Practice demonstrated maturity with technical capability and market validation coexisting alongside real deployment constraints limiting broader impact.\n- **2025-Q4:** Research field maturity confirmed via peer-reviewed bibliometric analysis of 1,096+ documents showing decisive shift from ML to deep learning; attacker AI adoption (82.6% of phishing) and training effectiveness remained contested (54% CTR for AI phishing vs vendor claims of 86% ROI). Critical infrastructure vulnerability exposed: Proofpoint misconfiguration exploit enabled 3-14M spoofed emails daily. Healthcare sector phishing-triggered ransomware reached $10M+ recovery costs per incident. Ongoing enterprise adoption (Chicago Blackhawks) indicated continued platform deployment in vertical markets. Practice reached mature technical plateau (>99% accuracy in controlled research) coexisting with widening production deployment gaps, attacker AI acceleration, and quantified cost impact, signaling that technical sophistication and market size mask persistent organizational and operational vulnerabilities limiting real-world effectiveness.\n- **2026-Jan:** Threat acceleration continued with 400% surge in successful AI-powered phishing scams in 2025. Barracuda threat research showed phishing kits doubled with 90% of high-volume campaigns using phishing-as-a-service, 48% incorporating MFA bypass and URL obfuscation tactics. Real-world deployments remained strong (Benchmark Electronics prevented 90% of incidents, Scalar achieved on-time email delivery), signaling continued platform adoption despite threat sophistication. Critical negative signal: Proofpoint service interruption on January 22 exposed reliability gaps in Microsoft 365 integration. Practitioner analysis predicted 90%+ of credential attacks will use sophisticated kits by end of 2026, with MFA no longer fail-safe. Practice sustained mature technical plateau coexisting with accelerating threat sophistication, organizational demand for advanced detection, and persistent platform reliability concerns limiting effectiveness in production environments.\n- **2026-Feb:** Research validation of dual-use AI published (LLM-automated phishing 54% CTR vs human experts, AI detection 97.25% accuracy with zero false positives), confirming technical parity but highlighting organizational deployment bottlenecks. Threat acceleration continued sharply: Cofense reported AI-powered phishing doubled pace to one attack every 19 seconds, with polymorphic attacks (76% unique URLs) and conversational attacks (18% of malicious emails) becoming standard; cross-industry analysis showed phishing 83% of email threats with 80% AI-powered, collaboration attacks surging 12%→31% YoY. Vendor ecosystem expansion: Proofpoint integrated AWS Security Hub Extended (Nexus AI stack); NTT DATA deployed Proofpoint protecting 6.5M emails daily. Practice revealed structural gap: research-validated defensive capability (97%+ accuracy) exceeded organizational deployment speed and cost constraints in production, with traditional gateway defenses and pattern-matching filters remaining ineffective against polymorphic, AI-generated attacks. Maturity plateau confirmed with synchronized threat acceleration and growing real-world ineffectiveness in mainstream deployments.\n- **2026-Mar/Apr:** Threat landscape documenting phishing-as-a-service ecosystem at scale: Microsoft Threat Intelligence exposed Tycoon2FA reaching 500K+ organizations monthly with MFA bypass, token interception, evasion infrastructure, and coordinated global takedown with Europol; Tycoon2FA accounts for 59% of adversary-in-the-middle phishing, with fake CAPTCHA attacks up 563% in 2025. Real-world attack analysis showed malicious actors appending benign content (157 average line breaks) to bypass NLP detection—evidence of attackers actively targeting and defeating AI defenses. CISA reported a 300% YoY increase in AI-powered phishing with 200+ organizations compromised in 30 days; Kaseya 2026 data shows 83% of phishing emails contain AI-generated content; Netcraft disrupted 1.3M phishing websites in 12 months while documenting a 37% increase in attacks. Microsoft Defender Security Research documented large-scale AI-enabled device code phishing (EvilToken PhaaS toolkit) with dynamic code generation and AI-personalized lures, representing escalation beyond password theft to auth token abuse. Hornetsecurity survey of 500 UK leaders found 57% cite AI phishing as primary worry with 50% uncertain they can defend against AI-powered attacks. Comprehensive threat statistics confirm: AI phishing achieves 54% click rates versus 12% for traditional phishing; phishing simulation market projected to reach $224B by 2034. Human-factor research confirmed critical constraint: UC San Diego Health study found annual training shows 1-2% improvement vs 10-30% real click rates; 75% complete training in <1 minute. Vendor platform maturity: Proofpoint announced agentic workspace security with unified SEG/API architecture and AI governance, with Nexus AI ensemble analyzing 3.4B emails deployed at 85 Fortune 100 companies. However, post-detection gap identified: MDR analysis revealed structural fragmentation across email/identity/endpoint/cloud layers allowing 29-minute average eCrime breakout. Practice sustained mature technical equilibrium (detection 97%+, platforms GA at scale, analyst validation) coexisting with widened real-world deployment gaps, accelerated attacker adoption of phishing-as-a-service, and documented human-factor limitations in operational resilience.