Phishing as a service (PhaaS) is a criminal business model in which a provider sells or rents, by subscription, ready-made kits to launch phishing campaigns: email templates, fake login pages, sending infrastructure and dashboards to collect the stolen credentials. There are more attacks for a simple reason: the model lowers the barrier to entry. Someone who once needed to know how to code now pays a monthly fee and operates as if a technical team were behind them, so the volume and the quality of email phishing rise at the same time.
If you run security for a mid-size company in the region, this explains why the feeling of "more emails arrive every time, and better made" is not an impression: it is a market. Below we take that market apart piece by piece, and explain why the point of defense is still the same as always.
What phishing as a service (PhaaS) is in one sentence
Phishing as a service is the criminal version of subscription software: a provider packages everything needed to deceive a person and steal their credentials, and rents it to other attackers who lack the skills to build it themselves. The buyer codes nothing. They pick a template that impersonates a known brand, point it at a list of emails and launch. The provider charges the subscription and, in many cases, keeps a cut of what is stolen.
Human risk is managed automatically.
Turn human risk into your first line of defense.
Book a demoFree demo · 30 minutes · No commitment
The analogy with legitimate software is exact, and that is why the term stuck. Just as a company hires a cloud tool instead of building its own, the attacker "hires" the ability to run phishing instead of learning how to do it. The result is an economy of scale: a single well-built kit can feed hundreds of campaigns from dozens of different operators.
How the attacker's subscription model works
The PhaaS provider operates like any digital business, only on the wrong side. It maintains the infrastructure, updates templates when a brand changes its design, evades email filters and offers support to its "customers". The operator who pays simply aims and fires.
A typical kit bundles, in a single package, several components that used to require separate assembly: email templates that copy banks, cloud providers and payroll services; fake login pages nearly identical to the real ones; a sending system that rotates domains and servers to avoid getting burned; and a dashboard where the operator sees in real time which victims fell and which credentials they handed over. The most advanced kits even intercept the second authentication factor at the moment the person types it, which lets them get in even when the account has two-step verification.
What matters for the defender is not the technical detail of each kit, but the consequence: the attack stopped being handmade. When something becomes a product with a provider, support and updates, it stops depending on one individual's talent and starts to scale like any industry.
Why the barrier drops and the volume rises
Setting up a credible phishing campaign used to demand time, technical knowledge and dedicated infrastructure that burned out fast. That friction limited how many attackers there were and how many emails they could send. The subscription model removes the friction: anyone with a card and bad intentions gains access to tools that were once for specialists.
When the cost of entry drops, more players come in, and more players mean more campaigns. It is not that each attacker is smarter, it is that there are now many more attackers, each launching more emails with less effort. That is why volume grows in a way that individual skill alone does not explain. As we cover in our review of the year's phishing statistics, malicious email is not in retreat: it is being industrialized.
For a mid-size company this has a direct reading. The "we are too small for anyone to bother attacking us" reasoning stops holding when attacking takes no effort. When the attack is a low-cost service, the size of the victim matters less: email lists are bought, and a seventy-person company is on those lists just like a seven-thousand-person one.
Why the emails are more and more believable
The other half of the problem is not the quantity, it is the quality. PhaaS kits compete with each other, so their providers improve the templates to get past filters and fool more people. On top of that comes artificial intelligence, which drafts emails without the spelling mistakes and clumsy translations that used to give a phishing message away. According to the Microsoft Digital Defense Report 2025, AI-driven phishing is now three times more effective than traditional campaigns.
The old advice of "be suspicious if the email has typos" no longer protects. The modern lure is well written, uses the right logo, cites a plausible context and arrives at a believable moment. When the trap is indistinguishable from a real email, the defense cannot depend on the person "noticing something off" in the text, because there is less and less to notice. We treat this in detail in our piece on AI phishing and deepfakes, where the point is the same: the attacker raised the realism, and the defense has to shift from the "trained eye" to trained behavior.
What does NOT change: email is still the way in
With so much noise about industrialization and AI, it is easy to forget the most stable fact of all: the entry point did not change. According to CISA, more than 90 percent of successful cyberattacks begin with a phishing email. PhaaS makes that email more frequent and more believable, but it does not invent a new channel: it perfects the one that already worked.
This is strategically good news, because it means the place to defend does not move. The surface widens (fraud by text message, by phone call, by QR code appears), but these add to email, they do not replace it. And behind each of those channels there is a constant: a person deciding, under pressure, whether to click or not. Cisco's 90-5-5 framework, which estimates that close to 90 percent of breaches involve a human factor, points to the same place. The attacker's technology evolves; the human decision it wants to trigger is always the same.
What your team can do when phishing is industrial
If the attacker scaled up their operation, the defense cannot keep being an annual course and a poster in the kitchen. When malicious email is a market product, the question stops being "does our staff know what phishing is?" and becomes "how do they behave when a well-made one arrives, and is that behavior improving?".
That shift has three practical implications. The first is to train behavior under pressure, not theory: the person needs to recognize and report a realistic lure, not recite a definition. The second is to assume the credential will leak at some point (through a third party, through password reuse, through a kit that captured it) and actively watch whether it already happened, instead of finding out months later. The third, and the most ignored, is to verify that the learning stuck.
Here it is worth pausing on a neutral concept that the evidence supports: the retest, that is, testing the person again weeks later with an equivalent but different lure, to tell whether their behavior truly changed or they just remembered that one email.
That nuance is not minor. Peer-reviewed studies published at the IEEE Symposium on Security and Privacy (Ho et al., 2025; Lain et al., 2022) found that completing a training does not, on its own, predict a reduction in real failures. What proves the change is not the course certificate or the click rate of a single campaign, it is testing the behavior again and seeing whether it improved. Against phishing that is being industrialized, measuring course completion is measuring what does not change the outcome.
This is the front we work on at Fensivo: we prepare people's behavior against email phishing with personalized simulations, we deliver the training at the moment of failure and we validate with retest that behavior changed, not just that the course was completed, all within a human risk management (HRM) approach built for companies of 25 to 500 employees. You can see how it applies in the use cases. It is not about detecting the attacker's infrastructure, but about their email, however good it is, meeting a person who is prepared.
Do you know today whether your team would recognize the next well-made lure, or do you only know how many finished the last course?
Sources and references
- CISA, "4 Things You Can Do To Keep Yourself Cyber Safe": https://www.cisa.gov/news-events/news/4-things-you-can-do-keep-yourself-cyber-safe
- Cisco, "The 90-5-5 Concept: Your Key to Solving Human Risk in Cybersecurity", 2025: https://blogs.cisco.com/security/the-90-5-5-concept-your-key-to-solving-human-risk-in-cybersecurity
- Microsoft, "Microsoft Digital Defense Report 2025": https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2025
- Ho, G. et al., "Understanding the Efficacy of Phishing Training in Practice", 2025 IEEE Symposium on Security and Privacy: https://ieeexplore.ieee.org/document/11023357
- Lain, D., Kostiainen, K. and Čapkun, S., "Phishing in Organizations: Findings from a Large-Scale and Long-Term Study", 2022 IEEE Symposium on Security and Privacy: https://ieeexplore.ieee.org/document/9833766
Human risk is managed automatically.
Turn human risk into your first line of defense.
Book a demoFree demo · 30 minutes · No commitment
