Industry News
AI vs. AI: What the 2026 Email Threat Data Actually Means for Security Strategy
September 24, 2026
Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Every vendor threat report released this year has arrived at roughly the same headline: artificial intelligence is reshaping the email threat landscape, and the defenders are answering with AI of their own. That framing makes for a clean narrative, but it obscures the more useful story sitting inside the data itself. The numbers from Barracuda, Microsoft, CrowdStrike, and Hoxhunt describe something more specific than an arms race between algorithms, and MSPs building 2026 security programs need the specific version, not the slogan.
Is AI Actually Making Phishing Worse, or Just Different?
Both. The volume of AI-assisted phishing is rising sharply in bursts tied to attacker campaigns, but the underlying attack techniques (credential harvesting, QR codes, account takeover) are the same ones defenders have fought for years, now executed faster and at greater scale. That distinction matters because it changes where a security budget should go.
Hoxhunt's 2026 Phishing Trends Report, built from more than 50 million data points across its detection network, found that the share of reported phishing emails showing signs of AI assistance jumped from 4% in November to 56% in December before settling at 40% in January, a pattern the report calls a <a href="https://hoxhunt.com/guide/phishing-trends-report" target="_blank">"14x holiday surge in AI phishing attacks"</a>. That is not a steady climb. It is attackers switching on generative tooling for seasonal campaigns when human attention is already thin. Barracuda's research points to the same acceleration from a different angle: its 2026 Email Threats Report analyzed more than 3.1 billion emails and found that AI-driven social engineering and phishing-as-a-service are <a href="https://www.barracuda.com/reports/2026-email-threats-report" target="_blank">increasing both the volume and effectiveness of email-based attacks</a>. Nearly half of all malicious email activity Barracuda observed in that dataset came from phishing specifically, and one in three messages overall was either malicious or unwanted spam, according to the company's own summary of the findings on its <a href="https://blog.barracuda.com/2026/05/12/ai-phishing-service-changing-email-threat-landscape" target="_blank">Barracuda blog</a>.
How Fast Are Attackers Actually Moving Now?
Fast enough that response time, not detection accuracy, is becoming the bottleneck. CrowdStrike's 2026 Global Threat Report found that the average eCrime breakout time, the gap between initial compromise and lateral movement, fell to 29 minutes in 2025, with the fastest observed case measured at 27 seconds. That is the number security leaders should sit with before reaching for another detection tool.
CrowdStrike's report also found that AI-enabled attacks surged 89% year over year, and it documented incident response at more than 90 organizations where adversaries directly targeted AI development tools and data platforms rather than just using AI to write better lures, according to the company's own <a href="https://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/" target="_blank">2026 Global Threat Report press release</a>. Speed like that turns email compromise into an identity problem almost immediately. Once a credential is harvested, the attacker is not sending a spoofed message from outside the organization. They are logging in and sending mail that clears every authentication check because, technically, it is legitimate. Microsoft's own Q1 2026 threat landscape analysis backs this up directly: credential phishing accounted for 94% of all payload-based attacks Microsoft tracked in March, up from 89% in January, and QR code phishing was the <a href="https://www.microsoft.com/en-us/security/blog/2026/04/30/email-threat-landscape-q1-2026-trends-and-insights/" target="_blank">fastest-growing attack vector</a> the company observed that quarter.
Can Defensive AI Actually Keep Pace?
Partially, and mostly at the filtering layer rather than the identity layer. AI-assisted detection is genuinely better at catching the linguistic and behavioral patterns of AI-generated lures, but it does not fix what happens after a credential is already stolen. That gap is exactly where basic authentication controls, not machine learning, decide the outcome.
This is the part that gets lost in "AI vs. AI" headlines. A phishing email written by a language model still has to get past the same protocols that have existed for over a decade: SPF, DKIM, and DMARC, as defined in RFC 7208, RFC 6376, and RFC 7489 respectively. None of those specifications care whether the message body was written by a human or a model. What they care about is whether the sending infrastructure is authorized to send mail for that domain. And on that front, the industry is still not where it needs to be. Client domains without a DMARC record, or stuck at a permissive p=none policy, offer zero protection against spoofing regardless of how sophisticated the detection layer behind them is.
The Adoption Gap That AI Headlines Obscure
The data on authentication adoption is the least discussed and most actionable number in this whole conversation. According to the EasyDMARC 2025 DMARC Adoption Report, DMARC adoption among the top 1.8 million domains grew from 29.1% to 47.7% between 2023 and 2025, but over half of adopters remain stuck at a policy that provides no real enforcement, a gap documented in detail by DMARC Report's analysis of MSP-scale authentication management. Fewer than half the domains that bothered to publish a record are actually blocking anything.
That gap is the market opportunity and the risk exposure at the same time. Here is how the two data sets line up:
| Metric | 2023–2024 | 2025–2026 |
|---|---|---|
| DMARC adoption (top 1.8M domains) | 29.1% | 47.7% |
| eCrime breakout time (average) | 48 minutes | 29 minutes |
| Credential phishing share of payload attacks | ~89% (Jan 2026) | 94% (Mar 2026) |
| AI-enabled attack growth (YoY) | baseline | +89% |
Read across a row and the strategic picture gets clearer. Attackers are moving faster and relying more heavily on stolen credentials, while the authentication layer that would blunt domain spoofing is still only half-deployed and often misconfigured. Faster attackers exploiting a still-open door is a worse outcome than faster attackers facing a properly enforced one.
What This Actually Means for an MSP Security Program
None of the 2026 data suggests that AI detection tools are unnecessary. It suggests they are being asked to compensate for a foundation that was never finished. An MSP that layers in AI-driven filtering on top of client domains still running p=none DMARC, no DKIM alignment, or a forgotten SPF record with too many includes is treating a symptom while leaving the actual entry point open.
Practical priority order for 2026 client reviews looks like this:
- Audit every client domain's SPF, DKIM, and DMARC configuration, and move enforceable domains from p=none toward p=quarantine or p=reject on a monitored timeline.
- Treat account takeover, not inbound spam, as the primary email risk, since Microsoft's data shows credential phishing now dominates payload-based attacks.
- Monitor DMARC aggregate reports on an ongoing basis rather than a one-time setup, since attacker infrastructure and sending patterns shift constantly.
- Reserve AI-assisted filtering budget for the campaigns authentication cannot stop, like lookalike domains and compromised legitimate accounts.
Scanning every client domain manually for these gaps does not scale past a handful of accounts, which is the exact problem ActiScan was built to solve for MSPs managing dozens or hundreds of domains at once. The platform's getting-started guide walks through connecting a first batch of client domains and reading the resulting authentication findings without requiring a dedicated security analyst on staff. For firms weighing how that fits into existing service tiers, the pricing page breaks down options by domain count rather than forcing a flat enterprise rate onto a ten-client shop.
The 2026 threat data is not an argument for buying more AI. It is an argument for finishing the authentication work that AI cannot substitute for, then layering detection on top of a foundation that actually holds. MSPs that get the order right will spend less time reacting to breakout speeds measured in minutes. Those ready to close the gap can create an account and start scanning client domains today.