All Posts
Announcements
Threat Research

The New World of AI Spearphishing

Attackers stopped writing malware. They started writing emails. This paper breaks down the $11.64B shift from payload-based attacks to identity exploitation — and why your existing stack can't see it coming.
Written by
Ana Moura
Emily Hudson
Published on
July 4, 2026

2025 FBI IC3 Report: By the Numbers

Three Critical Findings at a Glance2025 FBI IC3 Report: By the Numbers

The 2025 FBI IC3 Annual Report marks twenty-five years of documenting our digital vulnerabilities, but this year, the numbers tell a story of evolution rather than just growth. We’ve officially graduated from the era of "spray-and-pray" noise into a period of optimized execution. While the $20.8 billion in reported losses is a staggering figure, it’s merely the scoreboard for a much more dangerous game. The true narrative lies in AI Phishing, a tactical sharpening of the blade that demands we rethink what it means to be "secure" in an increasingly calculated threat landscape.

Three Critical Findings:

To understand the evolution of the "Perfect Phish," we must look at three critical findings that redefine how adversaries operate in the modern threat landscape:

  • Yield Up 208%: While the total volume of phishing complaints has remained virtually flat, the financial lethality of these attacks has skyrocketed in a single year, proving that precision is now more profitable than scale.
  • AI Attribution is Broken: Of $3.04B in BEC losses, only 1% carried a confirmed AI nexus — not because attackers aren't using it, but because current reporting frameworks have no mechanism to detect it at the point of compromise.
  • The Death of the Payload: Text-only, identity-based frauds like BEC and investment scams have surged ahead of artifact-heavy threats.

1. The Yield Paradox: Precision Over Volume

In 2025, the total number of Phishing/Spoofing complaints actually decreased slightly, dropping from 193,407 in 2024 to 191,561. However, the financial damage associated with these reports surged from approximately $70 million to over $215.8 million.

Phishing complaint volume has been flat since 2021 while financial losses surged +390%, confirming the Yield Paradox.

Aegis AI Response

While traditional security relies on community intelligence, waiting for an attack to hit thousands of targets before a signature is generated, we identified that in the last 30 days, 27.5% of our threats were “single-shot” attacks. These emails contained no known malicious reputation. In a legacy environment, these are functionally invisible. To us, they are a high-confidence signal indicator.

Real World Example: The "Zero-Error" Vendor Pivot

In a recent LinkedIn/AppSheet scam, flawless grammar and legitimate infrastructure allowed the email to bypass legacy filters. This attack successfully bypassed DMARC: PASS authentication, proving that "reputation-based" security is no longer a sufficient deterrent. AegisAI succeeded by identifying subtle shifts in sender intent that failed to align with historical vendor fingerprints.

2. The Shadow AI Threat

The report highlights a massive blind spot in Business Email Compromise (BEC). While total BEC losses reached $3.04 billion, only $30.2 million (roughly 1%) were explicitly reported with an AI nexus. This is not evidence that AI is a minor factor. It is evidence that AI is invisible to the victim.

AI-attributed losses (amber) represent less than 1% of total BEC losses ($30.2M of $3.04B) — the Attribution Gap made visible.

AegisAI Response

To solve the attribution gap, we leverage a  proprietary Contextual Model to perform Identity-Intent Correlation.

  • Contextual Models: Unlike off-the-shelf generative AI, we use our purpose-built models for email defense - trained to detect hostile intent by weighing the recipient's interactions, sender rapport, and the authority being invoked

  • Identity-Intent Correlation: We cross-reference a sender’s technical footprint against the professional authority they claim to hold

By isolating the contextual misalignment between a high-stakes request and a suspicious origin, we expose impersonation attempts that are linguistically "perfect" but psychologically uncanny.

Real World Example: Executive Impersonation on Subject (Redacted) & PII (Personable Identifiable Information) Request

A recent data-harvesting lure impersonated a high-profile executive. Despite achieving DMARC: PASS, the threat was stopped because it failed our Identity Modeling check, proving that intent and identity are the only reliable signals in a payload-less world.

