In January 2026, a finance manager at a UK logistics company received a phone call from someone who sounded exactly like her CEO. Same voice, same cadence, same slightly impatient tone when he wanted something done quickly. He asked her to authorise an urgent supplier payment of £47,000. The bank details were in an email he'd just sent.
She authorised it. The money was gone within 20 minutes.
The voice was AI-generated using a publicly available voice cloning tool. The email had spoofed the CEO's address convincingly enough to pass a quick visual check. The "supplier" was a fraudster who had spent approximately £30 setting up the attack.
Voice cloning fraud increased 400% in 2025. Deepfake-as-a-service platforms have made social engineering an industrialised process rather than a craft practised by skilled fraudsters. PanicVault The attacks aren't new in kind. They're new in scale, sophistication, and cost — and the cost is dropping every quarter.
This is the state of cybersecurity in 2026. Here's what actually changed and what actually works.
How AI Changed the Attack Side

Traditional phishing emails were identifiable by bad grammar, mismatched logos, and implausible scenarios. AI removed all three of those tells.
Microsoft screens approximately 5 billion emails per day for threats. In mid-2025, the Tycoon 2FA phishing-as-a-service operation generated approximately 62% of Microsoft-blocked phishing — over 30 million emails in a single month. Microsoft's data confirms that AI-crafted phishing lures show markedly higher user engagement in tests. DeepStrike
That last point is the one that matters. Higher engagement means more people click. More clicks means more compromised accounts. The underlying security weakness — humans trusting convincing communications — hasn't changed. AI just made the communications dramatically more convincing at dramatically lower cost.
The World Economic Forum reports that 94% of survey respondents see AI as the most significant driver of change in cybersecurity, and 77% report an increase in AI-enabled fraud and phishing. Bright Defense
But here's what most security coverage gets wrong: it focuses on AI-powered attacks as if they're fundamentally different in kind from what came before. They're not. They're the same attack vectors — phishing, credential theft, social engineering — made faster and cheaper. The defences that worked before still work. They just need to be applied more consistently, because the volume and quality of attacks has increased significantly.
Meet David: How a Targeted AI Voice Attack Actually Played Out
David is a 44-year-old operations director at a Manchester manufacturing firm. In late 2025, he received a call from "IT support" who knew his name, his manager's name, the name of the software system they used, and the approximate timing of a system migration that was actually underway. The caller said there was a security issue requiring immediate credential verification.
David provided his email credentials. His Microsoft 365 account was compromised within minutes. The attacker used it to send convincing internal emails to the finance team requesting two urgent supplier payments.
The attacker had gathered the background information — names, systems, migration timing — from LinkedIn and a data broker profile, both of which cost nothing to access. The call used an AI voice model. Total infrastructure cost for the attack: under $50 (£40).
Total cost to David's firm: £23,000 in payments, plus forensic investigation costs, plus the two working days lost to remediation.
"The thing that got me," he said, "was that they knew things about us. It felt internal. It didn't feel like a random scam."
That targeted quality is what AI has changed. Random mass phishing is being replaced by personalised attacks at scale. The £40 attack infrastructure scales to thousands of potential targets.
The Attack Landscape in Numbers
APWG observed 3.8 million phishing attacks in 2025. FBI IC3's 2024 report shows 193,407 phishing complaints, with Business Email Compromise losses of $2.77 billion — making BEC the most financially costly cybercrime category. DeepStrike
In 2024, infostealer malware lifted 548 million passwords and 17 billion session cookies from infected devices. A single PC malware infection yields on average 44 passwords and 1,861 cookies. DeepStrike
Despite their clear security benefits, only 36% of US adults use a password manager, leaving the majority reliant on memorisation, browser storage, or insecure habits. ITGuys Team In the UK, 59% of respondents manage passwords using memory alone. Astra Security That's not a niche vulnerability. That's the primary attack surface.
The numbers are large. The defences are not complicated. That gap — between what's known to work and what most people actually do — is where most successful attacks happen.
What Actually Protects You: A Personal Security Audit

