Shut down AI cyber threats before their tactics succeed.

Deception at Machine Speed: a deepfake phishing campaign with its victim targets, emails sent and compromise rate

Launching personalized attacks at scale used to require a ton of effort. AI has changed that. Now, attackers are creating tailored phishing campaigns at machine speed that often look just like normal activity. That’s why recognizing their tactics and outpacing them on defense is the first step towards solid AI attack protection.

AI-enabled cyberattacks are changing the game…

Read more about EvilTokens and the Rise of AI-Powered Phishing
EvilTokens and the Rise of AI-Powered Phishing
Report
Read more about A Defender’s Checklist Against AI-Powered Phishing
A Defender’s Checklist Against AI-Powered Phishing
Checklist
Read more about Why Minutes Matter: Catching Threats Moving at Machine Speed
Why Minutes Matter: Catching Threats Moving at Machine Speed
On-Demand

…but here’s what you can do to stop them.

Huntress platform

Follow the Money: How Your Stolen Data is Banking the Black Market

If there were an award for the industry making the biggest moves this year, organized cybercrime would be a top contender. It’s estimated to top $10 trillion a year, rivaling the world’s largest economies, with innocent businesses bearing the cost. That threat to commerce is why billions are being poured into cyber capabilities across the financial sector.

In this episode of _declassified, Huntress’ John Hammond joins a key leader from one of the world’s largest payments companies to follow the money. When businesses go dark, suppliers go unpaid, payroll gets disrupted, and customers spend elsewhere. Some of that loss becomes revenue for the adversary. Multiply it across millions of companies, and a dark industry emerges, with everyone else left paying for its success.

Save your spot to get an inside look at how organized cybercrime is reshaping the global economy.

Huntress platform

Meet the AI-powered adversary

AI has given attackers a serious upgrade: faster tools, more convincing lures, and the ability to scale a single campaign across hundreds of targets at once.

This ebook exposes how attackers are leveraging AI to manipulate trust and scale their operations, grounding that shift in real incidents our team investigated firsthand.

THE SITUATION

This is the true scale of AI-powered cyber threats

Easily accessible AI has given attackers unseen-before speed, scale, and ability to make their lures more believable. This is how AI has changed the threat landscape in the last year.

1,380%

Increase in device code phishing

53%

Of malware loader activity involved ClickFix & fake CAPTCHAs

57%

Of phishing attacks used malicious PDF attachments

See the rest of the stats

DECEPTION TODAY

How AI is changing social engineering

Modern social engineering is built to look like normal work, and the obvious phishing signs users expect aren’t the only tactic they have to look out for.

Read more about Social Engineering Leveled Up. Has Your Security Program?
Social Engineering Leveled Up. Has Your Security Program?
Blog
Read more about 2026 Cyber Threat Report: State of Phishing
2026 Cyber Threat Report: State of Phishing
Report
Read more about Fake Bank of America "Action Needed" Phishing Email Deposits ScreenConnect Instead
Fake Bank of America "Action Needed" Phishing Email Deposits ScreenConnect Instead
Blog

DETECTION AFTER COMPROMISE

Successful logins aren’t always legit logins

It might look like your users are logging in… but that doesn’t mean it’s actually your user logging in. Stolen credentials, session cookies, device codes, and OAuth tokens can let attackers easily use trusted identities and SaaS workflows.

Read more about From Cookies to Keys: The Threat of Session Hijacking
From Cookies to Keys: The Threat of Session Hijacking
Blog
Read more about What is Device Code Phishing?
What is Device Code Phishing?
Video
Read more about The Rise of Infostealers and Session Hijacking
The Rise of Infostealers and Session Hijacking
eBook

FROM TRUST TO EXECUTION

AI social engineering is just the beginning.

Social engineering can end in identity theft, getting a user to run a command, install a fake app, download a “fix,” or giving access to an endpoint. We follow the attack past the lure and show how the people and endpoint layers connect.

