AI-driven phishing prompts email security firms to adopt generative AI
Generative AI is transforming phishing attacks from easily-identifiable nuisances into sophisticated, highly personalized threats that can be launched at scale. By automating the creation of polished emails with authentic branding and contextual details, GenAI has democratized phishing, putting the technique within reach of attackers with minimal expertise, dramatically increasing cybercrime losses.
According to the FBI, phishing now accounts for 26 per cent of all cybercrime complaints, with losses rising by 274 per cent in recent years. Where traditional email security could spot obvious red flags – poor grammar, misspelt words, suspicious attachments – modern AI-driven phishing eliminates these tells, creating emails that are technically clean and highly targeted. In response, defenders are developing AI-powered counter-solutions focused on contextual analysis and detecting unusual behavioural patterns rather than surface-level flaws.
- GenAI enables phishers to create thousands of perfectly targeted emails with minimal expertise
- FBI reports phishing losses up 274 per cent recently, now 26 per cent of all cybercrime complaints
- Defenders developing AI counter-solutions using contextual analysis instead of spotting obvious errors
New here? Start with this
Phishing is when criminals send fraudulent emails designed to trick people into revealing sensitive information or clicking harmful links. It has become a major problem, with the FBI reporting that phishing complaints now account for over a quarter of all cybercrime cases, and losses from phishing attacks have risen dramatically in recent years.
Generative artificial intelligence has made phishing attacks far more dangerous by automating the creation of convincing, personalised emails. Rather than relying on crude messages with obvious spelling mistakes or poor formatting, criminals can now use AI to produce polished emails that look authentic, include relevant details about targets, and can be deployed against thousands of people simultaneously.
Email security companies are fighting back by adopting artificial intelligence themselves, but with a different focus. Instead of looking for obvious red flags like grammatical errors, they are using AI to spot unusual patterns in people's email behaviour and to analyse the broader context of messages, making it harder for sophisticated phishing to slip through.
Read the full article at the source →
Originally published by The Register as “Fighting GenAI with GenAI: The New Email Security Landscape”.