\n- **2026-May:** Threat acceleration reaches new measurable peaks with broadened operational evidence. KnowBe4 six-month analysis confirms 86% of attacks AI-driven with 7x efficiency over manual campaigns and documents multi-channel fragmentation: calendar phishing +49%, Teams attacks +41%, reverse proxy credential attacks +139%. Barracuda 2026 Email Threats Report (3.1B emails analyzed) shows 1 in 3 emails malicious, 48% phishing, 34% of organizations experiencing monthly account takeover, 90% of campaigns using phishing-as-a-service kits. UK government survey (612K+ organizations) confirms 38% phishing prevalence with 85% of breached orgs involving phishing in incident chain. Microsoft Defender Q1 2026 telemetry: 8.3B phishing blocked but QR phishing (+146%), CAPTCHA attacks (+125%), and HTML-in-attachment delivery (+175%) reveal detection gaps widening as attackers move evasion inside email. Aggregated statistics (89 verified datapoints across IBM, CrowdStrike, Microsoft, Mandiant) quantify the AI-driven acceleration: 54% CTR for AI phishing versus 12% human baseline, 47.3% bypass rate against leading filters, initial-access time collapsed from 8+ hours to 22 seconds. CERT-In formally documented AI-powered phishing bypassing traditional awareness-based detection via realism and contextual accuracy, urging a shift to adaptive defense; analysis across 4,600+ organizations (Abnormal) confirms tactics cluster precisely by organizational structure — file-sharing impersonation 25.1% in finance/accounting, redirect chains 21.6% in SMEs — reinforcing that AI-driven attacks now target organizational workflow gaps rather than generic users. Vendor product innovation: IRONSCALES released three purpose-built AI agents at RSAC 2026 (Red Teaming, Phishing SOC forensics, Simulation); Cofense Vision 3.2 clusters polymorphic campaigns with minutes-to-deployment response. Deployment maturity validated: Shinhan Financial Group's real-time voice phishing system prevented 800M won customer damage in two weeks. Structural negative signal: Mandiant M-Trends 2026 shows vulnerability exploitation (38%) now exceeds phishing (17%) as initial access vector, indicating phishing defenses have matured enough to force attacker pivot away from email. Practice demonstrates simultaneous technical maturation, expanded multi-channel attack surface, and persistent organizational deployment lag (17% AI defenses vs 82.6% AI-driven attacks).\n- **2026-June:** Detection capability and deployment economics diverge sharply. Verizon 2026 DBIR (22K incidents) confirms phishing in 62% of breaches with AI-assisted attacks doubling in volume; phishing accounts for 44% of AI-assisted initial access. Zscaler telemetry shows phishing volume declined 20% as defenses matured, yet effectiveness surged via personalization—services industry experienced 65.5% attack surge with 413K AI-generated phishing domains. Critical detection limitations emerge: Darktrace analysis reveals 70% of malicious emails bypass DMARC authentication; 1.6M newly created phishing domains evade blocklists; QR code phishing surged 336%. Browser-layer gaps documented: Menlo Security telemetry (millions of sessions) shows 20% miss rate across enterprise detection systems, with 95.2% of phishing delivered over TLS encryption and 115K evasive campaigns detected in parallel. KnowBe4 Threat Lab confirms 86% AI-assisted phishing prevalence with 54% versus 12% CTR advantage; Barracuda red team demonstrates AI-generated phishing escalating to full endpoint compromise in 5 minutes via ClickFix and Evilginx MFA interception. Defense validation: IRONSCALES Themis AI detected a multi-layer legitimate-service-abuse campaign (EdgePilot, Barracuda LinkProtect wrappers) that defeated gateway authentication; Cisco Secure Email Threat Defense earned SE Labs AAA rating with 98% phishing detection including 100% quishing protection and zero false positives; peer-reviewed PhishLumos framework identifies 192K malicious URLs 8 days faster than expert teams from 600 seed URLs. Practice demonstrates mature research capability (F1>0.97) coexisting with widening operational gaps (20%+ miss rates, 70% DMARC bypass, defenders 36% time-constrained), as attacker sophistication and multi-channel fragmentation continue to outpace detection improvements.\n- **2026-Jul:** Peer-reviewed research (hosted by Schneier) confirms AI-automated spear phishing now matches human expert click-through rates (54%) while defensive models (Claude 3.5 Sonnet) reach 97.25% detection with zero false positives, quantifying a roughly 50x attacker profitability increase. Production deployments continue validating behavioral detection at scale — Red Canary's orchestrated AI subagent triage hits 94% accuracy and Forrester TEI documents $4M in prevented losses with 95% SOC-hour reduction across four global organisations — even as adversary-in-the-middle campaigns (Tycoon2FA: 35,000 users across 13,000 organisations) push documented MFA failure rates to 84%.