Review on Phishing Threat Advancement in Todays Digital Environments: Detection Techniques, Agents and Future Directions
DOI:
https://doi.org/10.33003/fjs-2026-1014-5671Keywords:
Artificial Intelligence, Cybersecurity, Deep Learning, Machine Learning, Phishing Detection, Phishing LinksAbstract
Phishing threats serve as a continuous advanced digital security threat which remains active throughout all contemporary online platforms. The researchers conducted a systematic review to study the historical development of phishing link attacks by analyzing 26 peer-reviewed studies that researchers published between 2020 and 2025. The review employs the PRISMA 2020 framework to evaluate phishing agents and attack strategies and detection methods and upcoming research paths which it establishes through evidence from IEEE and ACM and ScienceDirect and Scopus databases. The research shows artificial intelligence combined with social engineering methods and multi-channel delivery systems which include email and SMS and voice calls and social media platforms results in more sophisticated phishing attacks. The research establishes machine learning and deep learning techniques which include CNNs and RNNs and transformers and GCNs and multimodal models as the most effective methods to identify phishing URLs and emails because they achieve more than 95% accuracy across different research studies. The deployment of machine learning solutions encounters difficulties because adversarial attacks and domain adaptation issues and the need for standardized benchmarking datasets remain unresolved. The review establishes that future defense systems need to incorporate explainable AI together with adversarial-resilient models and cross-dataset standardization and multimodal architectures and human-centric training strategies for effective defense against upcoming phishing threats.
References
Alhogail, A., & Alsabih, A. (2021). Applying machine learning and natural language processing to detect phishing email. Computers & Security, 110, 102414. https://doi.org/10.1016/j.cose.2021.102414
Alkhalli, Z., Hewage, C., Nawaf, L., & Khan, I. (2021). Phishing attacks: A recent comprehensive study and a new anatomy. Frontiers in Computer Science, 563060. https://doi.org/10.3389/fcomp.2021.563060
Aslam, S., Aslam, H., Manzoor, A., Hui, C., & Rasool, A. (2023). AntiPhishStack: LSTM-based stacked generalization model for optimized phishing URL detection. Symmetry, 15(10), 1986. https://doi.org/10.3390/sym15101986
Birthriya, S. K., Ahlawat, P., & Jain, A. K. (2025). Detection and prevention of spear phishing attacks: A comprehensive survey. Computers & Security, 151, 104317. https://doi.org/10.1016/j.cose.2025.104317
Divakaran, D. M., & Oest, A. (2022). Phishing detection leveraging machine learning and deep learning: A review. IEEE Security & Privacy, 20(5), 86–95. https://doi.org/10.1109/MSEC.2022.3175225
Greco, F., Desolda, G., Buono, P., & Piccinno, A. (2025). Enhancing phishing defenses: The impact of timing and explanations in warnings for email clients. Computers in Human Behavior Reports, 93, 103982. https://doi.org/10.1016/j.chbr.2025.103982
Guddanti, D. S., Chiramdasu, R., & Uppuluri, M. G. (2025). A multi-algorithm approach for phishing uniform resource locator's detection. IAES International Journal of Artificial Intelligence, 14(1), 358–367. https://doi.org/10.11591/ijai.v14.i1.pp358-367
Gupta, B. B., Yadav, K., Razzak, I., Psannis, K., Castiglione, A., & Chang, X. (2021). A novel approach for phishing URLs detection using lexical based machine learning in a real-time environment. Computer Communications, 175, 47–57. https://doi.org/10.1016/j.comcom.2021.04.023
Hannousse, A., & Yahiouche, S. (2020). Towards benchmark datasets for machine learning based website phishing detection: An experimental study. Mendeley Data, V2. https://doi.org/10.17632/c2gw7fy2j4.2
Hao, W., et al. (2024). Study on AI-generated spam emails. Columbia University.
Haq, Q. E. U., Faheem, M. H., & Ahmad, I. (2024). Detecting phishing URLs based on a deep learning approach to prevent cyber-attacks. Applied Sciences, 14(22), 10086. https://doi.org/10.3390/app142210086
Li, W., Manickam, S., Chong, Y.-W., Leng, W., & Nanda, P. (2024). A state-of-the-art review on phishing website detection techniques. IEEE Access, 12, 3514972. https://doi.org/10.1109/ACCESS.2024.3514972
Li, Y., et al. (2024). Quantifying the multidimensional impact of cyber-attacks in digital financial services: A systematic literature review. IEEE Access.
