Skip to content
← BlogDeliverabilityAnalysis5 min read

AI phishing jumped 14x in a month. Volume-based filtering can't keep up with that

Hoxhunt's 2026 data shows AI phishing going from 4% to 56% of reported attacks in a month, then settling near 40%. What breaks when growth outruns detection.

By Norbelys Chirinos, Co-founder

Founder-reviewed ·How we research and correct articles

Growth curves in security research are usually described in percentages. Hoxhunt’s 2026 Phishing Trends data — drawn from 4 million users’ interactions with 50 million real and simulated phishing attempts — needed a different unit. AI-assisted phishing went from 4% of all reported attacks in November 2025 to 56% in December: a 14x jump in a single month. It has since settled to roughly 40%, meaning four in every ten phishing attempts a Hoxhunt customer reports today involved AI-generated content in some form.

Tech Times’ coverage of the finding ties the surge to the same toolkit showing up across smishing, QR-code fraud, and voice cloning — different delivery channels, same underlying shift: generative tooling collapsed the cost of producing a convincing lure to close to zero, and attackers scaled output accordingly, particularly around the holiday period when inboxes are naturally noisier and defenses are thinner-staffed.

Why “jumped 14x” is a more useful number than “grew 40%”

A steady climb from 4% to 40% over a year would be a normal trend line, the kind filtering systems adjust to gradually as detection models retrain on new samples. Compressing that into roughly four weeks is a different kind of problem. Spam and phishing filtering has always leaned on pattern recognition trained on recent history — what did malicious mail look like last month. A threat that reshapes itself 14x faster than the baseline assumption breaks the premise that “recent history” is a stable enough foundation to detect on, at least during the window before models catch up.

What actually still catches this

None of that means detection is helpless against the surge — it means the parts of detection that were already the most durable are now carrying more of the weight, because the parts tuned to content patterns are chasing a moving target. Three categories hold up regardless of how fast the lure text itself evolves:

  • Authentication. SPF, DKIM, and DMARC alignment don’t care how convincing the copy is or how many variants of it exist — they check whether the sending infrastructure is who it claims to be. This is the one layer that a 14x content surge does nothing to weaken, which is exactly why ENISA and other threat-landscape reporting point back to authentication as the signal that survives content-based detection eroding.
  • Sender reputation and history. A domain or IP’s track record accumulates over time in a way attackers can’t shortcut by generating more text faster. It’s the same reason warming up a new sending domain takes weeks regardless of how good the copy is — reputation is earned on a clock content can’t speed up.
  • Behavioral signals. Complaint rate, reply patterns, and engagement reflect how real recipients respond to a message over time. A high-volume AI-generated blast still produces the same tell a low-effort human blast always did — more people reporting it as spam — because that signal is downstream of relevance, not authorship speed.

Why the holiday timing wasn’t a coincidence

The jump from 4% to 56% happened in December, and that timing lines up with more than just gift-buying season. Security teams are thinner-staffed around the holidays, inbox volume from legitimate retail and shipping mail is already elevated (making a malicious message easier to blend in), and attackers know both of those things as well as defenders do. A 14x surge concentrated in exactly the month when detection teams are least able to retrain models or tune rules quickly isn’t a random spike — it’s the same logic that drives a rise in smishing around tax season or QR fraud around large public events: attackers time volume to windows where the baseline “recent history” a filter learns from is least representative of what’s about to hit it.

That has a direct implication for anyone running outbound on a fixed calendar too. A sending pattern that looks normal in October can look anomalous in December simply because everyone’s baseline shifted — which is one more reason sudden volume changes deserve the same scrutiny a provider gives them, regardless of whether the surge is malicious or a planned campaign push.

What this means for anyone running legitimate outbound

The uncomfortable overlap is that a legitimate sender using AI to draft and scale outreach looks, from a pure velocity standpoint, a little like what’s driving this surge — content produced fast, at volume, from a small operating team. Microsoft’s telemetry suggests AI-generated phishing converts roughly 4.5x better per message than manually written attempts, which is exactly the gap a legitimate sender doing real personalization is also trying to close — the difference is what happens after delivery. A message a recipient wanted gets replies, not complaints; a mass-produced lure gets reported.

The practical takeaway isn’t to slow down AI-assisted drafting — it’s to make sure the infrastructure underneath it is doing more of the trust-signaling that content used to carry. That means authentication configured correctly before volume ramps, a domain with real sending history behind any surge in output, and reading DMARC reports regularly enough to catch drift before a provider does. A detection system racing to catch a 14x-faster-moving target is going to lean harder on the signals that don’t move at all — and those are the same signals that determine whether a legitimate campaign lands in the inbox.

Norbelys builds those specific signals in as defaults rather than optional configuration: every new sender goes through a warmup ramp before real volume flows, so a legitimate campaign never produces the sudden-burst pattern this surge exploits, and Norbelys’s own DMARC monitoring surfaces an alignment break on your domain automatically instead of waiting for you to go pull a report by hand. A 14x swing in what phishing content looks like this month doesn’t touch either of those — authentication and sending history were never reading the words in the first place, which is exactly why Norbelys treats them as the load-bearing layer instead of the content.