Read more about That “Friendly” Prompt is ClickFix
That “Friendly” Prompt is ClickFix
Blog
Read more about The AI Attack Surface: How Threat Actors Abuse Trusted AI Platforms
The AI Attack Surface: How Threat Actors Abuse Trusted AI Platforms
Blog
Read more about ClickFix Attack: Variants, Detection & How It Works
ClickFix Attack: Variants, Detection &  How It Works
Blog

DEFENDING AT MACHINE SPEED

AI-driven cybercrime isn’t slowing down. Time to speed up your defenses.

Attackers can rotate infrastructure, lures, and techniques quickly, so your defenses need to move just as fast. That’s why Huntress uses AI to accelerate investigation and handle some high-confidence, high-volume work, while human analysts and threat hunters own complex investigations, verdicts, and outcomes.

Read more about Riding the Rails: Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure
Riding the Rails: Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure
Blog
Read more about Human-Led AI in the SOC: Faster Than Manual, Smarter Than Autonomous
Human-Led AI in the SOC: Faster Than Manual, Smarter Than Autonomous
On-Demand Virtual Event
Read more about Meet Athena, Our Agentic SOC Analyst
Meet Athena, Our Agentic SOC Analyst
Blog

YOUR 24/7 TEAM

The Agentic SOC stopping AI cyber threats at machine speed.

If attackers are moving quickly, you have to match their speed. That’s where the Huntress Adversary Tactics and 24/7 Security Operations Center come in. These experts track real-world tradecraft, stop threats around the clock, and shut down attackers’ best-laid plans because they know what their plans are.

HUNTRESS PRODUCTS

Your Security Platform for Peace of Mind

The Huntress security platform is built, owned, and operated entirely by our team from first signal through remediation. Backed by a 24/7 AI-centric SOC, it detects and responds to today’s and tomorrow’s threats.

Huntress Managed EDR doesn't just watch your endpoints—it’s a complete solution. From the second a threat appears until it’s eliminated, we handle everything. You get 24/7 continuous protection, detection, and response that disrupts and remediates threats.

  • 5M+ Endpoints protected

Identity Threat Detection and Response (ITDR)

Finds and stops identity-based threats in Microsoft 365 and Google Workspace—because identity is the new endpoint, and attackers know it. Huntress Managed ITDR is designed to detect, respond to, and resolve critical identity-based threats like account takeovers, business email compromise, unauthorized logins, and more.

  • 15M+ identities protected

Huntress Managed SIEM takes away the complexity and overhead usually associated with traditional SIEMs, giving you everything you need and nothing you don’t. 24/7 threat response and strengthened compliance, fully managed by SOC experts, at a predictable price.

  • Smart Filtering to capture only security-relevant data
  • Total Compliance with long-term retention, search, and reporting

Engaging, expert-backed, personalized training content built on real-world threat intelligence and created by Emmy® Award-winning animators to reduce human risk and build a strong security culture.

  • Training built on threat intel from 5M+ endpoints and 15M+ identities
  • 98% completion rate for learners who start assignments

Most hackers don't break in — they just take advantage of messy settings, bad defaults, and accounts with too much access. Huntress Managed Identity Security Posture Management (ISPM) continuously finds and closes misconfigurations, risky access, and policy drift in Microsoft 365 so those attack paths stay closed.

  • Your hardening to-do list, done for you
  • Drift fixed in ~15 minutes, not 12–24 hours

Huntress Endpoint Security Posture Management is proactive security that hardens endpoints to defend against attacks like ransomware and infostealers, and prevent breaches. Get broad endpoint visibility and control over configurations, applications, vulnerabilities, and more in one location and a single solution.

  • Reduce the attack surface to take away the hacker’s advantage
  • A managed approach for less overhead and fewer headaches

Frequently asked questions

AI works mainly as an accelerator. Attackers use it to research targets, write personalized lures faster, and run far more of it than a human team ever could by hand. Work that used to take a skilled operator hours can now happen in the time it takes a page to load, and it’s no longer reserved for high-value targets worth the manual effort. Phishing starts to behave like a repeatable system instead of a one-off campaign.

The other half of the story is deception. AI makes those lures more convincing, and attackers deliver them through legitimate services and real authentication flows so the malicious activity looks like normal work. That gives them speed and scale on delivery and a better disguise on the human side, which is what makes modern threats harder to spot. It’s also why recognizing the underlying tradecraft matters more than scanning for spelling mistakes or an unfamiliar sender.

