AI-powered phishing affects 86 per cent of Fortune 100 companies

July 19, 2026

Dr Martin J. Krämer, CISO Advisor at KnowBe4

Phishing remains one of the most dangerous threats to businesses, and even the world’s leading corporations are not immune to it. Over the past twelve months, employee data at 86 per cent of Fortune 100 companies has been compromised by phishing attacks. The technology, aviation and automotive sectors were particularly hard hit. At the same time, 78 per cent of the organisations surveyed report that the volume of phishing attacks increased last year.

These findings reflect a security situation that is also tense in this country. According to the Cybersecurity Monitor 2026, 11 per cent of internet users in Germany were affected by cybercrime last year, with 12 per cent of these cases attributable to phishing. On the corporate side, the Bitkom Business Security Report 2025 highlights how relevant social engineering remains: 49 per cent of companies report having experienced such attempts, whilst 21 per cent encounter them frequently. At the same time, 72 per cent of companies rate the threat level as high. Against this backdrop, the figures relating to Fortune 100 companies appear less like an outlier and more like further evidence that phishing is becoming increasingly scalable through AI and ‘phishing-as-a-service’.

According to the SpyCloud survey, security managers are particularly alarmed by the issue of AI: 84 per cent of respondents regard AI-generated phishing as the most widespread form of attack and the most difficult to defend against. This is followed by business email compromise at 58 per cent and vendor impersonation – that is, pretending to be a supplier or service provider – at 52 per cent. Furthermore, attack vectors such as collaboration tool phishing and session hijacking are coming more into focus. This development is putting increasing pressure on traditional email security: When machines automatically personalise phishing messages, attacks become more convincing, can be scaled up more quickly and are harder to detect.

A key driver of this trend is the growing sophistication of Phishing-as-a-Service platforms. They significantly lower the barrier to entry for attackers, as ready-made phishing kits are already available at comparatively low monthly prices. For between 50 and 250 US dollars, threat actors gain access to fully managed kits featuring pre-built phishing pages, one-click deployment and admin panels with multiple exfiltration options. It can sometimes take just a few minutes from purchase to an active campaign, and no programming skills or technical expertise are required.

Prevention alone is no longer enough

Phishing is evolving into an industrially scalable attack model. AI is improving the quality of the deception, Phishing-as-a-Service is lowering the barrier to entry, and new attack vectors are expanding the playing field beyond the traditional inbox.

Companies should therefore assume that individual attacks will succeed despite all technical filters, and reduce the risk where it arises: at the point of clicking. When AI-generated messages are virtually indistinguishable from legitimate communication, it is the employees who play a crucial role. What is needed is continuous human risk management, featuring practical training, simulated phishing attacks and a security culture in which suspicious messages are reported without hesitation. This fosters a workforce that recognises social engineering risks in their day-to-day work and makes better security decisions. AI-supported security awareness training can provide an important additional layer of defence here.

Related Articles

All news in 2026

All news in 2026

26.07.2026 When environmental regulations jeopardise operational readiness: Fire engines require special consideration at European level 26.07.2026 Protecting the Protectors: Why Fire Stations Must Become Part of Critical Infrastructure Resilience 26.07.2026 Perimeter...

Perimeter security does not begin at the fence

DIN VDE V 0826-20 focuses on the security performance of the overall system and establishes a practical framework for the planning, installation, operation and evaluation of perimeter security systems Fence sensors, video technology, radar and other detection systems...

Share This