This isn't a theoretical framework. These are the five specific actions that meaningfully reduce your attack surface, in priority order.
Action 1 — Use a password manager. Today.
Password manager usage has increased steadily, reaching an estimated 35% of internet users in 2026. PanicVault That means 65% of users are still managing passwords unsafely. A password manager generates and stores unique, complex passwords for every account — meaning a breach of one service cannot cascade to others. This single action eliminates credential stuffing as a viable attack against you.
Action 2 — Enable two-factor authentication (2FA) on email, banking, and cloud accounts.
Multi-factor authentication can stop 96% of bulk phishing attacks and 76% of targeted attacks. Astra Security Those numbers are from Microsoft's own telemetry. It's the highest-return security action available. Enable it on Gmail or Outlook first — email account compromise is the master key that unlocks everything else.
Action 3 — Use an authenticator app, not SMS, for 2FA codes.
SMS-based 2FA is significantly weaker than app-based 2FA. SIM-swapping attacks — where a fraudster convinces your mobile carrier to transfer your number to their device — bypass SMS codes entirely. Microsoft Authenticator, Google Authenticator, and Authy are all free and take about four minutes to set up.
Action 4 — Create a verbal verification protocol with your team and family.
This is the specific defence against the voice cloning attack described above. Agree on a safe word or a personal question that anyone can ask during an unexpected financial or sensitive request over the phone. If the caller can't answer it, the call ends. Low-tech. Highly effective.
Action 5 — Check whether your email address appears in known data breaches.
Visit haveibeenpwned.com — free, no account required. Enter your email address. If it shows breaches, change the password for that account and any others where you used the same password. Then set up the password manager to prevent reuse going forward.
Password Manager Comparison: The Honest One
In February 2026, researchers from ETH Zurich identified critical vulnerabilities in three major cloud-based password managers. The study revealed 25 distinct attacks against Bitwarden, LastPass, and Dashlane that could compromise user vaults, ranging from integrity violations to complete access to all stored passwords — collectively serving over 60 million users and nearly 125,000 businesses. Aviatrix
That's significant. It doesn't mean password managers are unsafe — they're still dramatically safer than not using one. It means the specific manager you choose matters.
Manager | Free Tier | Paid Price | Encryption | UK/EU Data | Post-Feb 2026 Vulnerability |
|---|---|---|---|---|---|
1Password | No (14-day trial) | $2.99/mo (£2.39) individual / $4.99/mo (£3.99) family | AES-256, zero-knowledge | ✓ EU data storage option | Not implicated in ETH Zurich study |
Bitwarden | ✓ Generous free tier | $10/yr (£7.99) premium | AES-256, open source, audited | ✓ Self-host option available | Implicated — patches released March 2026 |
NordPass | ✓ Limited free | $1.49/mo (£1.19) on annual plan | XChaCha20, zero-knowledge | ✓ European company, EU storage | Not implicated |
Dashlane | ✓ 1 device free | $4.99/mo (£3.99) | AES-256, zero-knowledge | ✓ EU storage | Implicated — patches released March 2026 |
Honest verdict: For individuals, 1Password at $2.99/month (£2.39) is the most trustworthy mainstream option in 2026, was not implicated in the ETH Zurich vulnerabilities, and has a strong independent audit record. For users who need a free tier — and are comfortable with the February 2026 caveat being patched — Bitwarden's open-source model and self-hosting option remain its strongest distinguishing features. LastPass has had two major breach incidents in recent years and is difficult to recommend.
UK vs US: Reporting Cybercrime and Your Rights

The regulatory context differs significantly.
UK: Report cybercrime to Action Fraud (actionfraud.police.uk) — the national reporting centre. For data breaches affecting your personal data, you have rights under UK GDPR: the right to be informed within 72 hours if a breach is likely to affect you, the right to access your data, and the right to request deletion. The ICO can be contacted at ico.org.uk if you believe a company has mishandled your data.
US: Report cybercrime to the FBI's Internet Crime Complaint Center (ic3.gov). Under FTC regulations, companies experiencing data breaches must report certain breaches to the FTC and, in many states, notify affected individuals. The specific requirements vary by state.
VPN caveat: VPNs are frequently marketed as a comprehensive privacy solution. The honest answer is more limited. A VPN encrypts traffic between your device and the VPN server — useful on public Wi-Fi, useful for geographic restrictions, not a meaningful defence against phishing or credential theft. If you're evaluating VPNs for UK privacy: look for providers based outside the Five Eyes intelligence alliance, with independently audited no-logs policies. Mullvad (based in Sweden, €5/month) and ProtonVPN (Switzerland, £4.99/month) meet both criteria and have published independent audits.
What Most Security Guides Miss
Most reviews focus on password manager features and VPN speed. What they don't mention: the highest-risk attack vector for most UK professionals in 2026 isn't a technical exploit. It's a social engineering call that exploits urgency and authority — and no piece of software protects you from that.
The specific defence: slow down any unexpected request involving money, credentials, or sensitive data. Create friction deliberately. Call back on a number you look up independently, not one provided by the caller. Wait 24 hours on any unusual financial request. These aren't technical solutions. They're procedural ones. And they're what actually stopped similar attacks at the firms I spoke to that had successfully resisted.
Conclusion
AI has made social engineering attacks more convincing and cheaper to run — but the underlying vulnerabilities haven't changed.
Strong unique passwords, MFA on everything, and healthy scepticism about unexpected requests remain the correct defences.
A password manager is no longer optional.
Credential stuffing attacks — where stolen passwords are reused across services — accounted for 22% of all data breaches in 2024, the single most common breach vector. DeepStrike A password manager eliminates this attack category against you.
MFA stops 96% of bulk phishing attacks.
That's not a marketing claim — it's Microsoft's own telemetry from billions of accounts. Enable it on email first. Do it today.
Your next action: Open haveibeenpwned.com. Check your primary email address. If you appear in any breaches, spend 30 minutes this week setting up 1Password ($2.99/month, £2.39) and enabling an authenticator app for your email account. That combination addresses the two most common attack vectors at a cost of approximately three coffees a month.