How AI Is Making Phishing More Convincing—and Why Traditional Email Security Can Fall Short

· Original article ↗

Summary

The article explains how generative AI enables more convincing, personalized phishing and deepfakes, and outlines defenses including behavioral detection, phishing-resistant authentication, separate verification channels, and procedure-focused training.

Key points

  • The article describes the 2024 Arup fraud, in which an employee made 15 wire transfers totaling $25.6 million after a video call featuring AI-generated impersonations of executives and colleagues.
  • It cites Microsoft research reporting a 54% click-through rate for AI-generated phishing emails, compared with 12% for manually written phishing.
  • Generative AI and purpose-built tools can reduce the time and effort needed to create personalized phishing lures.
  • Compromised legitimate accounts, plausible requests without malicious links or attachments, and changing message patterns can make phishing harder for traditional filters to detect.
  • The article recommends behavioral detection, phishing-resistant MFA such as FIDO2 keys or passkeys, and independently initiated verification for financial requests.
  • It advises training employees to follow verification procedures and pause when requests create urgency, rather than relying mainly on spotting typos.

Article Details

Topic
AI-powered phishing: how generative AI enables more convincing and scalable social engineering, and recommended defenses.

People

Vendors

Products

Countries

Industries