Old phishing was easy to spot: broken English, weird greetings, logos from 2003. AI-assisted phishing is polite, on-brand, and tailored to your LinkedIn headline. Filters still catch plenty, but the messages that reach humans look like work, not spam.
You do not need to reverse-engineer every model. You need a few tells that survive good grammar and a plausible story.
What AI changes in the inbox
Faster personalization at scale. Cleaner tone in your company’s language. Fake threads that reference real projects scraped from public posts. Variants A/B tested until one gets clicks.
What does not change: the ask. Sign in here. Approve this payment. Open this file. Call this number. AI polishes the wrapper; greed and urgency still drive the plot.
Tell 1: channel and domain mismatch
The mail reads like IT support but the link domain is two typos away from yours. AI fixed the prose; it did not give the attacker your real SSO domain. Hover every link on desktop; long-press on mobile. If the display text says microsoft.com and the target says ms-login-secure.net, stop.
Teach staff that perfect grammar does not mean trusted sender. Phishing training pairs well with common cybersecurity mistakes in small companies.
Tell 2: urgency that forbids verification
“Pay before the board call in ten minutes.” “Your mailbox will delete in one hour.” “Do not contact security, this is confidential.” AI loves crisp deadlines. Real internal teams accept delay for verification.
Policy counter: any urgent money or credential request gets a callback on a known number. No exceptions for polished writing.
Tell 3: login pages that feel almost right
AI helps clone layouts. Micro-copy may be off: wrong button label, odd footer, MFA step that your real IdP never uses. Passkeys reduce password typing on real sites; fake sites still try classic forms. Read passkeys instead of passwords for why typed secrets on the wrong domain stay dangerous.
Tell 4: attachments that want macros or “enable content”
Clean cover letter, malicious macro inside. Or a PDF that links out to a credential harvester. AI drafts the letter; malware delivery is old school.
Default deny on unexpected attachments. Use viewer mode. Ask the sender on a second channel if you were not expecting a file.
Tell 5: voice and video follow-ups
Email sets the hook; a call “from the CFO” closes it. Synthetic voice is the next beat after a perfect mail. If the story jumps channels and forbids checks, treat it as one campaign, not two coincidences. More on audio fraud in the same family as deepfakes in business.
Tell 6: too much public context, too little private proof
The mail mentions your conference talk and your manager’s name, both from LinkedIn. It does not reference the internal project code you never posted. Flattery and public facts replace secrets an real colleague would know.
Ask a question only an insider would answer. Real colleagues may find it odd; phishers often ghost.
What filters and IT should still do
SPF, DKIM, DMARC, quarantine external “CEO” display names, flag new domains, sandbox links. None of this is optional because AI exists; it matters more because volume rose.
Shadow tools increase paste risk of internal snippets into public bots, which can leak context attackers reuse. Tighten shadow AI policy alongside mail defense.
Habits for teams who live in email
Report phish with one click. Praise people who report near-misses, not only those who blocked attacks. Rotate short examples monthly; AI themes age in weeks.
For customer-facing teams, remember clients can be lured with fake “your vendor changed bank details” mail that copies your tone. Out-of-band confirmation protects both sides.
If you already clicked
Disconnect from network if you ran a file. Reset passwords from a clean device. Notify IT with the full header. Check forward rules and MFA devices for changes attackers add after first access.
AI-made phishing wins when shame hides incidents. Make reporting fast and blameless.
Bottom line
Spotting AI phishing is spotting the same scams with better prose. Train eyes on domains, asks, and verification habits, not on spelling mistakes. The next mail will read like your best employee. Make sure your process still slows money and credentials anyway.
Brak komentarzy:
Prześlij komentarz