AI Policy & Regulation

PhishByte warns AI phishing has outpaced detection

PhishByte says AI-generated phishing hit 56% of all attacks in December 2025, up from 4%, as Australian businesses lost AUD $166.8 million to payment redirection fraud.

PhishByte warns AI phishing has outpaced detection

Key takeaways

  • AI-generated phishing accounted for 56 per cent of all phishing attacks during the December 2025 holiday period, up from a baseline of about 4 per cent, according to PhishByte.
  • Australian businesses lost AUD $166.8 million to payment redirection fraud in 2025, with AI-generated business email compromise messages increasingly tied to those losses.
  • Only 42 per cent of Australians can actually identify a deepfake, despite 90 per cent believing they can, PhishByte said.
  • The average cost of a cybercrime incident for an Australian small business now stands at AUD $56,600.
  • AI-related cyber threats across Australia and New Zealand doubled in 2025 from the previous year.

What Happened

In-body image for: PhishByte warns AI phishing has outpaced detection
Illustrative AI-generated image by Mindiam (Flux 1.1 Pro Ultra)

PhishByte, a provider of phishing simulation and security awareness training, published a warning on 16 September 2026 that AI-generated phishing has made traditional detection methods obsolete for many Australian organisations.

The company said generative AI has transformed phishing emails from broad, error-filled messages into tailored communications that appear credible and specific to each recipient. Spelling mistakes, generic greetings and implausible scenarios, once reliable signals of a scam, have largely disappeared from AI-generated attacks, PhishByte said.

The figures cited by the company show a sharp escalation. AI-generated phishing accounted for 56 per cent of all phishing attacks during the December 2025 holiday period, up from a baseline of about 4 per cent. AI-related cyber threats across Australia and New Zealand also doubled in 2025 from the previous year.


Why It Matters

Australian businesses lost AUD $166.8 million to payment redirection fraud in 2025, according to figures cited by PhishByte, with AI-generated business email compromise messages increasingly tied to those losses. The average cost of a cybercrime incident for an Australian small business now stands at AUD $56,600.

PhishByte also cited a widely reported case involving a finance employee in Hong Kong who authorised a USD $25 million payment after joining a video conference in which every other participant, including the Chief Financial Officer, was an AI-generated deepfake.

The company pointed to a confidence gap among Australian workers as a compounding factor. "90% of Australians are confident they can spot a deepfake. Only 42% actually can," PhishByte said. "The gap between confidence and capability is exactly what attackers are exploiting. And with AI-generated phishing accelerating at a pace the threat landscape has never seen before, the training your team received last year is already out of date," the company added.


Key Details

PhishByte said attackers are using dark-web tools such as FraudGPT and WormGPT to produce polished corporate language within seconds. AI-based personalisation systems can also use scraped employee information to generate thousands of unique emails built around a recipient's role, employer and work context.

The shift represents a change in attacker economics. Instead of sending large volumes of generic emails in the hope of catching a few recipients, criminals can now use large language models and automated data collection to produce tailored messages at scale.


Background and Context

PhishByte pointed to the federal government's AUD $90 million Horizon 2 commitment as a sign that policymakers now recognise the risks created by staff exposure to increasingly persuasive digital deception.

The Australian Cyber Security Centre has previously documented business email compromise as one of the costliest cyber threats facing Australian organisations. The ACCC's Scamwatch programme also tracks payment redirection fraud as a persistent and growing category of financial loss for businesses.


What Comes Next

PhishByte did not specify a timeline for any product releases or regulatory submissions. The company's warning was directed at organisations relying on security awareness training developed before the widespread availability of generative AI tools.

Sources & citations

  1. Joseph Gabriel Lagonsin, "PhishByte warns AI phishing has outpaced detection," *eCommerceNews Australia*, 16 September 2026. Available at: securitybrief.com.au
JUST THE WEEKLY ROUNDUP

One Friday email. The five things AU operators actually need to know.

Operator-tested, primary-source linked, citation-first. Written by an operator, not a marketing team. Or, for a personalised view first, take our 90-second quiz.

Unsubscribe anytime. No spam. See our privacy policy.