22:50 18 February, 2026Phishing has long since stopped being primitive emails filled with typos and suspicious links. Today, attackers create messages that look flawless: proper tone, official logos, personalization, and perfect grammar in Russian — or any other language. The main driver behind this evolution is artificial intelligence. Dmitry Penzov, an ethical hacker and technical director of ATLAS, explained this to Gazeta.Ru.
According to Penzov, modern phishing emails are increasingly disguised as messages from marketplaces, banks, delivery services, or corporate platforms. AI enables attackers to:
“Attacks are often extremely well disguised as legitimate sources, and artificial intelligence is increasingly used in their preparation. It allows the creation of persuasive texts, replication of official mailing styles, and even personalization of messages. As a result, even information security specialists cannot always immediately detect the deception. When an email appears to come from a familiar ‘official’ service, people tend to lower their guard,” Penzov noted.
Previously, creating a high-quality phishing scenario required hours or even days of work from copywriters and designers. Now AI can do it in minutes — and at massive scale.
“If earlier it took time to develop a high-quality attack scenario, AI now allows this process to be automated and scaled almost instantly. So the number of attacks will certainly not decrease — on the contrary, it will continue to grow,” the expert warned.
AI does more than just write text — it can now generate realistic images, voice messages, and even short videos (deepfakes). These tools are used in combined attacks: an email is followed by a phone call using a cloned voice, then a video confirmation. The victim receives multiple “proof points” of legitimacy, significantly increasing the likelihood of clicking a malicious link.
In addition, AI helps bypass traditional spam filters and antivirus systems. The text appears natural, without the typical phishing red flags such as excessive capital letters, spelling mistakes, or suspicious domains.
Penzov stresses that speed is critical.
“The most important thing is to act quickly. If you clicked on a suspicious link, immediately stop any further actions: do not enter passwords, do not download files, disconnect from the internet. If you have already entered your credentials, urgently change your passwords, revoke active sessions, and, if possible, isolate the device. This must be done without hesitation.”
According to him, clicking a link is not yet a disaster. The real catastrophe begins when an attacker gains access to accounts — and especially to backup data.
“Clicking a link is not yet a catastrophe. The catastrophe begins when an attacker gains access to accounts and backup data. That’s why time plays a decisive role in such situations. Recently, after a phishing attack, the attacker eventually targets backup systems. The key question after an incident is: was there unauthorized access to data, and were recovery mechanisms compromised?”
Phishing is becoming more dangerous because of AI. Attackers can now create emails that are nearly indistinguishable from legitimate ones, personalize them, and distribute them at scale within minutes. Even professionals do not always recognize the deception at first glance.
Dmitry Penzov, ethical hacker and technical director of ATLAS, warns that attacks will only increase. The most important defense is immediate action: disconnect from the internet, change passwords, and revoke active sessions. Above all, prevent attackers from accessing backup systems — this is often the ultimate target of modern phishing campaigns.