Carbuki Insights

Phishing Just Got Perfect Grammar. The Bigger Change Is That It Moved to Your Phone Room.

August 5, 2026

Verizon 2026 DBIR: how often the human layer shows up in breaches
Human element involved62%Social engineering breaches16%Pretexting as initial access(new category)6%

Share of confirmed breaches in the 2026 Verizon Data Breach Investigations Report, which analyzed more than 22,000 confirmed breaches across 145 countries. Pretexting - live, synchronous impersonation, most often by phone - was tracked as its own initial access vector for the first time this year.

The tell everyone was trained on just stopped working

For years, security training at a dealership came down to a short list of tells: broken English, a generic greeting, a misspelled domain, a demand that felt oddly urgent. It was a decent heuristic, and it made spotting a fake feel like proofreading.

On August 4, CDK Global's chief information security officer, Sergey Tsygalnitsky, published a short note arguing that the heuristic is finished. Criminals now use generative models to produce grammatically perfect messages, and they use the same tools to scrape public sources so the message can reference a real job title, a recent piece of company news, or a vendor a store actually works with. His instruction to retrain on: perfect grammar no longer means safe.

That is a software vendor telling its customers to be careful, and it should be read with the source in mind. But two independent datasets published earlier this year say the same thing with harder numbers - and they add a detail the email-centric framing misses. The fastest-growing version of this attack is not arriving in an inbox at all. It is arriving on the phone.

The myth: AI-driven fraud is an email problem, and the answer is a better spam filter.

The data: In the 2026 Verizon Data Breach Investigations Report, 41% of social engineering breaches used vectors other than email, and voice and text simulations produced a median click rate roughly 40% higher than email simulations. Verizon also added pretexting - live, synchronous impersonation, most often by phone - as its own tracked initial access vector, appearing in about 6% of breaches.

Source: Verizon 2026 DBIR.

What the FBI counted for the first time

The FBI's Internet Crime Complaint Center released its 2025 Internet Crime Report in May 2026, and two findings matter for anyone running a retail business with a phone room attached.

First, the scale. IC3 logged 1,008,597 complaints, the most in its 25-year history, and reported losses of roughly $20.9 billion - a 26% increase over the previous record. Phishing and spoofing remained the single most reported crime type at 19% of complaints. Business email compromise, the category that covers an employee being talked into sending money or credentials to the wrong place, accounted for $3.05 billion by itself.

Second, and more telling: AI-enabled crime appeared as its own category for the first time. It arrived at 22,364 complaints and $893.3 million in reported losses. That is a first-year tally for something that did not exist as a measurement twelve months earlier.

FBI IC3, 2025 Internet Crime ReportFigure
Total complaints1,008,597 (record)
Total reported lossesabout $20.9 billion, up 26%
Business email compromise losses$3.05 billion
Investment fraud losses$8.65 billion
Phishing and spoofing, share of complaints19% (most reported)
AI-enabled crime, first year tracked22,364 complaints / $893.3 million

Source: FBI Internet Crime Complaint Center, 2025 Internet Crime Report, released May 2026.

Verizon moved the attack out of the inbox

The Verizon Data Breach Investigations Report is the closest thing the security field has to an industry census. The 2026 edition, its nineteenth, analyzed more than 31,000 incidents and over 22,000 confirmed breaches across 145 countries.

Its headline number is familiar: the human element was present in 62% of breaches, up from 60% a year earlier. Social engineering held its place as the third most common breach pattern at 16%. A decade of awareness training has not bent that line downward.

What is new is the taxonomy. For the first time, Verizon broke out pretexting as its own initial access vector, at roughly 6% of breaches, and it was explicit about why: a meaningful number of high-profile ransomware breaches in this year's data began with pretexting rather than a link. The distinction is not academic. Phishing is asynchronous - a message lands, someone clicks, the attacker moves on. Pretexting is synchronous. There is a person, or a convincing imitation of one, on the other end of a live call, adapting in real time and applying pressure.

