Recorded Future says filtering, verification and training still blunt most AI phishing, with deepfaked voice and video the exception. Its advice is to stop treating a familiar face or voice on a call as proof of identity.
Reality
- Evidence45
- Adoption40
- Hype gap0
- Incentives45
- Confidence50
Abnormal says iAuthFlow v2 uses a phished Google session to register an operator-controlled passkey. The standard playbook of revoking sessions and resetting the password does not remove it.
Perspective Coverage
3 publishers
- Builder
- Builder 32%
- Operator
- Operator 60%
- Investor
- Investor 8%
Reality
- Evidence52
- Adoption15
- Hype gap+12
- Incentives55
- Confidence58
SOCRadar's teardown of the AnonyMousKIT service found 200 AI-voiced calls at about $0.10 each, most of them to Brazil. The skill in phone social engineering is now a script file.
Perspective Coverage
4 publishers
- Builder
- Builder 19%
- Operator
- Operator 76%
- Investor
- Investor 5%
Reality
- Evidence70
- Adoption40
- Hype gap+35
- Incentives40
- Confidence65
Any.Run's researchers found a phishing kit running in 46 countries whose final payload is a signed copy of ScreenConnect or GoTo Resolve, which moves the defensive question from malware signatures to which remote-access tools may execute at all.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives70
- Confidence60
CloudSEK took administrator access to the panel and counted 5,137 stolen records coming off 42 VPS nodes into five leasing affiliates' Telegram bots, with the phishing pages dark for three weeks while the panel itself stays reachable.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 60%
- Investor
- Investor 10%
Reality
- Evidence55
- Adoption30
- Hype gap+25
- Incentives40
- Confidence60
Microsoft's Digital Crimes Unit and its partners pulled down the EvilTokens phishing service about seven months after it launched, and British police arrested its two suspected operators. The authentication technique it sold survives on other platforms.
Perspective Coverage
8 publishers
- Builder
- Builder 25%
- Operator
- Operator 60%
- Investor
- Investor 15%
Reality
- Evidence66
- Adoption58
- Hype gap+18
- Incentives62
- Confidence64
Malwarebytes found a page promising 10,000 free months of Claude Max that skips the card and collects Google logins through a fake browser window loaded from a rented, actively maintained widget.
Reality
- Evidence58
- Adoption40
- Hype gap+12
- Incentives62
- Confidence66
Microsoft says the phishing-as-a-service platform reached more than 12,000 inboxes at over 10,000 organizations in seven months by abusing a legitimate OAuth flow, and its Digital Crimes Unit has now disrupted the infrastructure behind the service.
Reality
- Evidence58
- Adoption62
- Hype gap+20
- Incentives76
- Confidence57
Island says the adversary-in-the-middle service runs on at least 755 domains against hundreds of organizations. The session it steals arrives after an authentication the identity provider records as entirely normal.
Reality
- Evidence45
- Adoption58
- Hype gap+18
- Incentives65
- Confidence55
The FBI says a subscription kit sold on Telegram harvests Microsoft 365 OAuth tokens through device code lures. The mitigation it recommends is a tenant-wide block, and somebody has to decide the exceptions.
Publishers:fbi.gov
Reality
- Evidence65
- Adoption35
- Hype gap−10
- Incentives25
- Confidence60
Microsoft's researchers describe a device code phishing campaign that minted fresh codes the moment a target clicked, defeating the expiry that used to hold these attacks down. The flow it abuses is only needed by hardware that cannot show a login page.
Reality
- Evidence55
- Adoption45
- Hype gap+20
- Incentives65
- Confidence60
CloudSEK got inside the BigBear 2.0 administrative panel and found more captured Microsoft 365 session cookies than plaintext passwords, along with code written to switch FIDO2 off on the phishing pages.
Reality
- Evidence55
- Adoption58
- Hype gap+12
- Incentives72
- Confidence56
Group-IB says the phishing kit Google sued over in June kept producing pages after the FBI seized its admin servers and wallets, which puts the durable detection signal in the kit's file names rather than its hosts.
Reality
- Evidence44
- Adoption66
- Hype gap+6
- Incentives58
- Confidence46
The claim arrives as a Barracuda-authored commentary with one number behind it. The bill lands on awareness programs whose template libraries and click-rate baselines were built on deliberate typos.
Reality
- Evidence24
- Adoption
- Insufficient
- Hype gap+38
- Incentives76
- Confidence42
Island's write-up describes an adversary-in-the-middle proxy that hands passwords, push approvals and SMS codes to real Microsoft servers, then keeps the cookie Microsoft issues. Origin binding is the only listed control that breaks it.
Reality
- Evidence48
- Adoption40
- Hype gap+18
- Incentives66
- Confidence47
Island says the kit relays Microsoft 365 sign-ins behind genuine Docusign envelopes and legitimate Microsoft or Google redirects, leaving sender reputation nothing to grade.
Reality
- Evidence60
- Adoption58
- Hype gap+18
- Incentives74
- Confidence62
ANY.RUN says a commercial phishing kit ran against Microsoft 365 login flows from 2024 to 2026, harvesting session cookies. The control that matters now is what happens to the token.
Reality
- Evidence30
- Adoption38
- Hype gap+40
- Incentives85
- Confidence52
Okta Threat Intelligence says as-a-service phishing kits now let a caller change what the target sees in real time, synced to genuine MFA prompts. Push and OTP were not built to survive that.
Publishers:okta.com
Reality
- Evidence46
- Adoption28
- Hype gap+22
- Incentives78
- Confidence44