\n- **2026-Aug:** Indicator-based defenses continue eroding structurally: 89% of phishing domains stay active under two days and 95% of kits now evade bot protection, while Cisco Talos data shows phishing as primary attack vector in over half of Q2 incident-response engagements (up from a third in Q1). IBM/Ponemon's Cost of Data Breach study quantifies AI-driven attacks up 56% YoY (adding $1M per breach), and Microsoft telemetry logs 7.6B phishing threats in Q2 with a 92% volume decline after the Tycoon2FA takedown; Barracuda research documents attackers using text-salting (hidden CSS/HTML text) to defeat LLM-based filters, and a PRISMA systematic review of 36 studies confirms LLM-based detection now approaches human-level performance even as generation capability accelerates in parallel. MFA-bypass infrastructure industrializes further: device code phishing surged 1,380% (H2 2025→Q1 2026) via OAuth device-flow abuse defeating passkeys, and the Mirage2FA PaaS platform executes AiTM attacks at scale using compromised Microsoft 365 tenants with HTML smuggling and WebSocket relays; Arctic Wolf disclosed Storm-2755 (Payroll Pirates) targeting hundreds of organizations across sectors despite MFA deployment, while Abnormal AI's behavioral detection caught the same campaign 49 days ahead of public disclosure, and Push Security's briefing documents a broader shift toward multi-channel (vishing, callback phishing) attacks beyond email. Independent testing exposes a production accuracy gap: AI phishing detectors scoring 99.78% in-distribution drop to 77.8% on novel email corpora with 4 false alarms per 10 flags, reinforcing that agentic \"Phishing 3.0\" dynamics (Microsoft 365 missing 293 phishing/100 mailboxes per month, Google Workspace 350) are outpacing vendor detection claims.\n- **2026-Sep:** Attack vector broadens beyond email: Microsoft documents threat actors impersonating IT support via Teams to extract remote-access credentials and pivot into enterprise-wide lateral movement. Abnormal AI extends its production evidence base (Serta Simmons Bedding boosting security-awareness training participation from 10% to 40%; a 2,000-mailbox Japanese Google Workspace deployment blocking ~3,000 additional attacks/month) and ships Control Center, Email DLP Rules, and an upgraded Phishing Coach to general availability. Cisco Talos Q2 2026 IR data shows phishing as the primary initial-access vector in over half of engagements (up from ~33% in Q1) with MFA bypass present in 65% of cases (up from 35%), corroborated by aggregated threat intelligence showing 59% of compromised accounts had MFA enabled and device-code phishing surging 1,380% since H2 2025. Mid-month evidence confirms nation-state operationalization: Anthropic attributes AI-automated device-code phishing against 20+ government/defense organizations to Midnight Blizzard-linked GTG-20006, and Microsoft documents 100K-email/day campaigns impersonating ChatGPT, Claude, and DeepSeek to harvest credentials. Research quantifies AI personalization's edge (each personalization level raises click-intent odds 28% across 1,436 evaluations) while a novel blob-URL evasion technique renders phishing pages entirely client-side to bypass gateway detection. Foundational gaps persist: SANS' 1,700-practitioner survey ranks social engineering the top human risk (77%) with AI-enabled social engineering rising to 2nd-place concern, and Cynet's 304-incident analysis finds 80% of breaches start with phished credentials; DMARC enforcement is improving but uneven (only 50% of NZ government agencies at strict Reject) and education-sector targeting remains acute (58.8M phishing emails against 536 institutions in three months).",
  "historyEntries": [
    {
      "period": "2017",
      "text": "Phishing detection established as mature research discipline with widespread organizational awareness but selective AI-based defense adoption. Major vendor launches (Sentinel, Triage expansion) and documented deployments reducing susceptibility from 28% to under 10%; however, 64% of organizations lacked third-party solutions despite high threat volume and sophistication in campaigns like FreeMilk."
    },
    {
      "period": "2018",
      "text": "Vendor market consolidation and scale-up with Barracuda reaching 50,000+ customers (232% YoY Essentials growth) and Cofense's $400M acquisition by private equity, backing 10M+ workstation deployments. Enterprise validation through Fortune 500 testing showed Barracuda Sentinel outperforming Microsoft ATP by 621 missed attacks in side-by-side trial. Adversarial AI research (DeepPhish) demonstrated evasion capabilities accelerating in parallel with defense (0.69%→20.90% evasion rates), and real-world incidents at security-aware organizations (FS-ISAC phishing spread) revealed persistent human-factor vulnerabilities despite technical maturity."
    },
    {
      "period": "2019",
      "text": "Market consolidation and analyst validation with Cofense and Barracuda earning Gartner and Forrester recognition. USENIX Security 2019 research documented lateral phishing incidents across 92 organizations with 87.3% detection rates; separate Barracuda research showed cloud infrastructure (AWS, Azure) as phishing origin sources with deployed classifiers improving detection 3-5%. Global deployment expansion visible with Cofense entering Japanese market via managed services. Check Point analysis flagged detection gaps in cloud email platforms (Office 365, Gmail), highlighting architectural tensions as enterprises migrated."
    },
    {
      "period": "2020",
      "text": "Threat landscape intensity increased sharply with mobile phishing attacks rising 328% in Q3 while email gateways matured. Research methodologies advanced (NIST Phish Scale standardized training evaluation; comprehensive AI detection survey published). Vendor maturity demonstrated through international expansion and industry awards (Barracuda SC Awards for AI/ML in email security). However, critical vulnerabilities exposed limitations: Proofpoint URLDefense sandbox bypass (770+ character URLs) revealed gaps in production detection tools. Deployment infrastructure challenges persisted with tension between legacy email gateways and cloud-native solutions (Office 365, Gmail) as attack vectors diversified."
    },
    {
      "period": "2021",
      "text": "Market solidification continued with major platform GAs: Microsoft Attack Simulation Training launched integrated into Defender for Office 365; Barracuda released three new Email Protection plans validated by SE Labs as best in class; new entrants like Phished and dPhish provided alternative approaches to simulation and detection. Real-world deployments confirmed practice maturity with manufacturing and enterprise cases showing 30-50% email reduction and strong adoption metrics. However, attack success remained high: Proofpoint data showed 57% of organizations experienced successful phishing in 2020 with 34% paying follow-up ransoms, and CVE-2021-31608 revealed a URL bypass vulnerability in Proofpoint itself. Cross-customer threat intelligence sharing (demonstrated at Black Hat via Cofense) emerged as an emerging mitigation pattern, but detection limitations persisted."
    },
    {
      "period": "2022-H1",
      "text": "Vendor ecosystem expanded with new entrants (NVIDIA Morpheus with 99.68% accuracy) while established players consolidated. Threat volume accelerated: phishing attacks grew 29% globally to 873.9M annually with 400% surge in retail/wholesale. Real-world deployments (ACCO Brands with 6,000 users, Kappa Data) showed continued adoption and marginal improvements in awareness and team efficiency. Research advances: evasion-resistant detection models (Anti-SubtlePhish) achieved 98.8% accuracy but training effectiveness studies revealed fundamental limits—training alone insufficient to prevent user susceptibility, signaling maturity plateau where technical gains face persistent organizational barriers."
    },
    {
      "period": "2022-H2",
      "text": "Proofpoint's Supernova behavioral engine demonstrated large-scale efficacy, blocking 19M BEC/phishing attacks monthly and preventing a $194M theft among select customers. Training improvements measurable: KnowBe4 benchmarking 9.5M users showed phishing click rates dropping from 32.4% baseline to 5% after 12 months training. Research on AI-generated phishing and psychological trait scoring advanced detection techniques. However, critical incident exposed vulnerability: September 2022 Barracuda email security gateway outage caused global email delays, revealing infrastructure reliability concerns despite vendor maturity. Practice showed technical progress alongside operational and human-factor bottlenecks."
    },
    {
      "period": "2023-H1",
      "text": "Cloud-native ML pipelines accelerated deployment speed (Barracuda on Databricks blocking tens of thousands daily); Check Point's Zero Phishing GA claimed 4x zero-day detection. Research identified AI-generated phishing (71% undetected) and novel attacker tactics (11-15% of orgs hit). Analyst validation continued (Forrester Wave, Gartner Market Guide), but emerging threat sophistication—especially adversary-generated content—revealed structural limitations in purely technical defenses. Tension between detection capability advancement and threat evolution remained unresolved."
    },
    {
      "period": "2023-H2",
      "text": "Vendors expanded capabilities (Cofense vishing service, Proofpoint AWS Marketplace integration, Barracuda 950B event analysis across customers) and analyst recognition held. However, AI-driven threat acceleration became undeniable: 1,265% increase in malicious phishing since ChatGPT, 31,000 daily attacks. Detection systems degraded year-over-year: Microsoft Defender missed 25% more phishing, secure email gateways missed 29% more in 2023 vs 2022. IBM study showed ChatGPT-generated emails matched human-crafted campaigns in click effectiveness. 71% of AI-generated attacks evaded production detection. Practice reached inflection point where threat evolution outpaced defense advancement."
    },
    {
      "period": "2024-Q1",
      "text": "Vendor scale continued (Barracuda Sentinel ecosystem integration) and research advanced with IEEE Access study documenting GPT-4 phishing at 30-44% CTR and LLM detection trade-offs. However, production deployment fragility emerged: Proofpoint Attachment Defense outage at major university left emails unscanned; Cofense metrics showed SEGs missing 30-50% of threats with malicious bypasses increasing 100%+ YoY. Offensive AI tooling adoption accelerated (WormGPT, FraudGPT) with deepfakes enabling $25M attacks. Practice demonstrated sustained technical advancement masked by widening detection gaps in production systems—commodity AI tools now accessible to attackers, detection evasion techniques outpacing traditional ML defense models."
    },
    {
      "period": "2024-Q2",
      "text": "Vendor innovation accelerated with Proofpoint GA of LLM-based pre-delivery detection (NexusAI) and Adaptive Email Security platform updates; Barracuda continued ML pipeline scaling blocking tens of thousands daily. Threat landscape intensified: Zscaler documented 60% YoY increase in AI-driven attacks across 2B blocked transactions; BEC attacks grew to 10.6% of social engineering vectors with 70% surge in conversation hijacking. Research showed detection capability maturity (NTT ChatSpamDetector 99.70% accuracy) alongside robustness limitations (451k site evaluation revealed >93% false positive rate in visual detection). Practitioner overconfidence emerged: 96% of security professionals perceive GenAI threat yet 73% overestimate their deepfake detection ability, exposing perception-reality gap in organizational defenses."
    },
    {
      "period": "2024-Q3",
      "text": "ML research matured (274K-URL study: 97.52% accuracy; LLM-human framework: 80%+ effectiveness) while deployment dynamics shifted: Fortune 1000 manufacturer replaced Proofpoint with Abnormal AI citing 10x better detection and $876k savings, signaling vendor-neutral migration patterns. Threat acceleration continued: 40% of BEC attacks AI-generated; Microsoft 365 native security showed 47% phishing miss rate (70% for BEC), exposing platform dependency risks. Organizational investment surged: 75% of CISOs identified phishing as greatest AI-powered threat with 70% increasing budgets, yet 58% cited lack of expertise. Practice reached mature plateau where technical sophistication (detection accuracy near 97-99%) coexisted with widening real-world deployment gaps driven by mainstream platform limitations and accelerating attacker AI adoption."
    },
    {
      "period": "2024-Q4",
      "text": "LLM-based phishing research matured with frameworks improving detection robustness (PEEK raising training samples from 21.4% to 84.8%, boosting accuracy to 88%+) and adversarial approaches (PEN reducing attack success by 70%); human-subject studies validated AI-automated spear phishing at 54% CTR matching human experts, with AI detection exceeding 90% accuracy. Real-world deployments revealed critical gaps: Fortune 500 insurer detected 6,454 Proofpoint-missed attacks in three months, signaling that vendor market leadership masks persistent detection failures. Attacker adoption accelerated with 500K+ quishing campaigns in three months and LLM-generated emails becoming production threat; open-source detection reached 95-96% accuracy, democratizing defenses. Practice remained at inflection point: technical capability plateaued near theoretical maximums while threat sophistication and deployment fragility continued diverging, with attacker AI and evasion tactics outpacing vendor mitigation in mainstream platforms."
    },
    {
      "period": "2025-Q1",
      "text": "Vendor platform maturity deepened with Proofpoint Core Email Protection GA (99.99% threat block rate), Barracuda ML pipeline enhancements, and academic research advancing detection to 96.8% accuracy with reduced false positives. Channel expansion accelerated through Proofpoint-ConnectWise MSP integration enabling SMB deployment at scale. Threat landscape showed mixed signals: KnowBe4 reported 82.6% of phishing emails using AI with 76.4% polymorphic tactics and 17.3% volume increase; UC Berkeley warned of hyper-targeted AI-powered phishing becoming mainstream. Critical counter-signal emerged: Hoxhunt analysis from 2.5M users across 131+ countries found only 0.7-4.7% of phishing emails actually AI-generated, revealing hype-reality gap while human-crafted phishing remained dominant vector. Practice showed simultaneous technical advancement and threat acceleration with persistent deployment fragility in mainstream cloud platforms."
    },
    {
      "period": "2025-Q2",
      "text": "Attacker AI adoption accelerated with 51% of spam and 14% of BEC emails AI-generated by mid-year; threat volume surged with 70% YoY BEC increase and one malicious email every 42 seconds tracked by Cofense. Vendor platform capabilities matured: Barracuda launched multimodal AI sandbox with 3x detection power and 8x speed; Proofpoint and Cofense reported strong threat block metrics. However, real-world detection gaps persisted: global aerospace manufacturer deploying Abnormal alongside Proofpoint detected 3,232 missed attacks over three months ($5.8M exposure). Analyst perspectives highlighted fundamental tensions—AI-powered defenses advancing in capability, but plagued by false positives, privacy concerns, and organizational skill gaps limiting effective deployment. Practice showed highest evidence of simultaneous vendor capability advancement and attacker AI adoption with persistent deployment fragility and cost impact on real organizations."