The channel data lines up. Email phishing simulations across the industry now sit near a 1.4% median click rate, a genuinely impressive result after years of training investment. Voice and text simulations sit near 2% - about 40% higher for what is functionally the same attack delivered differently. Verizon itself flagged the small sample size on voice and text simulations, which is the point: almost nobody is measuring the channel where attackers are gaining ground.

Two other findings from the same report are worth a manager's attention. Vulnerability exploitation overtook stolen credentials as the most common initial access vector for the first time in the report's history, and third-party involvement in breaches rose about 60% year over year to nearly half of all breaches - a reminder that your software stack is part of your exposure, which we covered in what to ask your AI vendors.

Why a dealership is an unusually good target

Most coverage of pretexting focuses on corporate IT help desks. A car store has the same shape of vulnerability, arguably worse, for four reasons.

The phone is a primary business channel, not a legacy one. CDK's survey data puts 47% of sales appointments and 61% of service appointments as booked by phone. A dealership answers a high volume of calls from strangers as a matter of routine. The baseline is that unknown callers are normal.

The room is trained for speed. Average dealership service hold time runs about 9.3 minutes, and 29% of service shoppers report difficulty scheduling by phone. When the queue is backed up, staff move fast and skip steps - which is exactly the condition pretexting is designed to exploit. The cost of a slow phone is usually discussed as lost appointments; it is also a security condition.

The data is high value. F&I holds credit applications, Social Security numbers, and bank details. Dealers are already covered entities under the FTC Safeguards Rule, so a successful pretext is not only a loss - it is potentially a reportable one.

Real money moves by phone and email. Vehicle purchases, floorplan, vendor payments. A changed set of wire instructions that arrives in a well-written message from a familiar-sounding vendor is the classic business email compromise pattern, and it is now available with a matching voice.

Put plainly: everyone in the building is trained to be helpful, fast, and accommodating with strangers. Pretexting weaponizes precisely those instincts.

The control that still works is a process, not a product

The useful thing about both the CDK guidance and the Verizon findings is that they converge on the same countermeasure, and it is not a detection tool. It is a rule that does not require anyone to successfully spot a fake.

Out-of-band verification means that any request involving money, credentials, or customer data gets confirmed through a channel the requester did not choose. Not a reply. Not the number in the signature. The number already on file.

Request arriving by phone, email, or chatRule before anyone acts
A vendor says its bank or wire details have changedCall back on the number already in your records, never the one in the message
Someone claiming to be an owner or GM requests an urgent transferA second named approver confirms in person or on a known number
A caller asks staff to read back customer or credit informationVerify the caller against the record first; never volunteer data to confirm identity
A caller claims to be IT and needs a password reset or remote sessionReset and remote-access requests go through one known internal channel only
Anything framed as urgent with a deadline attachedTreat the urgency itself as the flag and slow the process down

This is a process framework, not survey data. What the research supports is the underlying principle: the defense that holds is procedural, because the detection cue people were trained on no longer exists.

Where an AI phone layer helps, and where it does not

We build AI voice agents, so the honest version of this section matters more than the flattering one.

Three things a well-built phone layer genuinely helps with. It applies the rule the same way every time, which humans under queue pressure do not. It produces a complete, searchable record of every call - transcripts, timestamps, what was asked and what was released - which is the difference between reconstructing an incident and guessing at it. And it removes the hold-time pressure that pushes a busy advisor to skip a verification step to clear the queue.

Three things it does not do. It is not identity verification; answering a call is not the same as confirming who is on it, and any serious deployment should treat identity as a separate control. It is not immune to manipulation itself - getting a language model to step outside its instructions is an active area of research, not a solved problem, which is why scoping and clean human handoff matter more than breadth of capability. And it does not resolve the harder second-order problem: as more legitimate dealer outreach becomes AI-placed, customers lose their own ability to tell a real dealership call from a fake one. That is an argument for disclosure discipline and consent hygiene, not against automation - a subject we covered in AI calling and TCPA compliance.