Maneriker, P., Stokes, J. W., Lazo, E. G., Carutasu, D., Tajaddodianfar, F., & Gururajan, A. (2020). URLTran: Improving phishing URL detection using transformers. In 2020 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP) (pp. 2927–2931). IEEE. https://doi.org/10.1109/ICASSP40776.2020.9052978
Mouncey, E., & Ciobotaru, S. (2025). Phishing scams on social media: An evaluation of cyber awareness education on impact and effectiveness. Journal of Economic Criminology, 7, 100125. https://doi.org/10.1016/j.jeconc.2025.100125
Nadeem, M., Zahra, S. W., Abbasi, M. N., Arshad, A., Riaz, S., & Ahmed, W. (2023). Phishing attack, its detections and prevention techniques. International Journal of Wireless Security and Networks, 1(2), 13–25.
Page, M. J., McKenzie, J. E., Bossuyt, P. M., Boutron, I., Hoffmann, T. C., Mulrow, C. D., Shamseer, L., Tetzlaff, J. M., Akl, E. A., Brennan, S. E., Chou, R., Glanville, J., Grimshaw, J. M., Hróbjartsson, A., Lalu, M. M., Li, T., Loder, E. W., Mayo-Wilson, E., McDonald, S., McGuinness, L. A., Stewart, L. A., Thomas, J., Tricco, A. C., Welch, V. A., Whiting, P., & Moher, D. (2021). The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ, 372, n71. https://doi.org/10.1136/bmj.n71
Ramesh, G., Lokitha, R. B., Monisha, R. R., & Neha, N. S. (2023). Phishing detection system using random forest algorithm. International Journal for Research Trends and Innovation, 8(4), 511–513.
Rashid, F., Doyle, B., Han, S. C., & Seneviratne, S. (2024). Phishing URL detection generalisation using unsupervised domain adaptation. Computer Networks, 245, 110398. https://doi.org/10.1016/j.comnet.2024.110398
Shuaibu, H. T., Adewumi, S. E., & Yemi-Peters, V. I. (2025). Phishing detection in social media platforms using machine learning. FUDMA Journal of Sciences, 9(11), 435–440. https://doi.org/10.33003/fjs-2025-0911-3944
Taha, M. A., Jabar, H. D. A., & Mohammed, W. K. (2024). A machine learning algorithm for detecting phishing websites: A comparative study. Iraqi Journal for Computer Science and Mathematics, 5(3), 275–286. https://doi.org/10.52866/ijcsm.2024.05.03.015
Tian, Y., Zhang, Y., Jia, Y., Sun, J., & Wang, Y. (2025). WebGuard++: Interpretable malicious URL detection via bidirectional fusion of HTML subgraphs and multi-scale convolutional BERT. arXiv. https://arxiv.org/abs/2506.19356
Uddin, M. A., & Sarker, I. H. (2024). An explainable transformer-based model for phishing email detection: A large language model approach. arXiv. https://arxiv.org/abs/2402.13871
Wiemken, M., Jeworutzki, A., Hildebrandt, K., & Putzar, L. (2025). Emotional manipulation in phishing emails: Experimental study of affective responses and human classification errors in a simulated email environment. In Proceedings of the 18th ACM International Conference on PErvasive Technologies Related to Assistive Environments (PETRA '25) (pp. 583–589). Association for Computing Machinery. https://doi.org/10.1145/3733155.3736796
Yamin, M. M., Ullah, M., Ullah, H., & Katt, B. (2021). Weaponized AI for cyber attacks. Journal of Information Security and Applications, 57, 102722. https://doi.org/10.1016/j.jisa.2020.102722
Zhou, J., Cui, H., Li, X., Yang, W., & Wu, X. (2023). A novel phishing website detection model based on LightGBM and domain name features. Symmetry, 15(1), 180. https://doi.org/10.3390/sym15010180
Downloads
Published
Issue
Section
Categories
License
Copyright (c) 2026 Dauda Buhari, Idris Ismaila, Moses Noel Dogonyaro, Suleiman Ahmad

This work is licensed under a Creative Commons Attribution 4.0 International License.