AI is most useful on defense when it takes the heavy, repetitive work off human hands and gives the judgment back to a person. In practice, that means using it to accelerate investigation: pulling context together and triaging high-volume signals so the clear-cut cases get handled fast. That speed matters because attackers now rotate infrastructure and lures quickly, and isolated alerts pile up faster than a lean team can work through them.

The part that keeps AI honest is human ownership. Analysts and threat hunters still own the complex investigations and the response decisions, because those calls carry consequences a model shouldn’t make on its own. The aim is to match machine speed with human judgment: let AI handle the legwork so people spend their attention where it counts. That pairing is how a lean team defends at the pace of the attack without standing up a 24/7 operation of its own.

The most common AI-powered threats are the familiar ones running at a new speed and scale. AI-accelerated phishing leads the list: tailored lures sent across email, text, calendar invites, and collaboration tools, written to match the target’s actual job. Closely tied to it is identity abuse, where attackers use stolen credentials, session cookies, device codes, or OAuth tokens to operate through a real account after a successful login. Business email compromise fits here too, since a compromised inbox lets an attacker study real conversations and insert fraud into a process people already trust.

Device code phishing has become one of the clearest examples. It abuses a legitimate login step, needs no malware or stolen password, and just asks a victim to do something that feels routine, which makes it cheap to run at volume and hard to flag. Huntress observed device code phishing attacks climb 1,380% between July–December 2025 and January–April 2026. On the endpoint side, human-enabled compromise (fake app installs, ClickFix-style “run this to fix it” prompts) rounds out the pattern, all of it built to pass for a routine task rather than obvious malware.

Defending against AI-enabled attacks starts with a shift in what you watch for. Because these attacks are built to look legitimate, the defense is coordinated visibility across identity, users, and endpoints, so a signal that looks fine in one layer gets caught when it doesn’t line up with the others. A login can succeed and still be wrong if it comes from the wrong device or a location that’s out of step with someone’s role.

A few habits do most of the work. Behavioral detection catches what signature-based tools miss, which matters against AI-generated tools that have never existed before and won’t match a known pattern. Training built around real tactics helps people question urgency and unexpected requests, even when those requests arrive through channels they already trust. And making reporting fast and blame-free means that when a convincing lure does work, defenders hear about it early enough to contain the damage. The thread running through all of it: question the workflow, not just the message.

Huntress treats phishing as a full attack path, because the message is usually only the setup. It starts at the people layer: Managed Security Awareness Training exposes users to the tactics attackers are actually using now, so recognition and reporting improve against current tradecraft rather than last year’s tells. When a lure does succeed, the important signals show up after the login.

That’s where Managed ITDR comes in, watching Microsoft 365 and identity behavior for the things that follow a successful phish: suspicious authentication, session and token abuse, rogue OAuth apps, and mailbox rule changes. If the attack pushes to the endpoint instead, through a fake app or a “run this fix” prompt, Managed EDR catches the infostealers and remote-access tools that follow. Tying it together is the 24/7 SOC, where AI accelerates the investigation and human analysts own the verdict. That combination is how Huntress catches an attack that looks like normal work, and it’s the reason coordinated visibility beats any single filter.

AI is changing social engineering mostly by removing its old limits. Social engineering always relied on human effort, since a person could only research so many targets and write so many convincing emails in a day. AI erases that ceiling. The same tailored lure that once took real time to craft can now be produced at volume and personalized from public information, then sent to far more people with far less manual work.

It’s also making the lures better. AI helps attackers polish impersonations and tune a message to a specific job or moment, mimicking someone’s writing voice closely enough to remove many of the signs people were taught to spot. In one campaign Huntress investigated, attackers used AI to scan a compromised inbox and calendar, then wrote a wire fraud email in the victim’s own voice within minutes. The manipulation tactics are the same ones that have always worked. What’s new is how cheap and convincing they’ve become at scale, which is why the real skill now is noticing when something perfectly ordinary is being used for the wrong purpose.

Huntress helps you keep up with AI cyber threats

See how Huntress can help you defend at machine speed. Book a demo to see it for yourself.

Schedule Your Demo
By submitting this form, you accept our Terms of Service & Privacy Policy