3. Social Engineering Is the Exploit: Identity Is the Vulnerability 

The 2025 IC3 report provides the statistical smoking gun for the end of artifact-heavy crime. The financial gap between payload-less and payload-bearing attacks is no longer a trend – it's a structural shift. 

  • Payload-less Dominance: Investment Fraud ($8.6B) and BEC ($3.04B) combined for $11.64B in losses — attacks that carry no file, no link, and no detectable artifact.
  • Artifact Decline: Ransomware ($32.3M) and Malware ($19M) combined represent less than 0.25% of that damage — a 365:1 financial loss ratio against payload-less threats.

Payload-less crimes (navy) account for $11.64B+ in combined losses versus under $52M for all artifact-heavy threats combined.

AegisAI Response

Our own telemetry confirms the operational reality behind these numbers. Over a recent 30-day period, AegisAI identified 16,620 payload-less threats — just 5.2% of total phishing volume. Yet the attack categories they belong to (BEC and Investment Fraud) account for 56% of the FBI's $20.8B in annual losses.

That is a 10:1 ratio between financial destruction and detection surface. These attacks contain zero scannable artifacts, bypass sandboxing entirely, and succeed not through code execution but through identity exploitation. For the modern adversary, a convincing sentence is more dangerous than a zero-day.

Real World Example: Contextual Fraud Pattern (GitHub)

An autonomous agent identified a financial lure delivered via a GitHub repository commit notification. This notification carried a DMARC: PASS status. We correlated the brand-new repository age with "0rder confirmed" urgency markers, a behavioral fingerprint that legitimate notifications never exhibit. 

Who Is Being Targeted: Victim Demographics

The FBI’s demographic data reveals a clear concentration of high-value fraud targeting the 40–49 age group — peak earning years, senior decision-making roles, and the primary audience for BEC and investment fraud. The 60+ cohort bears the heaviest burden from socially engineered scams where trust is weaponized.

The 40–49 age group dominates BEC and investment fraud victimization. The 60+ cohort is the primary target for tech support and romance scams.

Conclusion: The Identity Pivot

The 2025 IC3 data is more than a dataset. It’s a post-mortem for the legacy security stack. We can no longer protect our organizations by hunting for the "smoking gun" of a malicious file or the linguistic "tells" of broken syntax. The "Perfect Phish" has officially moved past the technical layer and into the psychological one, weaponizing flawless identity to achieve total cognitive capture.

To meet a threat this precise, our defensive architecture must be equally surgical. We have to stop hunting for signatures and start interrogating the semantic DNA of every interaction. At AegisAI we’ve shifted the focus from the artifact to the actor. We have moved beyond simple scanning to deep, intent-based modeling. It’s time to stop looking for what an email contains and start understanding what it intends.

Don’t Miss the Next Big Threat
Subscribe today to receive updates on the newest cyberattacks, product innovations, and best practices for protecting your organization.

Subscribe

Success! We’ll be in touch soon.
Something went wrong while submitting.
Related topic articles
Read All Articles
AegisAI AI-native email security for Microsoft 365 or Google Workspace
Email Security
AI
Cloud Email Security: Microsoft 365 & Google Workspace
AegisAI is API-native cloud email security for Microsoft 365 and Google Workspace. Stop the phishing, BEC, and account takeover that native filters miss.
TIDALGUEST self-replicating phishing worm: a stolen inbox becomes the next trusted sender, spreading through contact lists. AegisAI threat intelligence.
Threat Research
TIDALGUEST: A Self-Replicating Invitation Phishing Cluster
TIDALGUEST is a self-replicating invitation phishing cluster that turns each stolen inbox into a new sender and layers five evasion techniques past URL scanning.
Announcements
Introducing the AegisAI Red Team Agent: Test Your Own People Before an Attacker Does
We built an AI agent that runs spear-phishing the way attackers now run it, against your own people, scoped and approved by your security team, so you see who clicks before a real attacker finds out.