Phishing: Why It Remains the Biggest Cyber Threat

Next-generation firewall, EDR, a well-configured cloud — and a single email brings it all down. Year after year, phishing remains the main entry door in the incidents we investigate. The reason is simple: it does not attack the technology, it attacks the person. And a person in a hurry, pressured by an “urgent” from the boss or an invoice about to expire, clicks.

What changed was not the scam — it was its quality. Generative AI writes flawless lures, in your company’s tone, and already produces cloned voice and video for approval requests. That is why, in this article, we show how phishing operates today, what a wrong click costs and what actually protects, from the perspective of those who respond to these incidents in practice.

In one sentence — phishing remains the biggest threat because it exploits the link no software fixes on its own: human trust under pressure. Defense combines phishing-resistant MFA, realistic training and a culture of reporting without fear.

Why the scam became so much more dangerous

First, the channels multiplied. Beyond classic email, the scam arrives via SMS and WhatsApp, malicious QR codes and calls with cloned voice. Training the team only for “suspicious email” no longer solves it.

Second, personalization scaled up. Spear phishing — a scam built on prior research about the target — used to require manual work; today generative AI assembles a tailored lure in seconds, using public data from LinkedIn and the company website. As a result, the preferred target is still senior leadership, where a single access is worth more.

Third, the prize changed. More valuable than the password is the session token: with a stolen valid cookie, the criminal enters the cloud environment without typing any password — and without tripping the login alarm.

anatomy of modern phishing: AI-made lure (email, SMS, QR, cloned voice) · Click (credential or token stolen · the passkey break) · Intrusion (enters the cloud

The cost of one click

A successful phishing rarely ends with itself — it is the first domino. In our investigations, the most common consequences repeat:

  • Customer data leaks — which now trigger mandatory notification to the regulator and the data subjects, with the clock running;
  • Ransomware — with double extortion: data is encrypted and copied, and backup solves only half the problem;
  • Compromised employee accounts — used for new internal scams, now coming from a legitimate sender;
  • Direct financial fraud — the fake invoice, the switched supplier bank account, the approval forged with cloned voice.

Timing also matters: for an e-commerce operation, falling on the eve of Black Friday multiplies the loss. Not by chance, incident response and backup are the fastest-growing fronts within IT support.

Hybrid work blurred the boundary

With hybrid work normalized, the same phone reads the corporate email and the family WhatsApp; the company laptop makes the weekend purchase. That mix widens the risk: a scam that enters through a personal channel reaches the corporate credential. In practice, the answer is separating profiles, applying device-based conditional access and assuming the home network is not trustworthy.

Watch out — the person who clicked and reported within minutes helped contain the campaign; the person who clicked and hid it gave the criminal days of advantage. Punishing those who report is the fastest way to guarantee the next incident is discovered too late.

What actually protects

  1. Phishing-resistant MFA — passkeys or FIDO2 keys on critical access. With them, a stolen password and code stop working; it is the technical measure with the highest return.
  2. Session monitoring — to detect the use of stolen tokens, with frequent revocation of old sessions.
  3. Periodic, realistic simulations — including QR codes, SMS and audio requests. The team only learns from a scam that looks like the real one.
  4. Out-of-band verification — a payment request or a bank-account change is confirmed through another channel, always. That goes even for the “video call from the director”.
  5. A reporting culture — an easy button, a fast response from the security team and zero punishment. Every report calibrates the filter and blocks the campaign for everyone.

In short, phishing will keep leading the statistics as long as it targets people — and people will keep existing. The good news: the combination of passkeys, monitoring and realistic training strips the scam of almost all its power. Building that layered defense is the job of our cybersecurity practice, from the email filter to the response plan.