"Cloudy with a chance of Skynet"


.avif)
📅 March 31st, 2026
Join Petri Kuivala, CISO Advisor, and David Badanes, Human Risk Management Advisor, for a deep dive into the stats and trends that are defining 2026, as revealed by over 50 million simulated and real threat reports from over 4 million users globally.
One might call the cyber threat forecast for the first 11 months of 2025, “Cloudy with a chance of Skynet.” Contrary to headlines and hyped-up marketing campaigns, Hoxhunt analysis revealed that under 5% of attacks on our 4 million users each month were AI-generated – until Christmas, that is.
In December, the forecast darkened into a thunderhead. Hoxhunt analysts uncovered a 14X surge in AI-generated phishing attacks that bypassed email filters and landed in inboxes. Their proportion of all reported attacks across the Hoxhunt global threat detection network soared from 4% to 56% over the holiday season.

The good news is that phishing and social engineering risk can be measurably reduced when training is designed for behavior change and personalized to the employee’s background and skill level. We must build cyber muscles for self-defense skills; not force awareness exercises for compliance tick-boxes.
After adopting a security behavior change program over a SAT model (quarterly, manual, static trainings), employees recognize and report social engineering attacks with a 6X improvement in 6 months, according to Hoxhunt data. They reduce the number of malicious clicks by 87%.
The biggest human cyber-risk is neglecting your humans. Leaving them unattended enlarges the greatest risk factor in cybersecurity.
🔍 See the year’s most successful phishing lures — Recruitment scams, .ics Calendar Attacks, callback attacks, and more
📈 Learn which file types and services attackers abused most, including a 50x surge in weaponized SVGs and the growing misuse of legitimate platforms like Salesforce
🤖 Understand how AI changed phishing content quality, raising the baseline of believability--and how the same technology can be used for defense
🧠 Get the defender’s playbook for 2026, from token-centric defenses to behavior-first awareness programs that teach users to pause, verify, act.
👤 Petri Kuivala — CISO Advisor, Hoxhunt (former CISO, Nokia)
👤 David Badanes — Human Risk Management Advisor, Hoxhunt
👤 Eliot Baker — Director of Content Marketing, Hoxhunt
Reserve your seat now and make sure to prep for the session with Hoxhunt’s Phishing Trends Report 2026— and see how human risk, AI, and attacker tactics evolved across millions of real-world incidents.

Petri has been a world-leading CISO since the dawn of Nokia's mobile industry dominance.
David is an experienced leader of global enterprise-scale security awareness and human risk management programs.
Eliot has an extensive background in science, journalism, and cybersecurity
Subscribe to our newsletter for a curated digest of the latest news, articles, and resources on human risk and the ever-changing landscape of phishing threats.
"Cloudy with a chance of Skynet"
📅 March 31st, 2026
Join Petri Kuivala, CISO Advisor, and David Badanes, Human Risk Management Advisor, for a deep dive into the stats and trends that are defining 2026, as revealed by over 50 million simulated and real threat reports from over 4 million users globally.
One might call the cyber threat forecast for the first 11 months of 2025, “Cloudy with a chance of Skynet.” Contrary to headlines and hyped-up marketing campaigns, Hoxhunt analysis revealed that under 5% of attacks on our 4 million users each month were AI-generated – until Christmas, that is.
In December, the forecast darkened into a thunderhead. Hoxhunt analysts uncovered a 14X surge in AI-generated phishing attacks that bypassed email filters and landed in inboxes. Their proportion of all reported attacks across the Hoxhunt global threat detection network soared from 4% to 56% over the holiday season.

The good news is that phishing and social engineering risk can be measurably reduced when training is designed for behavior change and personalized to the employee’s background and skill level. We must build cyber muscles for self-defense skills; not force awareness exercises for compliance tick-boxes.
After adopting a security behavior change program over a SAT model (quarterly, manual, static trainings), employees recognize and report social engineering attacks with a 6X improvement in 6 months, according to Hoxhunt data. They reduce the number of malicious clicks by 87%.
The biggest human cyber-risk is neglecting your humans. Leaving them unattended enlarges the greatest risk factor in cybersecurity.
🔍 See the year’s most successful phishing lures — Recruitment scams, .ics Calendar Attacks, callback attacks, and more
📈 Learn which file types and services attackers abused most, including a 50x surge in weaponized SVGs and the growing misuse of legitimate platforms like Salesforce
🤖 Understand how AI changed phishing content quality, raising the baseline of believability--and how the same technology can be used for defense
🧠 Get the defender’s playbook for 2026, from token-centric defenses to behavior-first awareness programs that teach users to pause, verify, act.
👤 Petri Kuivala — CISO Advisor, Hoxhunt (former CISO, Nokia)
👤 David Badanes — Human Risk Management Advisor, Hoxhunt
👤 Eliot Baker — Director of Content Marketing, Hoxhunt
Reserve your seat now and make sure to prep for the session with Hoxhunt’s Phishing Trends Report 2026— and see how human risk, AI, and attacker tactics evolved across millions of real-world incidents.

Petri has been a world-leading CISO since the dawn of Nokia's mobile industry dominance.
David is an experienced leader of global enterprise-scale security awareness and human risk management programs.
Eliot has an extensive background in science, journalism, and cybersecurity