Before and After ChatGPT: The Impact of Artificial Intelligence on Today’s Phishing Landscape

By Audian Paxson, principal technical strategist, IRONSCALES [ Join Cybersecurity Insiders ]
Before-and-After-ChatGPT

This June, IRONSCALES and Osterman Research released a new industry report that measures the financial and operational impact of phishing on enterprises now that AI sits on both sides of the inbox. 

What makes it useful is the timing. The report, “The (Higher) Business Cost of Phishing,” is a direct follow-up to our original “Business Cost of Phishing” study from October 2022. ChatGPT launched that November. So we have a baseline from the weeks before generative AI went mainstream and a fresh read three years into it. (You rarely get a control group that is clean in this business). The new study surveyed 128 IT and security professionals at organizations with 1,000 to 5,000 employees.

Set against the 2022 numbers, the two give us a rare before-and-after look at what ChatGPT-era AI actually did to the phishing landscape. The answer surprised me. There’s no tidy story of better defense or faster remediation. AI helped enterprises and threat actors alike, and on balance, the threat actors came out ahead. 

So, let’s break down the findings and takeaways that matter most to practitioners today. 

The Post-AI Phishing Paradox: Despite Superior Defenses, Orgs Are Still Being Overrun

The most important finding of the report is somewhat paradoxical. While the average per-incident handling time for phishing attacks has fallen by over 16%, phishing now consumes more of security teams’ time overall and costs them nearly 14% more per analyst annually. 

So what’s behind this disconnect? The short answer is AI. For enterprises, AI-powered defenses have allowed teams to more quickly resolve individual phishing attacks. However, generative AI has also empowered threat actors to launch far more of those attacks, and they’re doing so with significantly greater speed and sophistication. That means, despite the per-incident improvements, the total number of incidents requiring security team intervention has ballooned, leading to an increase in the overall commitment to phishing defense.

In short, businesses are better at handling phishing attacks, but they’re simply being overrun by them. Let’s take a closer look at the numbers: 

  • AI-powered defenses cut per-incident handling time by 16% (27.5 minutes to 23.2 minutes) and reduced the cost per phishing email by 12% ($31.32 to $27.51)
  • Phishing now costs $51,948 per security analyst annually, up 13.6% from $45,726 in 2022. Phishing also consumes 37% of security team working hours, up from 33.5% three years ago.

The takeaway for practitioners here is both clear and a little grim. Because, although malicious use of generative AI has wiped out the advances afforded by AI-powered defenses, it’s important to consider what the landscape would look like without those enhanced defenses. 

For businesses that don’t adopt AI-powered tooling, the time and cost overrun would undoubtedly be tremendous. The lesson, therefore, is that while not a silver bullet, these AI-powered tools have become essential for SOC teams to have a fighting chance against today’s threat actors.

Beyond Volume: Why Speed, Sophistication and Evasiveness Matter

Generative AI has empowered attackers in more ways than one. While the increased volume of attacks is perhaps the most evident, it’s also important to note the growing speed, sophistication and evasiveness afforded by AI-powered attacks. 

Personalized phishing attacks that previously required hours or days of manual research now take minutes to prepare. That reduced preparation time leads to faster campaign cadence. At the same time, attackers are using AI to probe defensive configurations, craft more compelling phishing messages, and autonomously adapt campaign attributes (all of which lead to more evasive attacks). 

Net it out. More phish, arriving faster, and harder to spot. That’s not a great situation for organizations. In fact, in their 2026 Data Breach Investigations Report, Verizon reveals that the use of AI-assisted text in malicious emails has doubled in recent years, with phishing now accounting for 44% of all AI-assisted initial access attempts (which leaves little doubt about what AI has done to phishing).

Fear of Phishing Mounts in the Modern Enterprise

As a result of these changes,  organizations are becoming increasingly concerned about phishing. In “The (Higher) Business Cost of Phishing,” half of organizations rated phishing as a high or extreme threat, up from just one-third in 2022.

At the same time, a significant portion of professionals foresee the problem getting worse. Roughly 40% of respondents reported that they expected the volume, speed, and evasiveness of phishing attacks to worsen over the next 12 months (suggesting this trend is still just developing). 

The study also took a look at the impact that deepfakes are having on enterprises. In it, 62.5% of respondents said deepfake attacks are “immediately disruptive” to their security operations. Deepfake voice and video technology carried the highest “extremely impactful” rating (at 31.3%) of all emerging threats surveyed, showing that these “next-generation” attacks are in fact already here and causing real harm. 

Altogether, this paints a grim picture for enterprise cybersecurity. While projections alone aren’t always the best indicators of future outcomes, when coupled with real-time data around the rising time and costs associated with phishing—not to mention the immediate impact of emerging threats such as deepfakes—we see that the bleak outlooks amongst today’s IT professionals are likely justified. 

Now’s the Time for Preemptive Cybersecurity

Faced with these realities, it’s becoming increasingly clear that a new approach to phishing defense is needed. Even with AI-powered defenses, the balance of power remains in the hands of the threat actors of the world. 

Thankfully, we can look to advances in agentic AI for a way to tilt the scales back in our favor. With agentic tools, organizations can preempt attacks through things like autonomous red-teaming that continuously stress-tests and adapts AI defenses by imitating threat actor behavior. Other emerging tools include automated forensic investigation and simulation agents that generate training scenarios based on real-world threat intelligence. 

Though this is a small sampling of what can be done with these new tools, together, they allow organizations to “think like the enemy.” And with that knowledge and mindset, they are better equipped to act preemptively, closing gaps and shoring up defenses where needed. 

The cat and mouse game isn’t going anywhere. The only question is which end of it you’re on.

 

 

 

Join our LinkedIn group Information Security Community!

No posts to display