New phishing and social engineering techniques in 2025: deepfakes, QRishing, MFA fatigue, and multi-channel attacks. How to defend yourself with an offensive approach.
Phishing is no longer the poorly written email full of grammatical errors.
In 2025, attackers are exploiting AI, deepfakes, and sophisticated psychological techniques to target employees and companies in increasingly convincing ways.
Most traditional controls such as spam filters, annual training, and MFA are no longer sufficient.
Cybercriminals know exactly how to overcome these barriers.
In this article, we analyze new advanced phishing techniques and the critical role of the offensive approach.
Why phishing is so effective today
The attackers perfected three key elements:
1. Extreme customization
Thanks to public information (social media, conferences, LinkedIn) and datasets obtained from previous breaches, the messages are:
- credible
- contextualized
- perfectly consistent with roles and responsibilities
The result? The filters detect nothing and the user remains unsuspecting.
2. Massive use of generative AI
Artificial intelligence is used for:
- write flawless emails in any language
- imitate corporate writing styles
- generate voice deepfakes for spear-phishing calls
- create infected documents that appear legitimate
3. Optimized psychological techniques
Attackers exploit cognitive biases—urgency, authority, familiarity—with great precision.
An "urgent" request from the CFO (via deepfake voice or cloned email) is a classic example.
New phishing techniques that bypass controls
MFA Fatigue Attack
Attackers bombard the user with authentication requests until they approve "by mistake."
Widespread in 2024–2025.
QRishing (QR code phishing)
A simple QR code leads to a perfectly credible clone page.
Many SOCs do not monitor this vector.
Deepfake Voice Phishing
Voice calls with a cloned voice of the CEO or IT manager.
Used to request:
- urgent transfers
- MFA codes
- remote access
Browser-in-the-Browser Attack (BITB)
Login windowidenticalto the official one, but generated in the browser using CSS/JS. Steals MFA credentials and sessions.
Session hijacking using stolen tokens
The attacker does not steal the password, but thesession tokenspresent in the browser.
The victim does not notice anything.
Phishing on internal platforms
False messages about:
- Teams
- Slack
- Notion
- Google Drive
Users tend to trust internal tools more and verify less.
Why traditional security awareness no longer works
Many awareness programs are:
- theorists
- outdated
- predictable
- based on examples that are 5–10 years old
Users can recognize a fake email... butnot a malicious QR codeor avoice request from the CFO that is identical to the original.
A more realistic, practical, and dynamic approach is needed.
How an offense-first team anticipates these threats
The offensive approach is not limited to "explaining phishing," butsimulates real techniquesand measures the company's reaction.
Activities include:
1. Advanced phishing simulations
- voice deepfakes
- multi-channel social engineering
- cloud-based attacks
- scenarios on Teams/Slack
- user behavior analysis
2. Controlled exploitation of human vulnerabilities
Reproduction of real patterns used by attackers.
3. Evaluation of SOC detection
- which attacks are detected
- which go unnoticed
- which logs are missing
- which alerts are noisy or useless
4. Guided remediation
Not only training for users, but:
- hardening of business flows
- MFA improvement
- session token protection
- abnormal traffic monitoring
Users are not the weak link; they become so when systems leave them alone.
Modern phishing is not a matter of naivety: it is designed to deceive even experienced personnel.
Defense requires better tools, more robust processes, and, above all,realistic simulations.
With an offensive and controlled approach, companies can discover their weaknesses before attackers do.


