Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI phishing and email fraud: what IT and SOC teams must change


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: AI-crafted phishing, deepfake impersonation, credential theft and MFA bypass are now standard social engineering tools, while IT and SOC teams struggle with alert overload and fragmented visibility, according to Knowbe4’s whitepaper. The core issue is that human-risk controls and incident response still lag attack speed, making identity-centric detection and response essential.

NHIMG editorial — based on content published by Knowbe4: The 9 Biggest Email and Social Engineering Challenges Facing IT and SOC

Questions worth separating out

Q: How should security teams reduce password risk when AI can scale phishing and impersonation?

A: Security teams should focus on removing reusable credentials from the identity path, not just adding stronger verification on top of them.

Q: Why do social engineering campaigns still succeed in mature enterprises?

A: They succeed because many controls focus on message content while attackers target human trust and business context.

Q: What do security teams get wrong about human risk management?

A: They often treat it as a training completion problem instead of a resilience problem.

Practitioner guidance

  • Strengthen request verification for high-risk actions Require separate verification paths for payment changes, credential resets, mailbox rule changes, and privileged requests so an email alone cannot authorise action.
  • Connect email alerts to identity containment Ensure suspicious email, phishing click, and account takeover signals trigger account suspension, session revocation, mailbox isolation, and credential reset in one workflow.
  • Use human-risk scores to drive control changes Link phishing simulation outcomes, risky behaviour, and repeat exposure to actual policy changes such as stepped-up authentication, tighter approvals, or role-based training.

What's in the full article

Knowbe4’s full whitepaper covers the operational detail this post intentionally leaves for the source:

  • Specific breakdowns of the nine social engineering challenges and how each maps to different defensive workflows.
  • Practical guidance on combining Security Awareness Training, Cloud Email Security, and Anti-Phishing Incident Response.
  • Examples of how to detect threats that traditional tools miss without overwhelming IT and SOC teams.
  • The vendor’s approach to quantifying human risk for reporting and decision-making.

👉 Read Knowbe4’s whitepaper on the nine email and social engineering challenges →

AI phishing and email fraud: what IT and SOC teams must change?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Email is becoming an identity governance problem, not just a content-filtering problem. The article reflects a wider shift in which phishing, quishing, and impersonation target the trust layer that IAM, help desks, and users all depend on. That makes human identity control, credential governance, and verification policy part of the same risk surface. Practitioners should treat email abuse as a trigger for identity response, not only mailbox cleanup.

A question worth separating out:

Q: How should organisations respond when an incident starts with stolen credentials?

A: Treat it as a containment race. Disable the account, invalidate sessions and tokens, check for privilege escalation, and verify whether the same identity can reach cloud, email, or administrative systems. Where service accounts exist, review them too, because a human compromise often exposes broader access paths.

👉 Read our full editorial: Email and social engineering now blend AI, deepfakes and MFA bypass



   
ReplyQuote
Share: