One Phishing Email Cost This Company $100 Million

In 2023, MGM Resorts was brought to its knees — not by a sophisticated zero-day exploit, but by a phishing email and a follow-up phone call. Threat actors from the Scattered Spider group used social engineering to trick an IT help desk employee, ultimately leading to a ransomware attack that cost the company over $100 million in losses. One conversation. One moment of misplaced trust. Nine figures gone.

If you think your organization is too small, too obscure, or too well-protected to fall for a phishing email, I've got bad news. The Verizon 2024 Data Breach Investigations Report found that 36% of all data breaches involved phishing — making it the top initial attack vector for yet another year. And in 2026, these attacks are faster, more personalized, and harder to detect than anything we saw even two years ago.

This post breaks down what a phishing email actually looks like today, why your current defenses are probably failing, and what I've seen work in real-world environments to stop the bleeding.

What Is a Phishing Email in 2026?

A phishing email is a fraudulent message designed to trick the recipient into revealing sensitive information, clicking a malicious link, or downloading malware. In 2026, these messages are often generated or refined using AI tools, making them nearly indistinguishable from legitimate business communications.

Gone are the days of misspelled Nigerian prince scams. Today's phishing emails impersonate your CEO, your HR department, your cloud provider, and even your security team. They reference real projects, use correct branding, and arrive at exactly the right moment — like during open enrollment or a vendor migration.

The Anatomy of a Modern Phishing Email

Here's what I typically see when dissecting phishing emails that successfully bypassed filters in client environments:

  • Spoofed or lookalike sender domain: Instead of @company.com, it's @cornpany.com or @company-hr.com.
  • Urgency or authority: "Your account will be locked in 2 hours" or "The CFO needs this wire transfer completed today."
  • Credential theft landing page: A pixel-perfect replica of Microsoft 365, Google Workspace, or Okta login screens hosted on a freshly registered domain.
  • Minimal attachments: Modern phishing avoids attachments that trigger antivirus. Instead, they use embedded links or QR codes.
  • Thread hijacking: Attackers compromise one mailbox, then reply to existing email threads with malicious links. The recipient sees a familiar conversation and trusts it.

Why Your Email Filters Aren't Enough

I hear it constantly: "We use Microsoft Defender" or "We have Proofpoint — we're covered." These tools are essential layers, but they are not silver bullets. According to a 2024 report from CISA, threat actors routinely test their phishing campaigns against popular email security gateways before launching them — the same way malware authors test against antivirus engines on VirusTotal.

Here's the uncomfortable reality: email filters catch known threats. They struggle with novel phishing emails — especially those that use clean URLs at send time and weaponize them hours later, or those that embed malicious content inside password-protected attachments.

If your entire anti-phishing strategy is a technology layer, you have a single point of failure. And that single point fails regularly.

The $4.88M Lesson Most Organizations Learn Too Late

IBM's 2024 Cost of a Data Breach Report pegged the global average cost of a data breach at $4.88 million — the highest figure ever recorded. Phishing was the second most expensive initial attack vector. These aren't abstract numbers. They represent forensic investigation fees, legal costs, regulatory fines, customer notification expenses, and years of reputational damage.

In my experience working with mid-market companies, the organizations that get hit hardest are those that treated security awareness as a checkbox exercise. They ran one training session per year, never conducted a phishing simulation, and assumed their employees would "just know" not to click.

Your employees won't "just know." That's not a criticism of your people — it's a recognition that social engineering exploits human psychology, not human stupidity. Even security professionals fall for well-crafted phishing emails. The difference is preparation.

What Actually Stops Phishing Emails from Succeeding

After years of incident response and security program development, here's the layered approach I've seen deliver measurable results.

1. Continuous Security Awareness Training

Annual training is dead. It doesn't change behavior. What works is continuous, role-specific training that teaches employees to recognize phishing emails in context — not in a sterile classroom setting. I recommend enrolling your team in a structured cybersecurity awareness training program that covers social engineering, credential theft, ransomware tactics, and real-world case studies.

Training should be short, frequent, and directly tied to the threats your industry faces. A 5-minute module every two weeks outperforms a 2-hour annual seminar every single time.

2. Regular Phishing Simulations

You can't measure what you don't test. Running regular phishing simulations shows you exactly which departments, roles, and individuals are most vulnerable. More importantly, it creates a feedback loop — employees who click learn immediately what they missed.

Our phishing awareness training for organizations includes simulation-ready scenarios designed to mirror the actual phishing emails your employees will encounter. It's practical, not theoretical.

3. Multi-Factor Authentication Everywhere

Even when a phishing email successfully steals credentials, multi-factor authentication (MFA) can stop the attacker from using them. Deploy phishing-resistant MFA — like FIDO2 security keys or passkeys — across all critical systems. SMS-based MFA is better than nothing, but it's vulnerable to SIM-swapping attacks.

4. Zero Trust Architecture

A zero trust approach assumes that any user, device, or network segment could be compromised. This means verifying every access request, limiting lateral movement, and enforcing least-privilege access. When an attacker does get in through a phishing email, zero trust limits the blast radius.

5. Rapid Reporting and Response

Make it dead simple for employees to report suspicious emails — a one-click button in Outlook or Gmail. Then make sure your security team actually triages those reports within minutes, not days. The window between a phishing email landing and credentials being exfiltrated to a threat actor's server is often under 60 seconds. Speed matters.

How to Tell If an Email Is Phishing: A Quick Checklist

This is the checklist I give to every client. Print it. Pin it next to every monitor in your office.

  • Check the sender's actual email address — not just the display name. Hover over it.
  • Look for urgency or threats: "Act now or lose access" is almost always a red flag.
  • Hover over links before clicking. Does the URL match the supposed sender's domain?
  • Watch for generic greetings like "Dear Customer" from services that know your name.
  • Be suspicious of unexpected attachments, especially ZIP files, Office docs with macros, or HTML files.
  • Verify out-of-band. If your CEO emails asking for a wire transfer, call them on a known number. Every time.
  • Trust your gut. If something feels off, report it. Better a false alarm than a data breach.

AI-Generated Phishing: The Threat Multiplier

I need to address the elephant in the room. AI has fundamentally changed the phishing landscape. Threat actors now use large language models to generate phishing emails that are grammatically perfect, contextually appropriate, and available in any language. The old advice to "look for spelling errors" is nearly obsolete.

AI also enables personalization at scale. An attacker can scrape your LinkedIn profile, your company's press releases, and your recent conference appearances, then generate a phishing email that references a specific project you're working on. This level of targeting used to be reserved for nation-state actors. Now it's available to anyone with a laptop.

The only reliable defense against AI-generated phishing is a well-trained human who questions everything — combined with technical controls that verify identity independently of email content.

The Bottom Line: Layers Win, Luck Doesn't

No single tool, training, or policy will stop every phishing email. What works is defense in depth: technical controls that catch what they can, trained employees who catch what technology misses, and incident response processes that limit damage when something slips through.

I've seen organizations with million-dollar security budgets get compromised by a single phishing email because they neglected the human layer. And I've seen 50-person companies with modest budgets stay clean for years because they invested in consistent training and built a culture where reporting suspicious emails was celebrated, not punished.

Start by assessing where you are today. Run a phishing simulation. Enroll your team in phishing awareness training. Deploy MFA on every account that matters. Then do it again next quarter. Security isn't a destination — it's a practice.

The next phishing email targeting your organization is already being drafted. The only question is whether your people will recognize it.

Further Reading