Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI-powered phishing threats: are your email controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: AI-driven, payload-less phishing and account takeover attacks can bypass secure email gateways, while AI-native cloud email security and automated incident response improve intent detection, context, and response speed, according to KnowBe4. The governing issue is not detection volume but whether identity, email, and response controls can contain trusted-account abuse before it spreads.

NHIMG editorial — based on content published by KnowBe4: Closing the Gap in Email Security: How to Stop the 7 Most Sinister AI-Powered Phishing Threats

By the numbers:

  • Nearly 10% of employees have admitted to sending work emails to their personal accounts, according to KnowBe4 research.

Questions worth separating out

Q: What breaks when AI-powered phishing reaches a trusted mailbox?

A: Once attackers use a trusted mailbox, many email gateway controls lose effectiveness because the message source now looks legitimate.

Q: Why do AI phishing attacks create more risk than traditional phishing?

A: AI lowers the cost, time, and skill needed to produce personalised lures, so attackers can run more campaigns and iterate faster.

Q: How can teams tell whether phishing controls are actually working?

A: Look for fewer successful credential submissions on lookalike domains, lower password reuse, and faster reporting of suspicious messages.

Practitioner guidance

  • Link phishing response to identity telemetry Correlate suspicious mail, unusual sign-ins, inbox rule changes, token abuse, and privilege escalation so a phishing alert can trigger identity containment instead of isolated email triage.
  • Baseline trusted-account behaviour Track normal sender patterns, reply chains, forwarding behaviour, and login geography for privileged and high-risk mailboxes.
  • Automate campaign-wide quarantine Remove malicious messages from all affected inboxes as soon as the campaign is confirmed, not only from the reporting user’s mailbox.

What's in the full article

KnowBe4's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • A fuller breakdown of how AI-native cloud email security uses NLP and behavioural signals to detect intent-based phishing.
  • Step-by-step examples of anti-phishing incident response workflows, including enrichment, quarantine, and campaign correlation.
  • A comparison of traditional controls such as SEGs, SPF, DKIM, and DMARC against modern payload-less attacks.
  • The integrated approach section with product-category level implementation detail for SecOps and IT teams.

👉 Read KnowBe4's whitepaper on AI-powered phishing threats and email defence →

AI-powered phishing threats: are your email controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

AI-powered phishing is now an identity governance problem, not only an email security problem. The article shows that the decisive control gap is not whether an email looks malicious in the inbox, but whether the organisation can recognise when a trusted identity is being abused. That has implications for IAM, PAM, and NHI programmes because compromised accounts and delegated access can be used as delivery mechanisms for fraud, lateral phishing, and data theft. The practitioner conclusion is simple: email defence must be linked to identity telemetry and access governance.

A question worth separating out:

Q: Who is accountable when browser-based phishing leads to account takeover?

A: Accountability usually spans identity security, endpoint protection, and the business owners of high-value accounts such as advertising platforms. The practical answer is to define who owns browser-based authentication risk, who monitors suspicious redirects, and who can revoke access or sessions immediately.

👉 Read our full editorial: AI-powered phishing is outpacing legacy email security controls



   
ReplyQuote
Share: