Phishing is no longer limited to technically skilled criminals building fraudulent campaigns from scratch. Through phishing-as-a-service (PhaaS), attackers can rent ready-made infrastructure and tools that allow them to impersonate trusted organisations, harvest credentials and target victims at scale.
Phishing attacks use social engineering to persuade victims to surrender sensitive information. The lure can arrive through an email, text message, phone call, QR code, fake website or malicious application, often impersonating a bank, employer, delivery company or another trusted entity. Stolen passwords, financial details and authentication information can then be used for account takeovers, fraud, identity theft or further attacks.
The emergence of PhaaS has made this process considerably easier.
PhaaS lowers the barrier for cybercriminals
Instead of developing an operation independently, criminals can purchase packages containing fake login pages, legitimate-looking email templates, phishing-site hosting, target lists and setup instructions. Some providers also offer technical assistance and campaign-management capabilities.
The model mirrors legitimate software-as-a-service businesses, except the product is designed to facilitate cybercrime. Microsoft describes the wider cybercrime-as-a-service economy as increasingly commercialised, with specialised services allowing criminals to outsource different parts of an attack.
This creates a multiplier effect. Criminals with limited technical expertise can deploy infrastructure developed by more experienced operators, allowing phishing campaigns to reach far more people than a small group of skilled attackers could target independently.
The threat is therefore not simply that individual phishing messages are becoming more convincing. It is that the number of people capable of launching campaigns is increasing.
PhaaS is evolving beyond password theft
Modern phishing services can also target authentication sessions rather than simply collecting usernames and passwords.
Adversary-in-the-middle attacks, for example, place attacker-controlled infrastructure between a victim and the legitimate authentication service. The victim may still complete the expected login and MFA process, while the attacker attempts to capture authentication information or session tokens that can later be used to access the account.
Microsoft has documented phishing campaigns in which attackers captured tokens generated during legitimate authentication, demonstrating why stolen credentials are not the only concern.
The scale of these operations was illustrated in March 2026 when authorities disrupted Tycoon 2FA, a PhaaS platform that facilitated phishing attacks against nearly 100,000 organisations. Europol said the service generated tens of millions of phishing emails each month and, by mid-2025, accounted for roughly 62% of phishing attempts blocked by Microsoft.
AI is making familiar warning signs less reliable
Artificial intelligence is adding another advantage for attackers by making social-engineering content faster and easier to produce.
Poor grammar and spelling mistakes were once common indicators of phishing. Generative AI can now produce polished messages in seconds, allowing criminals to create more convincing communications and adapt them to different targets. Microsoft has reported that cybercriminals are using AI to automate phishing and generate synthetic content.
Users therefore need to focus less on whether a message is grammatically correct and more on what it is asking them to do.
Unexpected requests for passwords, payment information, verification codes or urgent account actions should be independently verified. Links should be inspected before opening, while sensitive websites are safer to access directly rather than through unsolicited messages. Unexpected attachments should also be treated cautiously.
Defence must account for stolen credentials
Basic security practices remain important, but organisations should also assume that phishing attempts will occasionally succeed.
Unique passwords stored in a password manager can limit the damage caused by credential reuse, while multifactor authentication adds another layer of protection. However, phishing-resistant authentication such as passkeys and FIDO-based methods provides stronger protection against attacks designed to capture authentication information.
Microsoft says phishing-resistant MFA can stop more than 99% of attacks of this type even when attackers possess the password.
Organisations should also monitor unusual account activity, remove unnecessary accounts and minimise user privileges so that compromised credentials do not automatically provide extensive access.
PhaaS has therefore changed more than the technical mechanics of phishing. It has changed who can conduct these attacks and how easily they can be scaled. As criminal infrastructure becomes increasingly commercialised and AI reduces the effort required to produce
[…]
Content was trimmed to protect the source. Please visit the original article for the full text.
Read the original article: