A business leader’s guide to AI-powered phishing and the identity blind spot most companies don’t know they have.
Let’s begin!
In 2024, U.S. businesses reported $2.77 billion in losses to a single category of attack: business email compromise. That’s a fraudulent wire, a redirected payment, an invoice quietly changed, usually sent from an email account that genuinely belongs to someone at the company. The account is genuine, which is exactly why the request gets honored.
For years, the standard defense against this was straightforward: teach employees to spot the fake. Watch for the misspelled domain, the suspicious link, the login page that isn’t quite right. That advice still matters. But it was built for a version of this threat that is quickly going out of date.
In the newer version, the employee is asked to complete a real login instead of falling for a fake one.
Here’s what that looks like. An employee receives a routine-looking email: a document to sign, a shared file, a security notice. They follow the prompt, land on a genuine Microsoft login page, enter their credentials, and complete multi-factor authentication exactly as they’ve been trained to. Nothing about the process looks wrong, because nothing about it is wrong. It’s a real Microsoft page. The MFA prompt is real. The employee did everything right.
And the attacker still walks away with access to the account.
No password was stolen. No fake page was involved. No malware touched the network. To every security tool watching, from the email filter to the endpoint protection to the MFA check, the login looked clean, because by every technical measure, it was. The compromise is invisible at nearly every layer a business relies on to catch it.
This is what makes the current generation of phishing different, and it’s why “train your people to spot fakes” is no longer a complete answer. The rest of this guide explains how these attacks actually work, why the defenses most companies already have don’t fully cover them, and most importantly, a practical checklist you can use to find out whether your own organization is exposed.
The newest attacks require no mistake at all. They succeed because your employee does everything right.
Attacks like this aren’t brand new. What’s new is how cheap, fast, and convincing they’ve become, and that shift traces directly to how attackers are using AI.
It helps to be precise here, because there’s a lot of noise about AI and cybersecurity. AI has not handed attackers some exotic new superweapon. Verizon’s 2026 Data Breach Investigations Report, which analyzed more than 22,000 confirmed breaches, found that attackers are mostly using AI to scale and refine techniques that already worked rather than to invent new ones.
That’s the honest version of the story, and it’s actually the more concerning one. It means the barrier that used to protect smaller organizations is disappearing. Building a convincing, tailored attack once took real time and real skill.
Three things changed:
The lures got personal, at scale. The old advice to “watch for bad grammar and generic greetings” worked because writing a convincing, customized message for every target was too much work. AI erased that cost. Attackers can now generate a unique, contextually relevant message for every recipient, referencing their role, their projects, and their vendors, as fast as they can send email. There’s no typo to catch anymore.
The barrier to entry collapsed. These capabilities are now sold as subscription products on criminal marketplaces, complete with dashboards and support. An attacker no longer needs technical skill to run a sophisticated, token-stealing campaign. They need a credit card. The kits that abuse the “real login” technique described in this guide have been marketed openly for a few hundred to a few thousand dollars.
The volume is climbing fast. Security researchers at Proofpoint documented this specific technique moving from rare, targeted use to widespread campaigns beginning in September 2025. Microsoft has issued its own advisories on the same pattern and now recommends businesses actively restrict the login method attackers are exploiting. When both Proofpoint and Microsoft are independently flagging the same shift, it’s a real change in the landscape.
There’s a second-order effect worth naming, because it hits mid-market companies especially hard. The same DBIR found that 48% of breaches now involve a third party, a 60% jump in a single year, as attackers exploit the vendors, platforms, and connected accounts businesses depend on.
A compromised account at one company becomes the launch point for an attack on its customers and partners. Your exposure is no longer limited to your own employees. It now extends to every organization whose systems touch yours.
AI removed the cost, skill, and time that used to keep sophisticated attacks rare and out of reach of the people targeting mid-sized companies.
You don’t need to be technical to understand this attack. Here’s the whole thing in four steps.
1. A believable message arrives. An employee gets an email that fits their workday: a contract to review, a shared document, a routine security prompt. It passes the spam filter because there’s nothing malicious in it: no bad link, no attachment, no malware. Just a message and an instruction.
2. The employee completes a real login. The message directs them to enter a short code at a genuine Microsoft sign-in page. They log in and complete MFA, exactly as trained. Every part of this is real: the page, the prompt, the approval. The employee has no reason to suspect anything.
3. The attacker quietly receives the keys. Because the attacker set up the login request behind the scenes, the “access token” the login produces, the digital key that keeps someone signed in, is handed to them, not just to the employee. No password changed hands. The attacker now has a working key to the account, and it bypasses MFA entirely, because MFA already happened.
4. The real damage begins. The attacker reads the mailbox, learns how the business communicates, finds a payment thread or a vendor relationship, and sends a fraudulent request, a changed wire or a redirected invoice, from the employee’s genuine account. By the time anyone notices, the money has often already moved. This is the step that shows up in that $2.77 billion figure.