Five changes worth making this month

  1. Write the out-of-band rule down and post it in the BDC, service drive, and business office. A rule that lives in a manager's head does not survive a busy Saturday.
  2. Name who can move money, and require two of them. Dual approval on wires and vendor payment changes stops both the scripted caller and the deepfaked one, because it does not depend on detecting either.
  3. Lock vendor banking changes to a callback on file. This single control addresses the most expensive category in the FBI's data.
  4. Rehearse a voice scenario, not just an email one. Verizon's own report notes that voice and text simulation is rare enough that the sample size is thin. If your training is email-only, you are drilling the channel that already works.
  5. Confirm your phone system actually logs. If you cannot pull what was said on a given call last Tuesday, you have no way to investigate, coach, or prove what happened.

The measured read

Nothing in this data says a dealership is about to be targeted tomorrow. The IC3 report does not break out auto retail, and the DBIR's pretexting figure is a first-year measurement that will likely be revised as reporting improves. Anyone selling you urgency on this topic is doing the same thing the attackers do.

What the data does support is narrower and more useful. The signal people were trained to look for is gone. The attack is moving toward the channel that dealerships use most and measure least. And the defense that survives contact with a good impersonation is a procedural one - written down, applied consistently, and not dependent on any employee's ability to detect a convincing fake at 4:45 on a Friday.

That is the same conclusion this blog keeps arriving at from the revenue side, in speed versus satisfaction and elsewhere: the phone is the least instrumented part of most stores. It turns out that is true for risk as well as for gross.


If you are thinking about how a dealership's phones should work - who gets answered, what gets logged, and what a system should never do without a human - that is the conversation we have every day at Carbuki. We build AI voice agents for U.S. dealerships, and we are happy to pressure-test the idea against your own process.

Sources

  • CDK Global, "Phishing Has Evolved: How Cybercriminals Are Using AI and How You Can Fight Back" (Sergey Tsygalnitsky, CISO), August 4, 2026: https://www.cdkglobal.com/insights/phishing-has-evolved-how-cybercriminals-are-using-ai-and-how-you-can-fight-back
  • FBI Internet Crime Complaint Center, 2025 Internet Crime Report (released May 2026): https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
  • dmarcian, "2025 Internet Crime Report: Nearly $21 Billion Lost" (complaint, loss, BEC and AI-category figures from the IC3 report), May 21, 2026: https://dmarcian.com/fbi-internet-crime-report-2025/
  • Verizon, 2026 Data Breach Investigations Report: https://www.verizon.com/business/resources/reports/dbir/
  • Help Net Security, "Verizon DBIR: Vulnerability exploitation is the dominant initial access vector," May 20, 2026: https://www.helpnetsecurity.com/2026/05/20/verizon-2026-dbir-findings/
  • Breacher.ai, "Verizon DBIR 2026: Social Engineering Findings and Analysis" (DBIR human-element, social engineering, pretexting and click-rate figures; note this vendor also sells social engineering simulation), May 27, 2026: https://breacher.ai/blog/verizon-dbir-2026-social-engineering/
  • CDK Global, "Missed Dealership Phone Calls Are Costing You Customers" (47% of sales and 61% of service appointments booked by phone; 29% difficulty scheduling; 9.3-minute average service hold), July 28, 2026: https://www.cdkglobal.com/insights/missed-dealership-phone-calls-are-costing-you-customers
  • CBT News, "CDK finds phone friction persists at dealerships as AI adoption grows," August 3, 2026: https://www.cbtnews.com/cdk-finds-phone-friction-persists/

Carbuki builds AI voice agents for retail automotive — answering sales and service calls, following up on leads, and booking appointments 24/7 in multiple languages.

See how it works →
Share:XLinkedInFacebookRedditEmail

← All articles