Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI-driven phishing: what it means for identity and email controls


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: AI has accelerated phishing by helping attackers bypass native defenses and secure email gateways, while Knowbe4 cites an average of 21 seconds to click a phishing link, 52% growth in attacks getting through SEGs, and 19% of phishes relying solely on social engineering. The practical issue is not just more volume, but faster credential capture that outpaces human review and conventional email controls.

NHIMG editorial — based on content published by Knowbe4: CISO Strategy Guide on social engineering in the age of AI

By the numbers:

Questions worth separating out

Q: What should security teams do when a phishing report includes a click or credential entry?

A: Treat the case as an identity incident, not just a mail event.

Q: Why do AI phishing attacks create more risk than traditional phishing?

A: AI lowers the cost, time, and skill needed to produce personalised lures, so attackers can run more campaigns and iterate faster.

Q: What breaks when users are the only verification control for high-risk requests?

A: Human review is inconsistent, especially under urgency, familiarity, or fatigue.

Practitioner guidance

  • Implement rapid credential invalidation workflows Automate session revocation, password reset, and MFA re-registration for users who report or trigger phishing indicators, then extend the same workflow to downstream tokens and delegated app access.
  • Add identity-centric detection to email controls Correlate suspicious login attempts, impossible travel, mailbox forwarding changes, and consent grants with phishing telemetry so the SOC can detect compromise even when the email itself looked benign.
  • Harden high-risk verification workflows Require out-of-band verification for password resets, payment approvals, and privilege changes, especially where help desks or internal chat channels are common attacker entry points.

What's in the full article

Knowbe4's full guide covers the operational detail this post intentionally leaves for the source:

  • Tactics for detecting advanced social-engineering phish targeting Microsoft 365 users
  • How AI changes bypass patterns against native defenses and secure email gateways
  • Practical examples of phishing content that relies on social engineering rather than malware
  • Guidance on recognising when user interaction becomes an identity incident

👉 Read Knowbe4's guide on AI-driven social engineering and phishing risk →

AI-driven phishing: what it means for identity and email controls?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

AI has not replaced phishing, it has made credential theft more scalable and more believable. The core problem is not novelty but throughput. Attackers can test language, timing, and pretexts faster than defenders can update filters or run awareness cycles. That means the unit of failure is no longer one bad email, but the speed at which identity controls are forced to respond. The practical conclusion is that phishing defence now needs to be measured as an identity containment problem, not only an email hygiene problem.

A question worth separating out:

Q: What should organisations prioritise after a phishing-led compromise, email cleanup or identity containment?

A: Identity containment first. Cleaning inboxes does not stop an attacker who already has a valid session, a token, or delegated access. Organisations should terminate sessions, revoke tokens, review privilege changes, and check for NHI exposure before they spend time on message remediation or training updates.

👉 Read our full editorial: AI-driven phishing is compressing the credential theft window



   
ReplyQuote
Share: