Security Leaders Cite AI-Driven Phishing Attacks as a Top Concern

KnowBe4 Team | Oct 6, 2025

iStock-621818158A new report has found that nearly 40% of security leaders believe their organizations are least prepared for phishing and other social engineering attacks, Help Net Security reports.

According to the report from VikingCloud, these concerns are driven by the increasing use of AI tools to assist in cyberattacks.

“Generative or agentic AI-driven phishing attacks (51%) are leadership teams’ top concern when it comes to new cyberattack techniques,” the report says. “Last year, only 22% of respondents said that their leadership teams were concerned about generative AI phishing attacks.

“This suggests that more leadership teams recognize the perils of AI-driven attack methods, especially as agentic AI becomes more ubiquitous and makes bad actors even more dangerous, efficient, and relentless than generative AI alone. Generative AI model prompt hacking (45%) and AI-vishing (voice deepfake) attacks (43%) are the other two most concerning modern threats.”

The report adds, “Cybersecurity leaders say their top 3 challenges are that (1) AI is creating new attack points (53%), (2) the tech behind cyberattacks is more sophisticated than the tech their teams have access to (36%), and (3) modern cybercriminals are more advanced than their internal teams (36%).”

In addition to lowering the bar for unskilled threat actors, nation-state hackers are also using AI to assist in their attacks.

“These hackers typically focus on long-term access, IP theft, and espionage, and they typically infiltrate by exploiting third-party software vulnerabilities,” the report says. “Many are leveraging AI to scale their attacks. Most businesses’ standard security practices and tools aren’t built to detect or defend against these advanced threats.”

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 HRM+ platform to strengthen their security culture and reduce human risk.

Help Net Security has the story


Live Demo: Supercharge Your Anti-Phishing Defense with PhishER Plus

Email alone is the highest cause of data breaches and 56% of all attacks bypass your legacy security filters! The upshot? Legacy email security layers let these digital time bombs slip into the inboxes of your users. Introducing PhishER Plus - the most powerful anti-phishing protection available in the world.

PhishER-Plus

To learn how we can make such a claim, get a product demonstration of the new PhishER add-on, PhishER Plus. In this live one-on-one demo we will show you how you can:

  • Block email threats that have bypassed all other email security filters or systems before they reach your users’ mailboxes with the Global Blocklist
  • Isolate malicious emails that already bypassed your mail filters through automated quarantine with Global PhishRIP
  • Crowdsource threat intelligence from 10+ million KnowBe4 trained users
  • Save time and budget by reducing the volume of remediation efforts handled by your SOC Team
  • Leverage the power of triple-validated threat intelligence to protect your organization from new attacks

Request A Demo

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/products/phisher-plus-request-a-demo



Subscribe to Our Blog


Gartner Magic Quadrant




Get the latest insights, trends and security news. Subscribe to CyberheistNews.