    },
    {
      "period": "2025-Q3",
      "text": "Research consensus solidified with peer-reviewed systematic review confirming >99% accuracy for DL/Gen AI models (CNN, LSTM, TCN); controlled study (N=480) validated AI-generated training for user resilience without complex personalization. Market maturity accelerated: global phishing simulator market reached $113B with 7.2% CAGR; Proofpoint Prime deployments showed 237% ROI over three years. Vendor innovation continued with Barracuda multimodal AI analyzing text, images, URLs, and QR codes. However, deployment barriers persisted: practitioner feedback highlighted high costs, complex interfaces, and localization gaps in market-leading solutions, exposing organizational friction masking adoption metrics. Practice demonstrated maturity with technical capability and market validation coexisting alongside real deployment constraints limiting broader impact."
    },
    {
      "period": "2025-Q4",
      "text": "Research field maturity confirmed via peer-reviewed bibliometric analysis of 1,096+ documents showing decisive shift from ML to deep learning; attacker AI adoption (82.6% of phishing) and training effectiveness remained contested (54% CTR for AI phishing vs vendor claims of 86% ROI). Critical infrastructure vulnerability exposed: Proofpoint misconfiguration exploit enabled 3-14M spoofed emails daily. Healthcare sector phishing-triggered ransomware reached $10M+ recovery costs per incident. Ongoing enterprise adoption (Chicago Blackhawks) indicated continued platform deployment in vertical markets. Practice reached mature technical plateau (>99% accuracy in controlled research) coexisting with widening production deployment gaps, attacker AI acceleration, and quantified cost impact, signaling that technical sophistication and market size mask persistent organizational and operational vulnerabilities limiting real-world effectiveness."
    },
    {
      "period": "2026-Jan",
      "text": "Threat acceleration continued with 400% surge in successful AI-powered phishing scams in 2025. Barracuda threat research showed phishing kits doubled with 90% of high-volume campaigns using phishing-as-a-service, 48% incorporating MFA bypass and URL obfuscation tactics. Real-world deployments remained strong (Benchmark Electronics prevented 90% of incidents, Scalar achieved on-time email delivery), signaling continued platform adoption despite threat sophistication. Critical negative signal: Proofpoint service interruption on January 22 exposed reliability gaps in Microsoft 365 integration. Practitioner analysis predicted 90%+ of credential attacks will use sophisticated kits by end of 2026, with MFA no longer fail-safe. Practice sustained mature technical plateau coexisting with accelerating threat sophistication, organizational demand for advanced detection, and persistent platform reliability concerns limiting effectiveness in production environments."
    },
    {
      "period": "2026-Feb",
      "text": "Research validation of dual-use AI published (LLM-automated phishing 54% CTR vs human experts, AI detection 97.25% accuracy with zero false positives), confirming technical parity but highlighting organizational deployment bottlenecks. Threat acceleration continued sharply: Cofense reported AI-powered phishing doubled pace to one attack every 19 seconds, with polymorphic attacks (76% unique URLs) and conversational attacks (18% of malicious emails) becoming standard; cross-industry analysis showed phishing 83% of email threats with 80% AI-powered, collaboration attacks surging 12%→31% YoY. Vendor ecosystem expansion: Proofpoint integrated AWS Security Hub Extended (Nexus AI stack); NTT DATA deployed Proofpoint protecting 6.5M emails daily. Practice revealed structural gap: research-validated defensive capability (97%+ accuracy) exceeded organizational deployment speed and cost constraints in production, with traditional gateway defenses and pattern-matching filters remaining ineffective against polymorphic, AI-generated attacks. Maturity plateau confirmed with synchronized threat acceleration and growing real-world ineffectiveness in mainstream deployments."
    },
    {
      "period": "2026-Mar/Apr",
      "text": "Threat landscape documenting phishing-as-a-service ecosystem at scale: Microsoft Threat Intelligence exposed Tycoon2FA reaching 500K+ organizations monthly with MFA bypass, token interception, evasion infrastructure, and coordinated global takedown with Europol; Tycoon2FA accounts for 59% of adversary-in-the-middle phishing, with fake CAPTCHA attacks up 563% in 2025. Real-world attack analysis showed malicious actors appending benign content (157 average line breaks) to bypass NLP detection—evidence of attackers actively targeting and defeating AI defenses. CISA reported a 300% YoY increase in AI-powered phishing with 200+ organizations compromised in 30 days; Kaseya 2026 data shows 83% of phishing emails contain AI-generated content; Netcraft disrupted 1.3M phishing websites in 12 months while documenting a 37% increase in attacks. Microsoft Defender Security Research documented large-scale AI-enabled device code phishing (EvilToken PhaaS toolkit) with dynamic code generation and AI-personalized lures, representing escalation beyond password theft to auth token abuse. Hornetsecurity survey of 500 UK leaders found 57% cite AI phishing as primary worry with 50% uncertain they can defend against AI-powered attacks. Comprehensive threat statistics confirm: AI phishing achieves 54% click rates versus 12% for traditional phishing; phishing simulation market projected to reach $224B by 2034. Human-factor research confirmed critical constraint: UC San Diego Health study found annual training shows 1-2% improvement vs 10-30% real click rates; 75% complete training in <1 minute. Vendor platform maturity: Proofpoint announced agentic workspace security with unified SEG/API architecture and AI governance, with Nexus AI ensemble analyzing 3.4B emails deployed at 85 Fortune 100 companies. However, post-detection gap identified: MDR analysis revealed structural fragmentation across email/identity/endpoint/cloud layers allowing 29-minute average eCrime breakout. Practice sustained mature technical equilibrium (detection 97%+, platforms GA at scale, analyst validation) coexisting with widened real-world deployment gaps, accelerated attacker adoption of phishing-as-a-service, and documented human-factor limitations in operational resilience."
