By Patricia A. Pramono • Studio 1080, Published on July 22, 2025
TABLE OF CONTENTS
Imagine getting an email from your work, asking you to review an urgent contract. The logo looks real, the tone feels familiar, and the link takes you to a login page that looks just like your company’s system. Then you click on the link.
That one click? It could cost your company millions.
This is what phishing does. Nowadays, the scams are cleaner, smarter, and crafted with tools like AI, deepfakes, and even fake QR codes. The messages don’t necessarily feature obvious typos anymore like they used to.
Phishing isn’t a new threat, but it’s evolving fast. In the past six months alone, phishing emails have gone up by over 17%, and more than 82% of them are now powered by Artificial Intelligence (KnowBe4, 2025). This certainly marks a shift for cyber threats. The lines between what’s real and what’s fake are getting blurrier, especially as attacks move from traditional emails to AI videos, QR codes, fake LinkedIn job offers, and even hijacked SMS support messages.
Phishing today doesn’t just steal data. It steals trust. And in some cases, it opens the door to something worse like ransomware, account takeovers, or massive supply chain breaches.
So what does modern-day phishing actually look like? Who’s being targeted, how are attackers doing it, and more importantly, what can we do about it?
Let’s break it down.
Understanding Phishing
Modern phishing has become a shape-shifter, evolving beyond the classic email scam. It’s now a full-blown ecosystem of deception, powered by AI, and more tailored or relatable tactics.
Phishing is, at its core, the act of tricking people into giving away sensitive information like passwords, credit card numbers, ID details, etc. But today’s phishing scams are more personalized, more believable, and more dangerous than ever before.
The Different Types of Phishing
To protect yourself and your business, it's crucial to understand the various phishing techniques currently in use. Below is a breakdown of the most common and emerging types of phishing attack:
1. Email Phishing
The classic and still the most widespread. Attackers impersonate legitimate institutions via email to trick recipients into clicking malicious links or downloading harmful attachments. These messages often use alarming language to create a false sense of urgency.
Example: An email from a “bank” requesting that you verify your account details immediately to avoid service suspension.
According to the 2025 KnowBe4 Phishing Trends Report, 54.9% of phishing emails contained a hyperlink payload, and 25.9% carried dangerous attachments.
2. Spear Phishing
Highly targeted phishing aimed at specific individuals or companies. Attackers often research their victims on platforms like LinkedIn to personalize the message, making it seem legitimate. In 2025, spear phishing attacks are often backed by AI-powered research, where attackers gather personal and professional details from public sources or data breaches to tailor hyper-specific scams.
Example: A new employee receives a personalized email that appears to be from their direct manager, referencing a recent onboarding task and requesting immediate access to internal files or login credentials.
Nearly all polymorphic phishing campaigns (those that change slightly in each instance to avoid detection) now rely on AI to personalize messages at scale. These kinds of messages are not only more convincing but also significantly harder for filters and humans to catch (Phishing Threat Trends report, KnowBe4, 2025).
3. Whaling
Whaling focuses on senior executives and high-profile decision-makers, often using customized content to initiate scams, such as financial transfers or data disclosures.
Example: A fake voicemail from a CEO authorizing the release of sensitive internal documents.
Whaling attacks increasingly leverage AI-generated video and voice deepfakes, making them very convincing.
4. Smishing and Vishing
Phishing via SMS (smishing) or voice calls (vishing). These methods exploit urgency and impersonation tactics, often spoofing legitimate numbers.
Example (Smishing): “Your delivery has been delayed due to unpaid customs. Click here to resolve.”
Example (Vishing): “This is your bank. We've detected suspicious activity. Please confirm your card number to proceed.”
Also read: Beware of Tax Scams: Recognize and Avoid New DJP Spoofing Schemes
5. Quishing (QR Code Phishing)
One of the fastest-growing phishing techniques is the QR code scams. Attackers place malicious QR codes in public places or digital communications, which lead users to fake login pages or malware downloads when scanned.
Example: A QR code on a stall that redirects to a fake payment portal that captures your card details.
26% of all scam links in 2025 were delivered through QR codes, with the energy, manufacturing, and finance sectors being especially vulnerable (Keepnet, 2025).
Also read: Quishing: How QR Code Phishing Attacks Your Business at Every Turn
6. Clone Phishing
A technique where attackers copy a legitimate email you’ve previously received and resend it with a malicious link or attachment.
Example: A duplicate of a real invoice from a vendor, except the new link leads to a malware installer instead of a secure payment page.
