Email security tools built for traditional phishing can't catch modern attacks that use no malicious payload and impersonate trusted contacts across voice, video, and collaboration platforms. A January 2026 study by Osterman Research, commissioned by IRONSCALES and surveying 128 security and IT leaders at US organizations with 1,000 to 5,000 employees, found that 88% experienced at least one incident that undermined confidence in their digital communications over the prior year. The report warns that phishing has evolved into a multi-channel, AI-powered threat where attackers deploy autonomous agents to research targets, craft personalized lures, and adapt in real time.
The data reveals a sector under pressure from threats that traditional defenses can't see. Eighty-two percent of respondents said they've noticed heightened threat actor interest in their specific industry, while 60% lack confidence in their ability to counter deepfake attacks even with current training programs. More than half—55%—said a failed response to a trust-based attack raises the likelihood of a full breach, and over a third saw attackers masquerade as a trusted vendor or partner. IRONSCALES analysis of production email traffic shows Microsoft 365 EOP missing 293 phishing messages per 100 mailboxes every 30 days, and Google Workspace missing 350, well above what a well-tuned gateway catches. In a 2026 Dark Reading readership poll, 48% of security professionals ranked agentic AI as the top attack vector for the year, ahead of deepfakes and every other option.
The report documents a shift from phishing that relied on malicious links or attachments—which secure email gateways were designed to block—to attacks that exploit trust and intent. According to the authors, "Phishing 2.0 is bad intent," with no malicious payload to scan, only social engineering that reads as a normal request from a person you trust, making gateways blind to it because there's nothing in the content to flag. The report cites a widely reported case at engineering firm Arup, where an attack opened with a phishing email impersonating the company's UK-based CFO, then escalated to a deepfake video call with what looked like several familiar colleagues, all synthetic, leading an employee to approve 15 transfers worth about $25 million. The study finds that reconnaissance used to cost an attacker time, but agentic AI removes that cost, allowing an agent to summarize a target's public footprint, pull from GitHub and cloud documentation, identify reporting lines, and generate a target-specific pretext in seconds, then repeat the process for the next 10,000 organizations.
The modern attack model breaks traditional detect-and-respond workflows because agents generate personalized, conversational, multi-channel attacks faster than a person can read them, the report explains. In a 2026 study by Crogl and the Ponemon Institute, enterprise SOCs reported an average of 4,330 alerts a day and investigated just 37% of them, making it impossible to out-hire an agent. The report argues defenders need their own agents that preempt attacks by anticipating what's being built, hardening detection before the first message lands, and letting automation handle routine work so humans focus on decisions that need judgment. Microsoft reports that its autonomous alert triage agent identified 6.5 times more malicious emails than manual review and saved one health network more than 200 analyst hours a month. The report recommends extending the threat model past email into voice and video, measuring email security by what reaches the inbox after the gateway rather than what gets blocked at the perimeter, and treating employee training as reconnaissance-aware, since generic simulations teach people to spot generic phishing while the attacks aimed at them are personalized. Organizations that put an agent of their own on the field will be the ones that stop trying to win a speed race against software with human hands alone. The challenge for security leaders is that automation must now mean autonomy, not just better dashboards, because tools that surface more alerts for human review add to the pile rather than subtract from it.

