Blog de WatchGuard

AI-Generated Phishing Achieves a 54% Click Rate

AI-generated phishing is increasing identity risk. Here's why MFA and Zero Trust are becoming essential for MSP security.

For years, phishing has worked for one simple reason: it exploits the weakest link, the user. The defensive strategy has followed the same formula: better email filtering, more user awareness, and an extra layer of authentication. It wasn't perfect, but it was a workable balance. 

That balance has now been broken. AI-generated phishing is not only growing, it is becoming far more convincing. According to the Microsoft Digital Defense Report 2025, AI-generated phishing campaigns achieve a 54% click-through rate, compared to just 12% for traditional campaigns. What attackers are after with that click is a valid credential. According to Mandiant's M-Trends 2025, stolen credentials became the second most common initial access vector in 2024, accounting for 16% of all intrusions, the highest level ever recorded. Behind this trend is the rise of infostealers, malware specifically designed to steal credentials stored on users' devices. 

Both trends point to the same reality: attackers are targeting credentials, while users are finding it increasingly difficult to distinguish legitimate emails from malicious ones. Identity has become both the target and the gateway. And if your business is protecting other organizations, this becomes your problem before it becomes your customers'. 

When Phishing Stops Looking Like Phishing 

What has changed isn't the volume of phishing attacks, it's the quality of deception. AI has eliminated many of the warning signs that once made phishing attempts easier to identify: spelling mistakes, awkward phrasing, inconsistent formatting, and obviously suspicious URLs. Today's phishing emails are polished, personalized, and tailored to the recipient's context. Many even leverage legitimate services to appear even more authentic. 

There is no longer a single template to block. Campaigns generate unique variations in real time, making it much harder for security filters to identify consistent patterns. The result is phishing that both technology and people struggle to detect as effectively as they once did. 

According to WatchGuard's From IT Support to Cybersecurity Powerhouse: The New Mandate for MSP Growth survey, 91% of organizations are concerned about AI-powered cyberattacks. This is precisely the area where your customers expect you to lead—and where they are increasingly willing to invest. 

Identity Has Become the Primary Entry Point 

The perfectly crafted email isn't the attacker's objective; it's simply the delivery mechanism. What they want is a valid credential, because logging in with legitimate usernames and passwords remains one of the cleanest ways to compromise an organization. 

Once attackers gain access using a legitimate account, their activity often raises little suspicion. To security systems, it looks like a normal login. There's no exploit, no malware, and no obvious alert, just someone who appears to be exactly who they claim to be. 

For managed service providers, this changes the starting point for security. You can no longer assume you'll stop every intrusion before it happens. The healthier assumption is the opposite: sooner or later, one of your customers' credentials will be compromised. That's not pessimism, it's what the data shows. In the same WatchGuard survey, 32% of organizations reported constant exposure to phishing and business email compromise (BEC) attacks. The strategy, therefore, can no longer focus solely on preventing credential theft, but also on limiting the impact when it inevitably occurs. 

Identity Is the New Security Perimeter 

Security awareness training still matters, but it is no longer enough. When phishing emails become virtually indistinguishable from legitimate communications, we're asking users to make increasingly difficult decisions. The problem has become structural, and identity now sits at its center. 

Protecting identity has become the first line of defense. You might think that multi-factor authentication (MFA) should be enough—and to a certain extent, it still forms the foundation. However, push notifications and one-time passcodes have a blind spot. Sophisticated adversary-in-the-middle (AiTM) attacks can intercept both passwords and authentication codes in real time by positioning themselves between the user and the legitimate website. Traditional MFA stops most attacks. These attacks are different. 

Passkeys eliminate that weakness. As a passwordless authentication method, they allow users to authenticate in much the same way they unlock their smartphones, with a fingerprint or facial recognition, while relying behind the scenes on a cryptographic credential tied directly to the legitimate website. There is no password to steal and no authentication code to intercept or replay. Attackers may be able to perfectly clone a website, but they cannot replicate the cryptographic trust that underpins passkeys. 

Passkeys become even more powerful when combined with risk-based access controls that evaluate every authentication attempt based on context, not just the credential itself. Who is logging in? From where? Under what conditions? Even if a credential is compromised, additional safeguards remain in place between the attacker and your customer's critical data. Identity also doesn't exist in isolation; it connects directly with endpoints and the network, which are the other key attack surfaces adversaries exploit. 

This is not simply another item on the cybersecurity checklist. It's where your service becomes indispensable rather than interchangeable. When access control becomes the focal point of security, the provider managing customer identities is protecting the most critical layer of the organization's defenses. That's a strategic service—not just another box to tick. 

A credential may be stolen today by an infostealer and then quietly used weeks later by an attacker logging in as a legitimate employee. Preventing that doesn't require endlessly adding more security tools, it requires moving control to identity, the new security perimeter and the cornerstone of every Zero Trust strategy. That's exactly what the WatchGuard Zero Trust Bundle delivers by bringing together network, endpoint, and identity security into a unified approach, enabling MSPs to move from reacting to customer breaches to preventing them in the first place.