Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI phishing at scale: are human defenses keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: SpamGPT illustrates how AI-generated phishing can industrialize deception by producing polished, context-aware lures at scale, shifting the security contest from human vigilance to automated detection and response according to Appknox. The implication is that phishing resilience now depends on layered controls, offensive testing, and mobile-channel hardening rather than awareness training alone.

NHIMG editorial — based on content published by Appknox: AI vs. Human: What SpamGPT Means for the Future of Security

Questions worth separating out

Q: How should security teams respond to AI-generated phishing campaigns?

A: Security teams should assume the message quality will be good enough to fool users and focus on reducing what a successful click can do.

Q: Why does AI-driven phishing change identity security decisions?

A: It lowers the reliability of human judgment in routine trust checks, which means organisations need stronger process controls.

Q: What breaks when phishing moves from email to mobile apps and notifications?

A: Desktop assumptions break first.

Practitioner guidance

  • Harden identity checks at the point of action Require step-up authentication for sensitive approvals, password resets, and session changes when messages or prompts originate from untrusted channels.
  • Extend phishing controls to mobile channels Add mobile threat defense, app reputation checks, and anti-tamper controls for users who receive SMS, push, or in-app prompts.
  • Test controls against personalised lure variation Run red-team exercises that generate many phishing variants across email, SMS, and app prompts, then measure which detections still fire.

What's in the full article

Appknox's full blog covers the mobile and offensive security detail this post intentionally leaves for the source:

  • Examples of how AI-generated phishing pressure extends into SMS, app-store listings, and in-app prompts.
  • The article's summary table linking threat vectors to response strategies across email, smishing, app phishing, and in-app deception.
  • Appknox's view on offensive security testing, including penetration testing and red teaming as validation methods.
  • The broader framing for mobile app security teams that need to harden user journeys against AI-scale lure variation.

👉 Read Appknox's analysis of SpamGPT and AI phishing risks →

AI phishing at scale: are human defenses keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

AI phishing is now an identity governance problem, not just a user-awareness problem. The article is right to frame SpamGPT as a shift in attacker economics, but the more important change is governance. Identity programmes were built to inspect credentials, sessions, and approvals under the assumption that the person on the other end could be coached into better judgement. AI-driven deception reduces the reliability of that assumption. Practitioners should treat phishing resilience as part of identity control design, not a communications exercise.

A question worth separating out:

Q: Who is accountable when AI-accelerated phishing leads to an identity breach?

A: Accountability should sit with the teams that own identity governance, privileged access, and incident containment, not only with security awareness programmes. AI makes phishing faster, but it is the organisation's access design that determines how far stolen credentials can go. If access is broad and durable, governance gaps become breach multipliers.

👉 Read our full editorial: SpamGPT shows why AI phishing now outpaces human defenses



   
ReplyQuote
Share: