AI is making phishing harder to spot, and Aussies are falling for it

AI is transforming phishing from clumsy spam into convincing, personalised deception. And Australians are falling for it. A recent survey shows 46% engaged with phishing messages in the past year. Among Gen Z, it’s 62%. When shown a simulated phishing email, over half couldn’t tell it was fake, and 35% believed it came from a trusted source.

 

This isn’t just a tech problem. It’s a behavioural one.

 

The Authentication Gap

Despite widespread distrust in passwords, they remain the default. Over half of Australians still use them for work and personal accounts. MFA adoption is inconsistent: only 55% report workplace-wide use, and 31% haven’t enabled MFA on personal email accounts, despite using those accounts for banking, shopping, and social media.

 

Modern MFA, including device-bound passkeys, offers phishing-resistant protection. But uptake is slow. The gap between awareness and action is leaving critical systems exposed.

 

Training Isn’t Reaching the Frontline

41% of employees say they’ve received no cybersecurity training. After engaging with a phishing attempt, only 15% adopted MFA. Just 18% reported the incident. These numbers point to a deeper issue: even when people recognise the threat, they don’t know what to do next.

 

Organisations may offer secure options, but without consistent training and behavioural reinforcement, those options go unused.

 

Cybermate’s Approach: Behavioural Nudges That Stick

Cybermate doesn’t just detect threats. We help users respond. Our platform guides people through real-world decisions, flagging suspicious messages, prompting MFA setup, and encouraging reporting. Because security isn’t just about knowing what’s risky. It’s about doing something about it.

 

What Needs to Change

  • MFA must become the default, not the exception
  • Training must be practical, ongoing, and behaviour-focused
  • Reporting must be normalised, not stigmatised
  • Platforms must support users in real time, not just after the fact

 

Phishing is evolving fast. AI is making it harder to spot. But with the right behavioural tools and sector-savvy support, we can close the gap between awareness and action.

EXPLORE THE BLOG

Don't wait for a cyber attack to happen

Protect yourself from cyber threats with cybermate today

No credit card required