AI-powered phishing beats email filters: 54% click rate at a fraction of the cost

Your clients receive thousands of emails every day, but it takes just one convincing message to turn a seemingly harmless email into a security incident you will be responsible for cleaning up. AI has fundamentally changed phishing, making it easier to launch, harder to detect, and far more convincing than traditional email filters were built to stop.
With a large language model and a few publicly available LinkedIn profiles, attackers can generate highly personalized phishing emails in minutes. Harvard Business Review found that AI-generated spear phishing campaigns achieved a 54% click-through rate, matching those of human experts at a fraction of the cost. This means that the same level of deception that once required skilled social engineers and hours of manual research can now be automated and scaled by anyone with access to an LLM.
Every AI-assisted phishing campaign follows the same basic path, but AI makes each stage faster, more convincing, and much harder for traditional defenses to detect. The process begins with reconnaissance: attackers use AI to scan LinkedIn, company websites, and other public sources to build a detailed profile of a specific employee. Within minutes, they know who that person works with, what projects they are involved in, and how they communicate internally. For MSPs, this is a critical concern: public information gives attackers everything they need to create a believable phishing email before it ever reaches a client's inbox.
The next stage is content generation, where AI uses the gathered information to write an email that looks completely legitimate. The message mimics the writing style of colleagues, references real ongoing projects, and uses the correct internal terminology. The result is a communication that lacks the typical red flags of phishing — no grammatical errors, awkward phrasing, or suspicious sender addresses. Traditional email filters, which rely on signature-based detection and sender reputation, fail to flag such messages because they appear perfectly normal.
AI also enables dynamic adaptation. If an initial email is questioned, the attacker can quickly generate a follow-up that addresses the concern, maintaining the conversation and increasing the likelihood of success. This makes it nearly impossible for static rule-based filters to keep up.
For MSPs, understanding how these attacks work and why traditional filters struggle to stop them is essential to protecting clients before a single email becomes a costly breach. The key takeaway is that AI has not just improved phishing — it has transformed it into a scalable, personalized, and highly effective threat that bypasses most existing defenses. Without advanced detection methods that analyze behavior, context, and intent, organizations remain vulnerable to attacks that are becoming cheaper and more sophisticated by the day.


