Cofense Report Reveals Shocking Phishing Statistics Cofense Report Reveals AI-Powered Phishing Accelerated to One Attack Every 19 SecondsReport reveals as attackers use AI to generate thousands of unique variants, weaponize trusted tools, and blend seamlessly into business workflowsCofense announced that it has released its latest threat intelligence report, The New Era of Phishing: Threats Built in the Age of AI, revealing how AI technologies are now central to how threat actors operate, fundamentally transforming the speed, scale, and sophistication of modern phishing attacks. In 2025, Cofense analysts documented a watershed moment in cyber defense: a malicious email attack every 19 seconds - more than doubling from 2024’s pace of one every 42 seconds. This dramatic escalation underscores how AI has shifted phishing from a periodic nuisance to a continuous, adaptive threat. The data reveals that AI is no longer an experimental tool for attackers but rather an operational requirement that enables them to generate, test, and deploy campaigns at unprecedented speed and scale while continuously evolving their tactics to evade detection. "AI has fundamentally changed the economics and effectiveness of phishing," said Josh Bartolomie, Chief Security Officer at Cofense. "Threat actors are now using AI as core infrastructure, not just to craft highly personalized emails, but to dynamically adapt phishing pages based on the victim's device, generate thousands of unique variants of the same attack, and manage infected systems at scale. Traditional perimeter defenses can't keep pace with threats that shape-shift after delivery. Organizations need post-delivery visibility, human intelligence, and context-aware detection to identify and remediate what gets through." The report outlines five critical trends defining the AI-powered phishing landscape:
As threat actors integrate AI into every phase of the attack lifecycle, from reconnaissance to evasion, organizations must adopt defenses that evolve just as quickly. Effective protection requires a post-delivery defense that pairs real-world threat insights with expert human context and automation to rapidly identify novel, constantly changing attacks. This approach enables a action in minutes, not hours. Success depends on unifying employee-reported intelligence, expert oversight, and automated remediation to shorten response times and limit the window of exposure. Source: Cofense media announcement | |