Phishing Recovery Costs Are Climbing as AI Enters the Picture
A newly published study covered on the Fortra security blog reports that phishing and social engineering incidents are becoming significantly more expensive to recover from, harder for security teams to detect, and increasingly augmented by artificial intelligence. The research puts a striking figure on the problem: organizations are facing recovery costs in the range of $5 million tied to these attacks, according to the study cited in the report.
The core finding lines up with what many security practitioners have been warning about for the past two years, generative AI tools have lowered the barrier to producing convincing phishing emails, voice clones, and fake business communications at scale. Attackers no longer need strong English writing skills, careful attention to formatting, or manual research on a target to craft a believable lure. AI models can do that work in seconds, and they can personalize it using publicly available information scraped from LinkedIn, company websites, and social media.
Why This Matters for Healthcare Practices, Tax Firms, and Small Businesses
Phishing has topped incident response reports for years as the leading initial access method for ransomware, business email compromise (BEC), and data theft. What's changing now is the economics of the attack. When a single well-crafted email can be generated instantly and tailored to a specific employee, defenders lose one of their most reliable signals: the awkward phrasing, generic greeting, or obvious spelling errors that used to help staff and email filters catch a scam.
For healthcare practices and tax professionals in particular, this shift is especially concerning. Both sectors handle high-value personal data, protected health information (PHI) and Social Security numbers or financial records, that make them attractive BEC and ransomware targets. A convincing AI-generated email impersonating a vendor, a patient, a client, or even a practice owner can trick staff into wiring funds, resetting credentials, or opening a malicious attachment before anyone notices something is off.
Small-business leaders should also note that recovery costs cited in studies like this one typically include far more than the immediate fraud loss. They often bundle in incident response, forensic investigation, breach notification, legal fees, regulatory follow-up, credit monitoring for affected individuals, and reputational damage. That combination is why a single successful phishing attack can threaten the survival of a smaller organization even when the initial financial theft seems modest.
Key Takeaway
AI is making phishing emails harder to spot by removing the traditional red flags, poor grammar, generic greetings, awkward tone. Staff training and technical filters built around "spotting bad writing" are losing effectiveness. Organizations need to shift toward verifying requests through a second channel and hardening account access, not just teaching people to "look for typos."
What This Means For Your Business
Because the underlying study wasn't published with full methodology details in the source material we reviewed, treat the $5 million figure as an industry cost signal rather than a number that applies uniformly to every organization. The exact impact on any given healthcare practice, tax firm, or small business will depend on its size, the data it holds, and its existing controls. That said, the direction of the trend, costlier, stealthier, AI-assisted phishing, is consistent with guidance already issued by agencies like the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI's Internet Crime Complaint Center (IC3), both of which have flagged business email compromise and phishing as persistent, high-dollar threats for small and mid-sized organizations.
Practical steps Bellator Cyber Guard recommends now:
1. Require out-of-band verification for financial requests. Any request to change payment details, wire funds, or reset credentials that arrives by email should be confirmed by phone using a number you already have on file, not one provided in the message.
2. Deploy phishing-resistant multi-factor authentication (MFA). Passwords and even SMS codes can be phished with AI-assisted kits. Where possible, move toward FIDO2/security-key or app-based authentication for email, financial systems, and EHR or practice management software.
3. Retrain staff around behavior, not appearance. Since AI removes the obvious grammar and formatting mistakes, refocus training on red-flag behaviors: unusual urgency, requests to bypass normal approval steps, and unexpected changes to vendor or payroll banking details.
4. Tighten email authentication and filtering. Confirm your domain has properly configured SPF, DKIM, and DMARC records, and work with your email provider or managed IT vendor to enable advanced phishing and impersonation detection.
5. Build an incident response plan before you need one. Given how much of the reported cost comes from response and recovery rather than the initial fraud, having a documented plan, including who to call, how to isolate compromised accounts, and breach notification obligations under HIPAA or state law, can materially reduce both cost and downtime.
AI is not creating a new category of attack; it's accelerating and refining an old one. The organizations that adapt their verification habits and access controls now will be far better positioned than those relying on employees to "spot the fake" the way they could a few years ago.
People also look for
Keep exploring Phishing & email security
Recognize manipulation, protect email accounts, and give people a clear way to report suspicious messages.
- Common question: what is phishingUnderstand how phishing worksLearn the common phishing types, why they work, and what attackers want.
- Common question: how to spot phishing emailsLearn the warning signs in an emailCheck sender details, urgency, links, attachments, and requests before taking action.
- Common question: email security best practicesUse the email security guideCombine account protection, filtering, safer habits, and reporting procedures.
- Common question: social engineering examplesRecognize social engineering tacticsSee how pretexting, impersonation, urgency, and authority are used to manipulate people.
- Common question: security awareness trainingBuild practical security awarenessHelp employees recognize threats and respond without creating a blame culture.
Learn first. Decide when you are ready.
Keep learning—or apply this to your situation
Continue with a related guide, compare your options, or ask a specialist to help turn the advice into a practical next step.