Because it appears nearly identical to a legitimate message, clone phishing is easy to successfully capture the victim easily.
7. Deepfake Phishing
Attackers use AI to mimic the voice or video appearance of executives, colleagues, or even public figures, to manipulate victims into taking action.
Example: A synthetic video call that appears to show your boss or family asking you to authorize a payment or share sensitive data.
Deepfake phishing is on the rise in remote-work environments where video communication is routine and face-to-face verification is rare.
Also read:From Fiction to Reality: How Deepfakes Are Changing Our World
8.Social Media Phishing
Scammers use platforms like LinkedIn, Facebook, or Instagram to impersonate people or brands, often posing as recruiters or customer service reps.
Example: A fake HR account messages you with a job offer, linking to a form that collects your personal information.
This tactic was heavily used in Operation Dream Job by the Lazarus Group, targeting IT professionals with fake job postings and interviews.
Also read: Phishing for Billions: Operation Dream Job
9.Fake BTS (Base Transceiver Station) Attacks
An advanced tactic where attackers hijack mobile towers to intercept calls and SMS coming from official organizations, sometimes used to bypass SMS-based two-factor authentication (2FA).
Example: You receive an SMS from your "mobile provider" asking to verify your billing information. In reality, it's coming from a fake BTS device placed nearby.
This technique is harder to detect and has become more prevalent in areas with poor network regulation.
Also read: Fake Base Transceiver Station (BTS) Scams Are Targeting Your Phone
10.Phishing PDFs and APK Files
Malicious files disguised as invoices, invitations, delivery updates, internal documents, etc. These files may contain embedded malware or redirect you to a phishing site.
Example: A WhatsApp message sends you a package delivery tracking file labeled which is actually an APK file that, once opened, installs spyware on your device.
Files ending in unusual formats or capitalizations (such as .PDF or .Pdf instead of .pdf) are often used to trick users into trusting them.
Phishing Is Getting Harder to Detect
Phishing is aggressively on the rise . According to the Phishing Threat Trends Report (KnowBe4, 2025), there has been a:
- 17.3% increase in phishing emails compared to the previous six months
- 82.6% of phishing emails now use AI, making them more realistic and harder to detect.
- 54.9% contained malicious hyperlinks, and 25.9% had attachments that contained dangerous malware
- The most common bait words being: “Urgent”, “Review”, “Sign”
AI is playing a huge role in making phishing not just more scalable, but also more evasive. “Phishing emails are now almost indistinguishable from legitimate ones and attackers use AI to test and perfect them in real-time.” (PCWorld, 2025)
- Industries most affected: Finance, Energy, Healthcare, Education, E-commerce, and Professional Services (KnowBe4, 2025)
- Quishing specifically targets: Energy (29% of attacks), followed by Manufacturing, Insurance, and Retail (Keepnet, 2025)
- New employees typically receive their first phishing attempt within 3 weeks of starting a job (KnowBe4, 2025)
- Executives are 42x more likely to be targeted by QR code phishing than average employees (Keepnet, 2025)
Social engineering remains the secret weapon of phishing. These attacks work not because of technical trickery, but because they exploit human behavior.
- Many scams start with a bait email, a harmless-looking message just to confirm your email is active
- Emotional manipulation is common. Scammers strike during life events (e.g., job changes, bereavement) when we’re most vulnerable (Dipayan Ghosh, 2025)
Also read: Stay Safe: An Employee’s Guide to Avoiding Phishing Attacks
How to Stay Safe (for Individuals)
Now that you’ve seen how phishing tactics are powered by AI and disguised as everyday communication, protecting yourself starts with mindset and awareness. You don’t need to be a cybersecurity expert to stay safe, but you do need to think critically because your habits are your first line of defense.
1. Always verify before you click
Links in emails, DMs, or even QR codes on posters and packages might seem harmless, but they’re increasingly used as phishing access. If something feels even slightly off (such as a misspelled domain, a document format like “.PDF” instead of ".pdf", or an attachment you weren’t expecting), it’s worth double-checking. This is especially important on mobile, where previewing links or spotting red flags can be more difficult.
2. Avoid oversharing online
The more personal information you post on social media (like your job title, travel plans, or recent life events), the easier it becomes for attackers to design believable scams tailored just for you. Many phishing campaigns start with a little bit of stalking on your social media. It is now one of the most common research tools for social engineering.
Also read: Why Oversharing Online Is Dangerous
3. Enable two-factor authentication (2FA)
Activate 2FA on your accounts wherever possible, but be mindful that SMS-based 2FA can also be intercepted (with fake BTS scam). If available, opt for multi-factor authentication (MFA) like app-based authenticators or physical security keys. These add an important layer of protection, even if your password is compromised.
Also read: Protect Your Accounts with 2FA – It's Easier Than You Think!
4. Stay informed
Learn how phishing works, follow trusted cybersecurity sources, and familiarize yourself with how scammers operate. The more you know, the quicker you’ll spot something suspicious and potentially stop an attack before it begins.
Also read: 5 Simple Steps to Enhance Your Online Privacy
5. If you’ve already fallen victim to a scam, know that you’re not alone. What matters most is how quickly you act afterward (in the first 24 hours).
Also read: What To Do After a Scam: 7 Steps for the First 24 Hours
How to Stay Safe (for Companies)
Phishing is no longer just a personal risk—it’s a critical business threat. And in 2025, the danger increasingly lies within the supply chain. Attackers are bypassing traditional defenses by exploiting trusted vendors, third-party access, and human behavior inside organizations. Here's how companies can protect themselves:
1. Vendor Due Diligence
Phishing emails don’t always come directly from hackers, many originate from compromised third-party vendors. 11.4% of phishing threats are delivered via supply chain partners (KnowBe4, 2025). That means your security is only as strong as the weakest link in your vendor ecosystem. Conduct regular assessments of your vendors’ cybersecurity practices, require minimum security standards, and ensure all external access is controlled and monitored.
Also read: How Supply-Chain Cyber Attacks Can Take Down Your Business ; Why Vendor Due Diligence is Important
2. Employee Training
A single careless click can trigger a breach that costs millions in damages and lost trust. But there’s good news: phishing error rates can drop by up to 85% within one year when employees go through consistent, simulated phishing training (KnowBe4, 2025). Regularly exposing staff to real-world scenarios helps build long-term habits and strengthens their ability to spot red flags.
3. Invest in Post-Delivery Email Security
Traditional Secure Email Gateways (SEGs) are no longer enough to stop phishing in its most dangerous form that is highly targeted, socially engineered, and AI-personalized messages. Post-delivery solutions (such as AI-powered email anomaly detectors) can analyze behavior patterns, flag suspicious content, and catch threats after they’ve landed in inboxes. These tools can also detect insider threats and compromised accounts operating within your network.
4. Incident Response Readiness
Even with the best tools and training, no system is 100% immune. That’s why response matters just as much as prevention. Having a CSIRT (Computer Security Incident Response Team) and a SOC (Security Operations Center) in place ensures your organization can react quickly and effectively when a phishing attack gets through. While the SOC provides 24/7 monitoring, detection, and alerting of suspicious activities, the CSIRT steps in to analyze the incident, contain it, and coordinate recovery efforts. Together, they form the frontline and emergency response system for cyber threats, helping you move from panic to resolution, fast.
Also read: Important Update! New Presidential Directive for CSIRT Capabilities ; What Makes a Next Gen SOC and Why Your Business Needs One Now
Conclusion
Modern-day phishing attacks mirror your habits, mimic your coworkers, and blend seamlessly into your digital routine. That’s what makes it so dangerous. It’s no longer about messages filled with grammatical errors and typos or shady email addresses. It’s about trust, and how easily it can be weaponized.
But awareness is growing, and so are the tools to fight back. Cybersecurity is no longer just a back-office concern, it’s a shared responsibility. From individuals being more cautious with links and QR codes, to companies investing in SOC, CSIRT, and continuous employee training, every action counts.
Because the next phishing attempt may not just target your inbox but it could also exploit your device, your identity, or your network. Staying ahead means staying informed, vigilant, and supported by the right partners.
Let’s secure the future together.
Schedule a free consultation with our cybersecurity experts at Cisometric and discover how we can help protect your organization from phishing attacks to full-scale cyber threats.
Book a meeting with us, click here.
For more updates on digital scams, cybersecurity insights, and expert tips, follow our social media:
LinkedIn: Cisometric
Instagram: @cisometric
Youtube: @Cisometric
Reference:
Phishing Threat Trends Report (khususnya yang part pertama)
50 Phishing Stats You Should Know In 2025
Phishing in 2025: How the Game Has Changed and Why Awareness Matters More Than Ever
AI-driven phishing scams exploded last year. The trend continues in 2025
2025 QR Code Phishing Trends: In-Depth Analysis of Rising Quishing Statistics