Threat Intelligence

AI Lets Scammers Send 1 Million Personalized Fraud Emails in Days

Dark Reading · 12 Sept 2026
Key Takeaway Train employees to verify unexpected requests through a separate channel rather than relying on spotting obvious phishing red flags, since AI-crafted emails may no longer contain them.

Security researchers have identified a fraud campaign in which a threat actor used artificial intelligence to produce one million personalized phishing emails within just three days. Traditionally, scammers had to choose between sending large volumes of generic emails or crafting smaller batches of convincing, tailored messages. AI now removes that trade-off, allowing attackers to combine scale with credibility.

This shift matters for small and medium businesses because personalized emails are far more likely to bypass spam filters and trick employees than generic mass mailings. AI-generated messages can reference specific details, mimic natural writing style, and adapt content for different recipients automatically, making traditional warning signs of phishing, such as poor grammar or obviously generic greetings, less reliable.

As AI-powered fraud campaigns become easier and cheaper to run at scale, businesses of all sizes should expect more convincing phishing attempts landing in employee inboxes, not just from sophisticated attackers but from opportunistic ones using accessible AI tools.

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.