    },
    {
      "period": "2026-May",
      "text": "Threat acceleration reaches new measurable peaks with broadened operational evidence. KnowBe4 six-month analysis confirms 86% of attacks AI-driven with 7x efficiency over manual campaigns and documents multi-channel fragmentation: calendar phishing +49%, Teams attacks +41%, reverse proxy credential attacks +139%. Barracuda 2026 Email Threats Report (3.1B emails analyzed) shows 1 in 3 emails malicious, 48% phishing, 34% of organizations experiencing monthly account takeover, 90% of campaigns using phishing-as-a-service kits. UK government survey (612K+ organizations) confirms 38% phishing prevalence with 85% of breached orgs involving phishing in incident chain. Microsoft Defender Q1 2026 telemetry: 8.3B phishing blocked but QR phishing (+146%), CAPTCHA attacks (+125%), and HTML-in-attachment delivery (+175%) reveal detection gaps widening as attackers move evasion inside email. Aggregated statistics (89 verified datapoints across IBM, CrowdStrike, Microsoft, Mandiant) quantify the AI-driven acceleration: 54% CTR for AI phishing versus 12% human baseline, 47.3% bypass rate against leading filters, initial-access time collapsed from 8+ hours to 22 seconds. CERT-In formally documented AI-powered phishing bypassing traditional awareness-based detection via realism and contextual accuracy, urging a shift to adaptive defense; analysis across 4,600+ organizations (Abnormal) confirms tactics cluster precisely by organizational structure — file-sharing impersonation 25.1% in finance/accounting, redirect chains 21.6% in SMEs — reinforcing that AI-driven attacks now target organizational workflow gaps rather than generic users. Vendor product innovation: IRONSCALES released three purpose-built AI agents at RSAC 2026 (Red Teaming, Phishing SOC forensics, Simulation); Cofense Vision 3.2 clusters polymorphic campaigns with minutes-to-deployment response. Deployment maturity validated: Shinhan Financial Group's real-time voice phishing system prevented 800M won customer damage in two weeks. Structural negative signal: Mandiant M-Trends 2026 shows vulnerability exploitation (38%) now exceeds phishing (17%) as initial access vector, indicating phishing defenses have matured enough to force attacker pivot away from email. Practice demonstrates simultaneous technical maturation, expanded multi-channel attack surface, and persistent organizational deployment lag (17% AI defenses vs 82.6% AI-driven attacks)."
    },
    {
      "period": "2026-June",
      "text": "Detection capability and deployment economics diverge sharply. Verizon 2026 DBIR (22K incidents) confirms phishing in 62% of breaches with AI-assisted attacks doubling in volume; phishing accounts for 44% of AI-assisted initial access. Zscaler telemetry shows phishing volume declined 20% as defenses matured, yet effectiveness surged via personalization—services industry experienced 65.5% attack surge with 413K AI-generated phishing domains. Critical detection limitations emerge: Darktrace analysis reveals 70% of malicious emails bypass DMARC authentication; 1.6M newly created phishing domains evade blocklists; QR code phishing surged 336%. Browser-layer gaps documented: Menlo Security telemetry (millions of sessions) shows 20% miss rate across enterprise detection systems, with 95.2% of phishing delivered over TLS encryption and 115K evasive campaigns detected in parallel. KnowBe4 Threat Lab confirms 86% AI-assisted phishing prevalence with 54% versus 12% CTR advantage; Barracuda red team demonstrates AI-generated phishing escalating to full endpoint compromise in 5 minutes via ClickFix and Evilginx MFA interception. Defense validation: IRONSCALES Themis AI detected a multi-layer legitimate-service-abuse campaign (EdgePilot, Barracuda LinkProtect wrappers) that defeated gateway authentication; Cisco Secure Email Threat Defense earned SE Labs AAA rating with 98% phishing detection including 100% quishing protection and zero false positives; peer-reviewed PhishLumos framework identifies 192K malicious URLs 8 days faster than expert teams from 600 seed URLs. Practice demonstrates mature research capability (F1>0.97) coexisting with widening operational gaps (20%+ miss rates, 70% DMARC bypass, defenders 36% time-constrained), as attacker sophistication and multi-channel fragmentation continue to outpace detection improvements."
