SabiSys - Your Network Is Always On.
Support
Home Services
OverviewCloud & collaborationNetwork & WiFiHardwareInternet & fibreLandline & mobile telephonyMaintenanceBackup & continuity
Managed IT Cybersecurity Security check-up About Blog FAQ Contact Request your free audit
FREN
Security check-up · My IP · Speed test
+32 4 325 51 40 support@sabisys.be Office: Mon-Fri 9am-5pm · SLA clients: extended availability
← All articles Cybersecurity

Turnkey phishing: when AI industrialises the scam

There was a time when you could spot a fraudulent email by its spelling mistakes and its crude layout. That time is over. In 2026, someone with no technical skill at all can launch a professional phishing campaign in an evening, for the price of a tank of petrol. Here is what has changed, and above all what your business can do starting today.

Kits sold for 300 €, ready to use

On messaging apps like Telegram, complete "phishing kits" now circulate, sold for between 200 and 350 euros. For that price, the buyer receives fake Microsoft 365 sign-in pages copied to perfection, a system that captures the password AND the two-factor authentication code in real time, and a dashboard to track their victims. Not a line of code to write. The business model of crime has copied that of software: they no longer hack, they subscribe.

The direct consequence for SMEs: the number of attacks is soaring because the technical barrier has gone. Phishing campaigns generated by AI are produced far faster than those written by hand, and their success rate has risen sharply since consumer language models arrived.

The perfect email, in your language, without a mistake

Artificial intelligence has removed the main clue that used to warn us: the language. A foreign attacker now writes flawless English, adopts the tone of your sector, imitates the signature of a supplier you know and times the message to your billing cycle. The message no longer looks suspicious because, on the surface, it no longer is.

The danger is no longer limited to writing either. Three seconds of an audio clip, taken from a video or a voicemail, are enough to clone a voice convincingly. Businesses have already lost considerable sums after a call or a video meeting in which a deepfake "director" ordered an urgent transfer. For an SME, the most common version stays simpler: a fake call from "IT support" or the "accountant" asking for a code or an access.

The one-sentence takeaway

You can no longer rely on your instinct to spot a scam. Defence no longer rests on vigilance alone, but on technical barriers that protect you even when someone is caught out.

Five habits that still protect your business

The good news is that however sophisticated the attacks have become, the defences that work have not changed: they have simply become essential rather than optional.

  1. Turn on phishing-resistant MFA. Two-factor authentication by SMS or notification is no longer enough against kits that intercept the codes. Physical security keys or trusted-device authentication, on the other hand, block the attack even if the password is stolen.
  2. Close off access from unmanaged devices. With conditional access, only the company's known and compliant computers reach your data. A sign-in page stolen from an unknown PC leads nowhere.
  3. Bring in a call-back rule. Any request for a transfer, a change of bank details or a code is verified through a different channel, using a number known in advance. Never by replying to the email or calling back the number given in the message.
  4. Back up outside Microsoft 365. If an attack succeeds despite everything, an external, tested backup of your emails and files is what separates a manageable incident from a disaster.
  5. Talk to your teams about it, regularly. Not one training session a year that is quickly forgotten, but a short, concrete reminder: showing a real recent example beats a long speech. Your staff are the first target, they can become the first barrier.

Where do you really stand?

Most of these protections already exist in your Microsoft 365 licences. The problem is almost never buying them, but turning them on and configuring them correctly. Our free security check-up places you in three minutes: eleven questions, a score, and your main weak point. And if you would rather talk it through directly, a free, no-obligation audit reviews your whole setup, on site, in an hour.

Want to know whether your business would hold up?

Three minutes are enough to find out.

Take the security check-up
Terms and conditions · SabiSys
Download the PDF

This site uses only technical cookies essential to its operation. No advertising cookies, no tracking.

FREN