A Single Partner for Everything You Need With more than 450 technology partners in its ecosystem, Optiv provides clients with best-in-class security technology and solutions that equip organizations to detect and manage cyber threats effectively and efficiently in today's growing attack surface. Optiv's Partner of the Year Awards recognize forward-thinking innovation, performance and growth, and unparalleled technology solutions.
We Are Optiv Security Greatness is every team working toward a common goal. Winning in spite of cyber threats and overcoming challenges in spite of them. It’s building for a future that only you can create or simply coming home in time for dinner. However you define greatness, Optiv is in your corner. We manage cyber risk so you can secure your full potential.
Securing the Human Element in the Age of AI-Enabled Phishing Breadcrumb Home Insights Blog Securing the Human Element in the Age of AI-Enabled Phishing September 28, 2026 Remember when phishing emails gave themselves away? Misspelled words, awkward phrasing and a stranger claiming someone had won a prize they never entered to win. Those were the tells that trained a generation of employees to hit delete. Attackers have since closed that gap. They now use artificial intelligence (AI) to write flawless, natural-sounding messages in seconds, and they've expanded far beyond email into text messages, QR codes and even cloned voices. Mobile devices compound the problem: smaller screens and constant notifications push people to react quickly instead of pausing to verify. Meanwhile, techniques such as reverse-proxy and adversary-in-the-middle let attackers hijack an active, already-authenticated session, so even a strong password and MFA prompt aren't automatically safe. For people and business leaders, that means phishing is no longer just an employee awareness issue; it is a human-risk challenge that needs leadership attention, clear processes and a culture that supports secure decisions. Phishing still works; it just works differently now. Verizon's 2026 Data Breach Investigations Report finds that complex social engineering is succeeding more often than ever, and that mobile social engineering now carries a 40% higher success rate than traditional email phishing. Optiv's own threat research echoes that shift: its 2025 Industry Threat Profile identifies human exposure as one of the defining risks organizations face today, driven by AI-powered phishing scams, deepfake impersonation and fatigued security teams. Adversaries Are Weaponizing AI Generative AI hasn't just made phishing faster to produce — it's made phishing harder to detect. Where attackers once needed time, language skills and some technical know-how to craft a believable lure, a large language model now does that work in seconds, and it does it convincingly in any language or tone the attacker chooses. No more red flags: Optiv's research on AI and cybersecurity explains that large language models eliminate the awkward phrasing and grammatical errors that once tipped people off, letting scammers generate countless polished variations of the same lure and test which ones perform best against a target Scale meets precision: Optiv's threat data shows that roughly 83% of phishing emails now carry signs of AI generation, and nearly 9 in 10 organizations report experiencing an AI-enabled cyberattack in the past year. AI-assisted phishing has moved from novelty to norm It's not just email: The National Cybersecurity Alliance (NCA)'s AI and the Future of Phishing initiative demonstrates how attackers use large language models to research a target and generate a custom, convincing phishing email built specifically around that person's public footprint Oversharing fuels the problem: The NCA's 2025 research found that 43% of employees have shared sensitive work information with AI tools without their employer's knowledge, and 58% have received no training on the security or privacy risks these tools introduce. This data can end up shaping the very lures sent back at them or their colleagues The takeaway isn't that phishing has become unbeatable; it's that the old checklist of typos and generic greetings no longer applies. Judging a message by how polished it looks is no longer a reliable filter. Leaders can help by building habits, expectations and reporting paths that make it easier for employees to pause at moments of pressure, verify requests independently, and report quickly. Phish Facts: Understand the Human-Risk Challenge Phishing works because it targets human decision-making, not just inboxes. Attackers pose as trusted people, organizations or tools to create urgency, fear, curiosity,or convenience. Any one of these pressures can make someone click a link, approve access, send money or share information before they stop to verify. That pressure can arrive through several channels, and each one is designed to make the request feel familiar, timely or easy to act on. Email phishing uses links, attachments or reply-based deception to make a routine message feel worth acting on Spear phishing goes further by tailoring the lure to a person’s role, relationships, projects or normal business processes Smishing moves the same manipulation into text messages, where small screens and quick replies can make verification easier to skip Vishing relies on voice calls or voicemail to create urgency or impersonate a trusted contact, a tactic that becomes more convincing as AI voice cloning improves Quishing uses QR codes to move the interaction to a mobile device, where the destination may be harder to inspect before tapping through Collaboration and calendar phishing hides in the tools people already use for work, such as chats, shared documents, meeting invitations and comments Consent and session phishing targets the moment after trust has already been established, asking users to authorize an application or exposing an authenticated session A useful leadership rule: don't train people to judge a message only by how professional it looks. Help teams judge the request, the context and the path it asks them to take. Don't Take the Bait: Eight Ways Leaders Can Reduce Phishing Risk 1. Build a Culture That Pauses at the Point of Pressure Urgency is a control tactic. Leaders should reinforce that unexpected requests to verify an account, reset a password, buy gift cards, change payment details, share sensitive data or approve a sign-in are cues to slow down and look closer. Encourage employees to ask whether the request is expected and appropriate for the sender Set expectations that employees should stay cautious when a message discourages verification or demands secrecy Create clear escalation paths for confirming high-impact requests through a known contact method, not the one the message provides 2. Reinforce Sender and Business Context Verification A familiar display name doesn't prove identity. Leaders should make it normal for employees to inspect the full sender address and reply-to address, check the domain and ask whether the request matches the person's role, the organization's normal process and the usual communication channel. 