Is AI making phishing attacks harder to detect for the average employee?
We’ve seen a surge in highly personalized phishing emails that don't have the typical "bad grammar" red flags. Is Generative AI being used by hackers to scale these attacks? How should we update our employee training to combat these more sophisticated social engineering tactics?
2025-11-12 in Cyber Security by Susan Nelson
| 14541 Views
All answers to this question.
Yes, GenAI is a massive force multiplier for attackers. Tools like ChatGPT (and their darker cousins on the deep web) allow hackers to write perfect English and mimic a specific executive's "voice" by analyzing their public posts or emails. We can no longer tell employees to look for typos. Training must now focus on "Context and Intent." If an email asks for an urgent wire transfer or a password reset, the employee should verify it through a second channel, like a quick Slack message or a phone call, regardless of how "real" the email looks.
Answered 2025-11-19 by Elizabeth Carter
Are you considering implementing FIDO2 security keys or other phishing-resistant MFA to take the pressure off the employees' ability to judge emails?
Answered 2025-11-21 by Richard Lewis
-
Phishing-resistant MFA is the only real solution. Even the smartest employee can be fooled on a busy Monday morning. If you use hardware keys, the password doesn't matter even if they "give it away" on a fake site. However, don't stop the training; people still need to be aware of "vishing" (voice AI) which is becoming a huge threat during Microsoft Teams or Zoom calls.
Commented 2025-11-23 by Brian King
We started using "AI-based" email filters that look for behavioral anomalies rather than just bad links. It's helped a lot in catching these spoofed messages.
Answered 2025-11-25 by Mary Green
-
Using AI to fight AI is definitely the future of defensive security. Those behavioral filters are becoming essential for any mid-to-large sized organization.
Commented 2025-11-27 by Susan Nelson
Write a Comment
Your email address will not be published. Required fields are marked (*)

