Phishing-as-a-Service: The Fuel Driving the Spread of Email Phishing — How It Became Available to Everyone
A Lebanese tech outlet explains how the Phishing-as-a-Service (PhaaS) criminal model lets low-skill attackers launch convincing data-theft campaigns, aided by AI-generated messages.
Intelligence analysis by Llama

Annahar walks readers through the rise of Phishing-as-a-Service, a crimeware rental model that bundles ready-made fake login pages, email templates, hosting, and target lists, lowering the technical bar for launching phishing campaigns and amplifying the volume of attacks.
Bad guys used to need special computer skills to trick people into giving up passwords. Now they can just buy ready-made phishing toolkits — fake website copies, scam email templates, even customer support — the same way you might buy a game starter pack. AI helps them write cleaner messages too, so spotting a scam by bad spelling no longer works.
Analysis
From Malware to Data Theft
The article frames a quiet shift in criminal priorities: attackers increasingly chase user data rather than compromising devices outright. Stolen passwords, banking details, and sensitive personal information can unlock funds, accounts, or become leverage for extortion. Phishing, the piece notes, is the primary delivery mechanism — an engine of social engineering that uses SMS, email, voice calls, fake websites, or malicious apps to lure victims into surrendering credentials. The fishing metaphor runs through the report: the user is the target, and the bait is the message, link, or spoofed page.
Phishing-as-a-Service as a Subscription Crime
The core of the report is the emergence of Phishing-as-a-Service, or PhaaS, a crimeware business model that mirrors legitimate SaaS distribution. Instead of building tooling from scratch, attackers can now purchase bundles that include fake login pages mimicking trusted brands, professional email templates, phishing-site hosting, curated target lists, setup guides, and even technical support. According to Annahar, this industrialization has the same effect it has had in every other software market — it collapses the skill floor required to operate. Campaigns that once required advanced expertise can now be launched by novices, multiplying both the volume and the variety of phishing attempts in circulation.
AI Raises the Cost of Being Wrong
A second accelerant the article highlights is generative AI. Traditional giveaways — broken grammar, awkward spelling — are no longer reliable signals because AI tools can produce polished, contextually appropriate phishing copy in seconds. The report stresses that this makes urgency the attacker's most reliable lever: most phishing still succeeds by pressuring the victim to act before they think. Defensive advice in the piece is therefore deliberately low-tech — pause before responding, verify links before clicking, type sensitive URLs directly, treat urgent money or password requests with suspicion, avoid unexpected attachments, and keep operating systems and browsers patched. Modern browsers and antivirus products block many malicious destinations, the outlet notes, but they cannot replace user vigilance.
Key points
- Phishing now targets user data — passwords, banking details, identity — rather than just compromising devices.
- Phishing-as-a-Service (PhaaS) sells ready-made attack kits including fake login pages, email templates, hosting, target lists, and setup guides, with some vendors offering support.
- The PhaaS model lowers the technical skill required to run convincing campaigns, multiplying the number of active attackers.
- Generative AI removes traditional phishing red flags such as poor grammar, making fraudulent messages harder to detect at a glance.
- Basic defenses remain unchanged: pause before clicking, verify URLs, type sensitive addresses manually, treat urgent requests with suspicion, and keep software updated.
Wider reporting on PhaaS, like this piece, helps raise user awareness across the Arab world that polished messages can still be scams. Continued investment in browser-level phishing protection and authentication standards such as passkeys could erode the effectiveness of even well-crafted lure pages.
If PhaaS bundles continue to drop in price and AI-generated lures become indistinguishable from legitimate communications, phishing-driven credential theft and financial fraud could surge across markets with uneven digital-security training, compounding losses for individuals and banks alike.