    },
    {
      "period": "2026-Jul",
      "text": "Peer-reviewed research (hosted by Schneier) confirms AI-automated spear phishing now matches human expert click-through rates (54%) while defensive models (Claude 3.5 Sonnet) reach 97.25% detection with zero false positives, quantifying a roughly 50x attacker profitability increase. Production deployments continue validating behavioral detection at scale — Red Canary's orchestrated AI subagent triage hits 94% accuracy and Forrester TEI documents $4M in prevented losses with 95% SOC-hour reduction across four global organisations — even as adversary-in-the-middle campaigns (Tycoon2FA: 35,000 users across 13,000 organisations) push documented MFA failure rates to 84%."
    },
    {
      "period": "2026-Aug",
      "text": "Indicator-based defenses continue eroding structurally: 89% of phishing domains stay active under two days and 95% of kits now evade bot protection, while Cisco Talos data shows phishing as primary attack vector in over half of Q2 incident-response engagements (up from a third in Q1). IBM/Ponemon's Cost of Data Breach study quantifies AI-driven attacks up 56% YoY (adding $1M per breach), and Microsoft telemetry logs 7.6B phishing threats in Q2 with a 92% volume decline after the Tycoon2FA takedown; Barracuda research documents attackers using text-salting (hidden CSS/HTML text) to defeat LLM-based filters, and a PRISMA systematic review of 36 studies confirms LLM-based detection now approaches human-level performance even as generation capability accelerates in parallel. MFA-bypass infrastructure industrializes further: device code phishing surged 1,380% (H2 2025→Q1 2026) via OAuth device-flow abuse defeating passkeys, and the Mirage2FA PaaS platform executes AiTM attacks at scale using compromised Microsoft 365 tenants with HTML smuggling and WebSocket relays; Arctic Wolf disclosed Storm-2755 (Payroll Pirates) targeting hundreds of organizations across sectors despite MFA deployment, while Abnormal AI's behavioral detection caught the same campaign 49 days ahead of public disclosure, and Push Security's briefing documents a broader shift toward multi-channel (vishing, callback phishing) attacks beyond email. Independent testing exposes a production accuracy gap: AI phishing detectors scoring 99.78% in-distribution drop to 77.8% on novel email corpora with 4 false alarms per 10 flags, reinforcing that agentic \"Phishing 3.0\" dynamics (Microsoft 365 missing 293 phishing/100 mailboxes per month, Google Workspace 350) are outpacing vendor detection claims."
    },
    {
      "period": "2026-Sep",
      "text": "Attack vector broadens beyond email: Microsoft documents threat actors impersonating IT support via Teams to extract remote-access credentials and pivot into enterprise-wide lateral movement. Abnormal AI extends its production evidence base (Serta Simmons Bedding boosting security-awareness training participation from 10% to 40%; a 2,000-mailbox Japanese Google Workspace deployment blocking ~3,000 additional attacks/month) and ships Control Center, Email DLP Rules, and an upgraded Phishing Coach to general availability. Cisco Talos Q2 2026 IR data shows phishing as the primary initial-access vector in over half of engagements (up from ~33% in Q1) with MFA bypass present in 65% of cases (up from 35%), corroborated by aggregated threat intelligence showing 59% of compromised accounts had MFA enabled and device-code phishing surging 1,380% since H2 2025. Mid-month evidence confirms nation-state operationalization: Anthropic attributes AI-automated device-code phishing against 20+ government/defense organizations to Midnight Blizzard-linked GTG-20006, and Microsoft documents 100K-email/day campaigns impersonating ChatGPT, Claude, and DeepSeek to harvest credentials. Research quantifies AI personalization's edge (each personalization level raises click-intent odds 28% across 1,436 evaluations) while a novel blob-URL evasion technique renders phishing pages entirely client-side to bypass gateway detection. Foundational gaps persist: SANS' 1,700-practitioner survey ranks social engineering the top human risk (77%) with AI-enabled social engineering rising to 2nd-place concern, and Cynet's 304-incident analysis finds 80% of breaches start with phished credentials; DMARC enforcement is improving but uneven (only 50% of NZ government agencies at strict Reject) and education-sector targeting remains acute (58.8M phishing emails against 536 institutions in three months)."
    }
  ],
  "historyFallback": false,
  "lastUpdated": "2026-09-18",
  "domain": {
    "id": "it-operations-security",
    "label": "IT Operations & Security",
    "icon": "🛡️"
  },
  "url": "https://www.thestateofplay.ai/practice/phishing-detection-and-prevention",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "generatedAt": "2026-10-01"
}