The uncomfortable part is that at no point in this sequence does anyone do anything obviously wrong. The employee followed their training. The login was legitimate. The tools stayed quiet. The only place the attack left a trace was in the authentication activity itself, an unusual sign-in pattern that most businesses aren’t watching closely, because they’ve never had a reason to. That gap, between “the login was technically valid” and “the login was actually safe,” is the entire problem. It’s also where the defenses in the next section come in.
Every security layer most companies trust, from the email filter to MFA to endpoint protection, sees this attack as normal activity. The only signal is in the sign-in data itself.
If your organization already requires multi-factor authentication, runs email filtering, and trains employees to spot phishing, you’ve done more than many companies your size. Those controls are worth having, and this guide is not an argument against any of them.
But it’s worth being honest about what they were built to do and where this particular attack slips past them.
Multi-factor authentication was designed to stop someone who has stolen a password from using it. It works by requiring a second proof of identity. But in this attack, there’s no stolen password to stop, and the second proof gets completed by the real employee, in real time. MFA does exactly what it was built to do, and the attack is built to let it happen anyway.
Email filtering catches messages carrying something malicious: a bad link, a dangerous attachment, a known-fraudulent sender. The lures in this attack often carry none of those. The message is just text and an instruction, frequently sent from a legitimate or compromised account. There’s nothing for the filter to flag.
Security awareness training teaches employees to recognize fakes. But this attack routes the employee through genuine pages and legitimate prompts, so there is no fake to catch. The single most common instinct we train people to rely on (“does this look real?”) returns the wrong answer here, because everything is real.
Notice the pattern. Each of these defenses is doing its job correctly. The attack succeeds because it was engineered to operate in the space between the controls, in a sequence where every individual step looks legitimate.
That’s why defending against this comes down to closing one specific gap: the ability to see whether a login that was technically valid was legitimate. That means paying attention to the sign-in activity itself: where a login came from, whether it fits the employee’s normal pattern, what happened right after access was granted. Most businesses have never had reason to watch that layer closely. It’s exactly the layer this attack lives in.
This is also where the size and shape of your IT function starts to matter. Watching authentication activity, spotting the subtle anomalies, and responding quickly when something looks off is ongoing work rather than a setting you switch on once. For a lean internal team already stretched across everything else, it’s often the piece that quietly goes uncovered. 93% of mid-market companies report a technology skills shortage, and 56% say it significantly affects them. The gap this attack exploits is frequently the same gap a growing company already feels in its own team.
The attack moves through the space between your defenses, where every single step looks legitimate.
You don’t need to implement all of this yourself, and you don’t need to be technical to use this list. Its purpose is to help you quickly find out where your organization stands, and what to ask the people responsible for your systems. Work through it in three parts.
Part 1: Do this now (this week)
Part 2: Harden over the next quarter
Part 3: Questions to take to your IT team or provider
This is the part most worth your time. You don’t need the technical answers yourself, but you need to know whether someone can give them.
The quality of the answers tells you most of what you need to know. Clear, confident, specific responses are a good sign. Hesitation, vagueness, or “we’d have to look into that” on several of these points is worth taking seriously. It rarely reflects a failure on your team’s part. More often it signals that this particular threat is sitting in a blind spot no one has been resourced to cover.
If you get vague answers to the questions in Part 3, it usually means no one has been given the time and tools to own this specific problem.
If you worked through that checklist and hit questions you couldn’t confidently answer, you’re in good company. You’re looking at exactly the kind of gap this guide was written to surface.
Here’s the honest framing. The attack described in these pages is hard to defend against because covering it well takes ongoing attention that a lean internal team rarely has room for. The fixes themselves are not exotic. Watching authentication activity, restricting the right login methods, responding fast when something looks off. All of it is steady, daily work, and all of it is usually the first thing to slip when a capable team is already stretched across everything else a growing business needs from IT.
That’s the work Macro Connect does. We’re a Detroit-based managed IT partner, and we’ve built our expertise in some of the most demanding, accountability-heavy environments: public school systems, municipalities, and mission-driven institutions where a security failure becomes public as fast as it becomes costly. The disciplines that protect those organizations are the same ones that close the gap this guide describes. We translate that depth into terms a growing company recognizes: fewer surprises, faster response, and a partner who understands what’s at stake when systems go quiet in the wrong way.
We’ll walk through this checklist with you in a focused 30-minute review and give you a straight answer on where your organization is exposed to this class of attack, and what, if anything, is worth doing about it. No pitch, no obligation. You’ll leave with something useful whether we ever work together.
Connect with our team today to get started.
Sources: FBI Internet Crime Complaint Center (IC3), 2024 Internet Crime Report · Verizon, 2026 Data Breach Investigations Report · Proofpoint threat research · Microsoft Security Blog · Node4 2025 Mid-Market Report.