
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
AI-generated phishing attacks have led to successful breaches in Australian and Singaporean enterprises, despite high awareness and detection rates among tech professionals. Reports show up to 58% of organizations in Singapore and 43% in Australia suffered AI-driven phishing incidents, highlighting vulnerabilities in legacy authentication practices.[AI generated]
Why's our monitor labelling this an incident or hazard?
The article explicitly states that 44% of respondents experienced AI-driven attacks in the past year, and that AI-generated phishing emails are making social engineering attacks more effective and harder to detect. This constitutes realized harm to organizations and individuals, including breaches involving stolen credentials. The AI system's use in generating phishing content is a direct contributing factor to these harms. Hence, this qualifies as an AI Incident under the framework, as the AI system's use has directly led to harm to communities and organizations through social engineering and data breaches.[AI generated]