Why Phishing Defense Should Focus on Campaigns, Not Individual Emails

Summary
The article argues that AI-driven phishing makes individual indicators less reliable and recommends correlating emails at the campaign level, combining automated analysis, human review, employee reporting, and coordinated remediation.
Key points
- AI lets attackers rapidly vary phishing messages and infrastructure, making indicators such as URLs, file hashes, and sender reputation shorter-lived.
- Campaign-level analysis correlates infrastructure, behavior, delivery patterns, and attacker tactics to identify related messages and assess an attack's scope.
- Investigating a campaign as a whole can reduce duplicate analyst work and help teams remediate threats across affected mailboxes.
- Machine learning can cluster similar emails, enrich investigations, prioritize risk, and automate repetitive tasks; the article emphasizes human oversight to validate decisions.
- Employee reporting can provide early warning and intelligence about phishing that bypasses perimeter controls.
- The article recommends connecting training, reporting, investigation, and automated remediation in a continuous defense lifecycle.
Article Details
- Topic
- Campaign-level phishing defense for email security