3. Make Independent Navigation the Easy Path For account, payment, benefits or delivery notices, employees should be encouraged to open the organization's official app or type a known web address into a browser rather than clicking the message's link. Leaders can reduce risk by making trusted paths easy to find and consistently communicated. On mobile devices, shortened text and compressed screens make deceptive domains easy to miss. Keep in mind: HTTPS and a padlock icon only mean the connection is encrypted. They don't prove a website is legitimate, so teams need guidance that goes beyond visual trust cues. 4. Treat Attachments, QR Codes and Shared Files as Links Every unexpected attachment, QR code or shared-file notification can pull employees outside the organization's familiar security controls. Leaders should reinforce the need to confirm the sender and purpose before opening anything, and teams should stay especially cautious with HTML files, archives, calendar attachments, and documents that ask them to enable content or sign in again. 5. Protect the Sign-In, Not Just the Password Leaders should support strong identity practices, including unique passwords for every account, approved password managers and multifactor authentication (MFA). Where available, organizations should prioritize phishing-resistant methods such as FIDO2 security keys or passkeys. Attackers can still target push, code and SMS-based methods through phishing or fatigue attacks. 6. Keep Devices, Browsers and Applications Current Updates close known security gaps and strengthen built-in protections. Leaders should make approved update processes clear, reinforce the importance of keeping operating systems, browsers, mobile devices, email clients and security tools current, and discourage employees from installing unapproved browser extensions or applications in response to a message. 7. Train for the Threats Teams Actually Face Security training should not be treated as a box to check. Leaders should help teams understand how phishing tactics keep changing, including how attackers now use AI to generate convincing lures at scale, and make sure employees know what the organization expects them to do when something feels off. The goal isn't to turn every employee into a security expert; it's to build enough awareness to pause, verify and report before a small interaction becomes a larger incident. Position simulations and reminders as practice for real decisions, not pass-fail exercises Refresh training to address new lures that use AI-generated language, mobile messages, QR codes, shared files or collaboration tools Make sure employees know where to report suspicious activity before they ever need to use that process 8. Make Reporting Fast, Safe and Useful Reporting helps security teams investigate, contain and warn others. Leaders should make the approved reporting method easy to find, reinforce that fast reporting is valued and encourage employees who interacted with a suspicious message to report exactly what happened and when. Encourage employees not to continue interacting with the sender Discourage broad forwarding and reinforce use of the approved reporting channel instead Make incident-response instructions clear for passwords, sessions, devices or payments The Bottom Line Attackers adapt to the tools people trust, and AI has now become one of their most effective tools. The defense still depends on a repeatable habit: pause, verify through a separate path and report quickly. Leaders play a critical role in making that habit visible, expected and supported by a security program that connects people, identity, messaging, endpoints and response. No single control can stop every phishing attempt. But layered defenses, combined with leaders who understand how AI has changed the threat landscape and empower their teams to respond with confidence, can prevent a single convincing interaction from becoming a business-wide incident. Want to learn more about building a cybersecurity education and awareness program that helps protect the human element? Find out here. By: Loreen Elbakry Cybersecurity Education Specialist Loreen Elbakry is a former educator with 17 years of experience in teaching and instructional design who now serves as a cybersecurity education specialist at Optiv. She leverages her background in learning and development to create impactful cybersecurity training programs, phishing simulations and awareness initiatives that help organizations build stronger security cultures. Loreen holds the ISC2 Certified in Cybersecurity (CC) certification and serves as a member of Optiv's Copilot Champions program, promoting effective use of AI-powered tools to enhance learning and productivity. Share: Optiv OT Security About Optiv Security: Secure greatness.® Optiv is the world’s largest pure-play cybersecurity company. With unmatched technology partnerships and deep technical expertise, Optiv securely enables the AI era for more than 6,000 clients. From financial services and health care, to government, energy and retail, organizations trust Optiv to advise, deploy and operate cybersecurity programs that reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at optiv.com.
About Optiv Security: Secure greatness.® Optiv is the world’s largest pure-play cybersecurity company. With unmatched technology partnerships and deep technical expertise, Optiv securely enables the AI era for more than 6,000 clients. From financial services and health care, to government, energy and retail, organizations trust Optiv to advise, deploy and operate cybersecurity programs that reduce risk and deliver real results. Learn why Optiv is the most trusted brand in cyber at optiv.com.